This site may contain affiliate or referral links. If you buy through one, we may be compensated. How we make money

Internal penetration testing: published prices, who needs it and what to scope

By The PenTest Index · Prices, terms and rule text checked October 9, 2026

Internal penetration testing is an authorized attack run from inside your network to show how far an intruder gets after one laptop or account is compromised. The lowest published price we found for a person-led test is $6,000 (Invadel, one site or one Active Directory domain). PCI DSS and New York's DFS rule require it by name; most rules do not.

Three different things are sold under this name. Pick the kind first, then the supplier.

Table columns: Your situation; What to buy; The condition that changes it.
Your situationWhat to buyThe condition that changes it
A rule, auditor, insurer or customer asked for an internal penetration testA person-led internal test from an outside firmAsk the requester whether a person must do the testing. Most published prices below are for this kind.
You want to test often, for your own assurance, and someone on your team can run itAn autonomous testing platformCheck that whoever reads the report accepts it before you count it as your annual test.
Nobody asked for a penetration test; you want to find missing patches and weak settingsAn internal vulnerability scanA scan lists known weaknesses. It does not try to chain them into a break-in.
You already had a test this yearMaybe nothingCheck that the old test covered the internal network, the current systems and what the requester wants.

Jump to the offers and prices ↓

What is internal penetration testing?

It is a test that starts inside your network and tries to gain more access than it was given. NIST describes the tester as taking the position of "a trusted insider or an attacker who has penetrated the perimeter defenses," usually starting with the access of an ordinary user (NIST SP 800-115, section 2.4.1, read October 9, 2026).

An everyday picture: an external test checks the locks on the outside doors. An internal test asks what someone can open once they are standing in the lobby with a visitor badge.

In practice the tester looks for a path. A weak password on one machine. A shared drive everyone can read. A saved login that works somewhere it should not. Providers who list their work name things like password attacks, moving from one machine to the next, and attacks on Active Directory, Microsoft's system for managing logins and permissions (TCM Security, Cobalt, both read October 9, 2026).

Two things people mix up:

  • "Internal" is where the test starts, not who does it. An outside firm can run an internal test. So can your own staff, if the rule you answer to allows it.
  • A scan run from inside is still a scan. Our page on penetration testing vs vulnerability scanning covers the difference.

Do you need an internal penetration test?

You need one if a rule or contract you answer to names it. Two widely used rules do. Others ask for penetration testing without saying "internal," or do not ask at all.

Table columns: Rule; What the text says; Names internal testing?.
RuleWhat the text saysNames internal testing?
PCI DSS v4.0.1, Requirement 11.4.2Internal penetration testing at least once every 12 months and after any significant infrastructure or application change, by a qualified internal resource or qualified external third party, with organizational independence of the tester. The tester does not have to be a QSA or ASV.Yes
PCI DSS v4.0.1, Requirements 11.4.5 and 11.4.6If you use segmentation to keep the cardholder data environment apart from other networks, the segmentation controls are tested at least every 12 months, or every six months for service providers, and after any change to them.Yes, for segmentation
New York DFS, 23 NYCRR 500.5(a)(1)Penetration testing "from both inside and outside the information systems' boundaries by a qualified internal or external party at least annually." DFS lists small-business and certain limited-exempt entities as exempt from 500.5.Yes
FTC Safeguards Rule, 16 CFR 314.4(d)(2)Without effective continuous monitoring or other systems that detect vulnerability-creating changes on an ongoing basis: annual penetration testing of your information systems, scoped by your risk assessment, plus vulnerability assessments at least every six months, after material changes to operations or business arrangements, and when circumstances you know or have reason to know may materially affect your information security program. This paragraph does not apply to financial institutions that maintain customer information about fewer than 5,000 consumers (§314.6).Not by name. Your risk assessment decides whether internal systems are in.
HIPAA Security RuleThe rule in force does not name a penetration test. A proposed rule issued December 27, 2024 would require one at least every 12 months. HHS still labeled it proposed when we checked.No. Proposed only.

Sources, all read October 9, 2026: PCI DSS v4.0.1 from the PCI SSC document library; 23 NYCRR 500.5 and DFS's exemption tables; 16 CFR 314.4; HHS fact sheet.

One PCI detail matters when you scope. The standard's applicability notes say testing from inside means testing both inside the cardholder data environment and into it from trusted and untrusted internal networks. "Test the office network" may not cover that.

If your reason is a SOC 2 audit, an insurance form or a customer contract, the answer is in that party's own words, not in a general rule. Send them this:

Does the test have to include our internal network? Does a person have to perform it, or is automated testing acceptable? Does the tester have to be independent of the team that runs those systems?

