A penetration test costs $5,000 to $100,000 or more depending on what you put in scope, and the market average lands around $18,300. The spread is the whole story. A narrow web-application test runs $5,000 to $30,000, an external network test $5,000 to $20,000, a cloud-configuration review $10,000 to $50,000, a social-engineering campaign $3,000 to $15,000, and a full red team $20,000 to $150,000+. One number to anchor on first: anything priced under about $4,000 is almost always an automated scan, not a manual pentest.
We’re gmware, a custom software development firm headquartered in Austin, TX with engineering centers in Bangalore and Mohali, India. We build and run production systems ourselves, including Shield Suite, a retail-intelligence product covering 60,000+ beverage-alcohol storefronts, so security testing isn’t an abstraction to us. This post breaks down what each pentest type tests and what it costs, what a real engagement includes from scoping to retest, the pricing models you’ll be quoted under, the compliance drivers that force the test, and the honest line where an automated scan is still enough.
Pentest cost at a glance
Pentest cost by type, because there’s no single pentest
There is no single pentest price because there is no single pentest. The work is scoped to an asset class, and each class carries its own range. Here are the seven types you’ll most often be quoted on, with the band each sits in for a moderate, single-vendor engagement.
| Pentest type | What gets tested | Typical cost | Typical duration |
|---|---|---|---|
| External network | Internet-facing IPs, firewalls, exposed services, VPN | $5,000 to $20,000 | A few days to two weeks |
| Internal network | Lateral movement, privilege escalation from an assumed foothold | $7,000 to $40,000 | One to two weeks |
| Web application | Auth, access control, injection, business-logic flaws | $5,000 to $30,000 | 3 to 10 days |
| Mobile application | iOS and Android client, local storage, API calls | $7,000 to $35,000 per platform | One to two weeks |
| Cloud configuration | IAM, storage exposure, network policy in AWS, Azure, GCP | $10,000 to $50,000+ | Several days to two weeks |
| Social engineering | Phishing, pretext calls, physical entry against your people | $3,000 to $15,000 | One to two weeks |
| Red team | Goal-driven, multi-vector attack simulation across all of the above | $20,000 to $150,000+ | 4 to 12 weeks |
Read the table as a menu, not a ladder. Most companies don’t need all seven. A SaaS team usually starts with web application plus the API behind it; a company with an office and a help desk adds social engineering; a regulated enterprise eventually gets to a red team. The API test on its own runs $6,000 to $30,000, and it’s the one teams forget to scope until the tester asks where the mobile app gets its data.
What each pentest type costs
What a real engagement includes, end to end
A real engagement is five phases, and you’re paying for all five whether the quote itemizes them or not. Skip any one and you’ve bought a worse version of the test.
Scoping and rules of engagement. Before anyone touches your systems, you agree on what’s in bounds, what’s off-limits, the testing window, and who gets the 2am call if something breaks. This is where a good firm pushes back on a too-narrow scope, and where a bad one rubber-stamps whatever you wrote down.
Testing. The actual work. A skilled tester maps your attack surface, finds weaknesses, and then does the thing a scanner can’t: chains them together and tries to exploit them. Testers bill at $100 to $300 an hour, and the senior ones are worth it because the findings that matter are the ones automation walks past.
Findings report. Every issue, ranked by severity, with enough detail for your engineers to reproduce it. A report that just says “SQL injection found” without the where, the how, and the impact is a finding you can’t act on.
Remediation guidance. Not just what’s broken, but how to fix it in your stack. This is where the test stops being a grade and starts being useful. Plan for real engineering work here: a serious round of fixes can run $18,000 to $30,000 in developer time over a three-week sprint, and that line never shows up on the testing quote.
Retest. After you fix the criticals, the tester verifies the fixes actually held. Retests run 30% to 50% of the original engagement cost, or a flat fee on smaller jobs. Here’s the opinion we’ll defend: a pentest without a retest is half a pentest. A report full of unverified “fixed it, trust me” closures is exactly the gap a real attacker walks through.
The five phases you're paying for
If a security program is what you’re building toward rather than a one-off test, our cybersecurity services cover the remediation engineering most testing firms hand off and walk away from. Tell us what you’re trying to protect and we’ll scope it straight. Reach out and you’ll have an answer within 48 hours.
