This site may contain affiliate or referral links. If you buy through one, we may be compensated. How we make money
External penetration testing: published prices, scope and retest terms
External penetration testing is an authorized attack on the systems you expose to the internet (firewalls, VPNs, mail and web servers) to show what an outsider could break into. A June 2025 Ingram Micro brief lists $2,975 for the first IP, but its newer playbook says to call for pricing. Pentest Express lists $4,995 for one asset. Testing behind a login, like your web app or API, costs extra unless the quote includes it.
Below: what each published price covers at your host count, and the retest terms that can quietly rule an offer out. Prices and terms checked October 9, 2026. We read each provider's own pages. We have not bought these services or judged their quality. How we check offers · How we make money
What does external penetration testing cover?
It covers agreed internet-facing systems, tested from outside your network. It does not automatically cover what a logged-in user can do.
Think of a locksmith walking around your building, trying every door and window from the street. Checking what a guest could do once they are inside is a different job, even if the same firm does both.
| Usually tested | Only if the quote says so | Normally left out |
|---|---|---|
| Public IP addresses and the services on them | Logged-in testing of your web app or customer portal | Your internal network |
| Firewalls, routers and other edge devices | API permission testing (can user A read user B's data?) | Third-party software you use but don't control |
| VPN and remote-access portals | Review of cloud account settings and permissions | Attacks meant to knock systems offline |
| Mail and DNS servers | Password-guessing against real staff accounts | Phishing your employees |
| Public websites, as an anonymous visitor | Hunting for hosts you didn't list |
Two providers spell out the app boundary in writing. Sophos says web apps found on your in-scope addresses get generic testing that "is not considered a comprehensive test" of the app. Pentest Express lists a review of your cloud console and permissions as excluded from its external test. If a customer wants proof that one client can't see another client's records, an external network test alone won't show that. You need a web application test as well.
One more boundary: reachable is not the same as allowed. A provider can only test what you are authorized to have tested and have approved in writing.
How much does an external penetration test cost?
Three sellers publish current numbers you can check today: one full price list and two starting prices. Ingram Micro's older list prices are shown for reference; its newer playbook says to call for pricing. The rest we looked at require a quote. Here is every published number, with the unit and the catch.
Offers with a published price
| Seller and offer | Who tests | Published price (USD) | Counted by | Retest | The catch |
|---|---|---|---|---|---|
| Blaze, external network test | Human-led; manual validation | "From $4,999 for focused external scopes." Blaze's own typical range for a small perimeter: $5,000 to $10,000 | Not stated ("limited public IPs and services") | One round of fix checking within 90 days, free, in "most" engagements | A starting figure and Blaze's own ranges, which it calls "planning ranges, not fixed quotes" |
| Ingram Micro, Network Penetration Assessment | Its staff, "a mix of manual and automated testing" | June 2025 historical list: $2,975 for the first IP, $619 for each one after | IP address | Not stated | A list price from a June 2025 brief, sold with a reseller. What you pay may differ. The newer playbook says to call for pricing |
| Pentest Express, external test | Manual testing | $4,995 for 1 asset. $7,995 for 2 to 4. $10,995 for 5 to 8. $15,995 for 9 to 16. $25,995 for 17 to 32. $36,995 for 33 to 64. $52,995 for 65 to 128. $72,995 for 129 to 256 | Host, IP or cloud endpoint | Free within 14 days of the report. 25% of the original fee from day 15 to day 60. Everything is retested | Website orders are paid in full up front, plus tax. Sharing the report with a customer needs written consent |
| Synack, Sara Pentest | AI-led | "Starts at $4,181" per test | Up to 100 host IPs, or 1 simple web app | "Patch verification" listed. No count or window | A platform line item is required and priced separately. Total is incomplete |
| Synack, SynackST | One human tester | "Starts at $10,283" per test | Up to 100 host IPs | Same as above | Same platform line item. Five-day testing window |
Sources: Blaze cost guide (dated May 11, 2026), Ingram Micro service brief (Rev. 06.01.2025) and newer playbook (published September 30, 2026), Pentest Express external page and terms, Synack pricing. All provider-published.
Synack says its platform "is required to purchase any of the testing products and is a separate line item." It also describes a Basic platform tier "available at no cost." Which one applies to a single test is not stated, so we do not add up a Synack total. An unknown required charge is not zero.
