Scope-based estimator
Penetration Testing Cost Calculator
Penetration test pricing is almost entirely a function of tester-days. Describe the scope below and this estimator converts it into a realistic 2026 quote range, including the retest that auditors and enterprise buyers usually want to see.
Scope
Multi-role app, integrations, ~30–100 screens
Separate apps, environments or network ranges tested in the same engagement.
More information given to testers means deeper coverage per day — and a higher day count.
A retest produces the clean letter most auditors and procurement teams ask for.
Estimated cost
Estimated penetration test cost
$11,880 – $32,120
Web application · medium scope · 1 target · retest included
| Cost line | Low | High |
|---|---|---|
| Web application penetration test1 target, greybox methodology. Most firms quote from estimated tester-days at roughly $1,800–$2,800 per day. | $8,000 | $16,000 |
| Reporting and readoutWritten report, executive summary and a live debrief. Usually bundled, itemised here so you can see it. | $640 | $1,920 |
| Remediation retestVerification pass after fixes, producing the clean letter auditors and enterprise buyers ask for. | $1,200 | $4,000 |
| Internal time (scoping, fixes, coordination)24–120 engineering hours at $85/hour for scoping calls, environment prep and remediating findings. | $2,040 | $10,200 |
| Total estimated first-year cost | $11,880 | $32,120 |
How this estimate is built
Reputable testing firms scope an engagement in tester-days and bill roughly $1,800–$2,800 per day in the US market for 2026, with boutique specialists and CREST/OSCP-heavy teams at the upper end. A small single web application is typically 3–5 days; a large multi-tenant platform with several roles and integrations can run 12–20 days. That day-count arithmetic is what produces the $4,000–$30,000 band you see across the industry.
Grey box is the default assumption in this model: testers receive credentials and basic architecture context, which buys far more coverage per day than pure black box. White box adds source code review, raising the day count by roughly a quarter. Black box looks cheaper but frequently finds less, and repeat black-box tests are a common way to spend money without reducing risk.
Two lines get forgotten in most budgets. The first is the retest: fixes need verification, and the verification letter is the artefact your auditor files. The second is your own engineering time — scoping calls, standing up a test environment, triaging findings and shipping fixes. We estimate 24–120 hours at $85 per fully-loaded hour.
Typical day counts by scope
| Scope | Small | Medium | Large |
|---|---|---|---|
| Web application | 3–5 days | 5–8 days | 8–15 days |
| API | 2–4 days | 4–7 days | 7–13 days |
| Mobile application | 3–5 days | 5–9 days | 9–15 days |
| Network | 2–4 days | 4–7 days | 7–13 days |
| Cloud configuration review | 3–5 days | 5–9 days | 9–15 days |
How to get a cheaper test without getting a worse one
- Scope precisely. A written scope with endpoint counts, user roles and environment details lets a firm quote days instead of padding for uncertainty.
- Test a staging clone. Production testing windows, change freezes and rate limits all add days.
- Fix the obvious first. Running your own dependency and configuration scans before the engagement means you pay tester-days for depth, not for findings a scanner would have caught.
- Book annually, not reactively. Firms discount recurring engagements and already understand your architecture on the second pass.
If the test is part of a broader audit program, put the number back into the SOC 2 calculator or the ISO 27001 calculator to see your total compliance spend.