Astrovion Logo
Journal

10 min readOleksii Buhaiov

How Much Does a Penetration Test Cost in 2026

What a pentest actually costs in 2026 — the $5,000–$30,000 web-app band, the day rates behind it, how many tester-days each scope takes, which rules really require one, and how to tell a pentest from a scan with a cover page.

  • penetration-testing
  • security
  • compliance
  • soc2
On this page

Cover pentest cost 2026

The US Department of Health and Human Services has put a price on a penetration test. In the cost analysis attached to its proposed HIPAA Security Rule update, it assumes each regulated organisation will spend 3 hours a year on one, at an information security analyst's wage of $119.94 an hour. That is roughly $360. Even HHS's high-end case, 10 hours, stays under $1,200.

Now ask any pentest firm for a quote on a single web application. You will hear something between $5,000 and $30,000.

Neither side is wrong. HHS is costing an employee's afternoon; the market is pricing an external specialist's week. But the gap — one to two orders of magnitude, on the same activity, in the same year — tells you something every buyer should carry through this article: a pentest price is not a price. It is a number of tester-days multiplied by a day rate, and you should always ask for both.

Where these numbers come from

Almost every pentest price guide is written by a company that sells pentests, sells the platform that replaces them, or sells the scanner that competes with them. We have marked each figure with who published it. The exceptions are worth knowing: supplier rate cards filed with the UK government, and HHS's own regulatory text. Full list at the end.


The honest headline answer

A web-application pentest costs $5,000–$30,000 per engagement. A small app from a competent provider usually lands in the lower half — roughly $4,000–$16,000.

That band is the best-corroborated figure in the whole security-compliance space. Astra Security and Blaze Information Security publish the identical $5,000–$30,000 range; a SOC 2 audit directory's $8,000–$25,000 for a standard SaaS scope sits inside it; Invicti — which sells automated scanning and has every reason to make manual tests look expensive — puts web apps at $4,000–$20,000+. When sellers with opposite incentives land in the same place, the shape is probably real.

The lower half comes from the better-attributed recent sources. Stingrai, working from published day rates, derives about $4,100–$6,800 for a small web app and $8,100–$16,300 for a deeper scope. SecureLeap, cited by Bright Defense, reports many of its startup clients paying $4,000–$8,000.

What sits underneath all of it is the day rate:

MarketDay rateWho publishes it
UK public sector£800–£1,200, median £1,00030 supplier rate cards on the UK government's G-Cloud framework, indexed by Stingrai
US$250–$340 an hourBlaze ($250–$300), Secure Ideas' list price ($340)
US$1,000–$3,000 a dayIntruder, via Bright Defense

The UK band is the most solid price data in this entire subject, because it is not an SEO estimate: it is what suppliers formally declared to government buyers. One individual supplier card we checked, filed by Pentest Cyber, lists £900 a day. A former UK pentester on Hacker News independently put boutique rates at £1,000–£1,200 a day — and added that the figure has barely moved in twenty years (one practitioner's recollection, not data).

Headline answer


What your quote buys, in tester-days

Here is the table we could not find in any pentest price guide. It takes the day counts vendors publish for each type of scope and multiplies them by the published day rates. The arrangement and the arithmetic are ours; the inputs are attributed below it.

What's being testedTester-daysUK, at £800–£1,200/dayUS, at $250–$340/hour
Internal network, up to ~150 hosts1–3£800–£3,600$2,000–$8,160
Small web application3–5£2,400–£6,000$6,000–$13,600
API4–9£3,200–£10,800$8,000–$24,480
One mobile platform (iOS or Android)5–10£4,000–£12,000$10,000–$27,200
Full-scope assessment10–20£8,000–£24,000$20,000–$54,400

Day counts: Precursor and EJN Labs, as compiled by Stingrai (September 2026). UK rates: G-Cloud 14 index. The US column assumes an 8-hour day — our assumption, not a published figure.

Three things fall out of it.

