This site may contain affiliate or referral links. If you buy through one, we may be compensated. How we make money
Network penetration testing services: prices, scope limits and which test you need
By The PenTest Index · Offers and sources checked October 9, 2026
Network penetration testing services are authorized tests where a provider attacks your internet-facing (external) network, your internal network, or both, to show what an intruder could reach. Which side you need sets the price: Invadel publishes starting prices of $4,200 for a small external test and $6,000 for a small internal one, each confirmed after scoping.
Below you'll find which test fits your situation, ten offers from seven companies side by side, and one example network checked against every one of them.
Which network penetration test do you need?
Most buyers need an external test, an internal test, or both. The person who will read the report decides, so ask them first.
Think of a building. An external test checks the doors and windows from the street. An internal test checks what a visitor could open once they're past reception. The U.S. standards body NIST draws the same line: external testing is done from outside your security perimeter, and internal testers work from inside the network as a trusted insider or an attacker who already got in (NIST SP 800-115).
| Your situation | Ask for | What must be written down |
|---|---|---|
| A customer, insurer or auditor asked for "a pen test" and didn't say which | Their answer first. See the question near the end of this page | Which systems, which sides, what the report must show |
| You only care what the internet can reach: VPN, mail, firewalls, remote access | External network test | The public hosts and services in scope |
| You want to know how far someone gets from a phished laptop or a rogue device | Internal network test | The starting point, the account they begin with, and how far they may go |
| PCI DSS Requirements 11.4.2 and 11.4.3 apply to you | Both, at least every 12 months and after a significant change | See the PCI section below |
| You use network segmentation to keep card systems separate | Add segmentation testing | Which zones should and shouldn't reach which targets |
| Office Wi-Fi is part of the worry | Wireless testing, named in the quote | Sites and networks. It is usually priced separately |
| Your business runs on SaaS logins and laptops, with no real office network | A scope built for identities and endpoints | See "mostly SaaS" below. A network package may not fit |
Two terms used from here on. A network zone is a group of systems separated from others by network controls. Segmentation means those controls. Active Directory is Microsoft's service for managing users and computers, and it is where most internal tests spend their time.
Know which side you need? See which offers cover it.
Network penetration testing services compared
Of the seven companies we compared, three publish a network price: Astra, Invadel and Synack. The other four ask for a quote.
These are offers to look into, not a ranking of who tests best. Companies appear A to Z within each group. Every detail is what the provider publishes on its own pages, which we read on October 9, 2026. "Not stated" means we didn't find it there. It doesn't mean the provider can't do it. Prices are in U.S. dollars.
Tests that include human testers
| Offer | Sides covered | Who tests | Published price and what it's based on | Retest after you fix things | Ask first |
|---|---|---|---|---|---|
| Astra Pentest Expert | "Network" is a listed target. External or internal not stated | Certified testers plus autonomous agents (Astra's wording) | $5,999 per year, per target | 2 expert re-scans. Request within 30 days of findings being reported | "Is our whole network one target or many?" The pricing page reads both ways |
| BreachLock Standard / Extended / Extensive | Standard is described for basic internal networks and external network infrastructure | In-house testers (BreachLock's wording) | Quote required | 1 / 2 / custom free manual retests. Window not stated | "Which package fits our hosts, and until what date can we ask for each retest?" |
| Cobalt external and internal network pentests | Both, as separate scopes | Cobalt's community of vetted testers | Quote required. Sold as annual credit packages, scoped by number of active IP addresses | Free within an active contract: 6 months on Standard, 12 on Premium and Enterprise, ending no later than 10 days before the contract does | "How many credits does our IP count need, and what is our last retest date?" |
