Penetration testing quote: request template and 12 lines to check

By The PenTest Index · Provider terms checked October 8, 2026

A penetration testing quote is only worth comparing once it names the same systems, user roles, report and retest terms as the others, in writing. Need one? Send every provider the request template below. Already have some? Check each against the same 12 lines. Any required work without a price means the total isn't finished.

These are plain links to each provider's own page. This site may contain affiliate or referral links, and if you buy through one we may be compensated. Payment doesn't decide who appears here or in what order. See how we make money.

I need a quote · I have quotes

Here is the rule this whole page rests on: don't compare the totals first. A quote that leaves out something you must have is out until the provider adds it in writing. A quote with blanks isn't cheap or expensive yet. It's unfinished. Once two quotes are complete on the same scope, price is a fair thing to choose on.

How do I request a penetration testing quote?

Send every provider the same written request. Say what needs testing, who needs the report and by when, then ask seven questions that force the price, the work and the dates onto paper. The same question gets you answers that line up.

A penetration test (pentest) is a planned attempt to break into your own systems, inside limits you agree in advance, so you learn what a real attacker could do. Providers price it from the details you give them. Vague details get you vague quotes.

Copy this, fill in the brackets and send it.

Penetration testing quote request template

Subject: Penetration testing quote request: [what needs testing], report needed by [date]

Please quote for the scope below. Mark every assumption, exclusion and anything you need more information on. Keep optional work separate from the work needed to meet this request.

Why we need it and who gets the report: [Customer request, audit, internal check. Name who will rely on the report and what they have asked for. Mark anything they haven't confirmed yet.]

What needs testing: [Each web app, API or other system. Production or staging. Number of user roles. Whether customers have separate workspaces. The workflows that matter most, such as payments or data exports. Keep this high level.]

Access we can arrange: [Test accounts, API documentation, source code, or none of these.]

Out of scope and limits: [Systems or third-party services you must not test. Testing hours. Any location or data-handling rules.]

Timing: [When access will be ready. When we need the final report. When our fixes are likely to be ready. Any deadline for proof that fixes were checked.]

Please make your quote answer these seven questions:

  1. What exactly are you quoting? List the systems, roles and customer-workspace checks that are included, and what is excluded. Say where you will test everything and where you will sample.
  2. Who does the testing, and how? Separate human testing from automated or AI testing. If you price in days, hours or credits, give the number and say what one unit means.
  3. What will we receive, and when? Please attach a sample report with the client details removed.
  4. What is the full minimum commitment? Give the currency, whether tax is included, the pricing unit, any required platform or subscription fee, the minimum term, the payment schedule and the date this quote expires.
  5. What retesting is included? Say how many retests, who performs them, what starts the window, whether the deadline is to request or to finish, what a later retest costs, and whether we get an updated report.
  6. What would change the price or the dates? Explain how scope changes are agreed, and what we would owe if we reschedule or cancel.
  7. What has to happen before testing starts? List the approvals, the final scope, the rules of engagement and how we share access safely.

If required work is not yet priced, please mark it "unpriced" instead of leaving it out. If you recommend a different scope, show it as a separate option.

This request is for pricing and scoping only. It does not authorize testing.

Two cautions before you send it. Don't put passwords, keys, detailed target lists or past security reports in the request. Share those later, with the provider you choose, through a channel you both agree on. And nothing here is permission to test. That comes later, in writing, for the exact systems and activities.

What if I don't know the full scope yet?

Start with whatever created the need. That usually tells you the system and the kind of test. Ask the person who asked you for the test three things:

  • "Which systems should the test cover, and is anything excluded?"
  • "What must the report show, and by when?"
  • "Is automated testing alone acceptable, or does a person have to do the work?"

Then check what you already pay for. If a current provider or a compliance platform includes a test, read that agreement before you ask anyone for a new quote. It may already cover you.

