How much does a penetration test cost?

Most vendors make you sit through a discovery call before they will name a number. Here are ours, by scope — plus an estimator that prices your actual environment in under a minute.

The short answer

For most small and mid-size organisations, a penetration test costs between $1,900 and $18,650. A single web application sits at the low end. A full-scope engagement across web, network and cloud sits in the middle. An objective-based red team engagement sits at the top.

Price is driven by scope, not by your company size or your industry: how many internet-facing hosts, how many distinct applications, how many Active Directory domains and cloud tenants, and whether internal testing is in scope.

Every range below is quoted two ways. The lower figure is the AutoPT-delivered option — the same scope, run by our AI agent swarm under expert oversight. The higher figure is the fully human-led option, delivered hands-on by senior consultants. Both include an executive summary, a full technical report, and a remediation retest.

Penetration testing prices by scope

Representative engagements, priced through the same model our quoting process uses. Your numbers will differ — use the estimator below for your actual environment.

EngagementRepresentative scopeAutoPT-deliveredHuman-led
Web application pen testOne production web application, authenticated and unauthenticated testing.$1,900$3,150
External network pen testInternet-facing perimeter — around a dozen exposed hosts and services.$2,550$4,450
Internal network pen testAssumed-breach internal test across roughly 400 endpoints and one AD domain.$2,900$5,150
Full-scope pen testWeb, network and cloud in one engagement for a mid-size environment.$3,900$7,150
Phishing campaignPhishing-to-access simulation against 250 users.$3,950$3,950
Red team engagementObjective-based multi-vector simulation against a mid-size environment.$6,650$18,650

All figures include an executive summary, a full technical report, and a remediation retest. Individual automated tests through AutoPT start at $35 per target if you only need a specific check.

Price your own environment

Pick what you want tested, tell us roughly how big it is, and see a real range immediately. No email required to see the number — you only give us details if you want to take it further.

Instant estimate

Same pricing model we use internally. No email required to see the number.

What do you want tested?

Pick everything that applies. You can change it later.

What moves the price

Pushes it up

  • More internet-facing hosts — each is a distinct attack surface
  • Multiple distinct web applications rather than one
  • Additional Active Directory domains or forests
  • Additional cloud tenants and subscriptions
  • Internal network testing on top of external
  • Objective-based red teaming rather than scoped testing
  • Physical or Wi-Fi testing across multiple sites

Brings it down

  • Tight scoping — test what matters, not everything you own
  • Choosing the AutoPT-delivered option: same scope, roughly half the testing cost
  • Bundling a ransomware or exfiltration simulation onto an engagement that already gives us access
  • Providing test credentials up front instead of making us earn them
  • Recurring testing rather than one-off engagements
  • Skipping the compliance report if no auditor is asking for it

Comparing quotes? Normalise these first

Penetration testing quotes are notoriously hard to compare because vendors scope and bundle differently. Before you compare price, confirm all five of these in writing:

Is exploitation actually attempted, or is this a scan?

A scan matches signatures and hands you a triage list. A test proves what is exploitable. The price difference is enormous and the deliverable looks superficially similar.

Exactly what is in scope?

Count of hosts, applications, domains and cloud tenants — in writing. Vague scope is where cheap quotes hide.

Is retesting included?

Proving your fixes worked is often billed separately. Ask before you compare.

Who writes the report, and what is in it?

CVSS scores alone are not remediation guidance. You want proof-of-concept evidence and specific fixes.

Is compliance mapping included if you need it?

If an auditor is going to read this, the mapping matters — and it is frequently an add-on.

Penetration Testing Cost — Common Questions