Penetration Testing Cost at a Glance
In the US market, most penetration testing engagements run $4,000–$25,000. A web application test typically falls between $3,000–$22,500, external network testing starts around $3,600, internal network assessments run $4,800–$35,000, and API testing $5,000–$30,000.
| Test type | US market range | Typical duration | Scope unit |
|---|---|---|---|
| Web application | $3,000–$22,500 | 1–2 weeks | Per application, by user roles |
| API | $5,000–$30,000 | 1–2 weeks | Per API, by endpoint count |
| Network — external | from $3,600 | 3–7 days | Per live IP |
| Network — internal | $4,800–$35,000 | 1–4 weeks | Per subnet / host count |
| Mobile application | Similar to web app, per platform | 1–2 weeks | Android and iOS priced separately |
Day rates across the market sit around $1,000–$3,000, with senior testers billing materially above junior ones. Most work is quoted as fixed scope, but the day rate is a useful sanity check on whether a fixed price implies enough hands-on time.
These are observed US market ranges. Avantcert scopes each engagement individually — get a figure for yours.
Cost by Test Type
Knowing which test you actually need is most of getting comparable quotes.
Web application. The most common engagement. Priced by application and, more importantly, by the number of distinct user roles — each boundary between roles is a separate set of tests.
API. Increasingly bought separately from web app testing, because a UI test does not exercise the API surface underneath. Priced by endpoint count and authentication model.
Network. External is priced by live IP and is usually the cheapest engagement available. Internal — where the tester operates as an attacker who already has a foothold — is materially more, because segmentation and lateral movement take time to map.
Mobile. Android and iOS are two tests. A quote that looks cheap for "mobile app testing" frequently covers one platform.
Cloud configuration review. Priced per account or subscription, driven by services in use and IAM complexity. Often bundled but genuinely distinct work.
What Drives the Price
| Driver | Effect | Why |
|---|---|---|
| Manual vs automated ratio | Largest | A scan is a day; manual exploitation is one to three weeks |
| Number of user roles | Large | Every role boundary is its own set of access control tests |
| Grey-box vs black-box | Moderate | Grey-box finds more per dollar — less time on reconnaissance |
| Tester seniority | Moderate | A named senior tester costs more and finds more |
| Retest rounds | Moderate | One is standard; zero should be questioned |
| Compliance mapping | Small on cost, large on value | Findings mapped to your framework save audit time later |
Grey-box is usually the better buy. Providing credentials and some architecture detail feels like doing the tester's job for them, but it means they spend the engagement testing rather than on reconnaissance — and reconnaissance is the part an actual attacker has unlimited time for and you are paying by the day for.
Get a Scoped Penetration Testing Quote
Tell us what needs testing — applications, APIs, network ranges, mobile platforms — and whether it is for a compliance requirement. Scoped estimate within 24 hours.
Our form could not load. Email your scope and you'll get the same estimate within 24 hours.
Email your requirements Open the full quote formWhat a Cheap Pentest Actually Buys
Quotes well below $4,000 for a real application are almost always an automated vulnerability scan with the tool output reformatted.
That product has a legitimate place — it catches known CVEs, outdated dependencies and misconfigurations, and running one regularly is good practice. What it cannot do is find business logic flaws, broken access control between user roles, insecure direct object references, or chained exploits, because those require a human who understands what the application is for.
The reviewer can usually tell. Enterprise security teams read a lot of these reports. One with no manual testing narrative, no exploitation evidence and generic tool-derived findings gets recognised — and when it is rejected you pay twice, having also lost the weeks in between.
One question that sorts quotes quickly: what proportion of the engagement is manual testing, and who performs it? A provider selling a scan cannot answer specifically.
Testing for Compliance
Most penetration testing is bought because a framework or a customer required it. What each actually expects:
| Framework | Requirement | Frequency |
|---|---|---|
| PCI DSS | Explicitly requires penetration testing | Annually and after significant change |
| SOC 2 | Not named, but CC7 covers vulnerability identification | Across the observation window |
| ISO 27001 | Technical vulnerability management and secure testing, Annex A | At least annually |
| HIPAA | Evaluation of controls protecting ePHI | Periodic |
| CMMC / NIST 800-171 | Vulnerability scanning and remediation | Ongoing |
Where a compliance consultancy differs from a pentest firm: a findings list is a security document. A findings list mapped to the exact controls your auditor will test, with a retest letter closing them, is audit evidence. We produce the second because we also run the audits — see testing for ISO 27001 and SOC 2.
Retest and Remediation
The most common omission in a pentest quote, and the one that costs clients most.
The report describes the state at the time of testing. You remediate, you send the report to your auditor or customer — and it still shows every finding open, because that is what it recorded.
The retest letter is what closes them. Without it, the original report is evidence you had vulnerabilities rather than evidence you fixed them.
Confirm retest is in scope before signing. A provider who priced without it priced a different job, and negotiating once findings exist is the worst possible moment.
Penetration Testing Cost FAQs
How much does a penetration test cost?
In the US market most engagements run $4,000–$25,000. A web application pentest typically falls between $3,000–$22,500, external network testing starts around $3,600, internal network assessments run $4,800–$35,000, and API testing $5,000–$30,000. Day rates are commonly $1,000–$3,000.
Why do penetration testing quotes vary so much?
Because scope is defined differently by every provider and because "penetration test" covers both automated scanning and genuine manual exploitation. The ratio of manual work is the largest cost factor, followed by the number of user roles and authenticated flows in the application. Two quotes for the same application can differ fivefold and both be honest.
What is a typical pentest day rate?
Around $1,000–$3,000 per day is common in the US market, with senior testers billing materially more than junior ones. Most engagements are quoted as a fixed scope rather than by day, but the day rate is a useful sanity check: a fixed price that implies fewer than five days of work on a multi-role web application is unlikely to be a manual test.
How long does a penetration test take?
A single web application typically takes one to two weeks of testing plus about a week for reporting. External network testing can be shorter; complex internal network or multi-application scopes run three to six weeks. Add two to four weeks before the retest, since you need time to remediate in between.
Is a $1,000 penetration test real?
At that price you are almost certainly buying an automated vulnerability scan with the tool output reformatted. That has legitimate uses, but it is not a manual penetration test and it will not find business logic flaws or broken access control between roles. In the US market, genuine manual testing of even a simple single-server application starts around $5,000.
Does SOC 2 require a penetration test?
SOC 2 does not name penetration testing as a mandatory control, but CC7 covers vulnerability identification and auditors routinely accept a current pentest report as evidence. PCI DSS does explicitly require penetration testing. ISO 27001 expects technical vulnerability management under Annex A, and a test report plus retest letter is the usual evidence.
Is a retest included in penetration testing cost?
Frequently not, and it is the most common omission in a pentest quote. A report showing open findings does not satisfy an auditor or an enterprise security review; a retest letter confirming they were closed does. Confirm retest is in scope before signing rather than negotiating it once findings exist.
Related Reading
See penetration testing services, VAPT vs penetration testing, what the report should contain, or what VAPT costs in India if you are buying from an Indian provider.
Reference: OWASP Web Security Testing Guide.
Get a quote that includes the retest
Scoped to what needs testing, mapped to the framework you need it for.