What Penetration Testing Costs

Penetration testing is quoted per engagement, not per seat, and the range is wide because the word covers very different work — from an automated scan with a report on top, to a manual test by an experienced team.

What moves the price

Scope

Number of applications, external IP ranges, and whether internal network and cloud configuration are included. Scope is the single largest driver.

Depth

An automated scan with a written summary sits at the bottom of the range. Manual exploitation by experienced testers sits at the top, and the gap between them is large.

Retesting

Confirming that findings were actually fixed is sometimes included and sometimes billed again. Check which, because a report without retest closes nothing.

Compliance driver

Tests performed to satisfy SOC 2, PCI DSS, or a customer questionnaire have documentation requirements that add cost over an internally motivated test.

Common questions

Is a vulnerability scan the same thing?

No, though it is often sold as one. A scan enumerates known weaknesses automatically. A penetration test involves a human attempting to chain them into actual access. If a quote looks unusually cheap, this is normally the reason.

How often is it needed?

Annually is the common baseline, plus after any significant architectural change. Some frameworks and customer contracts specify the interval for you.

Who should we not buy it from?

Ideally not the provider that built and manages the environment being tested. Independence is the point of the exercise.

Related

Compare penetration testing providers · What a SOC 2 audit costs · Managed security providers