This site may contain affiliate or referral links. If you buy through one, we may be compensated. How we make money

Network penetration testing services: prices, scope limits and which test you need

By The PenTest Index · Offers and sources checked October 9, 2026

Network penetration testing services are authorized tests where a provider attacks your internet-facing (external) network, your internal network, or both, to show what an intruder could reach. Which side you need sets the price: Invadel publishes starting prices of $4,200 for a small external test and $6,000 for a small internal one, each confirmed after scoping.

Below you'll find which test fits your situation, ten offers from seven companies side by side, and one example network checked against every one of them.

Which network penetration test do you need?

Most buyers need an external test, an internal test, or both. The person who will read the report decides, so ask them first.

Think of a building. An external test checks the doors and windows from the street. An internal test checks what a visitor could open once they're past reception. The U.S. standards body NIST draws the same line: external testing is done from outside your security perimeter, and internal testers work from inside the network as a trusted insider or an attacker who already got in (NIST SP 800-115).

Table columns: Your situation; Ask for; What must be written down.
Your situationAsk forWhat must be written down
A customer, insurer or auditor asked for "a pen test" and didn't say whichTheir answer first. See the question near the end of this pageWhich systems, which sides, what the report must show
You only care what the internet can reach: VPN, mail, firewalls, remote accessExternal network testThe public hosts and services in scope
You want to know how far someone gets from a phished laptop or a rogue deviceInternal network testThe starting point, the account they begin with, and how far they may go
PCI DSS Requirements 11.4.2 and 11.4.3 apply to youBoth, at least every 12 months and after a significant changeSee the PCI section below
You use network segmentation to keep card systems separateAdd segmentation testingWhich zones should and shouldn't reach which targets
Office Wi-Fi is part of the worryWireless testing, named in the quoteSites and networks. It is usually priced separately
Your business runs on SaaS logins and laptops, with no real office networkA scope built for identities and endpointsSee "mostly SaaS" below. A network package may not fit

Two terms used from here on. A network zone is a group of systems separated from others by network controls. Segmentation means those controls. Active Directory is Microsoft's service for managing users and computers, and it is where most internal tests spend their time.

Know which side you need? See which offers cover it.

Network penetration testing services compared

Of the seven companies we compared, three publish a network price: Astra, Invadel and Synack. The other four ask for a quote.

These are offers to look into, not a ranking of who tests best. Companies appear A to Z within each group. Every detail is what the provider publishes on its own pages, which we read on October 9, 2026. "Not stated" means we didn't find it there. It doesn't mean the provider can't do it. Prices are in U.S. dollars.

Tests that include human testers

Table columns: Offer; Sides covered; Who tests; Published price and what it's based on; Retest after you fix things; Ask first.
OfferSides coveredWho testsPublished price and what it's based onRetest after you fix thingsAsk first
Astra Pentest Expert"Network" is a listed target. External or internal not statedCertified testers plus autonomous agents (Astra's wording)$5,999 per year, per target2 expert re-scans. Request within 30 days of findings being reported"Is our whole network one target or many?" The pricing page reads both ways
BreachLock Standard / Extended / ExtensiveStandard is described for basic internal networks and external network infrastructureIn-house testers (BreachLock's wording)Quote required1 / 2 / custom free manual retests. Window not stated"Which package fits our hosts, and until what date can we ask for each retest?"
Cobalt external and internal network pentestsBoth, as separate scopesCobalt's community of vetted testersQuote required. Sold as annual credit packages, scoped by number of active IP addressesFree within an active contract: 6 months on Standard, 12 on Premium and Enterprise, ending no later than 10 days before the contract does"How many credits does our IP count need, and what is our last retest date?"
Invadel external network testExternalSenior in-house testers (Invadel's wording)Fixed price from $4,200 small, $6,800 medium, $8,400 large. Tier set by live hosts and exposed services, not per IPOne free retest with an updated report. Deadline not stated"Which tier are we, and by when must we ask for the retest?"
Invadel internal network testInternal, including Active Directory and segmentation testingSameFixed price from $6,000 small (one site or one domain, up to a few hundred hosts), $9,200 medium, $14,500+ largeSameSame, plus "Does one retest cover both tests if we buy both?"
NetSPI internal network pentestingInternal, including Active Directory and segmentation testing for PCI DSSHuman-led, testers employed by NetSPI (its wording)Quote requiredNot stated on the page we read"Please itemize each side, the report, any platform commitment and retesting"
Pentest-Tools.com Network PentestNot statedIn-house team (its wording)Quote required. It says you get a fixed-price proposal"Free re-testing phase." Count and window not stated"External, internal or both? How many retests and by when?"
Synack SynackSTInternal and external hosts1 human testerFrom $10,283 per test, for up to 100 host IPs. A platform line item is required and billed separatelyPatch verification listed. Count and window not stated"Which platform tier do we need and what does it cost?"
Synack Synack14Internal and externalA team of researchersFrom $27,120 per test, for up to 250 host IPs. Same platform noteSameSame

