What You Are Actually Paying For
When a provider quotes a penetration testing cost, the figure reflects human effort far more than technology. Skilled testers spend their time understanding the target, chaining small weaknesses into a realistic attack path, and documenting what they found so that another team can act on it. Every hour in the estimate maps to one of those activities, which is why the shape of the work — not the logo on the report — determines the price.
Two quotes for the same system can differ substantially without either being unreasonable. The gap usually comes down to how many days the scope genuinely requires, which type of testing was assumed, and how much of the deliverable is original analysis rather than output from an automated tool.
Effort Is Measured in Tester-Days
Most established firms build an estimate from tester-days: one tester working for one day. That figure is multiplied by a daily rate, and a fixed amount is added for reporting and project management. When you read a proposal, look for the breakdown rather than the total. A quote that says “assessment: one lump sum” tells you very little, while one that says “six tester-days plus two reporting days” tells you exactly what was assumed and gives you something concrete to negotiate against.
Day rates vary with seniority, region, and specialization. A generalist covering a small external footprint sits at one end of the range; a specialist who has spent years inside a particular technology stack sits at the other. You are rarely paying for scarcity alone. You are paying for the ability to recognize a subtle issue quickly instead of discovering it after several days of exploration.
Scope Size Sets the Floor
Scope is the largest single variable. The number of hosts, applications, user roles, and environments all multiply the work. Ten externally facing services do not cost ten times as much as one, but they cost meaningfully more than two, because each surface needs its own reconnaissance and its own attempt at exploitation.
Depth Matters as Much as Breadth
Two scopes with the same number of targets can differ enormously in effort depending on how deep the testing is expected to go. A configuration review that checks known weaknesses and reports them is one job. A full attempt to chain access from an unauthenticated starting point to a sensitive internal system is quite another. Both are legitimate; they answer different questions and carry different price tags.
Different Test Types, Different Effort Levels
- External network testing: the internet-facing estate, often the most standardized engagement
- Internal network testing: assumes an initial foothold, useful for validating segmentation
- Web and API application testing: usually the most labor-intensive work per target
- Mobile application testing: adds device, storage, and backend interaction effort
- Social engineering: priced by campaign size, staff numbers, and coordination overhead
- Adversary simulation: multi-stage, measured in weeks rather than days, and priced accordingly
Matching the test type to the question you are trying to answer is the single biggest lever on value. Buying an adversary simulation because it sounds comprehensive, when your real concern is a newly launched customer portal, spends money on the wrong question.
Reporting Quality Changes the Price
Part of what you buy is the report. A useful one includes a business-readable summary, findings with clear reproduction steps, an honest severity rating, the evidence that supports each rating, and remediation guidance specific enough to be implemented. Producing that takes time. A cheaper engagement that returns raw scanner output and a list of headings offloads the interpretation onto your team, which is rarely the saving it first appears to be.
How to Compare Proposals Fairly
- Normalize the scope: confirm both quotes cover the same hosts, roles, and environments.
- Confirm the test type and depth in writing, including whether authenticated testing is included.
- Ask for tester-days and reporting days as separate line items.
- Request a sample report so you can judge the deliverable, not just the testing.
- Check what happens after the engagement: is a retest of fixed issues included, and at what cost?
Frequently Asked Questions
Why do quotes for the same scope vary so widely?
Different assumptions about depth, the seniority of assigned testers, and how much analysis goes into the report. Ask each provider to state its assumptions, then compare like with like rather than the headline number.
Is a lower price a warning sign?
Not by itself, but an unusually low figure often means a shallower test, a less experienced team, or a templated report. Ask what the estimate excludes before drawing conclusions.
Can we reduce cost without weakening the test?
Yes. Narrowing scope to the systems that matter most, providing good documentation and test accounts up front, and consolidating related applications into one engagement all reduce effort without lowering quality.
Should we budget for a retest?
It is wise to. A retest confirms that fixes actually resolved the finding, and it is typically far cheaper than the original engagement because the scope is already known and the environment familiar.
Stepping back, a sound approach is to estimate effort first and apply rates second, rather than anchoring on a round number and asking providers to fit inside it. Anchoring on price encourages scope cuts that are invisible in the proposal and painful in the report. Agree on what must be tested, how deep the testing should go, and how results will be delivered, then price that arrangement.
This article offers general information about how assessment engagements are structured and priced. It is not professional advice. Engage qualified providers and advisors for decisions affecting your organization.