This site may contain affiliate or referral links. If you buy through one, we may be compensated. How we make money
Penetration testing for small business: who needs it and what it costs
By The PenTest Index · Prices and rules checked October 9, 2026
Penetration testing for small business is worth buying when someone requires it (a customer, card-payment rules or a regulator) or when you run your own app that holds customer data. Otherwise, start with a vulnerability scan. For one web app, published prices start at $2,999 a year for an AI-led plan (Astra) and $3,400 for a one-off manual test (Pentest-Tools.com).
Most small businesses land on one of three routes:
- Buy a test. Someone named a requirement, or you build and run your own app.
- Scan and fix the basics first. Nobody is asking, and you run on email, laptops and other companies' software.
- Ask first. Someone said "get a pen test" but not what to test, who reads the report, or by when.
Already know you need one for a web app or API? Jump to published prices.
Do small businesses need penetration testing?
Some do. It depends on who is asking and what you run, not on how many people you employ.
Two terms first. A penetration test (pentest) is an authorized attempt to break into a system you name, to show what an attacker could actually reach. A vulnerability scan uses software to check for known weak spots. A scan is someone walking around the building with a checklist. A test is someone trying the doors.
Find your row.
| Your situation | What the rule or request says | What to do |
|---|---|---|
| Nobody is asking. You use email, laptops and software other companies run. | No test has been requested. | Not yet. Turn on multi-factor sign-in, keep software updated, test your backups, then run a scan. NIST's small business guide lists these basics and never mentions penetration testing. |
| You build and run your own web app or API, and it holds customer data. | You don't need an outside rule. Logins, roles and customer data are what a scan checks least well. | Yes. Buy a web app test that includes logged-in users. See prices. |
| A customer's questionnaire or contract asks for a "pen test." | Whatever their words say, and they are often vague. | Ask first. Send three questions before you spend anything. |
| Your card processor sent a PCI form called SAQ A-EP (your own website controls the path to the payment page). | The form lists an external penetration test at least once every 12 months and after any significant change. | Buy an external test of the web server and network behind your checkout. Details below. |
| Your PCI form is SAQ A (checkout fully handed to a payment company by redirect or embedded frame). | PCI's standards body says external scans by an Approved Scanning Vendor apply (FAQ 1604, June 2026). | Get the scans. Then read your form's Requirement 11 section for anything else it lists. |
| You got a PCI form and don't know which one. | The form type decides. | Ask your processor: "Which SAQ do we file?" Don't guess, and don't treat "I don't know" as "not required." |
| You prepare taxes, broker or make loans, collect debts, or do similar financial work covered by the FTC Safeguards Rule. | Yearly penetration testing, unless you have effective continuous monitoring or other systems that detect, on an ongoing basis, system changes that may create vulnerabilities. This part doesn't apply if you hold customer information on fewer than 5,000 consumers. | Under 5,000: this clause doesn't require a test. 5,000 or more: plan a yearly test and vulnerability assessments, or one of those monitoring alternatives. |
| You handle patient data under HIPAA. | Today's Security Rule does not name penetration testing. A proposed change would. It is not final. | Not required by name today. Your own risk analysis or a customer contract may still call for one. |
| An auditor is reviewing you for SOC 2 or ISO 27001. | Your auditor decides what evidence is enough. | Ask the auditor in writing. Then check whether your compliance platform already includes a test. |
| A cyber-insurance form asks about testing. | The form's exact question. | Answer what it asks. If it says "scan," a scan answers it. If you can't tell, ask your broker in writing. |
| Your IT provider or compliance package says testing is "included." | Whatever that agreement covers. | Check it before buying another. Ask for its scope, who does the work, and the report. |
| You think someone has already broken in. | Incident-response and reporting duties may apply. | Get incident response help first. A routine test is a different job. |
Need check picker
Same headcount, different purchase
Here are two made-up companies with 24 people each.
| Row label | A software company | An office-based firm |
|---|---|---|
| What they run | One customer-facing web app and its API | Microsoft 365, managed laptops, a brochure website |
| What happened | A prospective customer asks for an independent, human-led test of the product | The owner wants to lower risk. Nobody asked for a report. |
| The real question | Can one user see another customer's data? | Are accounts, file sharing, devices and backups set up safely? |
| Route | Buy a web app and API test that covers each user role | Review settings and fix the basics. No test yet. |
The office firm isn't off the hook just because Microsoft runs the software. The provider secures the service. You still own your accounts, who has access, your devices and your data, and that is where the review belongs.
