How much does penetration testing cost?

A real penetration test costs $5,000 to $30,000 for a single web application in 2026. Below about $4,000 you are almost always buying an automated scan with a report cover. Cloud environments run to $50,000 and beyond. Every consultancy quote reduces to one formula: tester-days multiplied by a day rate. Here is that math, including our own numbers.

Infographic of 2026 penetration testing prices: 5,000 to 30,000 dollars for a real web app, under 4,000 is usually a scan

On this page: the price bands · the day-rate math · the AI pentest wave · why quotes differ 10x · the $500 pentest · what compliance makes you buy · our prices · how it gets this cheap

The price bands in 2026

Almost no firm in this market publishes prices. Directories of hundreds of providers list exactly zero rate cards, so every guide to this question is vague. The bands below are the published data that does exist, and they match what founders report paying.

Range chart of 2026 penetration testing price bands per engagement type, from automated scans to cloud environments, compared on the same dollar scale with the new AI pentest wave

What you are testing2026 market bandWhat pushes you up the band
Web application$5,000 to $30,000roles, payments, file handling, tenant isolation
API$6,000 to $30,000endpoint count, auth models, third-party consumers
Mobile app$7,000 to $35,000 per platformiOS and Android are separate engagements
Network$5,000 to $40,000host count, internal plus external, segmentation
Cloud environment$10,000 to $50,000+multi-account sprawl, IAM complexity
Automated scan sold as a pentest$300 to $2,000nothing: the tool run costs the same everywhere

The bands are from DeepStrike’s 2026 pricing guide, one of the few firms that publishes them, and they have held for years. Here is the same range on Hacker News in 2017:

$40k would be a pretty standard price point for a regular pentest.

That is a security practitioner writing in 2017. Nine years on, the consultancy mid-market still quotes the same numbers: the delivery model changed, the day-rate economics did not.

The day-rate math behind every quote

Strip away the sales language and every quote is the same calculation: the tester-days your scope needs, multiplied by what the firm’s testers cost per day.

Diagram of the day-rate math behind penetration test quotes, showing a ten day web application engagement priced between 12,000 and 25,000 dollars

What a tester-day costs

Work the published bands backwards: $5,000 to $30,000 for a web application over the 4 to 12 tester-days such engagements take implies roughly $1,200 to $2,500 a day. Junior-heavy shops sit at the bottom, senior boutiques and brand-name consultancies at the top. A quote far below that range is not defying economics; it is spending fewer person-hours on you, usually a scanner’s.

How many days your scope needs

Day count is driven by attack surface, not company size. One login role, a handful of forms and no payment flow is a 4 to 6 day test. Multi-tenant SaaS with role hierarchies, integrations and file uploads is 8 to 12. The quote call is really a surface census: arrive with an endpoint count, role list and architecture sketch, because firms price uncertainty.

What the new AI pentest wave charges

A generation of AI-led pentest companies entered the market in the last two years, and the surprise is how little pricing changed. RunSybil (founded by OpenAI’s first security hire, $40 million raised) publishes no prices. Horizon3’s NodeZero is quote-only through sales and the AWS Marketplace. Most of the wave rebuilt the consultancy playbook with a faster engine. XBOW is the exception:

Pricing starts at $6,000 so teams can test earlier and more often.

That is XBOW’s launch pricing for one machine-run, human-reviewed test, against their own market read of $10,000 to $35,000 per typical engagement. How far the floor can drop is a stack-ownership question: where our numbers come from.

Why two quotes for the same app differ by 10x

Founders collect quotes of $6,000 and $60,000 for the same application; neither is a scam, they price different amounts of work.

Methodology depth is the hidden variable

A black-box test attacks from outside with no credentials or source access. A white-box test reads your code while attacking, which finds deeper bugs in the same number of days. Ours is white-box by default. When comparing quotes, ask which one you are getting: a $9,000 white-box test routinely outperforms a $25,000 black-box test on findings that matter.

Who actually does the testing

The person matters more than the logo. Big consultancies bill partner-grade rates and staff junior testers; boutiques run senior people at similar prices. Cobalt’s 2026 State of Pentesting report, drawn from 1,500+ customers, shows how much delivery model matters:

Organizations with a programmatic model are 4.5x more likely to resolve critical findings in three days or less compared to ad-hoc teams.

The same report found 40% of organizations still test primarily for compliance. Even then quality matters, because the report gets read: see why a scan gets bounced.

A $500 pentest is a scan with a cover page

At $1,200 to $2,500 a day, $500 buys a few hours, and the only thing deliverable in a few hours is a tool run reformatted into a report. PCI DSS 11.4.1, the strictest testing standard in production use, frames the bar as attacks “by a competent manual attacker” (the standard is in the official PCI document library). A scan has value as hygiene between tests. Sold and submitted as a penetration test, it fails: enterprise reviewers read the methodology page before the findings and bounce reports that describe a tool run. Our manual pentest comparison shows what a human-plus-AI engagement covers that a scanner cannot. The exception that keeps $299 a month honest: machine-hours instead of billed human days (how that works).

