Penetration Testing Pricing
Every engagement is quoted as a fixed fee, in writing, within 24 hours. This page explains what drives that figure, what each tier covers, and what is included regardless of what you spend.
Three shapes of engagement
Tiers describe scope, not a shelf price. Most quotes land in one of these three shapes — the exact fee comes out of the scoping conversation.
Essential
A single application or a small external footprint
Quoted on scope
One web or mobile application, or a contained external network range. The usual fit for a first test, a startup answering its first security questionnaire, or an annual re-test of a stable app.
- One application or external range in scope
- Up to two authenticated user roles
- OWASP Top 10 and business-logic testing
- Risk-rated report with proof-of-concept
- Complimentary retest of critical and high findings
Professional
Multiple assets, or one asset with real complexity
Quoted on scope
Several applications, an application plus its API, or an internal and external network test together. The usual fit for a SaaS platform under enterprise procurement or a business preparing for an audit.
- Multiple applications, APIs, or network ranges
- All authenticated roles, including administrative
- API, cloud configuration, and multi-tenancy testing
- Compliance-aligned reporting (SOC 2, ISO 27001, PCI DSS)
- Remediation support call with your engineers
- Complimentary retest of all findings
Enterprise
Programme-level testing across an estate
Quoted on scope
A recurring testing programme, a red-team exercise, or an estate-wide assessment across subsidiaries and environments. Scoped as a programme with a named lead consultant throughout.
- Estate-wide or programme-based scope
- Red teaming and adversary simulation available
- Active Directory and internal infrastructure testing
- Named lead consultant and scheduled reporting cadence
- Attestation letters and auditor-ready evidence packs
- Retesting built into the programme schedule
What actually moves the number
Six factors decide what an engagement costs. Nothing else does — there is no per-seat licence and no platform fee.
Size of the scope
The number of applications, IP ranges, endpoints, or cloud accounts in scope. A single web app and a 300-host internal network are not the same job.
Authenticated roles
Every distinct user role is a separate set of permissions to attack. Testing admin, staff, and customer roles takes materially longer than testing one.
Type of engagement
A black-box external test, a fully authenticated grey-box assessment, and a red-team exercise with evasion requirements are different depths of work.
Reporting requirements
Standard reporting is included. Attestation letters and evidence packs mapped to a specific framework — PCI DSS 11.4, SOC 2, ISO 27001 — add scoped effort.
Timeline
Standard lead time is included in the quoted fee. Compressed schedules and out-of-hours testing windows carry a premium because they displace other work.
Complexity, not page count
A small application with heavy business logic, a payment flow, and multi-tenancy is a bigger test than a large brochure site. We scope on logic, not size.
What you get regardless of budget
These are not upsells and they are not tier-gated. They are the standards we hold ourselves to on every engagement we take.
See what we testQuestions about cost
Still unclear on something? Ask before you commit — scoping is free.
Because a penetration test is not a product with a shelf price — the same headline figure would be a bargain for one client and poor value for another. Cost tracks the scope, the number of authenticated roles, and the depth of testing required. What we do commit to is a fixed fee, quoted in writing within 24 hours of scoping, that does not move once agreed.
Get a fixed-fee proposal within 24 hours
Tell us what is in scope and a certified consultant will price it — in writing, with no obligation and no sales team in the middle.