If the scope is still fuzzy after that, our free tool walks you through the questions for your kind of system and gives you a scope checklist to copy or print. It asks for no contact details and it doesn't pick a provider for you.

Find My PenTest Match

Have a brief ready for a web app or API and need someone to send it to? Compare published offers and contact the providers you choose.

The Quote Check: 12 lines to check before you sign

does this proposal include more than scanning?

check what each proposal covers.

Every quote has to answer six questions, and each question has two lines worth finding. Mark each line as in writing, missing or wrong for you. What's left is your list of questions for that provider.

These are the same six questions we use across the site to check offers. The 12 lines are our method, not an industry standard.

#QuestionFind this line in the quoteWhy it changes what you're buyingIf it's missing, ask
1What will be tested?Each app, API or host range by name, and the environment"Your web application" is not a scope. Two prices for two different jobs can't be compared"Please list every application, API and environment this price covers, and what is excluded."
2What will be tested?User roles, signed-in testing, and whether the API is inside the priceA provider can charge per role, and an API can be a separate line"Which of our user roles does this price cover, and is the API included or priced separately?"
3Who will do the work?Human testing versus automated or AI testing, and who reviews findingsA scan, an AI-led test and a human-led test are different purchases"How much of this is human testing, how much is automated, and who reviews the findings?"
4Who will do the work?Effort in a unit you can check: tester-days, hours, or credits and what one credit meansA day rate, a credit or a testing window is not a total, and not a promise of human hours"How many days of human testing does this price buy? If you price in credits, how many, and what is one?"
5What report do you need?What you receive: full report, summary or letter, plus a sampleThe person relying on the report decides if it's enough"Please send a sample report and say whether a summary letter for customers is included."
6What report do you need?Whether the scope and method match what your auditor or customer asked forA compliance word on a quote is not approval from your recipientAsk the recipient: "Which systems must the test cover, and is automated testing alone acceptable?"
7What is the complete commitment?Every charge you must pay: test, platform or subscription, per-role or per-target fees, travel, taxA required charge with no price means the total is incomplete, not zero"Please itemize every charge required to deliver this test, including any platform fee."
8What is the complete commitment?Term and exit: one test or a year, renewal, credit expiry, payment timing, reschedule and cancel fees, how scope changes are pricedThis is where a cheap quote gets expensive"Is this one test or an annual term? What do we owe if we move the start date with two weeks' notice?"
9Who checks the fixes, and until when?How many retests, and whether a person or a scanner does them"Retest included" can mean one automated rescan"How many retests are included, and are they done by a person?"
10Who checks the fixes, and until when?The retest window, what starts it, and whether the deadline is to request or to finishA 30-day window can close before your fixes ship"When does the retest window start and end, and what does a retest after that date cost?"
11When will the report arrive?The start date and what it depends on"Starts in three business days" is often counted from a step you haven't done yet"What is the earliest confirmed start date once we sign and provide access?"
12When will the report arrive?The final report date, in writingA testing window is not a report date"Please put the final report delivery date in the statement of work."

How to read your result:

  • Supported means the quote answers that line in writing and it fits what you need. It says nothing about how good the testing will be.
  • Mismatch means the quote says something that doesn't fit. If it's a must-have, that quote is out unless the provider changes it in writing.
  • Unresolved means the quote is silent or too vague. Ask.
  • Conflicting means two parts of the quote disagree. Ask which one governs.
  • Not applicable means the line doesn't matter for your purchase.

Check one to three quotes

Mark the lines you have in writing. Must-have settings apply to every quote.

Don't paste passwords, keys, vulnerability details or architecture diagrams. You don't need them here.