The sources don't really disagree — their scopes do. Cobalt's figure for a "traditional" pentest, $20,000–$50,000, looks like an outlier until you notice it matches the full-scope row. Invicti's $4,000–$20,000+ matches a small app through an API. Stingrai's phrase for this is exact: quote variance is scope variance.

Mobile is priced per platform. Invicti's own FAQ adds "per platform" to its mobile range; its main text doesn't. An app on both iOS and Android can be two engagements.

You can reverse any quote. Divide it by the day rate. A $5,000 US quote at $250–$300 an hour is two to three days of work. A "$1,000 pentest" is less than half a day — which is why Bright Defense, asked whether such an offer is usually a real pentest, answers "No, not usually."

The one real contradiction is at the floor. Several vendors now publish fixed prices below the $5,000 band: Cobalt charges $3,500 per autonomous pentest, Intruder $3,500–$4,000 per white-box web-app test, Stingrai from $3,000. Some of those are automated or run with source access, which is a different product from a manual black-box test. Whether it is a worse product depends on what you need the report for — which is the next question.

Tester days


What actually moves the number

Once you think in days, the drivers become obvious — each one either adds days or changes the rate.

DriverWhat it doesSource
Scope — user roles, endpoints, apps, environmentsadds days; the largest single driverevery source
Depth — black-box vs grey-box vs white-boxwhite-box can be far cheaper per asset, because the tester isn't spending days discovering the appAstra; disputed by Intruder's pricing
Retestzero to 1–2 extra days on a 5-day job; "the most common gap between a quoted number and a paid invoice"Stingrai
Compliance evidencereport format, methodology, proof of exploitation that an auditor will acceptNetragard, VikingCloud
Audit timingfor a SOC 2 Type 2, the test should fall inside the observation window — so it is bought on the audit's calendar, not yoursNetragard
GeographyUK public rates imply roughly $180 an hour; US rates run $250–$340Stingrai, Blaze

Retesting deserves its own line in every quote. Blaze includes one round of fix validation within 90 days; Astra notes many providers bill it separately; Bright Defense puts a standalone retest at $2,000–$5,000 (single source, uncited — treat as a rough indication). Under PCI DSS the retest is not optional at all.

There is also a cost that never appears on the invoice: your own team's hours. The only numbers on it come from a 2017 interview study by Chenxi Wang, run in partnership with the PTaaS platform Cobalt: 89 minutes of triage per finding and 7.5 hours of engagement management per traditional test.

Single source — unverified

Those hours, and the study's better-known claim that pentesting-as-a-service is "31% less expensive" than traditional consultancies, trace to one vendor-commissioned study from 2017, republished on Cobalt's blog under a February 2024 date. The interviewees were existing PTaaS customers describing their past consultancy experience; the sample size is not stated. No independent study replicates it. Treat it as a vendor's claim, not a benchmark.

Price drivers


Who actually requires a pentest

This is where most price guides quietly overreach. They price a "SOC 2 pentest" or a "HIPAA pentest" as though a standard demanded it. Mostly, none does.

FrameworkDoes it require a pentest?How oftenStatus
PCI DSSYes — internal and external, by the standard itselfat least annually, and after significant change; fixes must be retestedin force
SOC 2No — Netragard: "Technically, no"expected inside a Type 2 observation windowmarket practice, not a rule
HIPAA (current rule)No specific mandatein force
HIPAA (proposed update)Yes, by a "qualified person"at least every 12 months; vulnerability scans every 6proposed; final rule not expected before July 2027

On SOC 2, the two sources that address it agree the AICPA's criteria don't mandate a pentest, and disagree about who applies the pressure. Drata, a compliance platform with no pentest to sell, says customers demand one in due diligence. Netragard, a pentest firm, says auditors "overwhelmingly expect" it as evidence. Both may be true. Either way, the obligation is negotiated rather than prescribed, which means its scope and cadence are yours to argue.

On HIPAA, the date matters. HHS published the proposed rule in January 2025. It had pencilled in a final rule for spring 2026; that slipped, and the US government's regulatory agenda now targets July 2027. A coalition of more than 100 hospital systems and provider groups has asked HHS to withdraw it, and the head of HHS's Office for Civil Rights has not confirmed it will be finalised at all. A pentest-industry article from April 2026 still told readers the rule would likely be final "by mid-2026". If a vendor tells you HIPAA requires an annual pentest today, that is a sales claim about a proposal.