Whoever receives the report decides whether it is good enough. A provider's "compliance-ready" label is the provider's claim.

Which internal test offers publish a price?

Four of the eight providers in these tables publish a price you can budget against: AZ Pentest, Invadel, Synack, and Horizon3.ai through AWS Marketplace. The other four quote.

Everything in these tables comes from the provider's own pages, read October 9, 2026 unless a row says otherwise. We did not buy or run any of these tests, so nothing here rates their quality. Providers are listed A to Z within each group. Prices are shown with a dollar sign as each provider shows them.

A person tests your internal network

Table columns: Offer; What the provider says you get; Published price and commitment; Retest; Confirm before you sign.
OfferWhat the provider says you getPublished price and commitmentRetestConfirm before you sign
AZ Pentest, Medium Full PentestExternal plus internal testing. An automated pass plus hands-on manual testing. Active Directory testing listed. Describes itself as serving Arizona businesses.From $6,500, flat and agreed in writing. Internal-only is quoted on request.30-day retest of fixed findings included.What the 30 days run from. Whether it serves you outside Arizona. The fixed price for your size.
Cobalt, internal network pentestRemote testing through a VPN or a small "jump box" server you host. Scanning, then manual assessment, including Active Directory. You can opt out of password spraying.Quote. Sold through annual credit packages.Free retests for 6 months (Standard) or 12 months (Premium, Enterprise) while the contract is active. Requests close at the end of that period or 10 days before the contract ends, whichever is first.Credits needed for your network. Total annual commitment. Your last retest request date.
Invadel, internal network penetration testingStarts from a standard domain user account. Remote, through an appliance or virtual machine Invadel supplies. Active Directory, lateral movement and segmentation testing. Says testers are senior and in-house.$6,000 (Small): one site or one Active Directory domain "of up to a few hundred hosts." $9,200 (Medium): a few sites or VLANs. $14,500+ (Large). Fixed price agreed in writing.Free retest; request within two months of report delivery. Report reissued with results."A few hundred hosts" is not an exact cap; get yours in writing. Invoice currency. Whether two months is enough time to fix things.
NetSPI, internal network pentestingEmployed testers. Lists segmentation testing for PCI DSS, password auditing, privilege escalation and Active Directory weaknesses.Quote. No price on the page.Not stated on the page.Starting access, retest count and window, total commitment.
Synack, SynackSTOne human tester. Up to 100 host IPs. Listed as covering internal and external hosts. 5-day assessment window.From $10,283 per test. The Synack Platform is a required, separate line item; a no-cost Basic platform is also described."Patch verification" listed; count and window not stated.Which platform tier you need and what it costs. How testers reach your internal network.
Synack, Synack14A team of testers. Up to 250 host IPs. Internal and external. 14-day window.From $27,120 per test, platform separate.Same as above.Same as above.
TCM Security, internal penetration testingHuman testers. Lists password, relay and Kerberos attacks on Active Directory. Offers to let your team shadow the testers.Quote within 48 hours after an intro call. In a July 2024 article TCM said its internal tests "typically" ran $7,500 to $30,000. That is TCM describing its own past work, not a current price."We offer retesting." Count, window and cost not stated.All of it: price, retest terms, whether a device or an on-site visit is needed.

Sources: AZ Pentest pricing · Cobalt method and retest rules · Invadel pricing and retest FAQ · NetSPI · Synack pricing · TCM service page and 2024 cost article.

Watch the Synack table. Its cheapest listed test, the AI-led Sara Pentest at $4,181, is listed for external targets only. Internal coverage starts at SynackST. Our Synack profile has the full terms.

Software that runs the attack for you

Table columns: Offer; What it is; Published price and commitment; Who does the work; Confirm before you sign.
OfferWhat it isPublished price and commitmentWho does the workConfirm before you sign
Horizon3.ai NodeZeroA platform Horizon3.ai describes as autonomous: it finds and exploits weaknesses and chains them together. Reports include a segmentation report.AWS Marketplace list price: $25,000 for 12 months, Core package, 500 assets. A Flex line lists $15,000 for 12 months, 1,000 assets, described as a one-time test.The software. Your team runs it and acts on the results.What "one-time" allows during the 12 months. How assets are counted. Whether your report reader accepts autonomous testing.
Kaseya vPenTestAutomated network pentest, internal and external, run monthly or on demand. Reports within 48 hours after testing ends.Quote.The software.The price and term. Kaseya says the product "meets compliance for PCI, HIPAA, SOC 2." That is Kaseya's statement; your assessor decides.

Sources: AWS Marketplace listing · Horizon3.ai · Kaseya.