AI-led test

Table columns: Offer; Sides covered; Who tests; Published price and what it's based on; Retest; Ask first.
OfferSides coveredWho testsPublished price and what it's based onRetestAsk first
Synack Sara PentestExternal hosts onlyAI-ledFrom $4,181 per test, for 100 host IPs or one low-complexity web app. Same platform notePatch verification listed"Will the person reading our report accept an AI-led test?"

Sources: Astra pricing and Astra re-scan rules (re-scan rules read October 7–8, 2026) · BreachLock packages · Cobalt pricing, Cobalt retest policy and Cobalt scoping · Invadel external pricing, Invadel internal pricing and Invadel pricing overview · NetSPI internal network · Pentest-Tools.com services · Synack pricing.

Four things in that table change what you'd pay.

Three providers, three ways of counting. Synack caps a package by host IPs. Cobalt scopes by the number of active IP addresses. Invadel says outright that it does not price per IP and sets a tier by live hosts and exposed services. The same network can land in very different places, so count your live hosts before you ask anyone for a number.

Astra's page gives two answers on what one "target" is. The plan card says networks, cloud and IPs are one target each. The pricing FAQ on the same page says several IPs can be grouped into one target at tailored pricing. Until Astra tells you in writing which applies, you can't work out what $5,999 a year buys for your network.

Synack's test price is not the total. Its pricing page says the Synack Platform is required and is a separate line item. It also describes a Basic Platform at no cost. Which one your purchase needs is not stated, so the total is unknown, not zero. Synack also says purchased credits expire one year from the purchase date.

Cobalt's retest wording differs between two pages. Its pricing FAQ says retesting is unlimited through your contract term. Its documentation gives 6 or 12 months by tier, for its Agile and Comprehensive pentests, and an end date no later than 10 days before the contract ends. The same pricing page also shows credit rollover of "up to 10%" in one table while its FAQ says credits do not roll over. Ask which terms will be in your agreement.

Two offers that often get mistaken for network tests are not. Astra's cheaper Pentest Auto plan lists web apps and SaaS only. The $3,400 price Pentest-Tools.com publishes is for a web application, not a network.

We read the public pages listed above. We did not buy or run any of these tests, and nothing here rates testing quality. How we check offers · How we make money

Which network offers deserve a closer look?

Start with whatever would rule an offer out. For network tests that is usually internal coverage, your host count, or how long you need to fix things before the retest.

Here is one example, worked all the way through. It is made up. No provider has quoted for it.

Say you run a 60-person firm with one office and one Active Directory domain. You have 12 internet-facing hosts and about 180 live internal hosts. Your PCI assessor wants internal and external tests, and your team needs about 45 days to fix what's found before a retest.

That gives three requirements: both sides, 192 hosts, and a retest you can still request on day 45.