Two details in the proposed text are worth knowing if you are a software company handling health data. It covers business associates, not only providers. And it requires a "qualified person", not an external firm — which is exactly why HHS could cost it at three hours of an in-house analyst.

Who requires it


The trap: a scan with a cover page

The cheap end of this market has a problem that its own sellers admit to. We found the same warning from five publishers with different incentives:

  • Blaze (manual pentest firm): many cheap offers "are vulnerability scans marketed as penetration tests."
  • SECFORCE (manual pentest firm): if it's much cheaper than average, "it may not be a pentest at all."
  • Invicti — a company that sells automated scanning — says budget pentest offers "can be little more than commissioned automated scans."
  • Bright Defense (compliance reseller): a "$1,000 pentest" is "not usually" a real one.
  • Pentest Cyber, in the rate card it filed with the UK government: "The term Penetration Testing is subjective and often used interchangeably" with a vulnerability scan and a vulnerability assessment.

When the scanner vendor and the manual testers say the same thing, believe it.

How to tell what you're buying

A scan runs automated checks for known vulnerabilities in minutes to hours. A pentest has a person try to exploit what they find, chain weaknesses together, and show you the impact. Before you sign, get:

  1. The number of tester-days and the day rate — in the same sentence. A provider who won't say is usually selling a scan.
  2. A redacted sample report from a past engagement, and the methodology the tester follows.
  3. Proof of exploitation and reproduction steps in the deliverable, not a list of CVE numbers.
  4. Authenticated testing in scope — most of an application sits behind the login.
  5. Retest terms in writing: included or not, how many rounds, within what window.

Two smaller traps are worth a line each. Search for "pentest cost per hour" and you will get wage data mixed with price data: UK contractors are paid a median of about £564 a day while clients are charged around £1,000; a US salary survey gives $29.79 an hour against a $340 list price. And the HHS figure this article opened with is a wage model too. Neither is what a vendor will charge you.

Scan not pentest


Bottom line

Budget $5,000–$30,000 per web application, expect a small app in the lower half, and do not accept any quote you cannot convert into tester-days.

Three moves that protect the number:

  1. Ask for days × rate, then check both. The UK public-sector band is £800–£1,200 a day; US rates run $250–$340 an hour; a small web app takes three to five days. A quote that doesn't reduce to something near those numbers is either a different scope or a different product.

  2. Find out who is actually asking. If it's PCI DSS, the requirement is fixed. If it's a SOC 2 auditor or an enterprise customer, ask what scope and cadence they will accept — and schedule the test inside the audit window so you buy it once. If someone says HIPAA requires it today, ask them for the final rule.

  3. Buy the retest and the report, not just the test. Retest terms, proof of exploitation and authenticated scope are the lines that separate a pentest from a scan — and the lines where quotes and invoices most often diverge.

The failure mode here is not overpaying. It is paying $3,000 for something that looks like a pentest, handing it to an auditor or a customer, and learning it was a scan.

Want to know what a pentest should cost for your product before you collect quotes? We start with a paid security scoping sprint — you walk away with which of your customers and frameworks actually require a test, an asset list with the expected tester-days for each, and a quote checklist covering day rate, retest, authenticated scope and report format. It's yours to keep, whoever ends up running the test. Request a consultation →

Cta security scoping


Sources

Price and day-rate data:

Requirements and regulation:

Third-party figures referenced above are attributed to their originators in the text: Intruder and SecureLeap (via Bright Defense); Secure Ideas, Cobalt's and Intruder's list prices, Precursor, EJN Labs, ITJobsWatch and PayScale (via Stingrai); the AICPA (Trust Services Criteria); the OMB regulatory agenda (via The HIPAA Journal).

All figures are quoted from these publications for commentary and analysis; the tables, comparisons and conclusions in this article are our own. Every image is generated for this article.

astrovion
0%