What those prices come to at your size
This is our arithmetic from the published figures. It is not a quote. These figures assume one billable IP or asset per host for each offer.
| Live internet-facing hosts | Ingram Micro (June 2025 historical list) | Pentest Express | SynackST |
|---|---|---|---|
| 1 | $2,975 | $4,995 | From $10,283 + platform |
| 4 | $4,832 | $7,995 | From $10,283 + platform |
| 8 | $7,308 | $10,995 | From $10,283 + platform |
| 12 | $9,784 | $15,995 | From $10,283 + platform |
| 16 | $12,260 | $15,995 | From $10,283 + platform |
| 25 | $17,831 | $25,995 | From $10,283 + platform |
| 50 | $33,306 | $36,995 | From $10,283 + platform |
| 100 | $64,256 | $52,995 | From $10,283 + platform |
Three things stand out.
Ingram Micro's historical per-IP figures climb fast. Ingram Micro's June 2025 list price is the lowest test component in this table up to 12 hosts. From 13 hosts on ($10,403), it passes Synack's "from $10,283" for up to 100.
These are not the same purchase. Pentest Express includes a retest window and says testing is manual. Ingram Micro's brief states no retest. SynackST is one tester for a five-day window whether you have 10 hosts or 100.
Confirm the seller's counting rule. Sophos defines a target as "a live system exposing at least one port/service to the Internet." Under Sophos's definition, if you own 254 addresses and 9 of them expose a port or service to the internet, you have 9 targets. Ask each seller how it counts before you compare.
Check the published figures at your host count
These figures assume one billable IP or asset per host for each offer.
Use a count only. Do not enter IPs, hostnames, credentials or findings.
Enter a whole number from 1 to 500.
Offers that need a quote, and the terms they do publish
| Seller and offer | What it says it covers | Retest terms | Ask this |
|---|---|---|---|
| BreachLock, Standard package | "Basic internal networks & external network infrastructure," small to medium web apps. In-house testing team. Platform access optional | One free manual retest. No deadline stated | "By what date must we use the included retest?" |
| Cobalt, External Network Pentest | "Reconnaissance, automated scanning, and manual exploitation" of public-facing infrastructure | Free retesting for 6 months (Standard) or 12 (Premium, Enterprise), only while your contract is active, with requests ending at the earlier of that period or 10 days before the contract does | "This is sold as an annual credit package. What is the total yearly commitment for one external test?" |
| Sophos, External Penetration Test | Small, Medium or Large: up to 50, 250 or 500 external IPs | One retest, high and critical findings only, excluding findings from pivoting or post-exploitation. You must request it by email within 30 days of the final report or you lose it. The retest must finish within 90 days of primary test completion | "Can the retest cover every finding, and can we request it later than day 30?" |
| TCM Security, External Penetration Testing | Perimeter systems, with a direct line to the testers. "Tailored quote within 48 hours" after an intro call | "We offer retesting." No count, fee or deadline stated | "Is a retest in the price, and until when?" |
Sources: BreachLock packages, Cobalt external pentest and retest rules, Sophos services catalog (marked Updated January 2025), TCM Security. All provider-published.
Cobalt's pricing page also says "unlimited on-demand retesting throughout your contract term," which reads wider than the 6 and 12 month limits in its documentation. Ask Cobalt for your retest end date in writing.
What about the "typical range" you see elsewhere? Those are the sellers' own estimates. Blaze says external network tests "usually" cost $5,000 to $20,000. We haven't measured a market average and won't pretend to.
One warning from a testing firm is worth passing on. Triaxiom says clients bring it quotes "from $900 to $5,500" for a small external test, and that the low end "will likely be little more than a vulnerability scan." So ask any seller: "How many hours of hands-on testing are in this price, and who reviews the scanner output?"
Which offers deserve a closer look?
Start with the thing that would rule an offer out for you.
- You have a handful of hosts and want a number today. Look at Ingram Micro's historical per-IP list price and Pentest Express's brackets. Ingram's is lower on paper. Its newer playbook says to call for pricing. Pentest Express is the only one whose published terms let you work out test plus retest in full.
