Laptop with security lock symbol on circuit board background

Home / Guides & Insights / Penetration testing cost

How much does a penetration test cost in 2026?

Real numbers from a firm that scopes these every week — what each price band buys you, what quietly drives quotes up, and how to spot the $500 "pen test" that's actually a scan with a logo on it.

In 2026, a professional penetration test for a US small or mid-sized business typically costs $4,000–$30,000+: roughly $4,000–$8,000 for an external network test, $6,000–$15,000 for a web application, and $10,000–$30,000 for a combined scope. Anything sold "per test" under about $1,500 is almost always an automated vulnerability scan, not a penetration test.

Pricing for penetration testing is one of the most opaque corners of the security market. Two quotes for "the same test" can differ by a factor of ten, and both vendors will insist theirs is the real one. We scope these engagements every week, so here are the actual numbers, what sits behind them, and the questions that separate a fair quote from an expensive PDF.

What you're actually paying for

A penetration test is skilled human labor. Tools are involved, but the thing you're buying is an experienced person spending days actively trying to break into your systems the way a real attacker would — chaining small weaknesses into real compromise, testing the logic of your application, not just its patch level. The deliverable is a written report a human can act on: what we got into, how, what it means for your business, and exactly how to fix it, ranked by real-world exploitability rather than raw scanner severity.

That's why price scales with scope and complexity rather than with company size. A 15-person fintech with a complex web platform will pay more than a 100-person firm with one office network and no custom software. The question isn't "how big are you" — it's "how much attack surface do you have, and how much of it is custom."

2026 price bands: what each range buys

ScopeTypical 2026 rangeWhat it coversEffort
External network$4,000–$8,000Everything you expose to the internet: firewalls, VPN, mail, remote access, exposed services. The "what can a stranger reach" test.3–5 days
Web application$6,000–$15,000One application tested in depth: authentication, session handling, access control, injection, business-logic abuse. Priced by size and complexity, not page count.5–10 days
Internal network$6,000–$12,000Assumes an attacker (or rogue device) is already inside: lateral movement, privilege escalation, path to your crown jewels.4–8 days
Cloud configuration$5,000–$12,000AWS/Azure/GCP: identities, storage exposure, network paths, secrets handling, logging blind spots.4–8 days
Combined SMB scope$10,000–$30,000External + one application + internal or cloud, tested as one engagement with one report. Most common for compliance deadlines.2–4 weeks

These are the bands we quote and the bands we see credible US competitors quote in 2026. Boutique specialists in regulated niches run higher; large-firm rates can double these numbers for the same technical work.

TYPICAL RANGE (USD, 2026) External network$4k–8k Web application$6k–15k Internal network$6k–12k Cloud config$5k–12k Combined scope$10k–30k

What drives the price up (or down)

When we scope an engagement, five factors move the number more than anything else:

  • Attack surface size. Ten external IPs is not a hundred. One login role is not six. Scope is counted, not guessed — a vendor who quotes without counting is guessing with your money.
  • Custom code. Off-the-shelf systems have known shapes. Your own application needs business-logic testing — the slow, manual work automated tools can't do, and where the worst findings usually live.
  • Compliance target. A test that must satisfy SOC 2, PCI DSS, or an insurer's wording needs specific coverage and reporting language. That's methodology, not padding.
  • Retest included or not. A finding you can't verify as fixed is half a finding. We include one retest in every engagement; some vendors sell it back to you at 20–30% of the original price. Ask up front.
  • Environment fragility. Testing production systems that can't go down (clinics, trading platforms, logistics) means safer techniques, agreed windows, and more coordination time.
Scoping a test right now? Send us your rough scope — IP count, apps, compliance driver — and you'll get a real quote from an engineer, usually within one business day.

The $500 "penetration test" problem

Here's the uncomfortable part of this market. A large share of cheap "penetration tests" are automated vulnerability scans with a cover page. The vendor runs a scanner for an hour, exports the findings, and ships you a 60-page PDF where 55 pages are boilerplate. It's not worthless — scanning has its place — but it is not what an auditor, insurer, or serious customer means by penetration testing, and it will not find the flaws that actually get companies breached: chained misconfigurations, broken access control, business-logic abuse.

Red flags we tell prospects to watch for, in any vendor including us:

  • A fixed price quoted before anyone asked about your scope. Real testing is priced from attack surface; a flat $499/$999 price means the work is fully automated.
  • A report sample that's all scanner output — CVE lists with CVSS scores, no narrative of what was actually exploited and what it led to.
  • No named tester, no methodology (PTES, OWASP), no rules of engagement, no retest.
  • Turnaround measured in hours. Human testing takes days; only scanners finish overnight.