| Invadel external network test | External | Senior in-house testers (Invadel's wording) | Fixed price from $4,200 small, $6,800 medium, $8,400 large. Tier set by live hosts and exposed services, not per IP | One free retest with an updated report. Deadline not stated | "Which tier are we, and by when must we ask for the retest?" |
| Invadel internal network test | Internal, including Active Directory and segmentation testing | Same | Fixed price from $6,000 small (one site or one domain, up to a few hundred hosts), $9,200 medium, $14,500+ large | Same | Same, plus "Does one retest cover both tests if we buy both?" |
| NetSPI internal network pentesting | Internal, including Active Directory and segmentation testing for PCI DSS | Human-led, testers employed by NetSPI (its wording) | Quote required | Not stated on the page we read | "Please itemize each side, the report, any platform commitment and retesting" |
| Pentest-Tools.com Network Pentest | Not stated | In-house team (its wording) | Quote required. It says you get a fixed-price proposal | "Free re-testing phase." Count and window not stated | "External, internal or both? How many retests and by when?" |
| Synack SynackST | Internal and external hosts | 1 human tester | From $10,283 per test, for up to 100 host IPs. A platform line item is required and billed separately | Patch verification listed. Count and window not stated | "Which platform tier do we need and what does it cost?" |
| Synack Synack14 | Internal and external | A team of researchers | From $27,120 per test, for up to 250 host IPs. Same platform note | Same | Same |
AI-led test
| Offer | Sides covered | Who tests | Published price and what it's based on | Retest | Ask first |
|---|---|---|---|---|---|
| Synack Sara Pentest | External hosts only | AI-led | From $4,181 per test, for 100 host IPs or one low-complexity web app. Same platform note | Patch verification listed | "Will the person reading our report accept an AI-led test?" |
Sources: Astra pricing and Astra re-scan rules (re-scan rules read October 7–8, 2026) · BreachLock packages · Cobalt pricing, Cobalt retest policy and Cobalt scoping · Invadel external pricing, Invadel internal pricing and Invadel pricing overview · NetSPI internal network · Pentest-Tools.com services · Synack pricing.
Four things in that table change what you'd pay.
Three providers, three ways of counting. Synack caps a package by host IPs. Cobalt scopes by the number of active IP addresses. Invadel says outright that it does not price per IP and sets a tier by live hosts and exposed services. The same network can land in very different places, so count your live hosts before you ask anyone for a number.
Astra's page gives two answers on what one "target" is. The plan card says networks, cloud and IPs are one target each. The pricing FAQ on the same page says several IPs can be grouped into one target at tailored pricing. Until Astra tells you in writing which applies, you can't work out what $5,999 a year buys for your network.
Synack's test price is not the total. Its pricing page says the Synack Platform is required and is a separate line item. It also describes a Basic Platform at no cost. Which one your purchase needs is not stated, so the total is unknown, not zero. Synack also says purchased credits expire one year from the purchase date.
Cobalt's retest wording differs between two pages. Its pricing FAQ says retesting is unlimited through your contract term. Its documentation gives 6 or 12 months by tier, for its Agile and Comprehensive pentests, and an end date no later than 10 days before the contract ends. The same pricing page also shows credit rollover of "up to 10%" in one table while its FAQ says credits do not roll over. Ask which terms will be in your agreement.
Two offers that often get mistaken for network tests are not. Astra's cheaper Pentest Auto plan lists web apps and SaaS only. The $3,400 price Pentest-Tools.com publishes is for a web application, not a network.
We read the public pages listed above. We did not buy or run any of these tests, and nothing here rates testing quality. How we check offers · How we make money
Which network offers deserve a closer look?
Start with whatever would rule an offer out. For network tests that is usually internal coverage, your host count, or how long you need to fix things before the retest.
Here is one example, worked all the way through. It is made up. No provider has quoted for it.
Say you run a 60-person firm with one office and one Active Directory domain. You have 12 internet-facing hosts and about 180 live internal hosts. Your PCI assessor wants internal and external tests, and your team needs about 45 days to fix what's found before a retest.
That gives three requirements: both sides, 192 hosts, and a retest you can still request on day 45.
