Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Privacy & security assessments

How much does a penetration test cost (and what affects the price)?

Reviewed by the Privacy Horizon team · Last reviewed

Quick answer

Penetration test costs vary widely because pricing is driven by scope and depth, not a fixed rate. The main factors are how many systems, applications, and IP ranges are in scope; the type of test (network, web app, mobile, cloud, social engineering); the testing depth and methodology; whether it is black-, grey-, or white-box; and retesting needs. A tightly scoped web-app test costs far less than a broad, multi-environment engagement, so an accurate quote requires defining your scope first.

On this page

Why is there no single price for a penetration test?

There is no flat rate for a penetration test because the work is effort-based. A tester scopes a defined target, then spends days probing it, so the price tracks the size and complexity of what is being tested rather than a fixed product fee. Two organizations of similar headcount can receive very different quotes because one has a single web application and the other has dozens of public services, cloud accounts, and a mobile app.

Most reputable firms price by the number of testing days required, which is estimated from your scope. That is why a credible provider asks scoping questions before quoting: anyone offering a firm price sight-unseen is either guessing or has narrowed the test so far that it may not give you meaningful assurance. The honest answer to 'how much will it cost' is 'it depends on scope,' and a good partner helps you scope it correctly so you pay for the assurance you actually need.

What factors affect the price of a penetration test?

Penetration test pricing is driven by how much there is to test and how deeply it must be tested. The biggest cost drivers are:

  • Scope size: the number of in-scope IP addresses, hosts, web applications, APIs, user roles, and cloud environments. More targets means more testing days.
  • Type of test: external network, internal network, web application, mobile application, cloud configuration, wireless, API, or social engineering and phishing. Each is a distinct discipline and adds effort.
  • Testing approach: black-box (no prior knowledge), grey-box (partial access such as a low-privilege login), or white-box (full source code and credentials). More information usually means more thorough, and more time-consuming, coverage.
  • Depth and methodology: a goal-based or red-team-style engagement that chains exploits and tests detection and response takes far longer than a standard vulnerability-focused assessment mapped to a framework like the OWASP Top 10 or PTES.
  • Complexity of the target: custom-built applications, intricate business logic, many user roles, and modern cloud or microservice architectures take longer to test than a simple brochure site.
  • Manual vs automated work: a real penetration test is largely manual expert effort. The more it relies on skilled hands-on testing rather than an automated scan, the higher, and more valuable, the cost.
  • Retesting and reporting: whether the engagement includes a remediation retest to confirm fixes, and the depth of the report, from an executive summary to technical findings, evidence, and an attestation letter for auditors.

Penetration test vs vulnerability scan: what are you paying for?

You are paying for skilled human judgment, not just a tool, and that distinction explains most of the price gap between a scan and a real test. A vulnerability scan is an automated tool that lists known weaknesses; it is fast and inexpensive but produces false positives and cannot understand your business logic. A penetration test uses qualified testers who manually verify findings, chain weaknesses together, and demonstrate real-world impact, for example turning a low-severity misconfiguration into actual access to sensitive data.

This matters when you choose a provider. A bargain 'penetration test' that is really just a scan with a logo on the report will satisfy almost no serious reviewer. Auditors, enterprise buyers, and healthcare or government clients increasingly expect evidence of genuine manual testing, so the cheapest option often fails to deliver the assurance you bought it for. The right level of rigour depends on why you need the test: regulatory expectation, customer requirement, or genuine risk reduction.

How often should you test, and how does that affect total cost?

Most organizations should run a penetration test at least annually and again after any significant change, such as a major application release, a new public-facing system, a cloud migration, or a merger, because each change can introduce new exposure. Frameworks and customers frequently expect this cadence, so budgeting for a recurring test rather than a one-off is more realistic.

Total cost of ownership therefore includes more than the initial engagement. Factor in retesting to confirm remediations, periodic re-tests as your environment evolves, and the internal effort to fix what is found. A scoped, repeatable annual test against a stable environment is usually more economical per cycle than an unplanned, rushed test triggered by a failed vendor security review or a customer demand.

How do you get an accurate penetration test quote?

The fastest way to a precise, fair quote is a short scoping conversation that defines exactly what will be tested and why. Before requesting pricing, it helps to know your in-scope assets (URLs, IP ranges, applications, cloud accounts), the type and depth of test you need, the driver behind it (a customer requirement, SOC 2 or ISO 27001 expectation, regulatory pressure, or proactive risk management), and your timeline.

Privacy Horizon scopes penetration tests around your actual environment and the reason you need one, so you pay for meaningful assurance rather than an off-the-shelf scan. We can also align the engagement with related work, such as a threat and risk assessment to prioritize what to test or readiness work for SOC 2 and ISO 27001, and provide an audit-ready report. Because pricing depends entirely on scope, we provide a tailored quote after a brief consultation rather than a generic figure.

Frequently asked questions

No. A vulnerability scan is an automated tool that lists known weaknesses, while a penetration test uses skilled testers to manually verify, exploit, and chain those weaknesses to show real-world impact. Scans are cheaper but produce false positives and miss business-logic flaws, which is why a genuine penetration test costs more and provides far stronger assurance.

Neither standard names a mandatory annual penetration test as a specific line item, but auditors and customers very commonly expect one as evidence that you test your security controls. In practice, most organizations pursuing SOC 2 or ISO 27001 run a penetration test to satisfy auditor and enterprise-buyer expectations, so it is wise to budget for one as part of your readiness work.

Active testing for a tightly scoped engagement can take a few days, while a broad, multi-environment test can run for several weeks. Add time for scoping, scheduling, reporting, and any remediation retest. The duration tracks the same scope and depth factors that drive the price, so a larger scope means both a higher cost and a longer timeline.

Black-box testing gives the tester no prior knowledge, simulating an external attacker. Grey-box provides partial access, such as a low-privilege login, to test what an authenticated user could do. White-box provides full information, including credentials and source code, for the most thorough coverage. White- and grey-box tests usually find more because the tester spends less time on reconnaissance.

Not a reliable one. Because pen test pricing depends on scope, type, and depth, an accurate quote requires a short scoping conversation about your in-scope systems and goals. Any firm that quotes a firm price before understanding your scope is either guessing or narrowing the test so far that it may not give you meaningful assurance.

Compliance & regulations

How do we prepare for a customer security questionnaire?

Customer security questionnaires (SIG, CAIQ, and custom) gate enterprise deals. Prepare with a control framework, ready evidence, a reusable answer library, and an owner.

Read
Compliance & regulations

What is a cybersecurity risk assessment, and how often should we do one?

A cybersecurity risk assessment identifies threats to your data and systems and how to manage them. Do one at least annually and after any significant change.

Read
SOC 2 & ISO 27001

SOC 2 vs ISO 27001 — which should we pursue first?

SOC 2 is a North American attestation report; ISO 27001 is an international certification. Compare them and decide which to pursue first — or whether you need both.

Read
Privacy & security assessments

PIA vs TRA: which assessment do you need (or do you need both)?

PIA vs TRA: a PIA assesses privacy risk to individuals; a TRA assesses security threats to systems. Learn which assessment you need, or whether you need both.

Read
Privacy & security assessments

What's involved in a Privacy Impact Assessment: inputs, timeline, and cost?

What's involved in a Privacy Impact Assessment — the inputs, timeline, and cost drivers of a PIA, and how to scope one for your project or product.

Read
Privacy & security assessments

When should you do a Privacy Impact Assessment in the product development lifecycle?

When should you do a Privacy Impact Assessment in the product development lifecycle? Start at design, finish before launch, and refresh when data handling changes.

Read

How Privacy Horizon can help

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.