What compliance actually makes you pay for

Compliance buys roughly two in five tests, so here is what each framework actually obliges you to spend:

  • SOC 2: $0 mandated, one test expected. No criterion requires a pentest, but your auditor expects a recent one inside your observation window. The full analysis is in does SOC 2 require a penetration test. Budget one real test a year.
  • PCI DSS: two tests plus retests, forever. Internal and external testing every 12 months and after significant change, a mandatory retest, and 6-month segmentation tests for service providers: the clause by clause breakdown.
  • HIPAA: annual testing is coming. The proposed Security Rule update (90 FR 898) would mandate a penetration test every 12 months. HHS’s own impact analysis prices that test at $359.82 (3 hours at $119.94 an hour); real market pricing is 15 to 80 times higher.

Our prices, published

Hiding prices is how this market got opaque, so here are ours: two paths. Both run a pentest every month and include SOC 2 controls. Need the SOC 2 report itself? We connect you with independent AICPA-member CPAs you pay directly, which keeps the audit independent.

WhoPentest, per monthIf you also need SOC 2 attested
Startups: teams of 10 or fewer (no funding or age limit)$299, AI-ledCPA from $2,500: about $6,088 all-in for the year
Every other company$2,999, human in the loopCPA from $15,000: about $51,000 all-in

The math in the open: $299 x 12 plus $2,500 is $6,088, against the $30,000 to $45,000 the traditional three-vendor stack costs. The standard path is $2,999 x 12 plus $15,000, buying twelve human-validated pentests a year instead of the retail stack’s one or two. Still true: if you ship a few times a year, an annual $8,000 boutique engagement is the right buy. A 20-minute call settles it; the subscription is on /pricing.

How a real pentest gets this cheap

The day-rate formula stops binding when the days are machine-days. We own the whole stack: the attack agents, the exploitation toolchain and the reporting tools are built in-house, so the marginal cost of a test is compute plus senior review time, not tester-weeks plus scanner licenses plus a sales process. The humans moved up the stack: AI does the coverage no human team can afford to do monthly, and hackers in the loop validate that findings actually exploit, then write the specialized report reviewers actually read. The same stack, pointed at hard targets, has found privately confirmed vulnerabilities in NASA and Tor, a critical remote code execution in velocity.js, and a reported RCE fixed in JSONPath Plus, a library downloaded 12 million times a week. Its runs on the 104-challenge XBOW benchmark are public. The catch, stated plainly: low tiers buy AI-led testing with human validation; fully human-led engagements price like the boutique bands, from anyone.

How to buy without overpaying

Five questions strip the opacity out of any quote:

  1. How many tester-days, at what day rate? It makes quotes comparable.
  2. Who is testing, by name? You are buying a person’s week, not a logo.
  3. Black-box or white-box? Same days, very different depth.
  4. Is the retest included? If not, add 10 to 25% to the real price.
  5. Show me a sanitized report. Your customers and auditors will read it; judge it before paying.

The short version

  • A real web application pentest costs $5,000 to $30,000 in 2026; cloud environments run to $50,000 and beyond.
  • Every human-led quote is tester-days times a $1,200 to $2,500 day rate; cheaper means fewer human hours.
  • Sub-$4,000 quotes at human day rates are scans. Reviewers can tell, and reports get bounced.
  • Compliance sets the cadence: annual for most frameworks, 6-month segmentation for PCI service providers, continuous if you ship fast.
  • Our prices are public: $2,999 a month, $299 for early-stage startups, no quote call required.

More background: does SOC 2 require a penetration test and how our pricing works.

Frequently asked questions

How much does a penetration test cost for a startup?

For a seed-stage product with one web app and an API, plan on 4,000 to 8,000 dollars from a credible boutique firm, or 8,000 to 25,000 with meaningful surface: multiple services, mobile apps, a cloud estate. Below roughly 4,000 dollars you are usually buying a scan, and reviewers can tell.

How long does a penetration test take?

A single web application takes 4 to 12 tester-days of actual work, usually spread over 2 to 4 calendar weeks once scheduling, scoping and report delivery are included. The retest after fixes adds a day or two. Time is the cost driver: every human-led quote is tester-days times a day rate.

Is the retest included in the price?

Ask before signing, because many firms bill the retest separately at 10 to 25 percent of the original fee. PCI DSS 11.4.4 makes retesting mandatory for card environments, and auditors everywhere expect fixed findings to be verified. Continuous testing models sidestep the question: the test never stops, so fixes get re-attacked by default.

Are 500-dollar penetration tests legitimate?

From a firm billing human day rates, no: 500 dollars buys a few hours, enough to run a scanner and paste its output into a template. That is a scan sold as a pentest, and it fails the review it was bought to pass, because security teams read the methodology section first. The exception is AI-led testing where the hours are machine-hours and humans validate the findings, which is the next question.

How often do I need a penetration test?

The baseline expectation across frameworks is every 12 months and after significant changes. PCI DSS puts service providers on a 6-month clock for segmentation testing. Ship weekly and an annual test certifies code that no longer exists, the argument for continuous testing; ship a few times a year and an annual engagement is genuinely enough.

How can an AI pentest cost under 300 dollars a month when firms charge 15,000?

Stack ownership. When the attack agents, exploitation toolchain and reporting tools are all built in-house, the marginal cost of a test is compute plus senior review, not tester-weeks, so the day-rate formula stops applying. Hackers stay in the loop to validate that findings exploit and to write the report. The honest catch: low tiers are AI-led with human validation. A fully human-led engagement prices like a boutique firm, from anyone.