Penetration testing is priced by effort: the number of tester-days required × the day rate of the testers, plus reporting and retesting. Everything else — "per-IP" pricing, "per-app" packages, PTaaS credits — is a different way of packaging that same effort. Once you understand what drives tester-days, quotes become far easier to compare.
Penetration testing price ranges by test type
The ranges below reflect typical market pricing from reputable firms for a single, clearly-scoped engagement including a report and one retest. They are indicative, not quotes.
| Test type | Typical effort | USD (US/EU firms) | INR (India-based firms) |
|---|---|---|---|
| Web application | 5–15 days | $4,000 – $25,000 | ₹40,000 – ₹2,50,000 |
| API (REST/GraphQL) | 4–12 days | $3,000 – $20,000 | ₹35,000 – ₹2,00,000 |
| Mobile app (iOS + Android) | 6–15 days | $5,000 – $25,000 | ₹50,000 – ₹2,50,000 |
| External network | 2–8 days | $3,000 – $15,000 | ₹30,000 – ₹1,50,000 |
| Internal network / Active Directory | 5–20 days | $6,000 – $30,000 | ₹75,000 – ₹3,50,000 |
| Cloud (AWS/Azure/GCP, per account) | 5–20 days | $6,000 – $35,000 | ₹75,000 – ₹4,00,000 |
| Wireless | 2–5 days | $3,000 – $10,000 | ₹30,000 – ₹1,20,000 |
| Social engineering / phishing | 3–10 days | $4,000 – $20,000 | ₹40,000 – ₹2,00,000 |
| Red team / adversary simulation | 4–12 weeks | $30,000 – $150,000+ | ₹5,00,000 – ₹30,00,000+ |
What drives the price of a penetration test
1. Scope and size
For applications, the main drivers are the number of user roles, dynamic pages or screens, API endpoints, and complex workflows (payments, approvals, multi-tenant logic). For networks, it is the number of live hosts and the size of the Active Directory forest. For cloud, it is the number of accounts/subscriptions and services in use.
2. Testing depth and approach
A black-box test (no credentials or documentation) is often shallower for the same budget than a grey-box or white-box test, where testers get accounts, documentation or source code. Grey-box usually delivers the most findings per dollar.
3. Manual vs. automated effort
The cheapest offers are often a vulnerability scan with a pentest label. Manual testing costs more per day, but it is the only way to find authorization flaws, business-logic abuse and chained exploits — the issues that cause real breaches.
4. Tester seniority and certifications
Day rates vary widely by geography and experience. Senior testers with OSWE, OSCE3 or CREST CCT credentials command premium rates — and usually find more, faster.
5. Compliance and reporting requirements
Reports formatted for PCI DSS, SOC 2, ISO 27001 or regulators such as RBI and SEBI may require additional evidence, attestation letters or specific methodology statements.
6. Retesting, timing and logistics
Retesting, after-hours windows, on-site work, urgent start dates and travel all add cost. Ask whether one retest is included.
Pricing models you'll encounter
- Fixed-price per engagement — the most common and the easiest to budget. Make sure the scope is written precisely.
- Time and materials (day rate) — common for red teams and complex environments.
- PTaaS subscriptions or credits — platform-based testing bought in credits or annual plans; good for frequent testing, harder to forecast.
- Per-asset bundles — "per IP" or "per app" packages; check what depth is included per asset.
How to reduce pentest cost without reducing quality
- Provide credentials and documentation (grey-box). Testers spend days on discovery otherwise.
- Fix the easy stuff first — run a vulnerability scan and patch known issues so testers focus on deeper flaws.
- Test in a stable staging environment that mirrors production to avoid downtime and delays.
- Bundle assets — web app, API and cloud together are cheaper than three separate engagements.
- Plan ahead of audit season — urgent starts often carry a premium.
- Consider a strong offshore provider — India-based firms can deliver equivalent depth at lower day rates. Our India-based team delivers senior-led testing for global clients — request a quote.
Red flags in cheap pentest quotes
- A fixed price quoted before any scoping questions were asked.
- Turnaround of 24–48 hours for a full application.
- No named testers or CVs; only "certified team".
- Sample report that lists scanner plugin IDs instead of reproducible steps.
- No retest, or a retest charged at full price.
Frequently asked questions
Why do pentest quotes vary so much?
Quotes differ mainly in tester-days, tester seniority, the share of manual versus automated work, retesting and reporting quality. A cheap quote often means a short, scanner-heavy engagement.
Is retesting included?
Many reputable vendors include one round of retesting of fixed findings within 30–90 days. Confirm this in writing.
Ready to compare? Request a fixed-price quote or explore our penetration testing services.