Penetration testing cost: published prices and what they include
By The PenTest Index · Prices checked October 8, 2026
Penetration testing cost for one web application starts at $3,400 for a published human-led test with no login, and includes offers with a $5,200 starting amount and a $6,800 one-time price once two logged-in user roles are in scope, on provider price pages we checked October 8, 2026. API coverage, retest deadlines and platform fees can change those totals. Most network and cloud work needs a quote.
Those numbers come from providers' own pages, not from an average. Below is every published price we found, what each one leaves out, and a way to work out the figure for your own scope.
A few plain definitions first. A penetration test (pentest) is a hired attempt to break into your system and report what worked. A role is a permission level, such as "customer" or "admin", not each person's account. A retest is the provider checking that your fixes worked.
This site may contain affiliate or referral links. If you buy through one, we may be compensated. How we make money.
How much does a penetration test cost for one web app?
For one web app, its API and two logged-in roles, tested by people, published offers include a $5,200 starting amount and a $6,800 one-time price. One provider starts lower, at $4,999, before your roles are counted.
Say you run a 30-person software company. You have one web app and the API behind it. A customer's security questionnaire asks for a penetration test that covers a normal user and an admin. Here is what each published offer says for that job, lowest figure first. This order is by price for this one example. It is not a ranking of the companies.
| Offer | Published amount for this scope | What you get for it | What is still open |
|---|---|---|---|
| Blaze, web application pentest | From $4,999 per test | Manual test. One free retest if it is performed within 90 days of the final report. | It is a starting price. Your roles and API set the real quote. |
| Pentest-Tools.com, grey box | $5,200 per test ($3,400 + 2 roles × $900) | Manual test as an anonymous and a logged-in user. 4 or more working days (best effort). | Starting amount. API work is not priced. A free retest is stated, with no deadline given. |
| Astra, Pentest Expert | $5,999 per year for one target | A manual test plus scanning for the year. The app and the APIs it uses count as one target. | Annual plan. Retests must be requested within 30 days of the findings being reported. |
| Stingrai, Hybrid Pentest | $6,800, one-time | One web app and its APIs. AI agent plus human testers. An attestation letter is listed. | Retests are "included" with no deadline given. More than one app needs a quote. |
| Synack, SynackST | From $10,283 per test, plus a platform line item | One human tester, 5-day window, one low-complexity logged-in app. | Total unknown. Whether the free Basic platform applies is not confirmed. |
Sources: Blaze listing, Pentest-Tools.com, Astra, Stingrai, Synack. All read October 8, 2026. The $5,200 is our arithmetic from Pentest-Tools.com's published formula. No provider has quoted for this example.
Which one should you price first?
Three answers decide it.
How long will your fixes take? If your team needs more than 30 days, Astra's included retests run out before you are ready, unless Astra agrees an extension in writing. Blaze states 90 days. Pentest-Tools.com and Stingrai state a free retest but no deadline, so ask for the date.
One test, or cover for the year? Pentest-Tools.com, Blaze and Stingrai price a single test. Astra's price is a yearly plan that adds scanning. Astra's help pages say monthly payment is only offered on its Scanner plan, so treat $5,999 as one annual amount.
Who reads the report? If your customer or auditor wants something specific, such as a signed letter or testing by people, check that before price. Stingrai's Hybrid plan lists an attestation letter on its price page. For the others, ask to see a sample report.
Our read of the evidence: for a one-off test with one or two roles, get written quotes from Pentest-Tools.com and Blaze first. They have the lowest published starting figures and both state a free retest. If you would use scanning all year and can fix within 30 days, add Astra. Use SynackST only once you have its platform charge in writing.
Already have a quote from a provider you like? Put it in the same table. If it covers the same roles and API and its retest window fits your fix time, you may not need to shop further.
See Blaze's web app pentest listing
See Pentest-Tools.com's price and scope
See Astra's Pentest Expert plan
Penetration testing cost by provider: every published price we found
We found 14 priced offers from seven providers. Most other firms we checked ask you to request a quote.
Read the "unit" before the number. "Per year" is a yearly plan. "From" is a starting price. "Not stated" means we did not find it on the pages we read. It does not mean free, and it does not mean no.
Prices appear as each provider shows them, with a $ sign. Stingrai's page states US dollars; Astra's published Pentest prices and the Intruder figures here are also identified as USD. The other listed test offers show no currency code in the price text we checked, so ask which currency the invoice will be in. Companies are listed A to Z in each group.
