How much does a penetration test cost?

Most vendors make you sit through a discovery call before they will name a number. Here are ours, by scope — plus an estimator that prices your actual environment in under a minute.

The short answer

For most small and mid-size organizations, a penetration test costs between $1,400 and $23,150. A single web application sits at the low end. A full-scope engagement across web, network and cloud sits in the middle. An objective-based red team engagement sits at the top.

Price is driven by scope, not by your company size or your industry: how many internet-facing hosts, how many distinct applications, how many Active Directory domains and cloud tenants, and whether internal testing is in scope.

There is one price and one way of working. Every engagement below is SwarmPT — our agent swarm driven throughout by an experienced penetration tester — because a cheaper tier is really just a way of giving you less attention while implying you got the same thing. Every price includes an executive summary, a full technical report, a remediation retest, and a 90-day Protection Window while your team fixes what we find.

Penetration testing prices by scope

Representative engagements, priced through the same model our quoting process uses. Your numbers will differ — use the estimator below for your actual environment.

EngagementRepresentative scopePrice
Web application pen testOne production web application, authenticated and unauthenticated testing.$1,400
External network pen testInternet-facing perimeter — around a dozen exposed hosts and services.$3,600
Internal network pen testAssumed-breach internal test across roughly 400 endpoints and one AD domain.$6,400
Full-scope pen testWeb, network and cloud in one engagement for a mid-size environment.$11,000
Phishing campaignPhishing-to-access simulation against 250 users.$4,100
Red team engagementObjective-based multi-vector simulation against a mid-size environment.$23,150

All figures include an executive summary, a full technical report, and a remediation retest.

Price your own environment

Pick what you want tested, tell us roughly how big it is, and see a real range immediately. No email required to see the number — you only give us details if you want to take it further.

Instant estimate

Same pricing model we use internally. No email required to see the number.

What do you want tested?

Pick everything that applies. You can change it later.

What moves the price

Pushes it up

  • More internet-facing hosts — each is a distinct attack surface
  • Each extra application adds to the total, though far less than the first did
  • Additional Active Directory domains or forests
  • Additional cloud tenants and subscriptions
  • Internal network testing on top of external
  • Objective-based red teaming rather than scoped testing
  • Physical or Wi-Fi testing across multiple sites

Brings it down

  • Tight scoping — test what matters, not everything you own
  • Several applications in one engagement — apps after the first are priced well below it, because our cost barely moves
  • Bundling a ransomware or exfiltration simulation onto an engagement that already gives us access
  • Providing test credentials up front instead of making us earn them
  • Recurring testing rather than one-off engagements
  • Skipping the compliance report if no auditor is asking for it

Comparing quotes? Normalise these first

Penetration testing quotes are notoriously hard to compare because vendors scope and bundle differently. Before you compare price, confirm all five of these in writing:

Is exploitation actually attempted, or is this a scan?

A scan matches signatures and hands you a triage list. A test proves what is exploitable. The price difference is enormous and the deliverable looks superficially similar.

Exactly what is in scope?

Count of hosts, applications, domains and cloud tenants — in writing. Vague scope is where cheap quotes hide.

Is retesting included?

Proving your fixes worked is often billed separately. Ask before you compare.

Who writes the report, and what is in it?

CVSS scores alone are not remediation guidance. You want proof-of-concept evidence and specific fixes.

Is compliance mapping included if you need it?

If an auditor is going to read this, the mapping matters — and it is frequently an add-on.

Penetration Testing Cost — Common Questions