HackproofHacks
Pricing guide

How Much Does a Penetration Test Cost?

Most small-to-mid-size penetration tests cost between $4,000 and $20,000. A single web application typically runs $4,000-$12,000, an API test $5,000-$12,000, and a compliance-driven test (SOC 2, PCI DSS, HIPAA) usually lands at $6,000-$20,000+ because of the extra evidence and reporting an auditor requires. Scope, not which vendor you pick, is what moves the number.

There's no single honest number here, because cost depends on what's being tested, not a flat rate any legitimate tester can quote before they understand your scope. But there is a real range, and quotes that dodge the question entirely are usually avoiding it for the wrong reasons.

This page breaks down what drives the price, gives realistic ranges by engagement type, and explains what should be included in a quote versus billed separately, so you can tell a fair price from an inflated one before you get on a call.

What drives the price

Four things move a pentest quote more than anything else: scope (how many applications, APIs, hosts, or user roles are in play), depth (an automated-scan-plus-review versus a fully manual test against business logic and access control), the tester's seniority (a solo contractor and a firm staffed with senior testers price the same scope differently), and whether the engagement has to produce a specific compliance artifact.

Scope is the single biggest lever, by far. A test scoped to one login flow and a handful of endpoints will always cost less than a full application with a customer portal, an admin panel, and a public API, regardless of who you hire. Ask any vendor to walk you through exactly what's included before comparing their number to anyone else's: two quotes for "a web app pentest" can differ by 3x because one included the API and the other didn't.

Typical price ranges by test type

These are directional market ranges for small-to-mid-size engagements, not a fixed price list. The only way to get an exact number is to scope the engagement. Use them to sanity-check a quote, not to skip the scoping call.

Engagement typeTypical rangeWhat moves it
Single web application$4,000-$12,000Number of user roles/tenants, whether the API is in scope, authentication complexity
API penetration test$5,000-$12,000Number of endpoints, whether it's standalone or bundled with the app it serves
SaaS platform (multi-tenant)$6,000-$18,000Tenant-isolation testing is the main driver: every tenant boundary has to be tested, not just one account
External network$3,000-$10,000Number of live IPs/hosts in scope, not overall company size
Mobile application (iOS/Android)$5,000-$14,000One platform vs. both, and whether the backend API is tested alongside the app
Cloud / AWS configuration review$4,000-$12,000Number of accounts and services in scope, IAM complexity
Compliance-driven (SOC 2 / PCI DSS / HIPAA)$6,000-$20,000+Same underlying test as above, plus the evidence mapping and report format an auditor or QSA requires

Compliance-driven testing (SOC 2 / PCI DSS / HIPAA) pricing considerations

A compliance-driven test isn't a different kind of testing. It's the same manual, OWASP-aligned work, plus a report built for a second audience. A SOC 2 report has to map findings to the Trust Services Criteria your auditor is examining (typically CC4.1 and CC7.1); a PCI DSS test has to satisfy Requirement 11.4 with in-scope cardholder-data environment coverage; a HIPAA-relevant test has to speak to the Security Rule's technical safeguards. That extra mapping, plus a methodology statement auditors will accept, is most of the price gap between a generic pentest and a compliance one.

The other real cost driver is retesting. Most compliance frameworks expect evidence that findings were fixed, not just found. A quote that skips at least one round of remediation retesting is just pushing that cost onto you later, usually at a worse rate because it's no longer competitive.

What's included vs. billed separately

  • Included in almost every legitimate quote: manual testing against the agreed scope, a written report with reproduction steps and remediation guidance, and a debrief call to walk through findings.
  • Should be included, but sometimes isn't: at least one free round of retesting after you fix the findings, and an auditor-ready report format if the engagement is compliance-driven. Ask for this explicitly if a SOC 2, PCI, or HIPAA report is the goal.
  • Usually billed separately, and reasonably so: social engineering / phishing simulations, physical security assessments, red-team engagements (as opposed to a scoped pentest), and testing additional environments added mid-engagement.
  • A red flag, not a normal add-on: a "free" or near-zero-cost pentest with no named methodology. That's almost always an automated scan relabeled as a pentest, and it won't satisfy an auditor or catch business-logic flaws.

How to get an accurate quote

Have this ready before you ask for a number, and any quote you get back will be far closer to the real price: what's in scope (which app, API, or network, and roughly how many roles or endpoints), whether it's for a specific compliance deadline, whether you've been tested before (share the last report if you have one, it speeds up scoping and can lower the price), and your target testing window.

A vendor that can give you a real number after a short scoping call, not a form-fill "get pricing" page with no conversation, is usually the one that scopes accurately and doesn't pad the quote to cover surprises later.

Frequently asked questions

Why won't companies list a fixed price on their website?

Because scope changes the price more than anything else, and publishing a number that fits nobody's actual engagement either scares off well-scoped buyers with an inflated price or under-quotes complex ones and forces a renegotiation later. A short scoping call costs you nothing and gets you a real number.

Is a cheaper penetration test ever the better choice?

Sometimes. If the scope is genuinely small (one low-complexity app, no compliance deadline), a lower price can be entirely legitimate. The risk is a cheap quote on a large or compliance-driven scope, which almost always means an automated scan relabeled as a pentest, or no retesting included. Compare what's included, not just the number.

Does penetration testing cost include retesting?

It should, and most reputable quotes include at least one round of free retesting after you remediate the findings. If a quote doesn't mention retesting, ask. Being billed again just to confirm a fix landed is a common way a cheap-looking quote ends up more expensive.

How much does a penetration test cost for a startup?

Most early-stage startups with a single web app or API fall in the $4,000-$10,000 range for a first test. The number moves up quickly once a SOC 2 or PCI DSS deadline is involved, since that adds evidence mapping and a specific report format, not just more testing hours.

What's the difference between penetration testing cost and a vulnerability scan's cost?

An automated vulnerability scan costs a fraction of a pentest, often a few hundred dollars a month for a tool subscription, because it is software checking for known issues, not a person testing your specific business logic. A scan is a reasonable starting point; it will not find broken access control, authorization flaws, or chained vulnerabilities, and most auditors will not accept it in place of an independent test.

Related guides

Related services

Ready to scope your test?

Book a free 30-minute scoping call. We agree the scope, timeline, and a fixed price up front, with no obligation and no surprises for your deadline.