Tests that include human testers
| Provider and offer | Published price and unit | What it covers | Retest terms | Not in the price, or unknown |
|---|---|---|---|---|
| Astra, Pentest Expert | $5,999 per year, per target | Manual test plus automated testing. One web app with the APIs it uses is one target. | 2 manual retests. Request within 30 days of findings being reported. | Extra targets. Extra retests are a paid add-on. |
| Astra, Enterprise | $9,999 per year onwards | Tailored | 4 manual retests, 90 days | Starting figure only |
| Blaze, web app pentest | From $4,999 per test | Manual test. Blaze states 5 to 25 person-days on average. | One free retest if performed within 90 days of the final report | Your scope sets the quote |
| Pentest-Tools.com, black box | $3,400 fixed, per test | Anonymous attacker only. 3 working days (best effort), report on day 4. | Free retest stated for its services. No deadline given. | No logged-in testing |
| Pentest-Tools.com, grey box | From $3,400 + $900 per user role | Anonymous and logged-in. 4 or more working days (best effort). | Same | API work and complexity |
| Stingrai, Hybrid Pentest | $6,800 one-time | One web app and its APIs. AI agent with human testers. Attestation letter listed. | "Retests included." No deadline given. | More than one app |
| Synack, SynackST | From $10,283 per test | 1 human tester, 5-day window. Up to 25 apps without login, or 1 low-complexity app with login, or 100 host IPs. | "Patch verification." No count or deadline given. | Required platform line item |
| Synack, Synack14 | From $27,120 per test | Team of testers, 14-day window. Up to 50 apps without login, or 1 app with login, or 250 host IPs. | Same | Same |
"Black box" means the tester starts with no login, like a stranger on the internet. "Grey box" means you give them test accounts so they can check what a logged-in user could do.
Tests led by AI
These are a different purchase. Software does most of the testing. Read what the people do in each one.
| Provider and offer | Published price and unit | The condition that matters |
|---|---|---|
| Astra, Pentest Auto | $2,999 per year, per target | 1 manual retest, requested within 30 days |
| Cobalt, Autonomous Pentest | $3,500 per test | A promotion. The test must start and finish before December 31, 2026. The price after that is not published. |
| Intruder, single test | $4,000 per test ($3,500 if you already subscribe to Intruder's platform) | You must connect your source code repository. "Unlimited retesting," no time limit given. |
| Intruder, 4-test pack | $12,000 ($10,500 for platform subscribers) | All four must be used within 1 year of purchase |
| Stingrai, Autonomous Pentest | $3,000 one-time | One web app and its APIs. Stingrai says you do not pay if it finds no High or Critical issue. |
| Synack, Sara Pentest | From $4,181 per test | One low-complexity web app or 100 host IPs. Required platform line item. |
For Cobalt's credit terms and test options, read how Cobalt credits and pricing work.
Quote only
Bishop Fox, BreachLock and NetSPI published no price on the pages we read on October 7, 2026. Cobalt's human-led testing is sold as yearly credit packages with no published price.
What can change the total?
Four things: how many roles are tested, whether your API is included, when the retest window closes, and any required platform or yearly commitment.
Each extra role adds to the price
Pentest-Tools.com is the one provider we found that publishes a per-role price, so it shows the effect clearly.
| Logged-in roles | Calculation | Starting amount |
|---|---|---|
| 0 (black box) | $3,400 | $3,400 |
| 1 | $3,400 + 1 × $900 | $4,300 |
| 2 | $3,400 + 2 × $900 | $5,200 |
| 3 | $3,400 + 3 × $900 | $6,100 |
| 4 | $3,400 + 4 × $900 | $7,000 |
| 5 | $3,400 + 5 × $900 | $7,900 |
At three roles, this starting amount passes Astra's $5,999 yearly plan. At four, it passes Stingrai's $6,800. So count your roles before you compare. These are starting amounts from one provider's formula, not quotes.
Your API may or may not be inside the price
Astra and Stingrai both say the APIs your app uses are part of the one-app price. Pentest-Tools.com's formula does not mention APIs, and its services page says price depends on things like "number of user roles, API endpoints." Ask this: "Does this price cover the app and every API we listed? Please itemize it."