1 of 3 quotes
Quote A
Mark each of the 12 lines for each quote. Must-have settings are shared across quotes.
LineMust-have?Quote A
Line 1What will be tested?Each app, API or host range by name, and the environment
Line 2What will be tested?User roles, signed-in testing, and whether the API is inside the price
Line 3Who will do the work?Human testing versus automated or AI testing, and who reviews findings
Line 4Who will do the work?Effort in a unit you can check: tester-days, hours, or credits and what one credit means
Line 5What report do you need?What you receive: full report, summary or letter, plus a sample
Line 6What report do you need?Whether the scope and method match what your auditor or customer asked for
Line 7What is the complete commitment?Every charge you must pay: test, platform or subscription, per-role or per-target fees, travel, tax
Line 8What is the complete commitment?Term and exit: one test or a year, renewal, credit expiry, payment timing, reschedule and cancel fees, how scope changes are priced
Line 9Who checks the fixes, and until when?How many retests, and whether a person or a scanner does them
Line 10Who checks the fixes, and until when?The retest window, what starts it, and whether the deadline is to request or to finish
Line 11When will the report arrive?The start date and what it depends on
Line 12When will the report arrive?The final report date, in writing
Cost helper — Quote A

Required additions

Retest and reschedule helpers — Quote A

Retest dates

Reschedule fee

A worked example: three quotes, one brief

Marking the lines changes the answer. Here, the lowest number on the first page ends up the most expensive finished quote, and the cheapest-looking total isn't a total at all.

This example is made up to show the method. The three quotes are not real offers, market prices or a judgment on anyone's testing. All amounts are US dollars before tax.

Say you run a SaaS company. A customer has asked for a human-led test of your web app and its API, covering three signed-in user roles and the wall between two customer workspaces. They want the report by November 20, 2026. You expect to ask for a human check of your fixes 45 days after the report, which is January 4, 2027. Your budget is $9,000, and you'd prefer to buy one test, not a subscription.

LineQuote AQuote BQuote C
Price on the first page$5,000 for the project$8,000 for the project$650 a month
App, API, three roles, workspace checks (lines 1–2)Base price covers the app and one role. API and extra roles are a priced add-on: $2,000All includedAll included
Human-led test, report by November 20 (lines 3, 5, 6, 12)In writingIn writingIn writing
Days of human testing (line 4)Not statedNot statedNot stated
Human retest with updated report (lines 9–10)Priced add-on: $1,500. One request within 60 days of the reportIncluded. One request within 60 days of the reportOne request within 60 days of the report. Fee not stated
Term (line 8)One projectOne project12-month minimum
Payment schedule$4,250 at booking, $4,250 at report$4,000 at booking, $4,000 at report$650 a month for 12 months
Commitment for the required work (line 7)$5,000 + $2,000 + $1,500 = $8,500$8,000$650 × 12 = $7,800, plus a retest with no price
FindingSupported on the must-haves. Costs $500 more than BSupported on the must-haves. Lowest complete totalTotal unresolved. Annual term doesn't match the preference

What to do with this. Quote B leads. It covers everything the customer asked for, it has the lowest finished total, and it's a single project. Quote A is a fair second choice at $500 more. The 60-day retest window in all three runs to January 19, 2027, so a request on January 4 is inside it.

Quote C is the one to slow down on. Its $7,800 is $200 under B, so it only wins on cost if the retest fee is less than $200 and you're happy with a 12-month term. A $200 retest ties B. Send this:

"Please confirm the complete first-year price for our listed scope, including one human retest requested 45 days after the report, with an updated report. What is the retest charge, and do your 60-day terms cover that request?"

Notice what the example can't tell you. None of the three quotes says how many days of human testing you're buying, so that's a question for all of them. And a lower total doesn't make B the better tester. It makes B the best-documented fit for this brief.

Why are my quotes so different?

Usually because they're quotes for different jobs. Before you read anything into the gap, check whether each one covers the same systems, the same roles, the same kind of testing, the same retest and the same length of commitment.

You don't have to take that on faith. Read what providers publish. We don't sell or perform penetration tests, and we haven't bought these services or judged their quality. We read each company's own public pages on October 8, 2026 and wrote down what they say, and what they leave for the quote to settle. Companies are listed A to Z. This is not a ranking.