| Offer | Both sides? | Fits 192 hosts? | Retest on day 45? | Where that leaves it |
|---|---|---|---|---|
| Invadel external + internal | Supported. Invadel says the two prices add | Internal fits its small tier as described. External is unresolved: 12 hosts sits between "a handful" and "several dozen" | Unresolved. One free retest, no stated deadline | Starts at $10,200 ($4,200 + $6,000) if external is small, or $12,800 ($6,800 + $6,000) if medium. Fixed price confirmed after scoping |
| Synack Synack14 | Supported | Supported on count. 192 is under 250 | Unresolved. Count and window not stated | From $27,120, plus a platform line with no confirmed price. Total unresolved |
| Synack SynackST | Supported | Mismatch. 192 is over the 100-host limit for one test | Unresolved | Two tests would start at $20,566 (2 × $10,283). Whether Synack sells it that way is unresolved |
| Synack Sara | Mismatch. External only | Not applicable | Not applicable | Out for this buyer |
| Astra Pentest Expert | Unresolved | Conflicting. Target count can't be worked out | Mismatch. Re-scans must be requested within 30 days | Out unless Astra extends the window in writing |
| Cobalt | Supported, as two scopes | Quote needed | Supported if day 45 falls within the tier's retest window and the contract runs at least 10 days past day 45 | Ask for credits and the last retest date |
| BreachLock Standard | Supported by its description | Quote needed | Unresolved. One retest, no stated window | Ask with the same brief |
| NetSPI | Internal read. External not checked on the page we read | Quote needed | Unresolved | Ask with the same brief |
| Pentest-Tools.com | Unresolved | Quote needed | Unresolved | Ask with the same brief |
The sums are ours, made from each provider's published starting prices. They are not quotes. "Supported" means that one condition is backed by the page we read. It says nothing about how well anyone tests, or whether your assessor will accept the report.
What we'd do as this buyer. Start with Invadel. It publishes separate prices for both sides done by human testers, and its smallest combination starts at less than half of Synack14's test price. Then send the same brief to BreachLock and to either Cobalt or NetSPI, so you have real quotes to hold against it. Keep Synack14 in mind if a published host limit and a 14-day window matter more to you than the starting price. Drop Sara, and drop Astra Pentest Expert unless it confirms a longer retest window.
If your situation is different:
- External only, a handful of hosts, and a reader who accepts AI-led testing: Synack Sara starts at $4,181 plus the platform line. Invadel's small external tier starts at $4,200 with human testers and a free retest.
- Both sides, 100 hosts or fewer: SynackST's limit fits. Compare it with Invadel's $10,200 start.
- Several tests a year across apps and network: Cobalt's annual credits are built for that. Get the credit count and retest cutoff in writing.
- PCI segmentation is the main job: Invadel and NetSPI both name segmentation testing on the pages we read. Ask the others directly.
- You want provider-employed testers: BreachLock, Invadel, NetSPI and Pentest-Tools.com each say their testers are in-house. That is their statement. Ask who will be assigned to your test.
Ready to look at one? Each link goes to the provider's own page. Keep the open question next to it in mind.
Invadel: confirm your tier and the retest deadline.
View Invadel external network pricing
View Invadel internal network pricing
Synack: confirm the platform tier and its price.
Astra: confirm how your network counts as targets, and the re-scan window.
BreachLock: confirm the package and retest dates.
Cobalt: confirm credits needed and your last retest date.
View Cobalt internal network testing
NetSPI: ask for each side itemized.
View NetSPI internal network testing
Pentest-Tools.com: ask which sides the proposal covers.
View Pentest-Tools.com services
How much do network penetration testing services cost?
Published starting prices for a test with human testers run from $4,200 (Invadel, small external) to $27,120 (Synack14, up to 250 host IPs). Four of the seven companies we compared publish no network price at all.
Here is every published network price we found, in U.S. dollars, read October 9, 2026.
| Provider and offer | Published price | What it covers | What it leaves out |
|---|---|---|---|
| Invadel external | From $4,200 / $6,800 / $8,400 (small / medium / large) | One fixed-price test. Report, one free retest, attestation letter | A starting point. Invadel confirms your figure after scoping |
| Invadel internal | From $6,000 / $9,200 / $14,500+ | Same, run remotely, with Active Directory and segmentation testing | Same. On-site work adds time and cost |
| Synack Sara | From $4,181 per test | AI-led, external, 100 host IPs | Required platform line item |
| Synack SynackST | From $10,283 per test | 1 human tester, up to 100 host IPs, 5-day window | Required platform line item |
| Synack Synack14 | From $27,120 per test | Researcher team, up to 250 host IPs, 14-day window | Required platform line item |
| Astra Pentest Expert | $5,999 per year, per target | Manual test, ongoing scanning, 2 re-scans | How many targets your network is |
| Astra Enterprise | From $9,999 per year | Custom | Everything specific to you |
Because Invadel says its external and internal prices simply add, you can work out every both-sides starting point yourself. We did it for you:
| Internal small ($6,000) | Internal medium ($9,200) | Internal large ($14,500+) | |
|---|---|---|---|
| External small ($4,200) | $10,200 | $13,400 | $18,700+ |
| External medium ($6,800) | $12,800 | $16,000 | $21,300+ |
| External large ($8,400) | $14,400 | $17,600 | $22,900+ |
These are sums of Invadel's published starting prices. Which tier you fall into is Invadel's call after scoping.
