Skip to content
MD-5

// Pricing

Penetration testing pricing

What each kind of test usually costs and how long it takes. Your own price is worked out from your scope and agreed with you before any work starts. No hourly billing, no surprise invoices.

// Typical prices

What a test usually costs

Most of our quotes land in these ranges, in USD. Each one covers testing, the report, a readout call and a retest of your fixes.

Very small scopes can come in under these ranges, and large or complex ones above them. Combining tests, such as a web app and its API, usually costs less than buying them separately. For what the wider market charges, read how much a penetration test costs.

// Ways to work with us

Pick the engagement that fits

All three include the same testing, reporting and retest. They differ in how often we test and whose name is on the report.

Single engagement

A customer asked for a pentest, an audit is coming, or you’re shipping something big.

  • One price for the scope we agree with you
  • Retest of fixes within 30 days
  • Attestation letter for customers and auditors
Get a quote

Retainer

You ship often, or need testing evidence all year for SOC 2 Type II.

  • Quarterly or twice-yearly testing
  • Lower price per test than one-off engagements
  • Retests between cycles included
Discuss a retainer

Partner (white-label)

You’re an agency, MSP or dev shop whose clients ask for security testing.

  • Reports in your branding
  • Partner rates on every engagement
  • No direct contact with your clients unless you want it
Ask about partnering

// Quoting

From first message to agreed price

  1. 01

    Tell us what needs testing

    Through the form or a 20‑minute call. Add your budget if you have one; it helps us scope honestly.

  2. 02

    Scoping

    We confirm targets, user roles, environments and dates. An NDA is signed first if you need one.

  3. 03

    Written proposal

    A written quote with the scope, the number of testing days, what’s excluded and the dates. Want something changed? We adjust it with you before you sign. After that, the price only moves if the scope does.

  4. 04

    Sign and schedule

    Statement of work and authorization signed, testing window booked. Payment: 50% to book the testing window, 50% on report delivery.

// Included

Included in every engagement

No add-ons for the things that should be standard.

  • Scoping call and written rules of engagement
  • Hands-on testing by a certified tester, every finding verified
  • Same-day notice of any critical finding
  • Executive summary and detailed technical findings
  • CVSS severity, evidence and reproduction steps
  • Stack-specific remediation guidance
  • Readout call with your team
  • Free retest within 30 days
  • Letter of attestation
  • NDA on request

// What affects price

What drives the quote

The number of days a thorough test needs comes down to four things.

Size of the target

Number of pages and features, API endpoints, or IP addresses in scope.

User roles

Each role (admin, member, viewer, tenant) multiplies the access-control checks.

Complexity

Payment flows, multi-tenancy, file processing and third-party integrations take longer to test properly.

Testing constraints

Production-only testing, narrow windows or on-site work add coordination time.

// FAQ

Pricing questions

Why a range and not a fixed price per test?

Because a five-page marketing site and a multi-tenant SaaS platform are both “a web app test”, but not the same job. One fixed price would either overcharge the small one or under-test the large one. The ranges show where most scopes land; your quote is worked out from your targets, user roles and constraints, and agreed with you before any work starts.

Can a quote fall outside the range?

Yes. A single small app or a handful of hosts can come in below it, and large or unusually complex scopes above it. If yours is outside the range, the proposal says why, in terms of days and what they cover.

Can you work to a set budget?

Yes. Tell us the number and we’ll scope a test that fits it, starting with the areas that carry the most risk, and say plainly what’s left out. If the budget can’t buy a meaningful test, we’ll tell you that too, and suggest a vulnerability assessment instead.

Is the quote negotiable?

Yes, through the scope. If the number is more than you planned, we can test the highest-risk areas first, cover fewer roles or environments, split the work into phases, or combine tests into one engagement, which usually costs less than separate ones. What we won’t do is keep the scope and cut the testing days, because that’s how findings get missed.

How fast will I get a price?

You’ll hear back within one business day. Most quotes follow within a day or two of the scoping call, once targets and roles are clear.

What are the payment terms?

50% to book the testing window, 50% on report delivery. Invoices can be paid by bank transfer or card.

How do you compare on cost with large security firms?

We’re usually well below them for the same scope. No sales team, account managers or office overheads: you pay for the days spent testing and reporting, not for the layers around them.