- Your fixes will take more than 30 days. Sophos's included retest must be requested by day 30. It can be completed within 90 days of primary test completion. Confirm that both dates work for you. Pentest Express charges 25% from day 15. Blaze states 90 days. Cobalt states 6 or 12 months.
- You need every finding re-checked, not only the serious ones. Sophos's retest covers high and critical findings, excluding findings from pivoting or post-exploitation. Pentest Express says it retests everything.
- You must hand the report to a customer. Pentest Express's terms require its written consent first. Get that consent in the order, or don't buy.
- You have dozens of hosts and want a per-test starting price. SynackST covers up to 100 host IPs from $10,283, but get the platform charge in writing first.
- Nobody has told you a person must do the testing. Then Synack's AI-led Sara (from $4,181) is an option. Ask whoever needs the report before you choose it.
- You already have a testing contract. Check it first. An existing Cobalt credit package or another provider's agreement may already cover your perimeter.
If one of these fits, go straight to the provider:
View Blaze penetration testing View BreachLock packages View Cobalt external pentest View Ingram Micro service brief View Pentest Express external test View Sophos external test View Synack pricing View TCM external testing
A worked example: 12 hosts and a customer questionnaire
Here is how we would check these offers for one made-up buyer. We call this a Purchase Check: take what the buyer must have, hold each offer's published terms against it, and write down what fits, what doesn't and what is still unknown.
Say you run IT for a 40-person firm. You have 12 live internet-facing hosts, including a VPN and a customer portal with a login. A customer's security questionnaire asks for an external penetration test and a copy of the report. You expect fixes to be done about 45 days after the report, and you want every finding re-checked. No provider has quoted for this example. These calculations assume one billable IP or asset per host for each offer.
| What you must have | Offer | Finding | Why |
|---|---|---|---|
| A full price for test plus retest | Pentest Express | Supported | $15,995 for 9 to 16 assets. A retest on day 45 costs 25%: $3,998.75. Total $19,993.75 before tax |
| A full price for test plus retest | Ingram Micro | Unresolved | June 2025 historical list: $2,975 + 11 × $619 = $9,784. The newer playbook says to call for pricing. No retest is stated, so the total is incomplete |
| A full price for test plus retest | SynackST | Unresolved | From $10,283, plus a platform charge with no published amount |
| Every finding re-checked on day 45 | Sophos | Mismatch | Retest is high and critical only, excluding findings from pivoting or post-exploitation. Day 45 can fit if requested within 30 days of the final report and completed within 90 days of primary test completion |
| Every finding re-checked on day 45 | Blaze | Unresolved | Fix checking "up to 90 days" in "most" engagements. Confirm it applies to yours and covers every finding |
| Every finding re-checked on day 45 | BreachLock, TCM Security | Unresolved | A retest is offered. No deadline is published |
| Report can go to the customer | Pentest Express | Unresolved | Its terms need written consent to share with a customer |
| Logged-in portal tested | Every offer above | Unresolved | None says logged-in app testing is included with this network scope |
Where that leaves this buyer. Sophos is out unless it changes the retest in writing. Pentest Express is the only offer with a complete published total. It stays in only if it agrees in writing to let you share the report. Ingram Micro's earlier list price was $9,784, but you now need its current test price as well as the answer to this question: "Is a retest of all findings on day 45 included, and at what price?" If the old list price still applies and the retest adds less than about $10,200, it comes in under Pentest Express. Blaze is worth a quote for the 90-day window.
And the portal changes the whole purchase. Ask the customer one thing before you buy anything: "Do you need the logged-in side of our portal tested, or only what's exposed to the internet?" If they say logged-in, your scope must include that application testing too.
"Supported" here means one published term meets one need. It does not mean the provider is good or that your customer will accept the report.
Do you need an external test, an internal test, a web app test or only a scan?
Match the test to the question you were asked. Buying the wrong one is the most expensive mistake on this page.
| The question you need answered | What to buy | Check this first |
|---|---|---|
| Can an outsider break in through what we expose to the internet? | External penetration test | Your list of live hosts and domains |
| Can a logged-in user reach data or features they shouldn't? | Web app or API test | Which roles and accounts get tested |
| How far could someone get once they're inside our network? | Internal penetration test | Where the tester starts from |
| Do we have known weaknesses on our public systems? | A vulnerability scan may be enough | The exact wording of the request |
| Did our software vendor test their own product? | Ask the vendor for their report | What you control and what they do |
External does not mean "outsourced." It describes where the tester stands. NIST's testing guide puts it this way: external testing "is conducted from outside the organization's security perimeter," and internal testing works "from the internal network." An outside firm can run either one.