Provider and offerWhat its own pages say (provider-published, checked October 8, 2026)What that leaves openAsk this
Astra, Pentest Expert$5,999 a year for one target. One web or SaaS app and the APIs it consumes count as one target; its pricing page says separate dashboards with different logins need separate targets for its DAST Scanner. Includes a manual pentest and two manual rescans, to be requested within 30 days "from the date the vulnerabilities were reported." Extensions are case by case. Extra manual rescans can be bought; no price is given. Its pricing FAQ puts the manual pentest at 10–15 working days. (pricing, rescan rules)Days of human testing. Whether your admin area counts as a second target. The price of a late rescan"Is our customer app plus admin area one target or two? Can you include a manual rescan requested on day 45, and what does it cost?"
BreachLock, penetration testing packagesNo prices published. Its pricing table lists 1, 2 and "Custom" free manual retests across its Standard, Extended and Extensive packages, with platform access marked "Optional." Its services page says every test includes "one free comprehensive manual re-test" and access to its platform. (pricing table, services page)Which package your quote is. The retest window. Whether platform access is included or extra"Which package governs this quote? State the number of retests, the deadline, and whether platform access costs extra."
Cobalt, annual credit packagesNo prices published. A credit "represents the equivalent of 8 hours of offensive security testing," and credits are sold in annual packages. Its FAQ says credits do not roll over into the next contract, but its Enterprise table lists rollover of up to 10%. For its Agile and Comprehensive pentests, free retesting lasts 6 months on the Standard tier and 12 months on Premium and Enterprise, only while the contract is active, and ends at the earlier of that period or 10 days before the contract ends (23:59 UTC). (pricing, retest rules)How many credits your test needs. How many of the "equivalent" hours are a person. What starts the 6 or 12 months"How many credits does our scope need, and how many hours of that are human testing? What is the last date and time we can request a free retest?"
Pentest-Tools.com, managed web app testBlack box (testing as an outsider with no login): fixed $3,400, three working days on a best-effort basis, report on the fourth day. Grey box (testing with logins): from $3,400 plus $900 per user role, four or more working days on a best-effort basis, report "when ready." (service page)The page doesn't mention API testing or retesting"Does the grey box price cover our API? Is a retest included, and until when?"
Synack, testing packagesPricing "starts at" $4,181 for an AI-led test, $10,283 for a human-led test and $27,120 for a researcher-team test. Its platform "is required to purchase any of the testing products and is a separate line item." A Basic platform is listed at no cost; no price is listed for the full platform. Credits expire one year from purchase. (pricing)Which platform tier your purchase needs, and its price. The full total"Is the Basic platform enough for our test? Please itemize the test, any platform charge and when our credits expire."

For Cobalt, take questions to send Cobalt before you sign.

Three things stand out.

A published price is a starting point, not a quote. For the example brief's three roles, the Pentest-Tools.com formula gives $3,400 + (3 × $900) = $6,100. That's a starting amount for the web app. It doesn't price the API or a retest, because the page doesn't mention either.

The same company can describe an offer two ways. BreachLock's pricing table and its services page don't read the same on retests and platform access. Neither has to be wrong. They may describe different packages. Your quote should say which one you're getting.

Even providers that publish prices leave some of the 12 lines blank on their public pages. That's normal, and it's why the written quote matters more than the pricing page. The quote is where the blanks get filled in.

If you want to check a term at the source:

See Astra's plans and target definition

See BreachLock's package table

See Cobalt's credit packages

See the managed web app test prices

See Synack's testing packages

Does the quote include the API and every user role?

Only if it says so. "One web application" doesn't tell you whether the API, the admin area or each kind of user is covered.

Three terms help here. An API is the interface other software uses to talk to your app. A role is a type of user with its own permissions, such as admin or standard user. A tenant is one customer's separate workspace inside your product.