If you only have scan money, buy a scan — honestly labeled, they're a few hundred dollars a month and genuinely useful. We explain the difference in detail in penetration test vs. vulnerability scan.

How we scope a quote (so you can compare anyone's)

Our process is four steps, and any credible firm's will look similar. First, a short technical call — what's exposed, what's custom, what's the driver (insurer, SOC 2, customer due diligence, or just wanting to know). Second, we count the scope: external IPs, application roles and endpoints, cloud accounts, internal segments. Third, you get a fixed price against that written scope — no hourly meters running. Fourth, the engagement itself: testing, a report written by the person who did the work, a walkthrough call, and a retest of fixed findings included. The crypto exchange we built and tested ran on exactly this model.

Is it worth it? The honest version

A penetration test is not the first thing every company should buy — and we say that selling them. If you don't have tested backups, MFA everywhere, and patched systems, spend there first; a test will just document what you already suspect. A pen test earns its price when the basics exist and you need to know what a motivated attacker could still do — or when someone with leverage (insurer, enterprise customer, auditor, regulator) requires proof. One real engagement produces the report you'll reuse for every questionnaire that year, and findings you fix once instead of arguing about annually.

Three worked examples (so the bands mean something)

A 12-person SaaS startup with one web application, one AWS account, and an enterprise prospect asking for "evidence of penetration testing." The right scope is the application plus a light external test — not the kitchen sink. Realistic spend: $8,000–$14,000, with the report written so it can be handed straight to the prospect's security team. The mistake to avoid: buying a cheap external-only test that never touches the app the customer actually cares about.

A 45-person clinic with no custom software but HIPAA exposure, one office network, remote access for billing staff, and a cyber insurance renewal asking about testing. External plus internal network is the meaningful scope: what can a stranger reach, and what can malware on a receptionist's PC do next. Realistic spend: $9,000–$16,000. The application tier isn't needed; the internal tier absolutely is — flat internal networks are where clinic incidents become clinic catastrophes.

A 30-person fintech with a customer-facing platform, KYC data, and a banking partner's due-diligence list. This is the combined scope — external, application with all user roles, and cloud configuration — because the partner will read the report, not just file it. Realistic spend: $15,000–$30,000 depending on application complexity. Here the report quality matters as much as the testing: findings written for engineers, an executive summary written for the bank.

Budgeting the full cycle, not just the test

The quote is not the whole cost, and pretending otherwise is how testing budgets fail. A realistic annual cycle looks like: the engagement itself; then remediation time — your team's or your provider's hours fixing what was found, which for a first-ever test is commonly days of engineering work; then the retest confirming fixes (included with us; up to 30% extra elsewhere — ask); then the delta next year, which is cheaper in effort terms because the backlog is smaller. First-year total for a typical SMB combined scope, all-in with remediation: plan around 1.5× the test price. From year two, closer to 1.2×. Companies that budget only the test price fix half the findings, fail the retest they didn't buy, and repeat the whole conversation twelve months later from scratch.

Frequently asked questions

Is a penetration test worth it for a small business?

Yes, when the basics are in place and there's a concrete driver — an insurer, a compliance framework, a big customer's security questionnaire, or real exposure like a customer-facing application. If the basics are missing, a security assessment that fixes fundamentals delivers more per dollar first.

How long does a penetration test take?

Typically one to three weeks from kickoff to report for an SMB scope: three to five days of active testing for a single external scope, up to two to four weeks for combined external, application, and internal work. Add a few days for the retest after you fix findings.

How often should we test?

Annually is the standard cadence, and after any major change — new application, infrastructure migration, acquisition. Most compliance frameworks and insurers expect at least annual testing; continuous vulnerability scanning fills the gap between tests.

Can a penetration test break our systems?

A properly run test shouldn't. Rules of engagement define what's off-limits, dangerous techniques are agreed in advance, and fragile production systems get safer methods and scheduled windows. Ask any vendor how they handle exactly this — the answer tells you a lot.

What should the report contain?

An executive summary in business language, a narrative of what was exploited and the path taken, each finding with evidence, impact, and a concrete fix, severity ranked by real exploitability, and a retest confirming what got fixed. If a sample report is just a CVE table, keep shopping.

Get a scoped quote How we run pen tests

Price ranges reflect our 2026 scoping and observed US market rates for comparable manual testing; your scope determines your number. General information, not a quote.