The five pricing models you’ll be quoted under
You’ll be quoted under one of five common models, and knowing which one you’re in tells you what you’re actually buying.
| Pricing model | How it works | When it fits |
|---|---|---|
| Fixed price (per scope) | One agreed fee for a defined scope | A single, well-bounded asset; the most common SMB quote |
| Time and materials | Hourly or daily billing for work performed | Scope you can’t fully define up front, or exploratory work |
| Retainer / credits | Pre-purchased hours used across the year | Continuous or recurring testing needs |
| Outcome-based | Fee tied to severity of what’s found | Rare; aligns incentives but hard to budget |
| Bundled / managed | Testing combined with monitoring on subscription | Teams who want testing as part of an ongoing service |
Under time and materials, the day rate is the lever. Mid-market firms run $1,500 to $3,500 per consultant day; top-tier boutiques and Big Four practices run $4,000 to $7,000. That gap is real, and it’s not all prestige tax. The senior end buys testers who find business-logic flaws and auth bypasses, the stuff that turns into an actual breach. The cheap end sometimes buys a scanner with a person watching it run. Ask who’s doing the testing and what they’ve found before, not just the price per day.
Cadence: annually, plus after any major change
Annually, at a floor, and again after any material change to what you’re protecting. The annual test is the baseline that compliance frameworks expect and that buyers ask about. The after-a-change test is the one that earns its keep: every new feature, cloud migration, major release, or acquisition introduces fresh attack surface, and the window between “we shipped it” and “we tested it” is exactly when you’re most exposed.
The cadence is also why pentest spend is a budget line, not a project. A small business should plan on $8,000 to $20,000 a year for foundational testing; a mid-market company more, scaling with asset count and compliance scope. Treat it like insurance with a renewal date, because that’s effectively what it is.
Which compliance frameworks require a penetration test?
Three drive most of the demand, and the cost moves with the framework.
PCI-DSS requires a penetration test outright if you handle cardholder data, and a PCI-scoped test runs $12,000 to $25,000. SOC 2 doesn’t name a pentest in the standard, but most auditors and enterprise buyers expect one as standing evidence, and a SOC 2-scoped test runs $5,000 to $20,000. HIPAA requires a security risk assessment, and a pentest is the practical way most teams satisfy the technical-evaluation piece; a HIPAA-scoped test runs $10,000 to $50,000. If you’re chasing a SOC 2 report on a deadline, we mapped where the pentest fits in our 90-day SOC 2 plan, and the same controls that clear the audit also clear most of a cyber-insurance application.
The honest framing: in practice, the compliance requirement is what gets the test funded. Almost nobody runs their first pentest because they woke up worried about lateral movement. They run it because a buyer’s security questionnaire or an auditor’s checklist demands proof.
Pentest cost by compliance driver
When is an automated vulnerability scan enough?
Often, and a good firm will tell you so. A vulnerability scan is an automated tool that checks your systems against a database of known weaknesses and reports what it finds. It runs roughly $2,000 to $15,000 a year, it’s fast, and you can run it weekly without anyone losing a sleep cycle. A scan is enough when you’re in any of these spots:
- You’ve never tested anything, and you need a cheap, broad first pass before committing to a manual engagement.
- You want continuous coverage between annual pentests to catch newly disclosed CVEs as they land.
- No compliance framework or enterprise buyer is yet asking you for a pentest report.
- Your environment is small and standard, with no custom auth, no complex business logic, and nothing a scanner won’t recognize.
The line between the two is real, not marketing. A scan reports flaws but never proves they’re exploitable; a pentest puts a human in the attacker’s seat to chain weaknesses, test the logic a scanner can’t read, and actually exploit findings to show real impact. You need the manual test, not just the scan, the moment any of these is true: a customer or auditor demands a pentest report, you handle sensitive data (payments, PHI, anything regulated), you’ve shipped custom application logic a scanner can’t reason about, or you genuinely want to know what a breach would cost rather than a list of theoretical holes. The two aren’t rivals. The scan gives you breadth on a schedule; the pentest gives you depth on the things that turn into incidents. Most mature programs run both, and use the scan to keep the pentest scope, and the bill, focused on what automation can’t reach.
How gmware approaches security testing
We’re engineers who run production systems, not a pentest shop selling reports by the pound. So our bias is toward the half of the work most testing firms skip: the remediation. A findings report is a to-do list, and a to-do list nobody closes doesn’t make you safer. Our cybersecurity practice does the fix-and-retest engineering, the IAM cleanup, the auth-bypass closures, the logging and config hardening, that turns a stack of criticals into a clean retest. Austin leads run scoping and coordination on US hours; our Bangalore and Mohali teams clear the remediation backlog without US-only burn rates.
We’ll also tell you when you’re over-buying. If you’ve never tested anything and no buyer is asking yet, the right first move is usually a scan plus a tight web-app test, not a six-figure red team. And if you’re building software that has to be secure by design rather than patched after the fact, the architecture decisions matter more than any single test, which is why we lay out the patterns in our HIPAA-compliant app architecture guide.
Tell us what you’re trying to protect, and whether it’s a compliance deadline, a buyer’s questionnaire, or a real worry about an exposure. Reach out and we’ll give you a straight answer on scope, the right testing type, and cost within 48 hours.