What do PCI, the FTC Safeguards Rule and HIPAA require from a small business?
PCI and the FTC rule name penetration testing for some small businesses, and each has a carve-out worth knowing. HIPAA does not name it today.
| Rule | What the text says | Who it skips | Who decides you've met it |
|---|---|---|---|
| PCI DSS v4.0.1, form SAQ A-EP (Requirement 11.4) | An external penetration test at least once every 12 months and after any significant change, done to a written method. Fix what's exploitable and retest. If you separate the payment systems from the rest of your network, test that separation too. The tester can be a qualified person on your staff or an outside firm, must be independent of the systems tested, and does not have to be a QSA or ASV. | Businesses that file a different form. Each form lists its own testing. | Your processor or acquiring bank |
| FTC Safeguards Rule, 16 CFR 314.4(d)(2) | Unless you have effective continuous monitoring or other systems that detect, on an ongoing basis, system changes that may create vulnerabilities, do penetration testing every year and vulnerability assessments at least every six months, whenever operations or business arrangements change materially, and whenever you know or have reason to know circumstances may materially affect your information security program. | Under 314.6, businesses that hold customer information on fewer than 5,000 consumers. | The FTC |
| HIPAA Security Rule | The current rule doesn't name penetration testing. HHS has proposed requiring it at least once every 12 months. The proposal was published January 6, 2025. HHS's page says the current rule remains in effect. | Nothing to skip yet. | HHS |
A few things this table should save you from.
A proposed rule is not a requirement. If a seller tells your clinic that HIPAA "requires an annual pentest," ask which section. Today there isn't one.
A passing scan is not PCI compliance. PCI's standards body says a scan report from an Approved Scanning Vendor does not show that any other requirement is in place (FAQ 1234).
"Compliance-ready" is a seller's label. The people in the last column decide, not the testing company and not us.
We read the SAQ A-EP wording in a copy of the PCI Security Standards Council's form dated October 2024. The official forms are in the council's document library. The FTC rule covers businesses such as tax preparers, mortgage lenders and brokers, and collection agencies. Whether you are covered, and who counts as a consumer, can be a legal question. These are United States rules plus the card industry's own standard. If you're elsewhere, ask the requester which rule they mean.
How much does penetration testing for small business cost?
For one web app, the published prices we found run from $2,999 a year for an AI-led plan to $5,999 a year for a plan with a manual test, and from $3,400 for a one-off manual test. Tests of an office network almost never have a public price.
Every row below is a price the provider publishes on its own site, shown with the provider's own unit. We read each page on October 9, 2026. We have not bought these services or judged their quality. Providers appear A to Z.
| Offer | What you get | Published price | Fix check (retest) | What can rule it out |
|---|---|---|---|---|
| Astra, Pentest Auto | AI-led test of one web or SaaS app, with the APIs it uses | $2,999 a year for one target | One re-scan by a person. Request within 30 days of the findings being reported. | It's a yearly plan, not a single test. It's AI-led, so check that whoever needs the report accepts that. |
| Astra, Pentest Expert | Manual test by people plus AI agents, one target | $5,999 a year for one target | Two re-scans, same 30-day window. Extensions are case by case. | Yearly plan. The 30-day clock starts when findings are reported, not when you finish fixing. |
| Intruder, AI web app pentest | AI-powered white-box test of a web app | US$4,000 per test, or US$3,500 for platform subscribers. Its cost article says "from $4,000, or $3,500 for existing customers." | "Unlimited retesting." No time limit stated. | Step one is "Connect your codebase." If you won't share source code, ask whether there's another way. |
| Pentest-Tools.com, black box | Manual test of a web app as an anonymous attacker, with no login | $3,400 fixed. Three working days, report on day four. | Its services page says a free manual re-test and an updated report are included. No count or deadline is stated. | No logged-in testing. Wrong fit if your risk sits behind the login. |
| Pentest-Tools.com, grey box | Manual test as both an anonymous and a logged-in user | From $3,400 plus $900 per user role. Four or more working days. | Same general statement. Confirm it applies to your quote. | A starting formula. API size and complexity aren't priced by it. |
| Synack, Sara Pentest | AI-led test of one low-complexity external web app or 100 external host IP addresses | From $4,181 per test, plus a required platform line item | "Patch verification" is listed. No count or window stated. | The total is incomplete. The platform is a separate line. A free Basic tier exists; ask if it applies to you. |
| Synack, SynackST | One human tester. One low-complexity logged-in web app, or 100 host IPs. | From $10,283 per test, plus the platform line item | Same as above | Same as above. Purchased credits expire a year after purchase. |
Pentest-Tools.com shows a dollar sign with no currency code on its service page, so confirm the currency on your quote.
