Penetration testing prices vary enormously, from a few thousand pounds for a focused web application test to well over £50,000 for a full red team engagement. If you’re trying to budget for security testing or compare quotes, this guide gives you the real numbers and explains exactly what drives the difference.
Penetration testing cost by test type
| Test Type | Typical Price Range | Duration |
|---|---|---|
| Network penetration test (internal) | $5,000 – $20,000 | 3–5 days |
| Network penetration test (external) | $4,000 – $15,000 | 2–4 days |
| Web application penetration test | $5,000 – $25,000 | 3–7 days |
| Mobile application test | $5,000 – $20,000 | 3–5 days |
| Social engineering / phishing | $3,000 – $15,000 | 1–2 weeks |
| Cloud security test | $8,000 – $30,000 | 3–5 days |
| Red team exercise | $25,000 – $100,000+ | 2–4 weeks |
These ranges reflect the UK and US market in 2025. Prices at the lower end typically reflect a narrower scope, smaller environment, or less experienced provider. Prices at the upper end reflect comprehensive testing of complex environments by senior certified testers.
What drives the cost of a pen test?
1. Scope: the single biggest factor
Scope is how many systems, applications, or IP addresses are being tested. A single web application with five or six functions is far cheaper to test than a network of 300 servers across multiple sites. Most providers quote per engagement based on scope rather than a day rate, so be specific when requesting quotes.
2. Test type
Web application testing requires different expertise and tools than network testing or red team exercises. Red team engagements (full-scale simulated attacks across all vectors) are the most expensive because they require a team of senior testers working over an extended period.
3. Tester experience and certifications
A test carried out by OSCP-certified, CREST-accredited, or CHECK-approved testers costs more, and delivers more value. The difference between a junior tester running automated tools and an experienced manual tester is significant in the quality of findings. Budget providers often deliver automated scan results dressed up as pen test reports.
4. Duration
More time means more depth. A five-day web application test will find issues a two-day test misses, particularly complex, chained vulnerabilities that require creativity and persistence to discover.
5. Report quality
A good pen test report includes evidence, exploitation walk-throughs, risk ratings, and specific remediation steps. Producing that takes time and expertise, which is reflected in price. Cheap reports often provide a list of vulnerabilities with no remediation guidance and no proof of exploitation.
What’s included in the price?
When comparing quotes, make sure you understand what’s included. A comprehensive pen test engagement should include:
- Scoping call, to define what’s in scope and agree rules of engagement
- Pre-engagement documentation, NDA, rules of engagement, written authorisation
- Active testing, the manual testing phase itself
- Full written report, executive summary plus detailed technical findings
- Debrief call, walkthrough of findings with your technical team
- Retest, verification that your fixes worked (included by some providers, additional fee for others)
Red flags in a pen test quote
- No scoping call, a provider who quotes without understanding your environment is guessing
- Very low price, very short duration, a £1,500 “pen test” completed in half a day is a vulnerability scan at best
- No mention of certifications, ask which certifications the testers hold (OSCP, CREST, CHECK)
- No rules of engagement, any legitimate provider will insist on written authorisation before testing begins
- Report delivered instantly, a genuine manual pen test takes time to document; same-day delivery suggests automation
Is penetration testing worth the cost?
The IBM Cost of a Data Breach Report 2024 puts the average breach cost at $4.88 million. A penetration test typically costs between 0.1% and 0.6% of that figure, and finding one critical vulnerability before attackers do can prevent a breach entirely.
For businesses with compliance obligations (PCI DSS, ISO 27001, SOC 2, HIPAA), pen testing is often not optional. For businesses without those obligations, the cost-benefit calculation still favours testing, particularly if you handle customer data, process payments, or operate in a supply chain with larger organisations that expect security assurance.
How to get an accurate quote
To get a useful quote from a penetration testing provider, be prepared to share:
- What you want tested (web application, internal network, external network, cloud, all of the above)
- How many systems, applications, or IP ranges are in scope
- Any compliance requirements driving the test (PCI DSS, ISO 27001, etc.)
- Whether you’ve had a pen test before, and what was found
- Your preferred testing window (avoid peak business periods)
Get a fixed-price scoping call with no obligation
garrisonOne provides transparent, fixed-price penetration testing with a free scoping call to define exactly what’s needed, no guesswork, no hidden costs.
Request a scoping call →Related reading: New to this topic? Start with What Is Penetration Testing? A Plain-English Guide or see Penetration Testing vs Vulnerability Assessment to understand how it compares to other assessment types.
Frequently Asked Questions
What is the average cost of a penetration test?
Most small to mid-size business penetration tests range from $5,000 to $30,000, depending on scope, while larger multi-system or red team engagements can exceed $100,000.
Why do penetration testing quotes vary so much?
Cost is driven primarily by scope: the number of applications, IP addresses, or systems tested, the testing type (network, web app, API, cloud, or red team), and whether retesting after remediation is included.
What red flags should I watch for in a penetration testing quote?
Be cautious of quotes that are unusually low relative to scope, vendors who cannot clearly explain their testing methodology, and reports that turn out to be automated vulnerability scans rebranded as penetration tests.