Roles and tenants matter because many serious flaws are about one user reaching another user's data. The PCI Security Standards Council's penetration testing guidance, written for card-payment environments, says testing should be performed against all roles or types of access, and recommends that an in-scope API behind a web app be tested independently of the web app (sections 2.3.1 and 4.2.1). That guidance dates from March 2015 and supplements the card standard; it isn't a rule for every buyer. It's still a good reason to ask.

Pricing follows the same lines. Pentest-Tools.com adds $900 per role. Astra counts an app and its consumed APIs as one target. Two quotes for "the app" can differ by thousands of dollars on this point alone.

How much work will the testers actually do?

You only know if the quote states it. A price, a five-day testing window or a number of credits doesn't tell you how many hours a person spends on your systems.

Keep four things apart when you read: the method (human-led, AI-led or a scan you run yourself), the people, the calendar time and the billing model. A subscription can buy human testing. A one-off project can be mostly automated. Cobalt's credit is a useful example of why to ask: it's defined as the "equivalent" of eight hours of testing, which is a unit of work, not a promise of eight human hours.

Some guides suggest dividing the total by a typical day rate to work out the days. We'd skip that. A guessed rate gives you a guessed answer. Ask for the days.

One more distinction, because it's the most expensive one to get wrong. A vulnerability scan is software that looks for known weaknesses. The same PCI guidance describes a penetration test as "a manual process that may include the use of vulnerability scanning or other automated tools" (section 2.1). Whether an automated or AI-led test is enough for you is your recipient's call. Ask them before you sign, not after.

What is the full cost of the quoted work?

Add up every charge you must pay to get the work in your brief, across the whole minimum term. If a required charge has no price, you don't have a total yet.

The sum is short:

Base commitment + required extras that are billed separately = commitment for the required work.

Keep three things out of that sum. Optional extras aren't part of it. A deposit isn't an extra; it's part of the total paid early. And a charge you can't see a price for is unknown, which is different from free.

Is the monthly price an annual commitment?

Read the minimum term next to the monthly figure. In the example above, $650 a month with a 12-month minimum is a $7,800 commitment before the retest.

Published offers show the same pattern. Astra's Pentest Expert is priced per year, per target. Cobalt sells annual credit packages, and its FAQ says unused credits don't roll into the next contract, but its Enterprise table lists rollover of up to 10%. Synack says credits expire a year after purchase and lists its platform as a separate line item. None of that is a problem if you test several times a year. All of it matters if you wanted one test.

What does it cost to change or move the test?

More than most buyers expect, and it's set out in the terms behind the quote. Two public contracts show what to look for.

NCC Group's published terms for security testing (revised December 2, 2024) set a fee of 50% of the cost of the scheduled days if you cancel 8 to 21 days before the start, 50% if you reschedule 8 to 14 days before with a firm new date, and 100% inside 7 days. Charging it is at NCC Group's discretion, and it is reduced if the testers can be moved to other work. If you rebook, the new dates are paid for on top (clauses 4.1 to 4.3). These are one large provider's terms, not an industry rule.

To make that concrete with a made-up figure: if the testing days on your quote cost $8,000 and you move the start with 10 days' notice under terms like those, the fee could be $4,000, and you'd still pay for the new dates.

The Center for Internet Security's penetration testing terms (version dated July 24, 2026) say the fee is "based on the scope, assumptions, and information provided by Customer." If those turn out to be materially wrong, or the work needs much more effort, the two sides agree an appropriate adjustment to the fee, timeline or other affected terms, and CIS doesn't have to do the extra work until that's agreed in writing. The same terms require the invoice to be paid in full before testing starts (sections 3 and 4).

Two lessons. An accurate scope protects your price. And the reschedule, cancellation and payment terms belong on line 8 of your check, even when they sit in a separate document.

Is this an estimate or a fixed quote?

Check what kind of number you're holding. An advertised starting price, an estimate, a written quote and a signed contract price are four different things, and the word at the top of the document doesn't settle which one you have.