A scan and a test are different work. A scan runs software that lists possible weaknesses. A penetration test has a tester try to use them and show how far they lead. If the person asking only wants a scan, a scan is the right purchase and you can stop here. If you're unsure which they meant, ask them. Our scan versus pen test comparison goes deeper, and our guide to choosing a test type covers the rest.
Is an external pen test required?
The payment card standard requires it by name. For most other requests, the person asking decides.
| If this applies to you | What the text says | Who has the final word |
|---|---|---|
| PCI DSS v4.0.1, Requirement 11.4.3 (where this requirement applies to your environment) | External penetration testing is performed "at least once every 12 months" and "after any significant infrastructure or application upgrade or change," by "a qualified internal resource or qualified external third party" with "organizational independence." The tester is "not required to be a QSA or ASV" | Your assessor or acquiring bank |
| PCI DSS v4.0.1, Requirement 11.4.4 | Exploitable findings are corrected, and "penetration testing is repeated to verify the corrections" | Same |
| PCI DSS v4.0.1, Requirement 11.3.2 | Separate from the above: external vulnerability scans "at least once every three months" by a PCI SSC Approved Scanning Vendor | Same |
| HIPAA Security Rule | Yearly penetration testing is a proposal, issued December 27, 2024. HHS says "the current Security Rule remains in effect" | HHS. Not a requirement as of our check |
| SOC 2, ISO 27001, cyber insurance, a customer contract | We don't quote a clause here. Get the requirement in writing from your auditor, insurer or customer | Them |
Two practical points where these PCI DSS requirements apply. The quarterly scan does not replace the yearly test; they are separate requirements. And Requirement 11.4.4 means a retest is part of the job when exploitable findings have been corrected, so a request deadline you can't meet (see Sophos's 30 days above) matters more for you than for most.
Sources: PCI DSS v4.0.1 (June 2024; we read a university-hosted copy of the PCI SSC document), HHS fact sheet. No provider's compliance claim settles this. Your assessor, auditor or customer does.
What should you send providers so the quotes line up?
Send every provider the same short request. If each one prices a different job, the cheapest quote tells you nothing.
Copy this, fill in the brackets in your own document, and send it to the providers you picked.
Request for an external penetration test quote
We need an external penetration test to answer [the request, such as "our customer's security questionnaire"] for [who will read the report] by [date].
Please quote this scope:
- Targets: about [number] live internet-facing hosts and [number] domains. Tell us how you count hosts, IPs, domains and cloud endpoints, and what happens to the price if you find more.
- Depth: network services on those hosts. [Add or remove: logged-in testing of our web app with (number) user roles.] Tell us what is excluded.
- Who tests: how much of the work is done by people and how much by automated tools, and who reviews the results.
- Dates: proposed start, testing days and report date.
- Report: what it contains, and confirmation that we may share it with [recipient].
- Retest: we expect fixes to be ready about [number] days after the report. Tell us what is re-checked, how many rounds, the cost, and whether your deadline is for requesting the retest or finishing it.
- Total: itemize testing, any required platform or subscription charge, retesting, tax and payment schedule.
Please flag any assumption that could change your price. This is a request for scope and pricing. It does not authorize testing.
Keep passwords, keys and network diagrams out of this request. Agree how to share access with the provider you hire.
That last line of the request matters. A quote request is not permission. Before any testing starts, you need a signed authorization that names the real targets, the dates and what is off-limits. If a host sits with a cloud provider or another company, check their testing rules too. Amazon, for example, publishes its own penetration testing policy.
What if the package covers fewer hosts than you have?
Don't quietly drop hosts to fit a package. First check what the person asking for the test needs covered. Then either get a quote for the full list, or agree a smaller list with them in writing and say so in the report. A report that skips half your perimeter without saying so is the kind that gets rejected.
Does one IP address cover every app behind it?
No. One address can front a VPN, a website and a customer portal. An IP count tells you which hosts get looked at. It does not tell you which logins, user roles or API calls get tested. Name the apps and roles in the request if you need them.