One more piece of arithmetic shows why host count matters with capped packages. SynackST's $10,283 start spread over its full 100 hosts is about $103 a host. Use it for 20 hosts and it is about $514 a host. That is our division, not a rate Synack offers, and it leaves out the platform line.
What moves a quote. The number of live hosts on each side. How many sites. How complicated Active Directory is. How much segmentation there is to check. Whether anyone must come on site. Whether wireless is included. And the retest: how many, by when, and what a late one costs.
When you ask for a price, ask for five things as separate lines: the test itself, any required platform or subscription, extras, the retest terms, and what you owe now versus over the year.
How is a network penetration test scoped, and can internal testing be done remotely?
Providers scope a network test by live hosts on each side, not by how big your company is. And yes, internal tests are usually run remotely.
What to count before you call anyone:
- Live external hosts and the services on them (VPN, mail, portals)
- Live internal hosts, roughly
- Sites, network zones and Active Directory domains
- Anything fragile or owned by someone else
How testers get inside. Cobalt's documentation asks for either a stable VPN into the internal network or a small Linux server placed inside it, called a jump box, with root access for the testers. It recommends putting that server on a normal, busy user network so the test looks like a real intrusion. Invadel says most of its internal tests run through a small appliance or virtual machine it provides, with on-site testing available if you need it. Either way, where that starting point sits and what account it starts with decides what the test can prove. Put both in writing.
Will it take anything down? It can. Agreed limits lower the risk, but nobody can honestly promise zero impact. The UK's National Cyber Security Centre makes the same point in its penetration testing guidance. What you can do is agree the rules first. Invadel says it agrees fixed source addresses, testing windows and lockout-safe password testing in writing before work starts. Cobalt says its testers coordinate password-spraying with your team and you can opt out. Ask every provider which systems they'll avoid, what hours they'll work, and who they call if something breaks.
Is a vulnerability scan the same as a network penetration test?
No. A scan lists weaknesses that might exist. A penetration test tries to use them, to prove what an attacker could actually reach.
NIST puts it this way: scanners check only for the possible existence of a vulnerability, and the attack phase of a penetration test exploits it to confirm it's real (NIST SP 800-115).
The card-payment standard treats them as two separate jobs. PCI DSS v4.0.1 asks for vulnerability scans at least every three months, and separately asks for penetration tests at least every 12 months. A quote for one doesn't cover the other.
So ask every provider three things. What will you try to exploit, not just detect? Who reviews the findings? What is left out?
The same questions apply to software-run tests. Synack's Sara is AI-led. Vonahi's vPenTest describes itself as an automated network penetration testing platform for internal and external networks. Judge these by what they exploit and what evidence they hand you, not by the label, and check that the person reading your report accepts that kind of test.
Does PCI DSS require network penetration testing?
Yes. If PCI DSS Requirements 11.4.2 and 11.4.3 apply to you, it requires both internal and external penetration tests at least once every 12 months and after any significant infrastructure or application change.