Ask one question: "Which assumptions, if they turn out wrong, would change this price?" Also look for an expiry date. A quote from last quarter may need confirming before you rely on it.

Is a retest included, and when does it expire?

"Retest included" is only useful if you know how many, who does it, when the clock starts and when it stops. Turn the window into a date and compare it with the day your fixes will be ready.

A retest is a check that the problems the testers found are fixed. Some providers call it a rescan. Don't read too much into the name. Ask what is rechecked, whether a person does it, and whether you get an updated report.

Dates make this real. Astra's Pentest Expert includes two manual rescans, requested within 30 days from the date the vulnerabilities were reported. If your findings are reported on November 20, 2026, that window closes about December 20. A team that needs until January 4 to ship fixes would be asking after the published 30-day window. Astra says extensions are considered case by case and doesn't publish a price for extra manual rescans, so the time to ask is before you buy. Astra also recommends fixing at least half of the Critical and High findings before you request a manual rescan.

A contract end date can cut a window short too. Cobalt's free retesting for its Agile and Comprehensive pentests ends at the earlier of the tier's 6 or 12 months and 10 days before your contract ends. If a contract ended on December 31, 2026, the last free retest request would be no later than December 21, 2026 at 23:59 UTC, even on a 12-month tier.

One timing trap: a deadline to request a retest is not a deadline for the retest to be finished. If your customer needs proof of fixes by a set date, ask for the completion date as well.

What if our fixes will be ready after the window?

Get a written extension or a priced retest before you choose that offer. If the provider can't cover a date you must hit, pick a different offer.

There's a practical reason not to let it drift. The PCI guidance notes that when fixes stretch long after the original test, a new test may be needed to reflect the current system (section 4.3.2). A late retest can turn into a second purchase.

Send this:

"Our fixes are likely to be ready [N] days after the report. Can you include a retest by a person at that point, with an updated report? Please confirm the last eligible date and any extra charge in writing."

Will the report meet your recipient's request and deadline?

Only the person relying on the report can say. Ask your auditor, customer or security team what they need before you compare quotes, then check each quote against their answer.

No provider can promise that for them. Treat a claim like "audit-ready" or "compliance report" as a description of the document, not a decision by your recipient. We've put the questions to ask your report recipient on one page.

Ask every provider for a sample report with the client details removed. When you read it, look for the things a careful reviewer looks for: a clear scope, the dates of testing, the methods used, evidence for each finding, how severity was rated, and whether a retest is needed. The PCI Security Standards Council publishes a short report evaluation checklist built on those points. It describes the checklist as a suggested minimum that isn't meant to produce a score (section 5.4).

Does the quoted duration include the final report?

Often not. "Five days of testing" and "report in your hands" can be weeks apart. Ask for five dates, and for each one ask whether it's a commitment or an estimate, and what it depends on:

  1. When your access and test accounts are due
  2. When testing starts
  3. When testing ends
  4. When the final report arrives
  5. When retest results arrive, if you need them

Published timings show why. Astra's pricing FAQ gives 10–15 working days for its manual pentest. Pentest-Tools.com says its grey box report comes "when ready." Both are fair statements about testing time. Neither is a delivery date for your project. If you have a deadline, the report date belongs in the statement of work.

Is the cheapest penetration testing quote a bad idea?

No. A low quote is fine when it's complete and the smaller job is what you need. It's a problem when the low price comes from a line you didn't notice was missing.

The cheaper option is often the right one when:

  • you're testing one small public site with no logins
  • nobody outside your company will rely on the report
  • your recipient has told you in writing that an automated or AI-led test is acceptable

Look harder when the low quote leaves out signed-in roles or the API, when its retest window closes before your fixes will be ready, or when your recipient asked for something it doesn't include. In the worked example, the $5,000 quote was for a smaller job. Priced for the full brief, it came to $8,500.

What should I ask before accepting a quote?