A worked price. Say your app has three kinds of user: owner, editor and viewer. Pentest-Tools.com's published grey-box formula gives $3,400 + (3 × $900) = $6,100 as a starting amount. Astra's Pentest Expert plan is $5,999 for the year. These are our sums on published terms. Nobody has quoted for this example, and neither figure settles API coverage.
Offers that fit a small scope but need a quote
| Offer | Why it's relevant | Published terms | What to confirm |
|---|---|---|---|
| BreachLock, Standard | BreachLock positions it for "small to medium-sized web apps, basic internal networks & external network infrastructure." It's one of the few packages here that names office networks. | No price shown. One free manual re-test. The feature table leaves on-demand report review out of Standard. | The price, the re-test deadline, and whether someone will walk you through the report. |
| Cobalt, Standard | People-led tests bought as yearly credits | No price shown. Cobalt says one credit equals eight hours of testing delivered through a mix of automation and people. Credits don't roll into the next contract. | How many credits your test needs, the minimum purchase, and your last retest date. Cobalt's documentation gives Standard six months, closing 10 days before your contract ends. Its pricing FAQ says "unlimited on-demand retesting throughout your contract term." Ask which governs. |
If you only need scanning
Scanning tools are a different, cheaper purchase. Astra lists its Scanner Lite at $69 a month or $699 a year, and its Scanner at $199 a month or $1,999 a year, each for one target. The government's CISA Cyber Hygiene scanning is free, but CISA lists government bodies and critical infrastructure organizations as eligible, so many small businesses won't qualify.
Why we don't give a "typical range"
Seller blogs do, and you should treat those as the seller's claim. One guide we read puts small-business tests at $3,000 to $15,000 with no source and no defined scope. A price only means something next to what was tested, who did the work and what the retest terms are. For budgeting beyond one small scope, see penetration testing cost.
Which offer fits which small business?
It comes down to three things: whether your risk sits behind a login, whether the person asking will accept AI-led testing, and how long your team needs to fix what's found.
- One web app with logins, and someone asked for a people-led test. Look first at Pentest-Tools.com's grey-box test and Astra's Pentest Expert. One is a single job with open retest terms. The other is a yearly plan with a 30-day retest window.
- A simple public website with no logins. Pentest-Tools.com's black-box test has the clearest published price, at $3,400.
- Whoever needs the report accepts AI-led testing, and budget is tight. Astra's Pentest Auto, Intruder if you'll connect your code, or Synack's Sara once you have the full total.
- You need more than 30 days to fix things. Astra's standard window won't fit without a written extension. Ask Pentest-Tools.com for its deadline. Cobalt's six months could fit, depending on your contract dates.
- You need your office network tested. Our index compares web app and API offers, so we have few matches for you. BreachLock's Standard package names small networks, and Synack's entry tiers cover up to 100 host IPs. Ask any provider for a fixed price by number of IP addresses.
- You already have a provider or an included test. If it meets the request, use it. That's a perfectly good result.
A worked check: three roles and 60 days to fix
Here's how one made-up buyer plays out. A 24-person software company has one app and its API, with owner, editor and viewer roles. Its customer wants an independent, people-led test, and proof that fixes were rechecked by a person. The team expects to ask for that recheck 60 days after the report. If the report lands March 3, that's May 2.
| Offer | Does the scope fit? | Does day 60 fit? | Result for this buyer |
|---|---|---|---|
| Astra, Pentest Expert | Manual test included. Three roles to confirm. | No. The window closes 30 days after findings are reported: April 2 if the findings are first reported on March 3. | Out, unless Astra extends the window in writing and states the cost. |
| BreachLock, Standard | People-led. Scope needs a quote. | Unknown. One re-test is published. The deadline isn't. | Stays in if the quote covers the scope and day 60. |
| Cobalt, Standard | People-led. Credits needed are unknown. | Maybe. Six months on paper, but it closes 10 days before the contract ends. | Stays in if the contract dates allow it. |
| Pentest-Tools.com, black box | No. No logged-in testing. | Doesn't matter. | Out. |
| Pentest-Tools.com, grey box | Roles are priced. API coverage to confirm. | Unknown. A free re-test is stated with no deadline. | Stays in if the retest deadline is confirmed. |
The AI-led offers are out for this buyer because the customer asked for people-led testing. A different customer might accept them.