A year of software and one project by a person are different purchases. Do not line up $25,000 against $6,000 as if they bought the same thing.

A scan from inside

Pentest-Tools.com sells NetSec, a scanning toolkit you run yourself, from $95 a month for five assets on monthly billing, plus a paid VPN Agent add-on for internal scanning (pricing, checked October 7, 2026). That is the right buy if you want to find missing patches. It is not an internal penetration test.

Which offers deserve a closer look?

  • One office, one Active Directory domain, and you want a fixed price for a person-led test. Start with Invadel's $6,000 Small tier. It is the only offer here that publishes an internal-only price, a starting account and a retest window together. It does not fit if you need more than two months to fix findings and request a retest, unless Invadel extends the window in writing.
  • You need external and internal together. AZ Pentest publishes the bundle from $6,500. It may not fit if you are outside Arizona or need longer than 30 days to fix things. Ask both questions first.
  • You want a named cap on hosts and a short, fixed window. Synack publishes both: 100 host IPs in 5 days, or 250 in 14. It does not fit a tight budget, and the total is incomplete until Synack prices the platform line.
  • You expect several tests a year. Cobalt's credit model is built for that, and its retest period is the longest published here. The contract end date can cut it short, so get the last request date in writing.
  • You will run tests yourself, often. Look at NodeZero or vPenTest. Settle acceptance with your report reader before you buy.
  • Nobody asked for a pentest. Buy a scan.

See Invadel's internal testing prices

See AZ Pentest's prices

See Synack's packages

See Cobalt's internal network pentest

See NetSPI's internal network testing

See TCM Security's internal testing

See NodeZero on AWS Marketplace

See Kaseya vPenTest

A worked example: one buyer, five offers

This buyer is made up. No provider has quoted for it.

Say you run a 60-person company. One office. About 150 computers and servers on the network. One Active Directory domain. Your assessor wants a person to do the test. You want to know whether an ordinary employee account can reach payroll or the backups. The report would arrive November 2, 2026, and your team expects to finish fixes and ask for a retest on January 16, 2027.

This is our Purchase Check: take what the buyer must have, hold each offer's published terms against it, and write down what the terms support.

Table columns: Offer; 150 hosts in one test; Starts as an ordinary user; Retest requested January 16; Published price.
Offer150 hosts in one testStarts as an ordinary userRetest requested January 16Published price
Invadel, SmallSupported as described ("up to a few hundred hosts"); confirm in writingSupportedMismatch. Two months from November 2 ends January 2.$6,000
AZ Pentest, MediumUnresolved; no host figure publishedUnresolvedUnresolved, likely a miss. If the 30 days run from the report, they end December 2.From $6,500, with external
SynackSTMismatch. Cap is 100 host IPs.UnresolvedUnresolved; no window statedFrom $10,283 plus platform
Synack14Supported (cap is 250)UnresolvedUnresolved; no window statedFrom $27,120 plus platform
CobaltUnresolved; quoteUnresolvedDepends on your contract datesQuote

"Supported" means the published terms back that one condition. It is not a verdict on the provider. A mismatch on something you must have rules the offer out unless the provider changes that term in writing.

What this buyer should do. Invadel is the closest fit on scope, starting access and price. The retest date is what breaks it. So one answer decides the purchase:

Our fixes will take about ten weeks. Can you extend the retest request window to January 16, 2027 in writing, at no extra charge?

If yes, Invadel fits on every condition checked. If no, either plan to request the retest by January 2, or get quotes from Cobalt and Synack14 with the same scope. With Cobalt, check the contract end date: if a contract ended January 31, 2027, retest requests would close no later than January 21 at 23:59 UTC.

TCM Security and NetSPI stay unresolved on every column until they quote. That is not a mark against them. It means you need the scope request below to get answers you can compare.

How much does an internal penetration test cost?

Published prices for a person-led test in this set run from $6,000 (Invadel, one site or one domain) to $27,120 plus a platform charge (Synack14, up to 250 host IPs). An autonomous platform lists at $25,000 for a year.

A few things we worked out from the published terms:

  • Bigger is not cheaper per host at Synack. $10,283 for up to 100 host IPs is about $103 per host at the full cap. $27,120 for up to 250 is about $108. You pay for the team and the longer window, not a volume discount. Both figures leave out the platform line.
  • Bundles hide the internal share. AZ Pentest's $6,500 covers external and internal together. Its external-only tier starts at $4,000.
  • "From" means the smallest job. Invadel's price steps from $6,000 to $9,200 to $14,500 or more as sites, network segments and domains are added.