Table columns: Offer; Both sides?; Fits 192 hosts?; Retest on day 45?; Where that leaves it.
OfferBoth sides?Fits 192 hosts?Retest on day 45?Where that leaves it
Invadel external + internalSupported. Invadel says the two prices addInternal fits its small tier as described. External is unresolved: 12 hosts sits between "a handful" and "several dozen"Unresolved. One free retest, no stated deadlineStarts at $10,200 ($4,200 + $6,000) if external is small, or $12,800 ($6,800 + $6,000) if medium. Fixed price confirmed after scoping
Synack Synack14SupportedSupported on count. 192 is under 250Unresolved. Count and window not statedFrom $27,120, plus a platform line with no confirmed price. Total unresolved
Synack SynackSTSupportedMismatch. 192 is over the 100-host limit for one testUnresolvedTwo tests would start at $20,566 (2 × $10,283). Whether Synack sells it that way is unresolved
Synack SaraMismatch. External onlyNot applicableNot applicableOut for this buyer
Astra Pentest ExpertUnresolvedConflicting. Target count can't be worked outMismatch. Re-scans must be requested within 30 daysOut unless Astra extends the window in writing
CobaltSupported, as two scopesQuote neededSupported if day 45 falls within the tier's retest window and the contract runs at least 10 days past day 45Ask for credits and the last retest date
BreachLock StandardSupported by its descriptionQuote neededUnresolved. One retest, no stated windowAsk with the same brief
NetSPIInternal read. External not checked on the page we readQuote neededUnresolvedAsk with the same brief
Pentest-Tools.comUnresolvedQuote neededUnresolvedAsk with the same brief

The sums are ours, made from each provider's published starting prices. They are not quotes. "Supported" means that one condition is backed by the page we read. It says nothing about how well anyone tests, or whether your assessor will accept the report.

What we'd do as this buyer. Start with Invadel. It publishes separate prices for both sides done by human testers, and its smallest combination starts at less than half of Synack14's test price. Then send the same brief to BreachLock and to either Cobalt or NetSPI, so you have real quotes to hold against it. Keep Synack14 in mind if a published host limit and a 14-day window matter more to you than the starting price. Drop Sara, and drop Astra Pentest Expert unless it confirms a longer retest window.

If your situation is different:

  • External only, a handful of hosts, and a reader who accepts AI-led testing: Synack Sara starts at $4,181 plus the platform line. Invadel's small external tier starts at $4,200 with human testers and a free retest.
  • Both sides, 100 hosts or fewer: SynackST's limit fits. Compare it with Invadel's $10,200 start.
  • Several tests a year across apps and network: Cobalt's annual credits are built for that. Get the credit count and retest cutoff in writing.
  • PCI segmentation is the main job: Invadel and NetSPI both name segmentation testing on the pages we read. Ask the others directly.
  • You want provider-employed testers: BreachLock, Invadel, NetSPI and Pentest-Tools.com each say their testers are in-house. That is their statement. Ask who will be assigned to your test.

Ready to look at one? Each link goes to the provider's own page. Keep the open question next to it in mind.

Invadel: confirm your tier and the retest deadline.

View Invadel external network pricing

View Invadel internal network pricing

Synack: confirm the platform tier and its price.

View Synack testing packages

Astra: confirm how your network counts as targets, and the re-scan window.

View Astra pentest plans

BreachLock: confirm the package and retest dates.

View BreachLock packages

Cobalt: confirm credits needed and your last retest date.

View Cobalt internal network testing

NetSPI: ask for each side itemized.

View NetSPI internal network testing

Pentest-Tools.com: ask which sides the proposal covers.

View Pentest-Tools.com services

How much do network penetration testing services cost?

Published starting prices for a test with human testers run from $4,200 (Invadel, small external) to $27,120 (Synack14, up to 250 host IPs). Four of the seven companies we compared publish no network price at all.

Here is every published network price we found, in U.S. dollars, read October 9, 2026.

