How much does a pentest cost: what drives the price and how not to overpay

2026-09-04

"How much does a pentest cost" has no short answer, because anything gets called a pentest: from a three-day automated scan to a month of manual work by a certified team. Here is what actually drives the price, where the line between a scan and a pentest runs, and how to get a quote that shows what you are paying for.

What determines the price

Pentest cost is almost always expert person-days multiplied by scope. Four things drive the volume of work:

  • Scope: how many hosts in the external perimeter, how many web apps and APIs, how many roles in each. One application with three roles means several times more scenarios than the same application with one.
  • Format: black box (the tester only knows the address), grey box (accounts and documentation provided) or white box (source code provided). Grey box is usually the best depth-per-budget ratio: time goes into finding vulnerabilities, not reconnaissance.
  • Depth: perimeter and typical attacks only — or business logic, vulnerability chains, escalation to sensitive data. Logic flaws are only found manually, and they produce the most expensive findings for the business.
  • Retest: re-verification of fixes after the report. If the retest is not included in the price, it is a separate invoice — ask upfront. We include it in every package.

Why a cheap pentest ends up expensive

The market is full of "pentest" offers priced below a single week of qualified work. Inside it is almost always the same thing: an automated scanner, a report generated from its export, and a couple of screenshots. Such a report satisfies a formal requirement but does not answer the main question — what an attacker can actually do to your infrastructure.

How to tell a scan from a pentest: the report has no reproducible PoCs, every vulnerability comes from a scanner database (software versions, headers, TLS), there is not a single business logic finding, and no "vulnerability → access → data" chains. If you need a checkbox, a scan is cheaper. If you need to know how you will be breached, you need manual work.

Work formats: from perimeter to infrastructure

We packaged typical engagements into three tiers: S — external perimeter (from $3,300, ~3 weeks), M — perimeter plus internal infrastructure (from $6,900, ~4–5 weeks), L — comprehensive work: perimeter, applications, infrastructure and Kubernetes (from $12,500). Pricing is per unit of scope — one application, one perimeter; a project with several targets is the sum of its units. Scope, timeline and report contents are fixed before work starts — the price does not change mid-project.

A separate track is GenAI Security: if your product has an LLM bot, RAG or an agent, a classic pentest does not cover that attack surface. You can start with a free express assessment.

How to order: from brief to report

  • Brief: a short form — what the product is, how many hosts/apps/roles, what access format you can provide.
  • Quote in 24 hours: fixed scope, timeline and price. No "let's discuss your budget" calls.
  • NDA and rules of engagement: agreement signed, testing windows and prohibited actions agreed.
  • Testing: attacks are performed manually, every finding is documented with a reproducible PoC.
  • Report and debrief: findings with risk levels and fix priorities, a call with your engineering team.
  • Retest: after fixes we re-verify the closed findings — included in the price.

FAQ

How long does a pentest take?
External perimeter — usually 1–2 weeks, a web application or API with a role model — 2–3 weeks, comprehensive engagements with internal infrastructure — from a month. The exact timeline is fixed in the quote.
Will a pentest take down production?
No. Destructive checks (DoS, mass data modification) are excluded by default and possible only by separate agreement on a staging environment. Testing windows and prohibited actions are fixed before the start.
Do we need a pentest if we already run a vulnerability scanner?
They solve different problems. A scanner finds known vulnerabilities in software versions; a pentest finds what a scanner cannot see at all: logic, access control, attack chains. Mature practice: scanner continuously, pentest 1–2 times a year and after major releases.
What are the price anchors?
Packages: external perimeter — from $3,300, perimeter + internal infrastructure — from $6,900, full-scope audit — from $12,500. Per unit: web application pentest (grey box) — $2,800–6,900, API up to 50 endpoints — $1,900–5,000, infrastructure up to 50 hosts — $4,200–9,700, GenAI pentest of LLMs and agents — $3,600–9,000. White box +30%, rush (deadline under 3 weeks) +15%. The exact price is fixed in the quote after a brief and does not change mid-project.
Pentest quote in 24 hours

Fill in a short brief — we return a fixed quote: scope, timeline, price. Retest included, the price does not change mid-project.

Get a quote