"Retest included" has a deadline
A free retest only helps if you can use it in time. Here is each stated rule turned into a date.
| Offer | The stated rule | What that means on a calendar |
|---|---|---|
| Astra Pentest Expert | Request within 30 days from the date the findings were reported. Extensions "case by case." | Findings reported March 2. Ask by about April 1. |
| Blaze | One free retest if performed within 90 days from the final report | Final report March 9. Retest done by about June 7. |
| Cobalt (Agile and Comprehensive tests) | 6 months on the Standard tier, 12 on Premium and Enterprise, but never later than 10 days before your contract ends | Contract ends December 31. Findings arrive December 1. You have until December 21, which is 20 days. |
| Pentest-Tools.com | Free re-testing phase, done by hand, with an updated report | No deadline or number of rounds given. Ask. |
| Stingrai | Retests included | No deadline given. Ask. |
| Intruder | Unlimited retesting | No time limit given. Ask. |
| Synack | Patch verification | No count or deadline given. Ask. |
Sources: Astra rescan rules, Blaze listing, Cobalt retest rules, Pentest-Tools.com services. Read October 8, 2026. The dates are our examples. Ask each provider for your real last day.
One more detail on Astra. Its automated re-checks are unlimited, but they only cover issues its scanner found. Issues found by its testers need one of the two manual retests.
The question to send any provider: "What is the last date we can ask for the included retest, how many rounds do we get, and when will we receive the updated report?"
Two places where a provider's own terms need confirmation
Synack. Its pricing page says the Synack Platform "is required to purchase any of the testing products and is a separate line item." The same page says "The Basic Platform is available at no cost." We cannot tell which applies to you, so we do not add up a Synack total. Ask: "Is the free Basic platform enough to buy SynackST? If not, what is the platform charge?"
Cobalt. Its pricing table lists credit rollover "Up to 10%" for Enterprise. The FAQ on the same page says "Credits do not roll over into the next contract." Ask which one will be in your contract.
Is a one-off test cheaper than a yearly plan or a pack?
Only if you would not use the extra. Count the full tests you will really run this year, then compare.
Intruder publishes both a single price and a pack price, so the math is easy to show. This uses its standard prices and assumes every test fits its offer.
| Full tests you use in the year | Buying singles at $4,000 | Buying the 4-pack at $12,000 | Cheaper |
|---|---|---|---|
| 1 | $4,000 | $12,000 | Single |
| 2 | $8,000 | $12,000 | Singles |
| 3 | $12,000 | $12,000 | Tie |
| 4 | $16,000 | $12,000 | Pack, by $4,000 |
The pack only wins at four. The same holds at the subscriber prices: three singles at $3,500 equal the $10,500 pack. A retest of your fixes is not a new test, so do not count those toward four. And Intruder's offer needs your source code connected, which some company policies do not allow.
See Intruder's single-test and pack terms
The same thinking applies to credits. Cobalt sells credits in yearly packages and says one credit is "the equivalent of 8 hours" of testing, delivered by a mix of AI and people. That is not eight hours of a person's time. Synack says its credits expire one year from purchase. Before you buy either, ask how many credits your test uses and what happens to the ones you do not spend.
Work out your own total
Enter your scope and see each published amount, plus what is still unknown for that offer.
Published prices for your scope
These are published prices applied to your answers. They are not quotes.
Ask your report reader before choosing an AI-led test.
Tests with human testers
| Provider and offer | Published amount | Scope fit | Retest finding | Open questions |
|---|---|---|---|---|
| AstraPentest Expert | $5,999 per year, per targetPrice label: per year | MatchAnnual plan. Astra says one app and the APIs it uses count as one target. | UnresolvedHow many days will fixes take, and can you request the retest within 30 days of the findings being reported? |
|
| BlazeWeb application pentest | From $4,999 per testPrice label: starting price | MatchPublished starting price; your roles and API set the real quote. | UnresolvedThe retest must be performed within 90 days from the final report. Your days-to-fixes answer does not establish either the final-report date or retest completion date. |
|
| Pentest-Tools.comGrey box | $5,200 starting amount per testPrice label: starting amount | Match2 logged-in roles applied to the published $3,400 + $900 per-role formula. | UnresolvedThe deadline is not published. Ask for the last request date and the number of retest rounds. |
|
| StingraiHybrid Pentest | $6,800 one-timePrice label: fixed | MatchThe published price covers one web app and its APIs. | UnresolvedThe deadline is not published. Ask for the last request date and the number of retest rounds. |
|
| SynackSynackST | Incomplete: from $10,283 per test, plus a platform line itemPrice label: incomplete | UnresolvedConfirm whether the free Basic platform applies and any paid-tier charge. Do not add an unknown charge. | UnresolvedThe deadline is not published. Ask for the last request date and the number of retest rounds. |
|
| Quote onlyBishop Fox, BreachLock, Cobalt credit packages and NetSPI | No published pricePrice label: quote needed | UnresolvedNo published price for these offers. | UnresolvedThe deadline is not published. Ask for the last request date and the number of retest rounds. |
|
Tests led by AI
