Penetration testing cost calculator
Estimate the cost and effort of a penetration test in about a minute. Indicative market ranges, no email required.
A penetration test typically costs between $5,000 and $30,000. A single web application at medium complexity usually runs $8,000 to $20,000 over 4 to 8 consultant-days, while a full red team engagement can exceed $50,000. Price is driven by the number of assets, their complexity, and whether retesting is included.
Estimate your test
A customer-facing or internal web app, tested against the OWASP Top 10.
Applications, IP ranges or cloud accounts of this type.
Indicative range
$10,000 – $24,000
Estimated effort: 5–9.5 consultant-days
Indicative estimate based on market benchmarks — not a quote.
Get an exact quoteWe scope properly before we price. No obligation.
What a penetration test typically costs
Indicative ranges for a single asset at medium complexity, testing production only. Use the calculator above for your own scope.
| What is tested | Typical effort | Indicative cost |
|---|---|---|
| Web applicationA customer-facing or internal web app, tested against the OWASP Top 10. | 4–8 days | $8,000 – $20,000 |
| Mobile applicationAn iOS or Android app plus the APIs it talks to, against OWASP MASVS. | 5–9 days | $10,000 – $22,500 |
| APIA REST or GraphQL API, against the OWASP API Security Top 10. | 3–6 days | $6,000 – $15,000 |
| External networkInternet-facing infrastructure and your public attack surface. | 2.5–6 days | $5,000 – $15,000 |
| Internal networkAssumed-breach testing from inside the perimeter, including AD. | 5–10 days | $10,000 – $25,000 |
| Cloud environmentAn AWS, Azure or GCP account reviewed against CIS benchmarks. | 4–9 days | $8,000 – $22,500 |
| Red team engagementGoal-oriented adversary emulation against people, process and technology. | 12.5–24 days | $25,000 – $60,000 |
These are market ranges drawn from published industry benchmarks, not an IntelligenceX price list. Real pricing depends on scope, and we confirm it with you before any work starts.
What actually drives the price
Number of assets
The biggest single factor. Each additional app, API or network costs less than the first, because methodology, tooling and reporting are set up once.
Complexity, not size
A small app handling payments takes longer than a large brochure site. Roles, business logic and sensitive data drive effort more than page count.
Depth of testing
An automated scan is not a penetration test. Manual, exploit-led testing costs more and is the only thing that finds business-logic flaws.
Retesting
A test that never confirms the fixes leaves you with a report, not a result. Budget for a retest — it is usually about 20% of the original engagement.
Penetration testing cost: common questions
Most penetration tests cost between $5,000 and $30,000. A single web application at medium complexity typically runs $8,000 to $20,000, an external network test $5,000 to $15,000, and a full red team engagement $25,000 to $60,000 or more. The number of assets and their complexity drive the figure more than anything else.
Because 'penetration test' describes everything from an automated scan to weeks of manual, exploit-led testing by a senior consultant. A cheap quote is usually a scan with a report attached. Always ask how many consultant-days are included and how much of the testing is manual.
Almost always by consultant-days. The firm scopes how many days of testing your environment needs, then multiplies by a day rate — typically $2,000 to $2,500 for senior offensive-security consultants. Anyone quoting before scoping is guessing.
Rarely. Below roughly $4,000 there is not enough consultant time to do manual testing, so you are buying an automated scan. That has a place, but it will not find broken access control or business-logic flaws, which is where real breaches begin.
Testing itself usually takes one to three weeks, depending on scope. Add roughly a week for scoping beforehand and reporting afterwards. A retest after your fixes typically takes a further two to three days.
Not always, and you should check. At IntelligenceX a retest is included as standard, because a finding you have not confirmed as fixed is not a finding you have closed.
Neither standard names penetration testing as a mandatory control, but both expect you to evaluate technical vulnerabilities, and auditors routinely accept a penetration test as that evidence. In practice most organisations pursuing either certification run one annually.
Want a real number instead of a range?
Tell us what you are running and we will scope it properly. Most quotes come back within two working days.