Settle the one answer that could change your choice, then make sure the scope, price, dates and retest terms you agreed appear in the final documents.

You're on one of three paths:

  • Every must-have is in writing and fits. Go ahead with that provider. That includes a provider you already use. You don't need a new search to confirm a good answer.
  • Something is missing or two parts disagree. Send the questions from your Quote Check and ask for a revised quote, not a reply by phone.
  • A must-have can't be met. Look at another offer. A discount doesn't fix a missing requirement.

If your quotes came from separate sales calls and no written scope, questions alone may not make them line up. Write the scope once with the scope checklist and ask each provider to quote it again.

Does a quote request authorize testing?

No. Accepting a price alone does not authorize testing. Testing needs written permission for the exact systems and activities, agreed with the provider before any testing begins.

That permission usually sits in a document called the rules of engagement: what may be tested, when, how far the testers may go, and who to call if something breaks. The PCI guidance describes the rules of engagement as what "authorizes the tester to test the environment," and notes that if a hosting or cloud provider's agreement requires its approval, you must get that approval first (sections 4.1.3 and 4.1.4).

The contracts are blunt about the risk. CIS's terms say there is "no guarantee that every vulnerability" will be found and that live systems can be disrupted during testing. If the agreement in front of you includes indemnity or liability terms you don't understand, that's the moment for a lawyer. The quote itself rarely needs one.

Three more questions

Can I get a price without a sales call?

For some offers, yes. On October 8, 2026, Astra, Pentest-Tools.com and Synack each published prices or starting prices you can read without talking to anyone, as shown in the table above. BreachLock and Cobalt publish package details but no prices for the packages listed above. Our comparison of published offers lists what each provider states. A published price still needs your scope confirmed before it becomes a quote.

Is a quote the same as a proposal or a statement of work?

Not quite, though providers use the words loosely. A quote is a price for a described scope. A proposal usually adds the approach, the team and the timeline. A statement of work sets out the agreed work, and it must be read with the other governing contract terms. Run the 12 lines on whichever document you're about to sign.

How long is a penetration testing quote valid?

For as long as the quote says. We found no published standard. Look for an expiry date, and ask whether the start date you were offered is held until then or only once you sign.

Sources and how we checked

We read each source below on October 8, 2026 and report only what it says. Provider details are provider-published: the company's own public page states them. We have not bought these services, seen any customer's quote, or assessed anyone's testing quality. The three example quotes are fictional. Terms change, so confirm anything that matters in your own written quote. How our checks work is explained in How The PenTest Index works.

SourceUsed forChecked
Astra: plans and pricingPentest Expert price, target definition, testing timeOctober 8, 2026
Astra: rescan quota rulesRescan counts, 30-day and 90-day windows, extensionsOctober 8, 2026
BreachLock: penetration testing pricingPackage retest counts, platform accessOctober 8, 2026
BreachLock: pentesting servicesServices FAQ on retest and platform accessOctober 8, 2026
Cobalt: pricingCredit definition, annual packages, rollover FAQOctober 8, 2026
Cobalt: Remediate FindingsRetest periods and contract-end cutoffOctober 8, 2026
Pentest-Tools.com: web app penetration testingBlack box and grey box prices and timingOctober 8, 2026
Synack: pricingStarting prices, platform line item, credit expiryOctober 8, 2026
NCC Group: Service Module, Security Testing Services (revised December 2, 2024)Cancellation and rescheduling feesOctober 8, 2026
Center for Internet Security: Network and Web App Pen Testing Terms and Conditions (July 24, 2026)Scope-change fees, payment before testing, limitsOctober 8, 2026
PCI Security Standards Council: Penetration Testing Guidance (March 2015)Scan versus penetration test, roles, API testing, rules of engagement, retesting, report checklist. Supplemental guidance; it does not replace the card standardOctober 8, 2026

The PenTest Index is not affiliated with any provider or standards body named on this page. We do not perform, authorize or certify penetration testing.