Table columns: Provider and offer; Published price; What it covers; What it leaves out.
Provider and offerPublished priceWhat it coversWhat it leaves out
Invadel externalFrom $4,200 / $6,800 / $8,400 (small / medium / large)One fixed-price test. Report, one free retest, attestation letterA starting point. Invadel confirms your figure after scoping
Invadel internalFrom $6,000 / $9,200 / $14,500+Same, run remotely, with Active Directory and segmentation testingSame. On-site work adds time and cost
Synack SaraFrom $4,181 per testAI-led, external, 100 host IPsRequired platform line item
Synack SynackSTFrom $10,283 per test1 human tester, up to 100 host IPs, 5-day windowRequired platform line item
Synack Synack14From $27,120 per testResearcher team, up to 250 host IPs, 14-day windowRequired platform line item
Astra Pentest Expert$5,999 per year, per targetManual test, ongoing scanning, 2 re-scansHow many targets your network is
Astra EnterpriseFrom $9,999 per yearCustomEverything specific to you

Because Invadel says its external and internal prices simply add, you can work out every both-sides starting point yourself. We did it for you:

Table columns: ; Internal small ($6,000); Internal medium ($9,200); Internal large ($14,500+).
Internal small ($6,000)Internal medium ($9,200)Internal large ($14,500+)
External small ($4,200)$10,200$13,400$18,700+
External medium ($6,800)$12,800$16,000$21,300+
External large ($8,400)$14,400$17,600$22,900+

These are sums of Invadel's published starting prices. Which tier you fall into is Invadel's call after scoping.

One more piece of arithmetic shows why host count matters with capped packages. SynackST's $10,283 start spread over its full 100 hosts is about $103 a host. Use it for 20 hosts and it is about $514 a host. That is our division, not a rate Synack offers, and it leaves out the platform line.

What moves a quote. The number of live hosts on each side. How many sites. How complicated Active Directory is. How much segmentation there is to check. Whether anyone must come on site. Whether wireless is included. And the retest: how many, by when, and what a late one costs.

When you ask for a price, ask for five things as separate lines: the test itself, any required platform or subscription, extras, the retest terms, and what you owe now versus over the year.

How is a network penetration test scoped, and can internal testing be done remotely?

Providers scope a network test by live hosts on each side, not by how big your company is. And yes, internal tests are usually run remotely.

What to count before you call anyone:

  • Live external hosts and the services on them (VPN, mail, portals)
  • Live internal hosts, roughly
  • Sites, network zones and Active Directory domains
  • Anything fragile or owned by someone else

How testers get inside. Cobalt's documentation asks for either a stable VPN into the internal network or a small Linux server placed inside it, called a jump box, with root access for the testers. It recommends putting that server on a normal, busy user network so the test looks like a real intrusion. Invadel says most of its internal tests run through a small appliance or virtual machine it provides, with on-site testing available if you need it. Either way, where that starting point sits and what account it starts with decides what the test can prove. Put both in writing.

Will it take anything down? It can. Agreed limits lower the risk, but nobody can honestly promise zero impact. The UK's National Cyber Security Centre makes the same point in its penetration testing guidance. What you can do is agree the rules first. Invadel says it agrees fixed source addresses, testing windows and lockout-safe password testing in writing before work starts. Cobalt says its testers coordinate password-spraying with your team and you can opt out. Ask every provider which systems they'll avoid, what hours they'll work, and who they call if something breaks.

Is a vulnerability scan the same as a network penetration test?

No. A scan lists weaknesses that might exist. A penetration test tries to use them, to prove what an attacker could actually reach.

NIST puts it this way: scanners check only for the possible existence of a vulnerability, and the attack phase of a penetration test exploits it to confirm it's real (NIST SP 800-115).

The card-payment standard treats them as two separate jobs. PCI DSS v4.0.1 asks for vulnerability scans at least every three months, and separately asks for penetration tests at least every 12 months. A quote for one doesn't cover the other.

So ask every provider three things. What will you try to exploit, not just detect? Who reviews the findings? What is left out?

The same questions apply to software-run tests. Synack's Sara is AI-led. Vonahi's vPenTest describes itself as an automated network penetration testing platform for internal and external networks. Judge these by what they exploit and what evidence they hand you, not by the label, and check that the person reading your report accepts that kind of test.

Does PCI DSS require network penetration testing?

Yes. If PCI DSS Requirements 11.4.2 and 11.4.3 apply to you, it requires both internal and external penetration tests at least once every 12 months and after any significant infrastructure or application change.