| Provider and offer | Published amount | Scope fit | Retest finding | Open questions |
|---|---|---|---|---|
| AstraPentest Auto | $2,999 per year, per targetPrice label: per year | MatchAnnual plan. Astra says one app and the APIs it uses count as one target. | UnresolvedHow many days will fixes take, and can you request the retest within 30 days of the findings being reported? |
|
| CobaltAutonomous Pentest | $3,500 per testPrice label: fixed | UnresolvedPublished scope is a web-only asset with up to 25 pages and 2 user roles. | UnresolvedThe deadline is not published. Ask for the last request date and the number of retest rounds. |
|
| IntruderSingle test and 4-test pack | $4,000 for 1 test at $4,000 each ($3,500 per test for platform subscribers). One test: $4,000.Price label: fixed | UnresolvedConfirm whether you can connect your source code repository. | UnresolvedThe deadline is not published. Ask for the last request date and the number of retest rounds. |
|
| StingraiAutonomous Pentest | $3,000 one-timePrice label: fixed | MatchThe published price covers one web app and its APIs. | UnresolvedThe deadline is not published. Ask for the last request date and the number of retest rounds. |
|
| SynackSara Pentest | Incomplete: from $4,181 per test, plus a platform line itemPrice label: incomplete | UnresolvedConfirm whether the free Basic platform applies and any paid-tier charge. Do not add an unknown charge. | UnresolvedThe deadline is not published. Ask for the last request date and the number of retest rounds. |
|
What your full budget should include
The test price is one line. Write down all of these before you compare offers. If a required line has no price yet, your total is not finished. Do not treat a blank as zero.
- Test price. The amount, the currency and what it covers.
- Required platform or subscription. For the whole term, not per month.
- Scope extras. More roles, APIs or environments, as quoted.
- Retest. How many rounds are included, the last date to ask, and the price of one more.
- Tax. Ask whether the published figure includes it.
- Amount due now and what is due later. A deposit is part of the total, not on top of it.
- Your own time to fix what is found. This is your cost, not the provider's. Keep it on a separate line.
The calculator only covers providers that publish a price. For a side-by-side cost comparison, see what a vulnerability scan costs compared with a penetration test. To get a number you can compare from the ones that do not, give every provider the same scope. Our scope checklist walks you through what to write down. It is free, needs no contact details, and you copy or print it yourself. It does not pick a provider for you.
Why are penetration testing quotes so different?
Because each provider is pricing a different job unless you hand them all the same one.
Think of two painters quoting your house. One prices the outside only. The other prices every room. The numbers will be far apart, and neither is wrong. Pentest quotes work the same way. One covers a stranger's view of your site in three days. Another covers five roles, the API and a retest.
That is also why the ranges you see online are so wide. Blaze, a testing firm, says a standard engagement usually costs $10,000 to $35,000, based on about 900 quotes it sent in 2025. Synack's guide says most organizations spend $10,000 to $30,000 per engagement. Those are each company's own figures. They may be fair for the jobs those firms see. They cannot tell you what your job costs.
To get quotes you can line up, send this to each provider:
Please price a penetration test of [app name and environment], covering [number] logged-in roles, [the API or APIs], and [the workflows that matter most]. The report is for [customer, auditor or internal team], who needs [what they asked for]. Please send a sample report. We need the first report by [date]. Please confirm the full price and currency, every required charge, the payment schedule, how many retests are included, the last date to request one, what is excluded, and what would change the price.
This is a request for a price. It is not permission to test. Before any testing starts, you and the provider need written authorization that names the real systems and activities. Do not put passwords or keys in a pricing request.
Is a $3,000 penetration test a real penetration test?
It can be a real AI-led test. It is not the same purchase as a test done by people, and it is not the same as a scanner.
Three different things get sold around this price.
AI-led tests, such as Stingrai Autonomous at $3,000 or Cobalt Autonomous at $3,500. Software attacks your app and writes the report. Each provider describes a different human part. Cobalt says its testers direct each engagement. Astra includes one manual retest.
Human-led tests at a low starting price, such as Pentest-Tools.com's $3,400 black box. People do the work, but only from the outside, with no login.
Scanners. A vulnerability scan is software that checks your system against a list of known problems. Astra's Scanner is $199 a month or $1,999 a year for one target. Its Scanner Lite is $69 a month or $699 a year. That is a tool you run. It is not a test someone performs for you.
Which one you can use depends on who reads the report. Ask them, "Is an AI-led test acceptable, or do people need to do the testing?" Get the answer before you buy. Intruder says it will refund the test if your auditor rejects the report. That is a refund promise, not a promise the report will be accepted. The questions for your report reader cover the rest.
How much does penetration testing cost per hour or per day?
