Cybersecurity Insights & Research

Threat reports, research papers, webinars and whitepapers from the Mercurius security team — staying ahead of the adversary.

Factors that determine the cost of a pentest

How much does a Pentest cost? Pricing factors

How much does a Pentest cost? Factors that influence the price

A pentest is usually priced per project or per day of specialized work, and the total cost depends far more on scope and depth than on any fixed price list. As a broad market reference, a focused test of a single application or external perimeter often falls in the range of a few thousand dollars, while a large, multi-environment engagement driven by compliance can reach tens of thousands. The honest answer is that the real number comes from a scoping conversation, because testing one website and testing an entire financial infrastructure are jobs of a completely different order of magnitude.

This article explains how penetration testing is priced, the factors that move the number up or down, indicative ranges by scope, and how to tell a fair price from a cheap scan disguised as a pentest. If you are new to the topic, the complete pentest guide covers what the test actually involves.

The short answer

There is no universal price for a pentest because there is no universal scope. The cost is a function of how much there is to test, how deep the test goes, and how senior the team is. A small, focused engagement and a broad, compliance-driven one can differ by a factor of ten or more.

The practical takeaway for a buyer: do not ask “how much does a pentest cost” as if there were a sticker price. Ask “what will you test, how deeply, and what will the report let me do”. The answer to that question is what determines both the price and the value.

How pentests are priced

Most providers price a pentest in one of two ways, and understanding the difference helps you compare quotes fairly.

The first model is per project, a fixed fee for a defined scope agreed in advance. This is the most common approach for buyers, because it gives budget certainty. The second model is per day, or per man-day, where the provider estimates the number of specialist days the work requires and multiplies by a daily rate. Complex or open-ended engagements, and Red Team work, are often priced this way.

In both models, the underlying driver is the same: the number of specialist hours the work demands, multiplied by the seniority of the people doing it. Everything below is really a way of estimating those two variables.

The factors that influence the price

The price of a pentest is driven by scope, complexity, test depth, team seniority, and compliance requirements. These are the factors that move a quote up or down:

  1. Scope size. The number of IP addresses, applications, endpoints, and environments in scope. More targets means more hours.
  2. Test depth and model. A black box test with limited access takes fewer hours than a white box test that includes source code review. Depth costs time.
  3. Technical complexity. Custom applications, microservices, cloud architecture, and legacy systems all raise the effort compared to a standard website.
  4. Team seniority. Testers with certifications such as OSCP find issues that automated tools and junior staff miss. That expertise is the single biggest driver of value, and it is reflected in the rate.
  5. Compliance requirements. Tests tied to PCI-DSS or ISO 27001 demand extra documentation rigor and a formal retest, which adds hours.
  6. Retest and support. A proper engagement includes a retest to confirm that the fixes worked. Whether that is included changes the price and the value.
  7. Reporting quality. A detailed, business-ready report with prioritized remediation takes more time to produce than an automated tool export, and it is worth the difference.

Typical price ranges by scope

The ranges below are indicative market references, not a Mercurius quote. They exist to help you budget and to sanity-check the numbers you receive. The real figure always comes from scoping.

Perfis de engajamento de pentest, o que cobrem e faixa indicativa de investimento em USD.
Engagement profile What it covers Indicative range (USD)
Focused A single web application or a small external perimeter 4,000 to 12,000
Standard External and internal network plus one or two applications 10,000 to 30,000
Complex Multiple environments, cloud, custom apps, compliance-driven 30,000 and up

Two caveats matter. First, these ranges shift with region, provider seniority, and the exact scope. Second, a number far below the low end of a range is not a bargain. It is a signal that the “pentest” may be an automated scan, covered in the next section.

Why the cheapest quote is usually a warning sign

The most expensive mistake in buying a pentest is choosing by price alone. A quote that comes in far below the market range almost always means one of two things: the scope was misunderstood, or the “test” is an automated vulnerability scan dressed up as a pentest.

An automated scan produces a long list of potential issues, many of them false positives, with no proof that any of them are actually exploitable. It has value as continuous hygiene, but it is not a penetration test, and it will not stand up to an auditor or protect you from a real attacker. You end up paying twice: once for the scan, and again for the real test you needed in the first place. The right way to compare quotes is on the depth of the methodology and the quality of the report, not on the headline number.

