Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What does a penetration test cost?
Last verifiedPen-test price tracks days, seniority, and attack surface — not a catalog SKU. Indicative, time-sensitive observation puts a scoped web-app test from the low thousands of US dollars into five figures when more surfaces are added. Do not choose on price alone. This page is not legal advice.
Pen-test cost, last verified 10 September 2026 against NIST SP 800-115 scoping methodology, CREST scoping and reporting materials, and OSSTMM scoping practice. Figures on this page are indicative and time-sensitive market observation, not a price list and not a vendor quote. Not legal advice.
This is not a price list
Audience: a founder budgeting an independent test. This page is not legal advice. Kind of text: NIST SP 800-115 and CREST / OSSTMM materials are scoping methodology and industry practice, not a statute and not a quote. ShipReady Metrics recommendation: score vendors on methodology and reporting first; treat price as a constraint, not the selection key. Caution: choosing on price alone is how you buy a scan dressed as a pen test.
Any dollar band below is indicative, time-sensitive market observation as of last verification on 10 September 2026. It is not a ShipReady Metrics price, not an average claimed from a study, and not a promise that YOUR quote will land there.
Cost-driver breakdown
Price is mostly days multiplied by seniority, then adjusted for access, environment count, and whether a retest is included. Last verified 10 September 2026. Not a price list. Not legal advice.
| Driver | What moves the quote | How to scope it (methodology) | Kind of text |
|---|---|---|---|
| Scope / attack surface | Number of apps, APIs, cloud accounts, network segments, and mobile binaries. | NIST SP 800-115: inventory in-scope assets and rules of engagement before days are estimated. | Methodology guidance. |
| Methodology depth | Unauthenticated smoke test versus credentialed, role-based, and business-logic abuse. | CREST and OSSTMM describe method depth; more depth is more days. | Industry practice / accreditation materials — not endorsement. |
| Application vs network vs cloud | A single web app is fewer days than that app plus VPC, identity, and Kubernetes. | Separate statements of work so you can see which surface you are paying for. | Scoping practice. |
| Retest inclusion | A bundled retest window costs more up front and less than a second full engagement later. | PCI 11.4 (if PCI applies) expects confirmation of remediation; ask whether retest days are in the quote. | Program requirement if PCI applies; otherwise best practice. |
| Seniority and specialization | Specialist cloud, ICS, or thick-client testers cost more per day than a general web tester. | Ask who will actually test, not who sold the work. | Industry practice. Accreditation is not endorsement. |
Indicative bands — observation only
As of last verification on 10 September 2026, publicly discussed commercial scoping (not a cited vendor quote, not a fabricated study) often prices a time-boxed web-application test for one product in the low thousands of US dollars for a short, narrow engagement, and into five figures when several applications, cloud, and network are combined. Enterprise or multi-region programs can exceed that. Those sentences are indicative and time-sensitive. They are not a price list. Verify current quotes. Not legal advice.
What to do now
Operational steps. Last verified 10 September 2026. Not legal advice.
- Write the in-scope inventory using NIST SP 800-115 before you request quotes. Vague scope produces incomparable prices.
- Require every quote to state methodology, tester seniority, retest policy, and report contents. Open the choosing-a-company and report-contents guides on this site.
- Do not select the lowest number. A cheap scan labeled “pen test” fails diligence.
- Budget the next annual (or significant-change) cycle now so cadence does not slip.
Checklist
Question list, not YOUR file. Not a price list. Not legal advice.
- Is the quote tied to a named asset inventory and rules of engagement?
- Are retest days included, time-boxed, or extra?
- Does the number buy exploitation and a narrative report, or only scanner output?
- Have you compared methodology quality, not only the total?
Where this shows up in ShipReady Metrics
This page is vendor-neutral. The product does not sell pen tests, does not quote testers, and does not replace an independent engagement.
Primary sources (last verified 10 September 2026)
NIST SP 800-115 (scoping and planning). CREST scoping and reporting materials (accreditation body practice, not endorsement). OSSTMM scoping practice. PCI DSS v4.0.1 Req. 11.4 for retest expectations if PCI applies. No vendor price sheet is cited because a dated public catalog is not a substitute for scoped quotes. Not legal advice.