How much does a penetration test cost? Price indication, factors and common mistakes

Security9 min read·
K

Kees van der Vlies

Partner | IT Auditor

Also available in:Nederlands

How much does a penetration test cost? It is one of the first questions organizations ask when considering a pentest, and at the same time a question that rarely gets a direct answer. That is not a sales trick: the price of a penetration test depends almost entirely on the scope and depth of the engagement. Still, there is more to say than "it depends". In this article we explain how pentest prices are determined, provide indicative price ranges for common situations and cover the factors you can influence yourself.

How pentest pricing works

A penetration test is almost always priced as days times a daily rate. The test duration is determined in a scoping call: how large is the application, how many user roles are there, are there APIs, and which test approach fits the goal? For a web application pentest, the effort usually lies between three and fifteen days, including reporting. Daily rates for qualified pentesters in the Dutch market are, as an indication, somewhere between one thousand and fifteen hundred euros excluding VAT. Also account for time spent on intake, coordination and a debrief of the report.

If you receive a fixed price without any scoping conversation ever taking place, you may wonder what that price is based on. Without insight into the size of the application, a serious estimate of the test effort cannot be made.

Indicative price ranges

With all the caveats that come with indications, and based on what we see in the Dutch market, you can roughly expect the following orders of magnitude (excluding VAT).

A small web application, with limited functionality and one or two user roles, typically requires three to five test days. Costs then come to roughly four to seven thousand euros.

An average web application, with multiple roles, its own API and sensitive data, quickly requires five to ten days. Think of a range of seven to fifteen thousand euros.

A large or complex platform, with a lot of custom functionality, integrations and multiple applications in scope, goes beyond that: from fifteen thousand euros and considerably more for broad scopes.

For comparison: an automated vulnerability scan costs a fraction of this, from a few hundred euros to around two thousand euros. That price difference is a warning in itself: anyone offered a "pentest" at the price of a scan is almost certainly getting a scan.

The factors that determine the price

The size of the scope is by far the biggest factor: the number of screens, functions, API endpoints and user roles determines how much there is to test. Testing two applications costs almost twice as much as one.

The test approach also matters. In a black box test, the tester receives no information in advance and relatively much time goes into reconnaissance. In a grey box test, the tester receives accounts and documentation, so the same test time yields more depth. A white box or crystal box test, with access to source code or architecture, often costs the least per finding, but requires more preparation. For most web applications, grey box offers the best value: you pay for testing, not for guessing something you could simply have shared.

Other factors include: the number of roles that need access control testing (every extra role means extra test combinations), the presence of APIs or mobile apps in scope, reporting requirements (a DigiD pentest, for example, sets specific requirements for scope and reporting), whether a retest is included and the planning: urgency costs money.

What should be included in the price?

A serious pentest proposal covers more than test days alone. Check whether the following components are included: an intake and scoping document with clear boundaries, the testing itself following a recognizable methodology (for web applications typically the OWASP Top 10 and the OWASP Web Security Testing Guide), a report with a risk classification per finding and concrete remediation advice, a debrief in which findings are explained, and preferably a retest verifying that the most important findings have actually been resolved. That retest is sometimes included and sometimes optional; ask about it, because a pentest without remediation verification is half a product.

Why the cheapest proposal can turn out expensive

The biggest risk in buying a pentest is not paying too much, but getting too little. A report full of scanner output without manual depth misses exactly the categories where the real risks are: access control and business logic. Such a report provides false assurance, which surfaces at the worst possible moment: during an incident, or when a client or auditor sees through the report.

When evaluating proposals, look at the qualifications of the testers (certifications such as OSCP are a common indication of manual testing skill), at a recognizable methodology, at whether the company holds a quality mark such as the Dutch CCV Pentesting quality mark, and ask for an anonymized sample report. A sample report shows at a glance whether someone thought or merely scanned.

How to keep costs manageable

There are legitimate ways to reduce the cost of a pentest without sacrificing quality. Define the scope sharply: test the application where the sensitive data lives, not everything at once. Choose grey box over black box, so test time goes into depth rather than reconnaissance. Make sure the test environment, test accounts and documentation are ready on day one; every day spent waiting for access is a paid day without results. Resolve known basics beforehand with a vulnerability scan, so the pentester spends time on what a scanner cannot find. And organizations that test annually can often negotiate better terms with a regular partner than with a new provider every time, apart from the advantage that the tester already knows the application.

Costs in perspective

Finally, the perspective that belongs with every investment decision: the cost of a penetration test pales in comparison to the cost of an incident. A data breach brings notification obligations, recovery costs, customer loss and potentially fines under the GDPR. For many organizations, the pentest is not a choice but a condition: DigiD connections require an annual penetration test, and clients in enterprise and government procurement ask for one by default. Those who schedule the pentest as a fixed part of the annual cycle, rather than as a panic measure just before a deadline, also avoid paying rush rates.

Frequently asked questions

How much does a web application penetration test cost on average?+

As an indication: a small web application costs roughly four to seven thousand euros, an average application with multiple roles and an API seven to fifteen thousand euros, both excluding VAT. The exact price follows from a scoping call.

Is a retest included in the price?+

That differs per provider. Sometimes one retest round is included, sometimes it is optional. Ask explicitly, because without a retest it has not been established that findings have actually been resolved.

How often should I have a penetration test performed?+

For most web applications, annually is a reasonable rhythm, supplemented with a test after major changes to authentication, authorization or architecture. For DigiD connections an annual penetration test is mandatory.

Why is a penetration test so much more expensive than a vulnerability scan?+

A scan is automated and recognizes known patterns; a penetration test is several days of manual specialist work that also examines access control and business logic. You pay for depth and verified findings.

How do I recognize a good penetration testing provider?+

By a scoping call preceding the proposal, qualified testers (for example OSCP), a recognizable methodology such as OWASP, a quality mark such as the Dutch CCV Pentesting mark and an anonymized sample report with manual findings.

Need help with security?

How secure is your IT environment really? We test it with vulnerability scans and pentests, and guide the implementation of ISO 27001 and IEC 62443.

Explore Security

About the author

K
Kees van der Vlies

Partner | IT Auditor

Back to knowledge base

Have a question?

Get in touch for advice on IT audit, compliance and information security.

Contact us