So no published package settles every condition here. That's normal. One question sorts it out, and you can send it to all of them:
For our app, its API and three user roles, what is the complete price? Can we request a manual retest 60 days after the final report? Please give the last date we can request it, any extra cost, and when we would get the updated report.
"Fits" in that table means one condition matched the published terms. It isn't a quality rating, and it doesn't mean your customer will accept the report.
If you've picked one, go straight to the provider:
View Intruder's pentest pricing
Still deciding? A fair comparison needs every provider to price the same job. Find My PenTest Match walks you through what needs testing, who needs the report and when, and gives you a scope checklist to copy or print. It's free and asks for no contact details. It doesn't pick a provider for you.
Should a small business start with a penetration test or a vulnerability scan?
Start with a scan unless someone has asked for a test or you run your own app. A scan costs less, you can repeat it every month, and it finds the common problems a tester would report first anyway.
A scan stops being enough in two cases. One is an app you built, where the serious problems are usually about who can see what once logged in. A scanner can't judge whether an editor should be able to open another customer's invoice. The other is when the person who needs the report asked for a test. A scan report won't answer that request, whatever it's called on the cover.
Be careful with names. Some products sold as an "automated pentest" do more than a scan and some don't. Ask what was actually attempted, and what evidence you'll get. There's more in penetration testing vs vulnerability scanning.
What should a small business test first: website, app or office network?
Test what the requester named. If nobody named anything, test what faces the internet and holds customer data.
- Your own web app or API. A web app test that includes each kind of logged-in user.
- An online shop where your site controls the checkout path. Whatever your PCI form lists.
- An office with servers, a VPN or remote desktop open to the internet. An external network test of those addresses.
- Email, laptops and software other companies run. Your accounts, data and devices still need protection. Review your settings and access instead.
Not sure which type you need? Penetration testing services explains each one.
A customer or insurer asked for a "pen test." What do you send back?
Ask them three things before you spend anything. The answers decide what you buy.
Thanks. To get this right, could you confirm:
- Which systems should the test cover, and is anything excluded?
- What must the report show, and by when do you need it?
- Does the tester need to be independent or hold particular qualifications, and is automated testing alone acceptable?
Here's what each answer changes.
- They name a system. That's your scope. Don't pay to test anything else for this request.
- "Automated is fine." The AI-led offers in the price table are open to you.
- They give a date. Work backward. You need time for the test, the fixes and a retest before that date.
- They already accept a report you have. You may not need to buy anything.
Once you know the scope, send every provider the same short request. A request like this asks each supplier the same question, so the answers line up:
We're a [size] company comparing proposals to test [app or system] and [its API]. Whoever needs our report requires [their exact wording]. Scope: [addresses], [number] user roles, [staging or production]. Please tell us: who does the testing and how much is automated; what's excluded; the complete price and currency, with any platform or subscription fee; how many retests are included and the last date we can request one; and when we'd receive the report. This is a request for a proposal. It does not authorize any testing.
That last line matters. A scope checklist, a request or a quote is not permission to test. Before work starts, you and the provider need written authorization that names the exact systems, the allowed activities and the dates. If someone else hosts your systems, check their testing policy too. Never put passwords or keys in a request.
For a fuller template with a worked example, see penetration testing scope.
Can your MSP or IT provider do the penetration test?
Sometimes. It depends on whether the person who needs the report wants an independent tester.
PCI's SAQ A-EP form is a useful example. It lets a qualified internal person or an outside firm do the test, as long as the tester is independent of the systems being tested. The company that built and runs your network testing its own work is a hard case to make. Ask whoever needs the report before you rely on it.
The more common problem is a scan dressed up as a test. Five questions tell them apart:
- Who does the work, and how much of it is a person rather than a tool?
- What did you try to break into, and what did you actually reach?
- Can we see a sample report with the evidence for each finding?
