Skip to content
2026

Now taking on 4 new clients this year — white-glove onboarding, month to month.

Book a call
HomeBlogCost Guides

How Much Does Penetration Testing Cost?

Security engineer reviewing a network map and terminal output on two monitors in a dimly lit office

Penetration testing cost is set by scope before anything else: what is being attacked, how deep the tester goes, and how much of the work is done by hand. An external test of a few public systems is a small engagement. A full review of a custom application's source code is a much larger one. NetSys does not publish a price list. Our Tier 1 external penetration test is free for any business, and our Tier 2 source code test is quoted per codebase after we look at what you have built. The rest of this guide explains what moves a penetration testing quote up or down, what a good quote should include, and how to compare two proposals that look nothing alike.

What moves the price of a penetration test?

Cost driverWhat it meansEffect on the quote
Scope typeExternal network, web application, internal network, wireless, social engineering, source codeEach scope is its own engagement with its own hours
Size of the targetPublic IP addresses, applications, user roles, API endpoints, lines of codeHours scale with the size of the attack surface
Depth of accessBlack box (no information), grey box (credentials and documentation), white box (source and architecture)More access means more findings and more hours
Manual versus automatedA scanner run with a cover page, or an engineer chaining findings by handManual work is what you are paying for
RetestVerifying your fixes after remediationIncluded, capped, or billed as a new engagement
Report qualityExecutive summary, reproduction steps, evidence, ranked fixesWriting time is engineer time
Compliance driverPCI DSS, SOC 2, HIPAA, a customer's security questionnaireAdds methodology and attestation requirements

How are external, web application, internal and source code tests priced differently?

An external test starts from the internet with no credentials. The tester maps what your domain and public IP addresses expose, checks logins and remote access, and looks at what public records and staff profiles give an attacker to work with. Hours scale with the number of hosts and exposed services. For most small businesses that is a short list, which is why external testing sits at the low end of the market and why NetSys can offer its Tier 1 version at no charge.

A web application test is priced by the application, and within that by user roles, forms and API endpoints. An application with a public login, a customer role, an administrator role and a mobile API has several times the ground to cover of a brochure site with a contact form. Testers work from the OWASP Web Security Testing Guide, and a quote should say which categories will be covered.

An internal test assumes the attacker is already inside: a phished laptop, a rogue device on the office network, or a contractor's account. The tester tries to move from that foothold to domain administrator. This is usually the most expensive network test because it touches the most systems, and because a careful tester avoids knocking over production while doing it.

A source code test is a different animal. The engineer reads the code, builds and runs it in an isolated environment, attacks the running application and its APIs, and scans dependencies and committed secrets. Cost follows the size and age of the codebase, the number of languages and frameworks involved, and how much of the build the tester has to reconstruct. NetSys quotes Tier 2 per codebase for exactly this reason: two applications with the same feature list can take very different amounts of work.

Is the retest included in the price?

A penetration test that finds twelve problems is only useful once those twelve are fixed and confirmed fixed. Some firms include one retest of the reported findings within a set window. Others cap the retest at a number of hours. Others treat it as a new engagement at full price. None of those is wrong, but you need to know which one you are buying before you sign, because a retest bought later at full rate can double the cost of the project.

Ask how long after delivery the retest window stays open, whether the retest covers every finding or only those rated high and critical, and whether a second retest is available if a fix introduces a new problem. Firms that include a retest are betting you will fix things, which is a good sign about who you are hiring.

Why does report quality change the price?

The report is the product. A cheap test tends to deliver scanner output with a logo on the front: hundreds of pages, most of it informational, with no indication of which items an attacker would use together. A good report has an executive summary a business owner can read in ten minutes, a ranked list of fixes with the effort each one takes, and a reproduction path with evidence for every finding, so your engineer or your IT provider can confirm the problem and later confirm the fix.

Writing that takes a meaningful share of the engagement hours, and it is one of the first things to go when a firm competes on price. When you compare quotes, ask for a sanitized sample report. If the sample would not tell you what to do on Monday morning, the price does not matter.

What do you get for free, and what should you pay for?

Free scanning tools and free external checks have their place. NetSys offers a free Tier 1 test because the external attack surface of a typical small business is bounded, the findings are usually fixable within days, and a business that has seen its own exposure makes better decisions about everything else. What the free tier does not do is test authenticated application logic, internal lateral movement, or your source code. Those take engineer time in proportion to the target, and any firm offering them at a flat rate without asking about the target is planning to do less than you think.

Compliance shapes this too. PCI DSS requires penetration testing on a regular cycle and after significant changes, and the PCI Security Standards Council publishes guidance on what that testing must cover. SOC 2 auditors and enterprise customers increasingly expect a recent report as evidence. When a test is being done for one of those reasons, the scope has to match the requirement, which is worth telling the tester up front.

How do you compare penetration testing quotes?

  • Same scope, written down. Compare the list of targets, roles and IP addresses, not the headline price. If one quote has no scope statement, it is not a quote.
  • Named methodology. Look for references to the OWASP testing guide, the Penetration Testing Execution Standard, or NIST SP 800-115. It shows the firm follows a process rather than a checklist.
  • Hours and who does them. Ask how many engineer hours are behind the number and whether the person doing the work is the person on the call.
  • Retest terms. Window, coverage and limits, in writing.
  • Deliverables. A sample report, a debrief meeting, and a letter of attestation if a customer or auditor will ask for one.
  • Safety. Rules of engagement, testing windows, an emergency contact, and how production data is handled.

Frequently asked questions

How much does a penetration test cost for a small business?

It depends on what is tested. An external test of a small public footprint is the least expensive engagement, and NetSys runs its Tier 1 external test free for any business. Web application, internal and source code tests are priced on the size of the target and the depth of access the tester is given, so responsible firms quote after a scoping call rather than from a rate card. Treat a flat price offered before anyone has asked what you run as a sign that the scope will be thin.

How often should we run a penetration test?

Annually is the common baseline, plus after any significant change: a new public application, a cloud migration, a merger, or a new remote access method. Regulated businesses may have a set cycle; PCI DSS, for example, ties testing to a schedule and to significant changes. Between full tests, regular vulnerability scanning keeps the gaps short. Our comparison of penetration testing and vulnerability scanning explains where each one fits.

Is a vulnerability scan the same thing as a penetration test?

No. A vulnerability scan is automated software that lists known weaknesses. A penetration test is a person who tries to exploit them, chains them together, and shows what an attacker could reach. Scans are cheap and should run often. Tests cost engineer time and prove which of the scan results matter. Firms that sell a scan as a penetration test are the reason report quality is worth checking before you buy.

Do we need a penetration test for cyber insurance?

Many applications ask if you have had one, and some carriers require it above a certain policy size or for certain industries. Even when it is optional, a recent report with the findings fixed is strong evidence during underwriting and after a claim. If insurance is the driver, tell the tester, so the scope and the report format match what the carrier expects. Our guide to cyber insurance requirements covers the other controls carriers ask about.

Getting a quote for your environment

The fastest way to find out what a penetration test would cost for your business is to start with the one that costs nothing. NetSys runs a free Tier 1 external test that shows what an attacker sees from outside, and if you build or depend on custom software, we scope a Tier 2 source code test per codebase after an NDA and a look at the repository. Details and the request form are on our penetration testing page, or call 845-203-3914 and ask for an engineer.

Sources and further reading

Reading is free. So is knowing where you stand.

Turn insight into action.

Take a free cybersecurity or AI readiness assessment, or book a call with a NetSys engineer — no obligation, no runaround.