How much does penetration testing cost?

A real penetration test costs $5,000 to $30,000 for a single web application in 2026. Below about $4,000 you are almost always buying an automated scan with a report cover. Cloud environments run to $50,000 and beyond. Every consultancy quote reduces to one formula: tester-days multiplied by a day rate. Here is that math, including our own numbers.

Infographic of 2026 penetration testing prices: 5,000 to 30,000 dollars for a real web app, under 4,000 is usually a scan

On this page: the price bands · the day-rate math · the AI pentest wave · why quotes differ 10x · the $500 pentest · what compliance makes you buy · our prices · how it gets this cheap

The price bands in 2026

Almost no firm in this market publishes prices. Directories of hundreds of providers list exactly zero rate cards, so every guide to this question is vague. The bands below are the published data that does exist, and they match what founders report paying.

Range chart of 2026 penetration testing price bands per engagement type, from automated scans to cloud environments, compared on the same dollar scale with the new AI pentest wave, including HackZero at 299 to 499 dollars a month and 2,999 dollars per human-validated engagement

What you are testing2026 market bandWhat pushes you up the band
Web application$5,000 to $30,000roles, payments, file handling, tenant isolation
API$6,000 to $30,000endpoint count, auth models, third-party consumers
Mobile app$7,000 to $35,000 per platformiOS and Android are separate engagements
Network$5,000 to $40,000host count, internal plus external, segmentation
Cloud environment$10,000 to $50,000+multi-account sprawl, IAM complexity
Automated scan sold as a pentest$300 to $2,000nothing: the tool run costs the same everywhere

The bands are from DeepStrike’s 2026 pricing guide, one of the few firms that publishes them, and they have held for years. Here is the same range on Hacker News in 2017:

$40k would be a pretty standard price point for a regular pentest.

That is a security practitioner writing in 2017. Nine years on, the consultancy mid-market still quotes the same numbers: the delivery model changed, the day-rate economics did not.

The day-rate math behind every quote

Strip away the sales language and every quote is the same calculation: the tester-days your scope needs, multiplied by what the firm’s testers cost per day.

Diagram of the day-rate math behind penetration test quotes, showing a ten day web application engagement priced between 12,000 and 25,000 dollars

What a tester-day costs

Work the published bands backwards: $5,000 to $30,000 for a web application over the 4 to 12 tester-days such engagements take implies roughly $1,200 to $2,500 a day. Junior-heavy shops sit at the bottom, senior boutiques and brand-name consultancies at the top. A quote far below that range is not defying economics; it is spending fewer person-hours on you, usually a scanner’s.

How many days your scope needs

Day count is driven by attack surface, not company size. One login role, a handful of forms and no payment flow is a 4 to 6 day test. Multi-tenant SaaS with role hierarchies, integrations and file uploads is 8 to 12. The quote call is really a surface census: arrive with an endpoint count, role list and architecture sketch, because firms price uncertainty.

What the new AI pentest wave charges

A generation of AI-led pentest companies entered the market in the last two years, and the surprise is how little pricing changed. RunSybil (founded by OpenAI’s first security hire, $40 million raised) publishes no prices. Horizon3’s NodeZero is quote-only through sales and the AWS Marketplace. Most of the wave rebuilt the consultancy playbook with a faster engine. XBOW is the exception:

Pricing starts at $6,000 so teams can test earlier and more often.

That is XBOW’s launch pricing for one machine-run, human-reviewed test, against their own market read of $10,000 to $35,000 per typical engagement. How far the floor can drop is a stack-ownership question: where our numbers come from.

Why two quotes for the same app differ by 10x

Founders collect quotes of $6,000 and $60,000 for the same application; neither is a scam, they price different amounts of work.

Methodology depth is the hidden variable

A black-box test attacks from outside with no credentials or source access. A white-box test reads your code while attacking, which finds deeper bugs in the same number of days. Ours is white-box by default. When comparing quotes, ask which one you are getting: a $9,000 white-box test routinely outperforms a $25,000 black-box test on findings that matter.

Who actually does the testing

The person matters more than the logo. Big consultancies bill partner-grade rates and staff junior testers; boutiques run senior people at similar prices. Cobalt’s 2026 State of Pentesting report, drawn from 1,500+ customers, shows how much delivery model matters:

Organizations with a programmatic model are 4.5x more likely to resolve critical findings in three days or less compared to ad-hoc teams.

The same report found 40% of organizations still test primarily for compliance. Even then quality matters, because the report gets read: see why a scan gets bounced.

A $500 pentest is a scan with a cover page

At $1,200 to $2,500 a day, $500 buys a few hours, and the only thing deliverable in a few hours is a tool run reformatted into a report. PCI DSS 11.4.1, the strictest testing standard in production use, frames the bar as attacks “by a competent manual attacker” (the standard is in the official PCI document library).

A scan has value as hygiene between tests. Sold and submitted as a penetration test, it fails: enterprise reviewers read the methodology page before the findings and bounce reports that describe a tool run. Our manual pentest comparison shows what a human-plus-AI engagement covers that a scanner cannot. The exception that keeps $299 a month honest: machine-hours instead of billed human days (how that works).

What compliance actually makes you pay for

Compliance buys roughly two in five tests, so here is what each framework actually obliges you to spend:

  • SOC 2: $0 mandated, one test expected. No criterion requires a pentest, but your auditor expects a recent one inside your observation window. The full analysis is in does SOC 2 require a penetration test. Budget one real test a year.
  • PCI DSS: two tests plus retests, forever. Internal and external testing every 12 months and after significant change, a mandatory retest, and 6-month segmentation tests for service providers: the clause by clause breakdown.
  • HIPAA: annual testing is coming. The proposed Security Rule update (90 FR 898) would mandate a penetration test every 12 months. HHS’s own impact analysis prices that test at $359.82 (3 hours at $119.94 an hour); real market pricing is 15 to 80 times higher.