PCI DSS is the security standard for organizations that handle payment card data. The cardholder data environment (CDE) includes the systems, people and processes that store, process or transmit cardholder data or sensitive authentication data, plus systems with unrestricted connectivity to those systems. Here is what version 4.0.1 says, in the requirement text published by the PCI Security Standards Council (Prioritized Approach for PCI DSS v4.0.1, read October 9, 2026).

Table columns: Requirement; What it asks for; How often.
RequirementWhat it asks forHow often
11.4.1A documented testing method that covers the whole CDE perimeter and critical systems, tests from inside and outside the network, checks segmentation controls, and includes network-layer testsOngoing
11.4.2Internal penetration testingAt least every 12 months, and after a significant change
11.4.3External penetration testingSame
11.4.4Fix exploitable findings according to your risk assessment, then repeat testing to verify the fixesAfter each test
11.4.5If you use segmentation to isolate the CDE, test those controlsAt least every 12 months, and after changes to them
11.4.6Service providers: the same segmentation testsAt least every six months, and after changes to segmentation controls or methods
11.3.1 and 11.3.2Vulnerability scans, internal and external. External scans must be done by a PCI SSC Approved Scanning Vendor (ASV)At least every three months

Three points people get wrong.

The tester does not have to be a QSA or an ASV. Requirements 11.4.2 and 11.4.3 allow a qualified internal resource or a qualified external third party, as long as the tester is organizationally independent. A QSA is a Qualified Security Assessor, the person who assesses your compliance.

Retesting is part of the requirement. Requirement 11.4.4 says testing is repeated to verify corrections. That is why the retest window in your contract matters as much as the test itself.

An ASV claim is something to check. Astra's pricing page describes "PCI-ASV" reports. That is Astra's statement. ASV status is granted by the PCI Security Standards Council, which publishes the list of approved vendors. Check any provider's name there before relying on it for your quarterly scans.

We read the requirement text, not the full standard's guidance notes, so confirm how each line applies to you with your assessor. They decide what they accept. We don't.

For SOC 2, HIPAA, insurance and other rules, there is no single answer. Our rules tracker goes through them one source at a time. For cyber insurance, each insurer's own form decides. Ask your broker what the form requires.

How long does a network penetration test take?

Published testing windows run from about four days to 15 working days. The real schedule is longer, because scoping comes before and fixes and retesting come after.

What each provider states, as read October 9, 2026:

Table columns: Provider; Stated timing.
ProviderStated timing
InvadelTesting usually starts within a week of scoping. A small perimeter or a single-site network takes about a week of testing, plus reporting
SynackAssessment windows of 4–5 days (Sara), 5 days (SynackST) and 14 days (Synack14)
AstraManual testing takes 10–15 working days, per its pricing FAQ
Pentest-Tools.comEngagements typically finish within 7–10 business days
CobaltSays a pentest can start in 24 hours and retesting takes 7 days or less

These are the providers' own statements, not booked dates. A testing window is also not a report date.

Plan backward from the day you need evidence in hand. You need five dates in writing: access ready, test start, first report, fixes done, and the last day you can ask for a retest.

That last one catches people. Astra Pentest Expert's included re-scans must be requested within 30 days. Cobalt's free retesting ends at the tier cutoff or 10 days before your contract does, whichever comes first. So if a Cobalt contract ended 50 days after your report, your last retest request would be day 40, even on a tier with a six-month window. That is our arithmetic on a made-up contract, but the rule is Cobalt's.

What should a network penetration testing report include?

It should show what was tested, from where, what was found and what was fixed. Agree that with whoever will read it before testing starts.

Table columns: Ask to see; The question it answers.
Ask to seeThe question it answers
Named scope, dates, starting points and exclusionsDoes this describe the test we paid for?
Each finding tied to the affected systems, with steps to reproduce itCan our team see the problem and fix it?
Severity explained, with practical fix guidanceWhat do we fix first, and why?
What was blocked, skipped or not testedWhat does this report not tell us?
Status of each finding after the retestWhich fixes were checked, and which are still open?

Ask for a sample from a network test, not a web application test. A sample from a different kind of test shows you the format and little else.