- Is a retest included, how many, and what is the last date we can ask for one?
- What is excluded?
If your provider answers all five clearly and whoever needs the report is happy, keep them. You don't need a new vendor to have a real test.
How do you prepare without a security team?
Name two people before you book: one who can give access and make quick decisions during the test, and one who will fix what's found. Then book around the second person's calendar.
A test moves through the same steps whoever runs it. You agree the scope, hand over test accounts if needed, the testing happens, the report arrives, you fix things, and, if a retest is agreed, the tester rechecks and you get updated evidence. The price usually covers the testing and the report. It doesn't cover the fixing. That's your developer's or IT provider's time, and for a small team it's the part that runs long.
That's why retest deadlines matter more to a small business than to a big one. A 30-day window is fine if your developer is free the week the report lands. It isn't if they're booked for six weeks.
When the report comes, check that it shows:
- what was tested, when, and what was left out
- how the testing was done and with what access
- each finding with evidence you can follow and a severity that's explained
- how to fix each one, in terms your developer can act on
- after a retest, which findings are fixed and which are still open
How often does a small business need a penetration test?
As often as your requirement says. PCI's SAQ A-EP form says at least every 12 months and after any significant change. The FTC rule says yearly for covered businesses that hold customer information on 5,000 or more consumers and don't have effective continuous monitoring or other systems that detect, on an ongoing basis, system changes that may create vulnerabilities.
With no requirement, there's no fixed schedule. Retest after a major change to an app you run. And ask whoever needs the report how recent it has to be, because a test from 14 months ago may not count for them.
Other questions small businesses ask
Can you do penetration testing yourself?
You can run scans yourself, and you should. A test meant for a customer, a processor or an auditor usually needs someone independent of the systems. Ask them before you rely on your own.
Is penetration testing dangerous for a small business?
It can affect live systems. Agree in writing what's allowed, when testing happens, what's off limits and who to call to stop it. Ask the provider how they avoid outages. A short test or a staging copy is not a promise that nothing will break.
How long does a penetration test take?
It depends on the offer. Pentest-Tools.com lists three working days for its black-box test, with the report on day four. Astra's pricing FAQ says its manual test takes 10 to 15 working days. Those are the providers' own estimates, not booked dates. Ask for your report date in writing.
Is there a free penetration test?
Free scans exist. A free "pentest" is almost always a scan with a sales call attached.
Sources and how we checked
We read each source below on October 9, 2026, and applied the published terms to made-up buyers. Offer details are what each provider publishes about itself. We haven't bought these services, received quotes or tested anyone's work. We compare specific offers against stated buying needs, and payment doesn't decide which offers appear or in what order. See how we check offers and how we make money.
| Source | What we used it for | Checked |
|---|---|---|
| Astra plans and pricing | Plan prices, target definition, testing time | October 9, 2026 |
| Astra re-scan rules | Re-scan count and 30-day window | October 9, 2026 |
| BreachLock packages | Standard package positioning and re-test count | October 9, 2026 |
| Cobalt pricing and retest documentation | Credit model, retest period and cutoff | October 9, 2026 |
| Intruder pentest pricing and cost article | Price per test and the platform-subscriber condition | October 9, 2026 |
| Pentest-Tools.com managed web app test and services page | Prices, role formula, timing, free re-test statement | October 9, 2026 |
| Synack pricing | Starting prices, scope limits, platform line item | October 9, 2026 |
| 16 CFR Part 314 (eCFR) | FTC Safeguards Rule sections 314.4(d)(2) and 314.6 | October 9, 2026 |
| PCI SSC, SAQ A-EP for PCI DSS v4.0.1 (October 2024), via the document library | Requirement 11.4 wording. Read in a hosted copy of the council's form. | October 9, 2026 |
| PCI SSC FAQ 1604 and FAQ 1234 | Scans for SAQ A merchants; what a scan report does not show | October 9, 2026 |
| HHS fact sheet and Federal Register notice | Status and content of the HIPAA proposal | October 9, 2026 |
| NIST SP 1300, Small Business Quick-Start Guide (February 2024) | Basic steps for the "not yet" route | October 9, 2026 |
| CISA Cyber Hygiene Services | Free scanning and who is eligible | October 9, 2026 |
None of these organizations endorses this site or any provider. The PenTest Index does not perform, authorize or certify penetration testing.