A penetration test (pentest) is a controlled, ethical hacking attempt in which specialists attack your systems the way a real attacker would, in order to find vulnerabilities before criminals do. Costs vary widely because "a pentest" is not a fixed product: the scope determines the price.
Which factors determine the price?
- Scope and size: the number of applications, IP addresses, systems or user roles that are tested.
- Type of test: a web application, network, cloud, mobile or API test requires different expertise and time.
- Depth: a black box test (no prior knowledge) differs from a grey box or white box test (with access and documentation).
- Complexity: custom software and many integrations take more research time than a standard environment.
- Retest: a check after the findings have been remediated, often quoted separately.
What do you get in return?
A good pentest delivers more than a list of vulnerabilities. You receive a clear report with a risk classification per finding, concrete recommendations for remediation, a priority order and a management summary. That report is also usable as evidence for NIS2, ISO 27001, customers and your cyber insurer.
What to look for when comparing quotes?
- Is the scope precisely defined, so that you compare like with like?
- Is testing done manually, or is only an automated scan run? Real pentests are largely handwork.
- Are a retest and a clear report included in the price?
- What certifications and experience do the testers have?
- Do you receive a verbal explanation of the findings?
Pentest or vulnerability scan?
Do not confuse a pentest with a vulnerability scan. A scan is an automated, ongoing check that flags known vulnerabilities, ideal for keeping continuous visibility. A pentest is in-depth handwork that also finds logic flaws and combined attack paths. They complement each other: scanning for continuity, pentesting for depth.
Would you like a sharp, well-defined quote for a penetration test?
View our penetration tests