What should you send to network testing companies?

Send every provider the same brief. A brief asks each supplier the same question, so the answers line up and you can compare them.

One first-time buyer on Reddit's r/sysadmin put the problem plainly: "What questions should I be asking to any company that wishes to quote?" This is our answer. Copy it, fill it in, and send it to each provider you're considering.

Network penetration testing scope brief

1. Purpose and reader. Why we need this test. Who will read the report. What they've told us they need.

2. Sides requested. External, internal, both, segmentation, wireless. What each one should show.

3. External inventory. Public address ranges, live hosts, hostnames and services. What happens if you find hosts we didn't list.

4. Internal inventory. Approximate live hosts, sites, network zones and Active Directory domains. Our most important systems.

5. Starting points and access. Where the internal test starts (employee network, guest network, VPN). What account it starts with. What we need to set up.

6. Boundaries to check. Which zones should and should not reach which protected systems.

7. What's in and out. Web applications and APIs, wireless, cloud accounts, laptops, physical access, industrial systems. Mark each included, excluded or to be discussed.

8. The work and the evidence. How much is done by people and how much by software. Who reviews findings. How urgent findings are reported. A sample network report.

9. Limits. Approved hours. Fragile systems. Actions that are off limits. Systems owned by third parties. Who to call to stop the test.

10. Dates. Access ready, test start, first report, fixes expected, last retest request, updated report.

11. The full commitment. The test, any required platform or subscription, extras, on-site costs, taxes, number of retests and their deadline, late-retest fees, payment schedule and renewal terms.

12. What we already have. Any current provider or included test, what it covers, and what's still open.

Please reply by marking each line included, excluded or needing clarification, and return your written scope, total commitment and dates.

This is a buying brief. It is not permission to test. Written authorization must come from the owners of the actual systems and must name the targets and activities. Don't put passwords or keys in this brief.

Prepared with The PenTest Index: https://thepentestindex.com/network-penetration-testing-services/

Still working out what goes in the brief, or need to cover more than the network? Find My PenTest Match is our free scope checklist. You pick what needs testing, it shows what to settle and what to ask, and you copy or print it. It asks for no contact details. It also lists compared offers whose published terms mention network or host testing.

Find My PenTest Match

What if you mainly use SaaS, or already have a provider?

Then you may not need to buy a network test at all. Tie the test to the systems and the question you actually have.

If your company runs on cloud apps and laptops, with no servers in an office, an "internal network" may barely exist. Your real exposure is logins, devices and cloud settings. A standard internal network package would test very little. Ask for a scope built around identities, endpoints and cloud configuration.

If you already have a tester, or a test bundled with a compliance tool, check it against the brief above before you shop. If it covers the sides, the dates and the evidence your reader wants, you're done. That's a good outcome.

And if you've only been told "we need a pen test report," send the person who asked this:

Which systems and which sides of the network must the test cover, and what must the report show for you to accept it?

Their answer tells you whether you need external, internal, an application test, or something else.

Common questions

How often should a network be tested?

Where PCI DSS Requirements 11.4.2 and 11.4.3 apply, at least every 12 months and after any significant change, for both internal and external tests. Outside PCI there is no single rule. Your customer, auditor or insurer sets the expectation, so ask them.

Can our IT provider or MSP run the test?

PCI DSS allows a qualified internal resource or a qualified outside party, but the tester must be organizationally independent. A team that built and runs the network may not meet that. For any other reader, ask whether they need an independent tester.

Are wireless and cloud included in a network test?

Usually not unless the quote says so. Invadel lists wireless testing from $3,800 and cloud testing from $6,800 as separate services. Astra's plan card counts networks and cloud as separate targets. Name each one in your brief.

Do we need a local company?

Usually not. Invadel and Cobalt both describe running internal tests remotely. You need someone on site if your contract requires it, or if wireless or physical access is in scope.

Sources

All read on October 9, 2026 unless noted. Provider pages show what each provider publishes about itself.

Spotted a changed price or a missing provider? Send us the source and we'll check it and update the date. For app and API offers, see penetration testing companies compared.