Our prices, published

Hiding prices is how this market got opaque, so here are ours. One product, two prices, split on headcount. Both include SOC 2 controls, continuous monitoring, and an AI pentest every month, or unlimited pentests if you bring your own Anthropic key, because the real cost of a run is model tokens. Headcount is self-attested: no application, no approval, no waitlist.

WhoPriceWhat it includes
Fewer than 10 people$299 a month, or $2,990 a yearSOC 2 controls, continuous monitoring, one AI pentest a month, unlimited on your own Anthropic key
10 people or more$499 a month, or $4,990 a yearthe same
Human-validated pentest$2,999 per engagementhackers confirm exploitability and write the report, added on top of any plan, never a subscription
SOC 2 attestationfrom $2,500paid straight to an independent AICPA-member CPA, never billed through us, which is what keeps the audit independent

The math in the open. Under 10 people it is $299 x 12 plus a $2,500 CPA, so $6,088 for the year, or $5,490 if you pay the year up front at $2,990. At 10 people or more it is $499 x 12 plus the same CPA, so $8,488, or $7,490 paid annually.

Both numbers sit against the $30,000 to $45,000 the traditional three-vendor stack costs, and the plan runs a pentest every month instead of the retail stack’s one or two. Want hackers driving a named engagement on top? That is $2,999, once, per engagement.

Still true: if you ship a few times a year, an annual $8,000 boutique engagement is the right buy. A 20-minute call settles it; the full price list is on /pricing.

How a real pentest gets this cheap

The day-rate formula stops binding when the days are machine-days. We own the whole stack: the attack agents, the exploitation toolchain and the reporting tools are built in-house, so the marginal cost of a test is compute plus senior review time, not tester-weeks plus scanner licenses plus a sales process.

AI does the coverage no human team can afford monthly, and hackers in the loop validate that findings actually exploit, then write the report reviewers actually read. The same stack, pointed at hard targets, has found privately confirmed vulnerabilities in NASA and Tor, a critical remote code execution in velocity.js, an RCE in JSONPath Plus (PR #266, 12 million downloads a week), and a cookie-leak in tough-cookie, half a billion a month. Its runs on the 104-challenge XBOW benchmark are public.

The catch, stated plainly: the subscription buys AI-led testing with human validation. If you want hackers driving a named engagement, that is a $2,999 add-on, once, per engagement, which is still under the floor of the boutique bands above.

How to buy without overpaying

Five questions strip the opacity out of any quote:

  1. How many tester-days, at what day rate? It makes quotes comparable.
  2. Who is testing, by name? You are buying a person’s week, not a logo.
  3. Black-box or white-box? Same days, very different depth.
  4. Is the retest included? If not, add 10 to 25% to the real price.
  5. Show me a sanitized report. Your customers and auditors will read it; judge it before paying.

The short version

  • A real web application pentest costs $5,000 to $30,000 in 2026; cloud environments run to $50,000 and beyond.
  • Every human-led quote is tester-days times a $1,200 to $2,500 day rate; cheaper means fewer human hours.
  • Sub-$4,000 quotes at human day rates are scans. Reviewers can tell, and reports get bounced.
  • Compliance sets the cadence: annual for most frameworks, 6-month segmentation for PCI service providers, continuous if you ship fast.
  • Our prices are public: $299 a month under 10 people and $499 at 10 or more, with a human-validated pentest at $2,999 per engagement. No quote call, no application.

More background: does SOC 2 require a penetration test, what a SOC 2 audit costs line by line, and how our pricing works.

Frequently asked questions

How much does a penetration test cost for a startup?

For a seed-stage product with one web app and an API, plan on 4,000 to 8,000 dollars from a credible boutique firm, or 8,000 to 25,000 with meaningful surface: multiple services, mobile apps, a cloud estate. Below roughly 4,000 dollars you are usually buying a scan, and reviewers can tell.

How long does a penetration test take?

A single web application takes 4 to 12 tester-days of actual work, usually spread over 2 to 4 calendar weeks once scheduling, scoping and report delivery are included. The retest after fixes adds a day or two. Time is the cost driver: every human-led quote is tester-days times a day rate.

Is the retest included in the price?

Ask before signing, because many firms bill the retest separately at 10 to 25 percent of the original fee. PCI DSS 11.4.4 makes retesting mandatory for card environments, and auditors everywhere expect fixed findings to be verified. Continuous testing models sidestep the question: the test never stops, so fixes get re-attacked by default.

Are 500-dollar penetration tests legitimate?

From a firm billing human day rates, no: 500 dollars buys a few hours, enough to run a scanner and paste its output into a template. That is a scan sold as a pentest, and it fails the review it was bought to pass, because security teams read the methodology section first. The exception is AI-led testing where the hours are machine-hours and humans validate the findings, which is the next question.

How often do I need a penetration test?

The baseline expectation across frameworks is every 12 months and after significant changes. PCI DSS puts service providers on a 6-month clock for segmentation testing. Ship weekly and an annual test certifies code that no longer exists, the argument for continuous testing; ship a few times a year and an annual engagement is genuinely enough.

How can an AI pentest cost under 300 dollars a month when firms charge 15,000?

Stack ownership. When the attack agents, exploitation toolchain and reporting tools are all built in-house, the marginal cost of a test is compute plus senior review, not tester-weeks, so the day-rate formula stops applying. Hackers stay in the loop to validate that findings exploit and to write the report. The honest catch: the subscription is AI-led with human validation. If you want hackers driving a named engagement, that is 2,999 dollars per engagement, once, on top of the 299 or 499 a month.