Illustrated cover graphic: how much does a penetration test cost

How Much Does a Penetration Test Cost? A Practical Buyer’s Guide

“How much does a penetration test cost?” is one of the first questions buyers ask, and it is also one of the hardest to answer with a single figure. Two quotes for what looks like the same engagement can differ widely, not because one provider is overcharging, but because they are quietly proposing very different pieces of work. This guide explains what actually drives the price, how the main test types differ in effort, and how to tell a genuinely thorough assessment from a cheap scan dressed up as a pentest.

What actually drives the cost

Penetration testing is priced primarily on effort, and effort is a function of scope. The clearest driver is the size of the target: the number of applications, IP addresses, hosts, or cloud accounts in play. Beyond raw count, application complexity matters just as much. An application with dozens of user roles, complex business logic, and multiple integrations takes far longer to test properly than a simple brochure site.

Testing depth is the next big factor. Automated scanning is fast and cheap; skilled manual testing, which is where most serious vulnerabilities are actually found, takes time. The tester’s seniority feeds into this too, as experienced testers cost more but tend to find issues that tools and junior staff miss. Other variables include the testing perspective (black-box with no prior knowledge, grey-box with limited access, or white-box with full documentation and source), whether the work is remote or on-site, whether a retest round is included, and how much formal, compliance-ready reporting you need. Each of these adds or removes days of effort, and days of effort are what you are paying for.

Test types and how their effort differs

Not all security testing is equal, and the type of engagement shapes both effort and price. A web application test involves manual exploration of every function, role, and input, and effort scales with the number and complexity of applications. An external network test probes your internet-facing perimeter, while an internal network test assumes a foothold inside and typically covers a larger, messier estate, which usually means more effort.

A cloud configuration review examines how your cloud environment is set up against good practice, and its scale depends on the number of accounts and services. Mobile application testing adds platform-specific analysis of the app and its back-end. API testing focuses on the endpoints behind modern applications, where authorisation flaws are common. At the top end, a full red-team engagement simulates a determined adversary across people, process, and technology over an extended period, and is correspondingly the most involved and expensive option. Matching the test type to your actual risk is the single best way to control spend.

Why the cheapest quote is often a false economy

When one quote is dramatically lower than the rest, it is worth asking what has been left out. The most common cause is a “pentest” that is really just an automated vulnerability scan with a logo on the report. Scanners are useful, but they produce false positives, miss business-logic flaws entirely, and cannot chain several small weaknesses into a serious compromise the way a human tester can.

Cheap engagements also tend to skip manual verification, so you receive a raw tool output that nobody has validated or prioritised. They frequently exclude a retest, which means you never get confirmation that your fixes actually worked. A low headline price that leaves you with unverified findings and no proof of remediation is rarely the bargain it appears to be, because the risk it was meant to reduce is still sitting on your network.

What a good proposal and deliverable includes

A strong proposal is specific. It states exactly what is in scope and what is not, the testing perspective and depth, the methodology being followed, and the seniority of the testers assigned. Vague, one-line quotes are a warning sign in their own right.

The deliverable matters even more than the test. A good report presents evidence-backed findings, each rated by severity so you can prioritise sensibly, with enough detail to reproduce the issue. Crucially, it gives clear, practical remediation guidance aimed at the people who will fix the problem, not just a restated tool description. It should also include at least one retest round, so that once you have made changes, the provider re-checks the findings and confirms they are genuinely closed. That cycle of test, fix, and verify is what turns a report into real risk reduction.

Questions to ask before you buy

  • Is the testing manual, automated, or a blend, and how much of each?
  • What methodology do you follow, and how do you rate the severity of findings?
  • What is the seniority and relevant qualification of the testers on my engagement?
  • Is a retest round included, and how long do I have to request it?
  • Can I see a sample report so I can judge the quality of findings and remediation advice?
  • Exactly what is in and out of scope, and how did you arrive at the effort estimate?
  • Will the report satisfy the specific compliance requirement I am trying to meet?

Clear answers to these questions tell you far more about value than the headline number ever will. The goal is not the lowest price, but the most risk reduced for the budget you have.

How Baknet can help

Baknet Cyber Solutions scopes penetration tests around your actual risk rather than a one-size-fits-all package, combining skilled manual testing with clear, severity-rated reporting and practical remediation guidance. Every engagement is built around evidence you can act on and a retest round to confirm your fixes have worked. If you are weighing up quotes and want an honest, no-pressure view of what your organisation actually needs, book a consultation with our team.