PCI DSS is the security standard for organizations that handle payment card data. The cardholder data environment (CDE) includes the systems, people and processes that store, process or transmit cardholder data or sensitive authentication data, plus systems with unrestricted connectivity to those systems. Here is what version 4.0.1 says, in the requirement text published by the PCI Security Standards Council (Prioritized Approach for PCI DSS v4.0.1, read October 9, 2026).
| Requirement | What it asks for | How often |
|---|---|---|
| 11.4.1 | A documented testing method that covers the whole CDE perimeter and critical systems, tests from inside and outside the network, checks segmentation controls, and includes network-layer tests | Ongoing |
| 11.4.2 | Internal penetration testing | At least every 12 months, and after a significant change |
| 11.4.3 | External penetration testing | Same |
| 11.4.4 | Fix exploitable findings according to your risk assessment, then repeat testing to verify the fixes | After each test |
| 11.4.5 | If you use segmentation to isolate the CDE, test those controls | At least every 12 months, and after changes to them |
| 11.4.6 | Service providers: the same segmentation tests | At least every six months, and after changes to segmentation controls or methods |
| 11.3.1 and 11.3.2 | Vulnerability scans, internal and external. External scans must be done by a PCI SSC Approved Scanning Vendor (ASV) | At least every three months |
Three points people get wrong.
The tester does not have to be a QSA or an ASV. Requirements 11.4.2 and 11.4.3 allow a qualified internal resource or a qualified external third party, as long as the tester is organizationally independent. A QSA is a Qualified Security Assessor, the person who assesses your compliance.
Retesting is part of the requirement. Requirement 11.4.4 says testing is repeated to verify corrections. That is why the retest window in your contract matters as much as the test itself.
An ASV claim is something to check. Astra's pricing page describes "PCI-ASV" reports. That is Astra's statement. ASV status is granted by the PCI Security Standards Council, which publishes the list of approved vendors. Check any provider's name there before relying on it for your quarterly scans.
We read the requirement text, not the full standard's guidance notes, so confirm how each line applies to you with your assessor. They decide what they accept. We don't.
For SOC 2, HIPAA, insurance and other rules, there is no single answer. Our rules tracker goes through them one source at a time. For cyber insurance, each insurer's own form decides. Ask your broker what the form requires.
How long does a network penetration test take?
Published testing windows run from about four days to 15 working days. The real schedule is longer, because scoping comes before and fixes and retesting come after.
What each provider states, as read October 9, 2026:
| Provider | Stated timing |
|---|---|
| Invadel | Testing usually starts within a week of scoping. A small perimeter or a single-site network takes about a week of testing, plus reporting |
| Synack | Assessment windows of 4–5 days (Sara), 5 days (SynackST) and 14 days (Synack14) |
| Astra | Manual testing takes 10–15 working days, per its pricing FAQ |
| Pentest-Tools.com | Engagements typically finish within 7–10 business days |
| Cobalt | Says a pentest can start in 24 hours and retesting takes 7 days or less |
These are the providers' own statements, not booked dates. A testing window is also not a report date.
Plan backward from the day you need evidence in hand. You need five dates in writing: access ready, test start, first report, fixes done, and the last day you can ask for a retest.
That last one catches people. Astra Pentest Expert's included re-scans must be requested within 30 days. Cobalt's free retesting ends at the tier cutoff or 10 days before your contract does, whichever comes first. So if a Cobalt contract ended 50 days after your report, your last retest request would be day 40, even on a tier with a six-month window. That is our arithmetic on a made-up contract, but the rule is Cobalt's.
What should a network penetration testing report include?
It should show what was tested, from where, what was found and what was fixed. Agree that with whoever will read it before testing starts.
| Ask to see | The question it answers |
|---|---|
| Named scope, dates, starting points and exclusions | Does this describe the test we paid for? |
| Each finding tied to the affected systems, with steps to reproduce it | Can our team see the problem and fix it? |
| Severity explained, with practical fix guidance | What do we fix first, and why? |
| What was blocked, skipped or not tested | What does this report not tell us? |
| Status of each finding after the retest | Which fixes were checked, and which are still open? |
Ask for a sample from a network test, not a web application test. A sample from a different kind of test shows you the format and little else.
What should you send to network testing companies?
Send every provider the same brief. A brief asks each supplier the same question, so the answers line up and you can compare them.
One first-time buyer on Reddit's r/sysadmin put the problem plainly: "What questions should I be asking to any company that wishes to quote?" This is our answer. Copy it, fill it in, and send it to each provider you're considering.
Network penetration testing scope brief
1. Purpose and reader. Why we need this test. Who will read the report. What they've told us they need.
2. Sides requested. External, internal, both, segmentation, wireless. What each one should show.
3. External inventory. Public address ranges, live hosts, hostnames and services. What happens if you find hosts we didn't list.