The request above covers an external test. If you also need to sort out who reads the report, what your recipient expects and what else belongs in scope, Find My PenTest Match gives you a fuller scope checklist to copy or print.
Free scope checklist. Copy or print. No contact details required. It does not pick a provider for you; the comparison on this page is where to do that for external testing.
Will the report work for your customer or auditor?
Only they can tell you, so ask before you book. Then check two things in the offer.
What the report contains. Look for the list of targets tested and not tested, the testing dates, evidence for each finding, how severe each one is and why, and what to fix. If fixes were re-checked, the report should show which ones.
Whether you're allowed to share it. This catches people out. Pentest Express's terms say you may not share its reports with third parties "without our prior written consent," with exceptions for disclosures required by law or regulation and for reasonably necessary sharing with legal counsel, auditors and insurers under confidentiality. A customer is not on that list. Ask every provider: "May we share the full report with [customer name] under NDA?"
Our tool has a short list of questions to ask your report recipient. To compare the proposals that come back, see our quote comparison guide.
How long does an external penetration test take?
The testing takes days. The whole job, from first email to a re-checked report, takes weeks, and the retest deadline is the date people miss.
What providers state, in their own words:
- Synack: a five-day assessment window for SynackST.
- Pentest Express: a single asset in "as little as 3 business days" from checkout. Its catalog calls this typical and not guaranteed.
- TCM Security: "Typical engagements last 1–3 weeks."
- Blaze: 1 to 3 or more weeks for network tests.
None of these is a booked start date or a promised report date. Get both in writing.
Work backward from when the report is due. Say your customer wants the final, re-checked report by June 30. If your fixes take 45 days and the retest takes a week, the first report has to land by early May, which could mean testing in April and a signed order in March.
Then check that date against the retest clock:
- Pentest Express: free through day 14 after the report, 25% through day 60, a new test recommended after that.
- Sophos: request by day 30 after the final report. The retest must be completed within 90 days of primary test completion.
- Blaze: up to 90 days.
- Cobalt: 6 or 12 months, or 10 days before your contract ends, whichever comes first.
- BreachLock, Ingram Micro, Synack, TCM Security: not published. Ask.
Other questions
Is it safe to test live systems?
It is done on live systems all the time, but it is not risk-free. Agree the testing hours, anything off-limits, and a phone number that stops the test. Sophos, for one, says it will discuss "any exploits with high risk of Customer service impact" before using them. Ask your provider for the same promise in writing.
Can our own team do the test?
For most purposes, whoever asked decides. Under PCI DSS the text allows "a qualified internal resource" as long as the tester has "organizational independence," which usually means not the people who built or run the systems. A customer who asks for an independent test almost always means an outside firm. Ask them.
How often should you repeat it?
PCI DSS says at least every 12 months and after significant changes. Outside PCI, go by what your customer, insurer or auditor asks for, and test again after a big change such as a new VPN, a cloud move or an acquisition.
Sources
Provider pages, read October 9, 2026. Everything attributed to a provider is that provider's own published statement.
- Blaze Information Security: Penetration Testing Cost & Pricing (dated May 11, 2026), Network Penetration Testing
- BreachLock: Penetration testing packages
- Cobalt: External Network Pentest, Pricing, Remediate Findings
- Ingram Micro Services: Network Penetration Assessment brief (Rev. 06.01.2025), Network Penetration Assessments playbook (published September 30, 2026; page 2 says to call for pricing)
- Pentest Express: External testing, Terms (updated July 28, 2026), Catalog (updated September 23, 2026)
- Sophos: External Penetration Test service description (updated January 2025), complete service description (revised December 5, 2025)
- Synack: Pricing
- TCM Security: External Penetration Testing
- Triaxiom Security: How Much Does an External Penetration Test Cost
Standards and rules, read October 9, 2026.
- PCI Security Standards Council: PCI DSS v4.0.1, June 2024, Requirements 11.3.2, 11.4.1, 11.4.3 and 11.4.4 (university-hosted copy)
- U.S. Department of Health and Human Services: HIPAA Security Rule proposed rule fact sheet
- NIST: SP 800-115, Technical Guide to Information Security Testing and Assessment, section 2.4.1
The PenTest Index does not perform, authorize or certify penetration testing. For broader budgeting across test types, see penetration testing cost.