None of the providers we checked sells its tests by a published hourly rate. The hourly figures you see online are each company's own estimate.
Blaze says providers commonly charge $250 to $300 per hour. Synack's guide says $150 to $400 per hour and $1,200 to $3,000 per day for a senior tester at a small firm. We have not verified either, and neither is a price you can buy at.
An hourly or daily rate is not a total until the number of days is in writing. If a quote gives you a day rate, ask for the number of testing days, who does them, and the fixed total. A stated "5-day window" is a stretch of calendar time. It does not tell you how many hours of work you get.
What do network, mobile, API and cloud penetration tests cost?
For SaaS-specific scope and offers, see what a SaaS penetration test costs.
We found few published prices for these, so we will not hand you a range. Here is what is published.
| What is tested | Published price we found | Source |
|---|---|---|
| API on its own | From $4,999 | Blaze |
| Mobile app | From $5,299 | Blaze |
| Mobile app, when Android and iOS share a code base | "Starting from $2200/app depending on the scope" | Astra pricing FAQ |
| External network (a small, focused scope) | From $4,999 | Blaze |
| Network, up to 100 host IPs | From $10,283, plus a platform line item | Synack, SynackST |
| Cloud | From $7,500, "but varies" | Blaze |
Sources: Blaze's price article, Astra, Synack. Read October 8, 2026. All are starting prices.
Two counting rules to know. Astra counts an Android app and an iOS app as two targets. Synack's packages use "or," not "and." SynackST covers web apps or 100 host IPs, not both.
For anything in this group, the price follows the size of the job. A provider will need the number of IP addresses, apps, cloud accounts or sites, where the testing happens, and what is off limits. Our tool has a short list of what to take to a provider for these tests.
How much does a SOC 2 penetration test cost?
We found no separate price list for it. Providers sell the same tests and describe the report as suitable for SOC 2. Your auditor decides what is acceptable.
Several price pages mention it. Stingrai's Hybrid plan lists an attestation letter "for SOC 2, HIPAA, PCI DSS and more." Astra says its reports are "recognized by all auditors." Blaze's article puts a SOC 2 pentest at $8,000 to $25,000 for a standard scope, with small ones from $4,999. Each of those is the company's own statement.
So budget from your scope, using the tables above. Then ask your auditor two things before you buy: what the test must cover, and whether they need to see that fixes were retested. If the second answer is yes, the retest deadline matters as much as the price.
How to pay less without buying less
Cut what you do not need. Keep the scope and the report your reader asked for.
- Check what you already have. Your current provider, or a compliance tool you pay for, may include a test. Read its terms and compare it with the request before buying another.
- Count your roles. If your customer asked about two roles, do not pay to test five.
- Buy for the tests you will run. A pack or a yearly plan only saves money if you use it.
- Plan your fixes before you sign. If your team needs 60 days and the free retest ends at 30, you may need to pay for another one.
Do not drop something your report reader requires to make a number fit.
How we checked these prices
We opened each provider's own price page and policy pages on the dates shown and read the words on the page. Where a detail was missing, we left it as unknown. Where we did arithmetic, we say so. We did not buy or run any of these tests, and we cannot tell you how good any provider's testing is.
The PenTest Index does not sell penetration testing. Payment never decides which companies appear, the order, or what we say about them. How the site works. Methodology.
A few more questions
Is penetration testing cost different in the UK, Australia or India?
Probably, but we have not checked local price lists. Every price on this page is shown the way the provider shows it, with a $ sign. Some of these providers are based outside the United States, so ask which currency you will be billed in.
How long does a penetration test take?
It depends on the offer. Pentest-Tools.com states 3 working days for black box and 4 or more for grey box, both best effort, and says its engagements typically finish in 7 to 10 business days. Astra says its manual test takes 10 to 15 working days. Synack's packages use 5-day and 14-day windows. Blaze says reports arrive within five business days after testing ends. None of these is a booked date. Ask for your report date in writing.
What about penetration testing certification cost?
That is the price of an exam for people who want to become testers. It is a different topic, and this page does not cover it.
Sources
All provider pages were read on October 8, 2026 unless noted.
- Astra: plans and pricing, rescan rules, purchase steps
- Blaze Information Security: web application penetration testing listing, price article
- Cobalt: pricing, retest rules
- Intruder: pentest pricing
- Pentest-Tools.com: web app penetration testing, services and FAQ
- Stingrai: plans and pricing
- Synack: pricing, cost guide
- Bishop Fox, BreachLock and NetSPI: read October 7, 2026, as listed on our company comparison
Want the wider picture of who does what? See our comparison of penetration testing companies.