4. Internal inventory. Approximate live hosts, sites, network zones and Active Directory domains. Our most important systems.
5. Starting points and access. Where the internal test starts (employee network, guest network, VPN). What account it starts with. What we need to set up.
6. Boundaries to check. Which zones should and should not reach which protected systems.
7. What's in and out. Web applications and APIs, wireless, cloud accounts, laptops, physical access, industrial systems. Mark each included, excluded or to be discussed.
8. The work and the evidence. How much is done by people and how much by software. Who reviews findings. How urgent findings are reported. A sample network report.
9. Limits. Approved hours. Fragile systems. Actions that are off limits. Systems owned by third parties. Who to call to stop the test.
10. Dates. Access ready, test start, first report, fixes expected, last retest request, updated report.
11. The full commitment. The test, any required platform or subscription, extras, on-site costs, taxes, number of retests and their deadline, late-retest fees, payment schedule and renewal terms.
12. What we already have. Any current provider or included test, what it covers, and what's still open.
Please reply by marking each line included, excluded or needing clarification, and return your written scope, total commitment and dates.
This is a buying brief. It is not permission to test. Written authorization must come from the owners of the actual systems and must name the targets and activities. Don't put passwords or keys in this brief.
Prepared with The PenTest Index: https://thepentestindex.com/network-penetration-testing-services/
Still working out what goes in the brief, or need to cover more than the network? Find My PenTest Match is our free scope checklist. You pick what needs testing, it shows what to settle and what to ask, and you copy or print it. It asks for no contact details. It also lists compared offers whose published terms mention network or host testing.
What if you mainly use SaaS, or already have a provider?
Then you may not need to buy a network test at all. Tie the test to the systems and the question you actually have.
If your company runs on cloud apps and laptops, with no servers in an office, an "internal network" may barely exist. Your real exposure is logins, devices and cloud settings. A standard internal network package would test very little. Ask for a scope built around identities, endpoints and cloud configuration.
If you already have a tester, or a test bundled with a compliance tool, check it against the brief above before you shop. If it covers the sides, the dates and the evidence your reader wants, you're done. That's a good outcome.
And if you've only been told "we need a pen test report," send the person who asked this:
Which systems and which sides of the network must the test cover, and what must the report show for you to accept it?
Their answer tells you whether you need external, internal, an application test, or something else.
Common questions
How often should a network be tested?
Where PCI DSS Requirements 11.4.2 and 11.4.3 apply, at least every 12 months and after any significant change, for both internal and external tests. Outside PCI there is no single rule. Your customer, auditor or insurer sets the expectation, so ask them.
Can our IT provider or MSP run the test?
PCI DSS allows a qualified internal resource or a qualified outside party, but the tester must be organizationally independent. A team that built and runs the network may not meet that. For any other reader, ask whether they need an independent tester.
Are wireless and cloud included in a network test?
Usually not unless the quote says so. Invadel lists wireless testing from $3,800 and cloud testing from $6,800 as separate services. Astra's plan card counts networks and cloud as separate targets. Name each one in your brief.
Do we need a local company?
Usually not. Invadel and Cobalt both describe running internal tests remotely. You need someone on site if your contract requires it, or if wireless or physical access is in scope.
Sources
All read on October 9, 2026 unless noted. Provider pages show what each provider publishes about itself.
- Astra: Plans and pricing
- Astra: Re-scan rules (read October 7–8, 2026)
- BreachLock: Penetration testing packages and pricing
- Cobalt: Pricing
- Cobalt: Retest policy
- Cobalt: Internal network methodologies
- Cobalt: Internal network pentest service and scoping (page copies dated October 8, 2026)
- Invadel: External network penetration testing cost
- Invadel: Internal network penetration testing cost
- Invadel: Pricing overview
- NetSPI: Internal network penetration testing
- Pentest-Tools.com: Offensive security services
- Synack: Pricing
- PCI Security Standards Council: Prioritized Approach for PCI DSS v4.0.1 (requirement text)
- NIST SP 800-115: Technical Guide to Information Security Testing and Assessment
Spotted a changed price or a missing provider? Send us the source and we'll check it and update the date. For app and API offers, see penetration testing companies compared.