What moves a quote, according to the providers that say so: the number of systems, the number of sites, how the network is split up, and whether a device has to be shipped or a tester has to travel (AZ Pentest, TCM Security).

You will see "typical ranges" for internal tests on other sites. Each is one vendor's estimate with no stated scope. We do not average them, and you should not budget from them.

For the whole project, including external and web app testing, see penetration testing cost. If you already hold proposals, our guide to comparing penetration testing quotes shows how to line them up.

How much access should you give the testers?

Give the access that matches the question you want answered, and make the report say which access was handed over and which was earned. Two quotes for "an internal pentest" can test very different things depending on this.

Take the same 60-person company. The tester's device sits on the employee network in all three cases. Only the login changes.

Table columns: Login you supply; What the test can show; What it cannot show.
Login you supplyWhat the test can showWhat it cannot show
NoneWhat someone who plugs into the network can get with no account at allWhat a stolen employee login could reach, if the tester never gets one
One ordinary employee accountHow far a phished or careless employee's account can go: more permissions, other machines, sensitive dataHow an attacker would get that first account
An administrator accountWhat damage is possible from the top, or a review of high-privilege settingsWhether an attacker could ever reach administrator rights on their own

For the question most companies have, "what happens after someone's laptop or password is stolen," the middle row is the one to buy. Invadel's published offer starts there. NIST describes ordinary-user access as the usual starting point too.

Starting with nothing sounds tougher. It often is not more useful. If the tester spends four days failing to get a login, you learn little about what a real stolen login could do. If you want both, ask for two phases and agree in advance when the account gets handed over.

Two more points:

  • Where the device sits matters as much as the login. A VPN connection that lands on a management network is a different test from a device on the employee network.
  • Admin rights on the tester's own device are not admin rights on your systems. Testers need control of their testing machine or virtual appliance. That is setup, not scope.

The question to send every provider:

Will you test from the network position we name, with the account permissions we specify, and show separately in the report any access we give you later?

Is an automated internal pentest enough?

It depends on who reads the report. Autonomous tools do attempt real attacks; Horizon3.ai describes NodeZero exploiting weaknesses and chaining them. None of the rules above bans software. None says software alone is enough, either.

Three things to weigh:

  • PCI DSS leans toward people. The standard's guidance calls penetration testing "a highly manual process" and says scanning for vulnerabilities alone is not a penetration test. Your assessor applies that to the method and evidence you bring.
  • PCI DSS also wants independence. Requirement 11.4.2 lets your own qualified staff test, as long as the tester is organizationally independent. If the person who runs your network also runs the tool against it, ask your assessor whether that counts.
  • A vendor's compliance claim is a claim. Kaseya says vPenTest "meets compliance for PCI, HIPAA, SOC 2." Take the sample report to the person who will receive yours and ask.

If nobody outside your company needs the report, and you want to check your own network every month, software you run can be the better buy. No purchase of a consulting project is needed.

Internal vs external penetration testing: do you need both?

External asks whether someone can get in. Internal asks what happens once they are in. One does not answer the other.

Table columns: ; External; Internal.
ExternalInternal
Starts fromThe internetInside your network
ShowsWhich exposed systems can be broken intoHow far a foothold spreads
Named byPCI DSS 11.4.3; NY DFS 500.5 ("outside")PCI DSS 11.4.2; NY DFS 500.5 ("inside")

PCI DSS and New York's DFS rule each require both. If you have a current external test and only the internal half is missing, say so when you ask for quotes. AZ Pentest sells the two together by default and quotes internal-only on request. Invadel and Synack price internal work on its own.

What should you send before asking for quotes?

Send every provider the same request, so the answers line up. It is like asking three builders to price the same drawing instead of three different houses.

Fill this in privately and send it to the providers you choose.

Internal penetration test: scope request

  1. Why we need it and who reads the report: [audit, insurer, customer, our own assurance] [name the recipient and what they asked for]
  2. The question the test must answer: [for example: can an ordinary employee account reach payroll data or the backups?]
  3. Size: [live computers and servers, and how we counted] [sites] [network segments] [Active Directory domains or other login systems]
  4. Where the test starts: [employee network, guest network, VPN, another named segment]
  5. Logins we will supply: [none / one ordinary user / named admin account / more than one phase, reported separately]
  6. Boundaries to check: [from which segment to which, and what should be blocked]
  7. Out of scope and handle with care: [fragile or old systems, third-party systems, production hours, whether password spraying is allowed]
  8. Who does the work: [must a person test, or is automated testing acceptable to our recipient?]
  9. How you will connect: [shipped device, virtual machine, VPN, on site] [who on our side gets told testing has started]
  10. Report: [what we need to see: starting access, the path taken step by step, what was tried and failed, fixes in priority order, any letter or summary for our recipient]
  11. Dates: [access ready] [testing starts] [report due] [when our fixes will be done] [date we expect to ask for a retest]
  12. Price: please give the complete fixed price in [currency], any platform or subscription charge, the payment schedule, and what would change it.
  13. Retest: how many rounds are included, the last date we can request one, who performs it, and what updated report we receive.

