We use cookies to understand how the site is used and to improve your experience. Privacy policy

    Skip to main content

    5 October 2026 · 9 min read · By Michael van Mameren, Lead Penetration Tester (OSCP)

    Penetration Testing Cost in 2026: What Drives the Price and How to Compare Quotes

    Every pentest quote is built from the same handful of variables. Once you know them, you can read any proposal, spot what is missing, and compare two offers that look nothing alike. This guide uses published market ranges, not our own price list; HackersHub quotes every engagement on scope.

    What a penetration test costs in 2026: the published ranges

    Pricing guides published by testing firms and buyer-guide sites in 2026 converge on a broad picture. In the US and UK, most commercial engagements fall between roughly USD 5,000 and 35,000, with an often-quoted project average near USD 18,000. By type, external network tests are typically quoted at USD 5,000 to 20,000, web application tests at USD 5,000 to 30,000, internal network tests at USD 7,000 to 40,000, and red team or multi-environment programmes from USD 40,000 upward. Consultant-day rates in those guides run USD 1,500 to 3,500 for mid-market firms and USD 4,000 to 7,000 for top-tier boutiques and Big Four practices.

    In the Netherlands, firms that publish indicative pricing quote day rates between EUR 1,000 and 2,500 for an experienced tester, a web application test at three to five days (EUR 6,000 to 12,000), an internal network test at three to five days (EUR 6,000 to 15,000), and full red team engagements at EUR 50,000 or more. Those are third-party figures, cited so you have a reference point. They are not HackersHub prices: we scope every engagement individually and do not publish a price list, because the variables below move the number more than any list could capture.

    The six variables that set the price

    Every serious quote is consultant-days multiplied by a day rate, plus reporting and retest. These are the inputs to the day count.

    1. Scope: how much there is to test

    Number of applications, APIs, IP addresses, cloud accounts, user roles and business functions. A single web application with two roles is a different engagement from a platform with twelve microservices and a partner API. Scope is the single largest driver, which is why a quote without a scoping call is a guess.

    2. Depth: black, grey or white box

    Black box (no information) spends days on discovery that grey box (credentials and documentation) skips. White box (source code access) finds more per day but needs reviewers who can read code. Grey box is usually the best value for a first test: more findings per day than black box, less preparation than white box.

    3. Test type and position

    External perimeter, internal assumed-breach, web application, API, mobile, cloud configuration, Active Directory, OT or hardware. Each needs different skills and tooling, and internal tests add logistics (VPN, hardware drop, on-site days).

    4. Tester seniority and certification

    A senior tester with OSCP, OSWE or CREST credentials costs more per day and finds more per day. Compliance frameworks and enterprise procurement increasingly require named, certified testers, which removes the lowest-priced tier from the comparison.

    5. Reporting requirements

    A findings list takes little time. A report with executive summary, auditor-ready scope statement, compliance mapping (ISO 27001, SOC 2, PCI DSS, DORA, NIS2), reproducible evidence and remediation plan takes one to two extra days and is what procurement, auditors and insurers actually consume.

    6. Retest and support

    A retest of remediated findings, usually within 30 to 90 days, confirms the fix and closes compliance requirements such as PCI DSS 11.4.4. Some quotes include it, some charge separately, some omit it. Always ask.

    Typical effort by test type

    Indicative consultant-day ranges for a mid-sized scope, based on published guides and common practice. Multiply by the day rate on the quote to sanity-check it.

    Test typeTypical effortWhat moves it
    External network penetration test2 to 5 daysNumber of hosts and exposed services, cloud perimeter
    Web application test (one app, grey box)3 to 8 daysRoles, workflows, API surface, business-logic depth
    API test2 to 6 daysEndpoints, authentication schemes, documentation quality
    Internal network, assumed breach4 to 10 daysNetwork size, Active Directory complexity, segmentation
    Mobile application (one platform)3 to 7 daysBackend API coverage, certificate pinning, local storage
    Cloud configuration review (one account)2 to 5 daysServices in use, IAM complexity, number of accounts
    Red team engagement15 to 40+ daysObjectives, stealth requirements, threat-intel phase, duration

    How to compare two quotes that look nothing alike

    Put both proposals through the same questions. Differences in price usually come from differences in one of these.

    • Is the scope written down, with the exact applications, hosts and roles listed, or is it a line item called penetration test
    • How many consultant-days, and at what day rate; a total without the day count hides the maths
    • Who tests: named individuals with certifications, or an unnamed team or an automated service
    • Methodology stated (OWASP, PTES, NIST SP 800-115) and manual testing explicitly included
    • Report deliverables listed: executive summary, evidence, severity model, compliance mapping
    • Retest included, priced separately or absent
    • Testing window, communication during the test, and how critical findings are escalated before the report
    • What happens if scope grows during the test

    Where the money is wasted, and where it is not

    The expensive mistake is not a high day rate. It is paying for days that do not find anything: a black-box test on a system you could have given credentials for, a test scoped to a marketing website while the customer portal goes untested, or a report nobody can act on. The second expensive mistake is the opposite: a low-priced automated scan sold as a penetration test, which satisfies nobody at audit time and has to be redone.

    Money spent on scoping, on a senior tester for the highest-risk systems, and on a report that your auditor and engineers can both use, is the part of the spend that returns value. That is where HackersHub puts the days.

    How HackersHub quotes

    We do not publish prices because we do not sell a fixed product. A short scoping call establishes what you need to test, why (audit, customer requirement, launch, incident), and at what depth. You receive a written scope, the number of consultant-days, the named lead tester, the deliverables and the retest terms. Compare it line by line with any other proposal; that is what the written scope is for.

    Frequently asked questions

    Want a quote you can compare line by line?

    A 20-minute scoping call gives you a written scope, the day count, the named lead tester and the retest terms. No price list, no surprises. Talk to an expert.