Scope-based estimator

Penetration Testing Cost Calculator

Penetration test pricing is almost entirely a function of tester-days. Describe the scope below and this estimator converts it into a realistic 2026 quote range, including the retest that auditors and enterprise buyers usually want to see.

Scope

Multi-role app, integrations, ~30–100 screens

Separate apps, environments or network ranges tested in the same engagement.

More information given to testers means deeper coverage per day — and a higher day count.

A retest produces the clean letter most auditors and procurement teams ask for.

Estimated cost

Estimated penetration test cost

$11,880$32,120

Web application · medium scope · 1 target · retest included

Itemised cost breakdown
Cost lineLowHigh
Web application penetration test1 target, greybox methodology. Most firms quote from estimated tester-days at roughly $1,800–$2,800 per day.$8,000$16,000
Reporting and readoutWritten report, executive summary and a live debrief. Usually bundled, itemised here so you can see it.$640$1,920
Remediation retestVerification pass after fixes, producing the clean letter auditors and enterprise buyers ask for.$1,200$4,000
Internal time (scoping, fixes, coordination)24–120 engineering hours at $85/hour for scoping calls, environment prep and remediating findings.$2,040$10,200
Total estimated first-year cost$11,880$32,120

How this estimate is built

Reputable testing firms scope an engagement in tester-days and bill roughly $1,800–$2,800 per day in the US market for 2026, with boutique specialists and CREST/OSCP-heavy teams at the upper end. A small single web application is typically 3–5 days; a large multi-tenant platform with several roles and integrations can run 12–20 days. That day-count arithmetic is what produces the $4,000–$30,000 band you see across the industry.

Grey box is the default assumption in this model: testers receive credentials and basic architecture context, which buys far more coverage per day than pure black box. White box adds source code review, raising the day count by roughly a quarter. Black box looks cheaper but frequently finds less, and repeat black-box tests are a common way to spend money without reducing risk.

Two lines get forgotten in most budgets. The first is the retest: fixes need verification, and the verification letter is the artefact your auditor files. The second is your own engineering time — scoping calls, standing up a test environment, triaging findings and shipping fixes. We estimate 24–120 hours at $85 per fully-loaded hour.

Typical day counts by scope

ScopeSmallMediumLarge
Web application3–5 days5–8 days8–15 days
API2–4 days4–7 days7–13 days
Mobile application3–5 days5–9 days9–15 days
Network2–4 days4–7 days7–13 days
Cloud configuration review3–5 days5–9 days9–15 days

How to get a cheaper test without getting a worse one

  • Scope precisely. A written scope with endpoint counts, user roles and environment details lets a firm quote days instead of padding for uncertainty.
  • Test a staging clone. Production testing windows, change freezes and rate limits all add days.
  • Fix the obvious first. Running your own dependency and configuration scans before the engagement means you pay tester-days for depth, not for findings a scanner would have caught.
  • Book annually, not reactively. Firms discount recurring engagements and already understand your architecture on the second pass.

If the test is part of a broader audit program, put the number back into the SOC 2 calculator or the ISO 27001 calculator to see your total compliance spend.