What a fair price should include

A fairly priced pentest is not just the testing hours. It should include, and you should confirm in writing, the following:

  • A clear, agreed scope and rules of engagement before any testing begins.
  • Manual testing by certified specialists, guided by a recognized methodology (PTES, OWASP, NIST SP 800-115), not just an automated scan.
  • A report with an executive summary in business language, findings with proof of exploitation, severity ratings, and prioritized remediation.
  • A mapping of findings to a framework such as MITRE ATT&CK, so the results are defensible and actionable.
  • A retest after remediation to confirm the fixes actually worked.

 

If a quote is missing the manual testing, the retest, or a real report, it is cheaper for a reason, and the gap becomes your risk.

How to reduce the cost without losing quality

You can lower the cost of a pentest responsibly, without cutting the depth that makes it worthwhile. A few practical levers:

  1. Prioritize the scope. Test the assets that carry the most risk first, such as internet-facing systems and applications that handle sensitive data, rather than everything at once.
  2. Provide access up front. A gray box test, where the tester receives a standard user credential, often finds more for the same budget than a pure black box test, because less time is spent on reconnaissance.
  3. Prepare the environment. Having documentation, test accounts, and points of contact ready reduces wasted hours.
  4. Plan a testing cadence. An annual program with a defined scope is easier to budget and often more cost-effective than one-off emergency tests after an incident.

What you should not cut is the manual depth, the seniority of the team, or the report. Those are the parts you are actually paying for.

How Mercurius prices a pentest

Mercurius prices each engagement from a scoping conversation, because a real number requires understanding what is being tested and why. The work is performed by certified engineers (OSCP, OSWE, among other credentials), follows recognized methodologies (PTES, OWASP, NIST SP 800-115), and includes a business-ready report with findings mapped to MITRE ATT&CK and a retest to confirm remediation.

The principle is simple: the price reflects the depth of the work and the seniority of the people doing it, and the report is built to be acted on by both the technical team and the board. If you want a realistic figure for your environment, that scoping conversation is the fastest path to one. Learn more about the pentest and offensive security service, and if you are still weighing pentest against a broader exercise, see Pentest vs Red Team.

The guiding principle is to recommend the exercise that fits the organization’s maturity, never to sell a Red Team to a company that first needs a pentest. Learn about the pentest and offensive security service and the Red Team service, and if you are unsure which one fits your stage, that conversation is the right place to start.

See your network the way an attacker does — before one does!

Mercurius runs manual-led Red Team, penetration testing and cloud assessments that don’t just list vulnerabilities — they prove the exact path an adversary would take to your crown jewels, and how to close it.

Attack Path → Crown Jewels RED TEAM
External Recon TA0043 · exposed asset Initial Access TA0001 · web exploit Priv. Escalation TA0004 · misconfig Lateral Movement TA0008 · cred reuse Crown Jewels
5 steps · 0 alerts triggered ● objective reached

Learn about the pentest and offensive security service from Mercurius

Frequently asked questions

How much does a pentest cost on average? There is no single average, because the cost depends on scope. As a broad market reference, a focused test of one application or external perimeter often falls between 4,000 and 12,000 dollars, a standard engagement covering network and applications between 10,000 and 30,000 dollars, and a complex or compliance-driven engagement above 30,000 dollars. The real figure comes from scoping.

Why do pentest quotes vary so much? Because scope, depth, and team seniority vary. A black box scan of one website and a white box test of a full infrastructure with a source code review are different amounts of work. A very low quote usually means a narrower scope or an automated scan rather than a real pentest.

Is a cheap pentest worth it? Usually not. A quote far below the market range is often an automated vulnerability scan disguised as a pentest, delivering false positives and no proof of exploitation. It will not satisfy an auditor or protect against a real attacker, so you often end up paying again for the real test.

Does the price include a retest? It should. A proper engagement includes a retest after remediation to confirm the fixes worked. Always confirm whether the retest is included, because it materially affects both the price and the value.

How can I reduce the cost of a pentest? Prioritize the highest-risk assets, provide user access for a gray box test to save reconnaissance time, prepare documentation and test accounts in advance, and plan a regular testing cadence instead of one-off emergency tests. Do not cut the manual depth, the team seniority, or the report.

How often should I budget for a pentest? Plan for at least one pentest a year, plus additional tests after significant changes such as a major application release, a cloud migration, or an incident. High-criticality environments often budget for a semiannual or quarterly cadence on their most exposed assets.

Did you enjoy the content? Share it with your network!

Categories

Last contents