Please confirm what is included, what is excluded, and anything that would change the scope, price or dates.

This request is a buying aid. It does not give anyone permission to test. Testing needs written authorization, signed by someone with authority over the systems, that names the actual networks and activities. Keep passwords, keys and network diagrams out of it; agree how to share those with the firm you hire.

Prepared with The PenTest Index: https://thepentestindex.com/internal-penetration-testing/

Not sure yet what needs testing, or who will read the report? Our free tool walks through those questions and gives you a general checklist to copy or print. It asks for no contact details. It does not pick a provider for you.

Find My PenTest Match

How is the test delivered, and will it disrupt us?

Most internal tests are now done remotely, in one to two weeks. The provider needs a way in, and providers describe three:

  • A small device they ship to you, which you plug into the network (AZ Pentest, Invadel, TCM Security).
  • A virtual machine or "jump box" you host for them (Cobalt, Invadel).
  • A VPN connection into the network (Cobalt).

An on-site visit is still offered by some and can add travel cost (TCM Security).

On timing, providers state their own estimates: about a week of testing for a single site (Invadel), one to two weeks from scoping to report (AZ Pentest), one to two weeks typical (TCM Security). These are estimates, not booked dates. If you have a deadline, get the report date in writing.

The work itself follows four phases in NIST's guide: planning, discovery, attack, reporting. Planning is where you protect yourself. Before testing starts, agree in writing:

  • which systems are off limits or need gentle handling;
  • whether password guessing that could lock accounts is allowed (Cobalt documents an opt-out for password spraying);
  • testing hours, and a named contact on each side who can stop the test;
  • who on your side is told, so your security monitoring does not treat the test as a real attack, or so it deliberately does;
  • that the device, accounts and any tools left behind are removed at the end.

No honest provider promises zero disruption. A clear list of fragile systems is what keeps the risk low.

What should the report show?

It should let someone who was not in the room see what was tested, from where, and what it proved. Before you sign, ask each provider for a sample report from an internal network test, not a web app test, and check it against these questions.

Table columns: Your question; What to look for in the report.
Your questionWhat to look for in the report
Did they test what we bought?Starting position, logins supplied, dates, scope and exclusions, any access added later
How far did they get?The path, step by step, with evidence: which accounts and systems were reached
Did our boundaries hold?Each segment-to-segment check and its result, not just "segmentation tested"
What held up?What was tried and failed. TCM Security says its reports include failed attempts and controls that worked.
What do we fix first?Findings in priority order with practical steps
Were the fixes checked?After the retest: each finding marked fixed, partly fixed or not fixed. Invadel says its reissued report does this.

Invadel's public sample is a web application report for a fictional client, so it does not show you an internal report. Ask for one. More on deliverables is in our guide to the penetration testing report.

Questions buyers still ask

Can our own team do the internal penetration test?

Under PCI DSS and New York's DFS rule, yes, if the tester is qualified. PCI DSS adds that the tester must be organizationally independent, which usually means not the people who manage the systems being tested. Your assessor judges both points.

How often is internal penetration testing required?

At least once every 12 months and after any significant change under PCI DSS 11.4.2. At least annually under 23 NYCRR 500.5. The FTC Safeguards Rule asks for annual penetration testing where there is no effective continuous monitoring or other ongoing detection of vulnerability-creating changes, except for financial institutions that maintain customer information about fewer than 5,000 consumers. Other rules leave timing to your risk assessment.

What tools are used for internal penetration testing?

Testers combine scanners with tools for password attacks and for mapping Active Directory. Buying a tool is not the same as commissioning a test. If you want software to run yourself, see the autonomous and scanning options above.

Is wireless testing part of an internal penetration test?

Often not. TCM Security, for one, lists wireless penetration testing as a separate service. If Wi-Fi matters to you, name it in item 3 of the scope request.

How we checked

We read each provider's own pricing, service and help pages, and the text of each rule, on the dates shown. We applied those published terms to one made-up buyer and showed the arithmetic. We did not buy, run or observe any test, and we have not seen any provider's contract. Our methodology explains how Purchase Checks work. How we make money explains how the site is funded; payment plays no part in which offers appear here or in what order.

Sources

Checked October 9, 2026 unless noted.