Physical penetration testing: prices, scope and who must sign

By The PenTest Index · Prices and terms checked October 10, 2026

Physical penetration testing is an authorized attempt to get into your building or restricted rooms the way an intruder would: tailgating staff, copying a badge, slipping a latch, talking past reception. Published prices we checked run from $5,000 for a one-door test to at least $19,500 for a one-week engagement. Nothing should start until whoever controls the building has signed.

Those prices are not for the same job. Travel, the number of doors, and a return visit to check your fixes are where they split, and the tables below show each one.

Which kind of physical test do you need?

Most first-time buyers need one of two things: a walkthrough that lists weak spots, or an active test where someone really tries to get in. The other two routes are bigger purchases.

Table columns: Your question; Route; What you get; Published price example.
Your questionRouteWhat you getPublished price example
What is weak, and what should we fix first?Walkthrough review (often sold as a "physical security audit" or "assessment"). An assessor looks around with your knowledge.A list of gaps with photos and priorities. No proof anyone could get in.BreachPoint: $1,500 to $2,500 for a site under 5,000 square feet
Could a stranger actually reach a named room?Active physical penetration test. Testers try agreed ways in.Photo or video proof of what worked, what was blocked, and how to fix it.$5,000 to $19,500 and up; see the next table
Once inside, could they get onto our network?Entry test with network work written into scope.The path from the front door to your systems.Quoted as a combined scope
Would our security team notice a quiet, multi-route attack?Red team (a goal-led exercise that may use email, the network and the building).The story of one attack, not a list of every way in.Invadel: from $12,500. BreachPoint: $15,000 to $25,000 for 1 to 50 employees

Think of a walkthrough as a home inspector's list. An active test is someone trying your doors.

Three quick checks before you spend anything:

  • You already know the side door doesn't latch. Fix it first. Paying a tester to prove it buys you nothing new.
  • Your landlord controls the lobby and says no. A walkthrough of your own suite may be all you can authorize.
  • Someone asked you for "a pentest" and you assumed the building. Ask them. They may mean your network or your app. Our guide to choosing the assessment type covers the others, and we compare a red team with a penetration test separately.

Sources for the routes: Secureworks sells escorted and covert versions as different services; BreachPoint and Invadel price the audit, the entry test and the red team separately.

How much does physical penetration testing cost?

For one ordinary office, the published prices we found sit between $6,800 and $12,000 before any extra travel charges. A one-door test starts at $5,000, and the one published week-long engagement has a floor of $19,500.

Every figure below is in US dollars and comes from the provider's own page, read on October 10, 2026. None is a quote for your building. Providers are listed A to Z, not ranked. "Not stated" means we did not find it on the pages we read; it does not mean the answer is no.

Table columns: Provider and offer; Published price; What that price covers; Travel; Return visit to check your fixes; Confirm before you rely on it.
Provider and offerPublished priceWhat that price coversTravelReturn visit to check your fixesConfirm before you rely on it
BreachPoint, Physical Penetration TestFocused: $5,000 to $8,000. Comprehensive: $8,000 to $12,000. Advanced: $15,000 to $25,000. All are estimates; a statement of work sets the price.Focused: one door, one attempt window, half to one day. Comprehensive: several entry points, 1 to 2 days. Advanced: 2 to 3 operators, 2 to 3 days.No surcharge in Utah. Elsewhere, travel is agreed in advance.Not statedA 50% non-refundable deposit reserves dates. Two details on its pages disagree; see below.
Invadel, Physical, Small$6,800, fixedOne New York metro office up to about two floors. Two operators, up to 3 days on site, business hours. No forced entry or damage.Included in the New York metro. Elsewhere is quoted.Free re-check of the controls you fix, business hours, New York metroIncludes one attempt to plug a test device into your network. Remove it if you don't want it.
Invadel, Physical, Medium$10,500, fixedA guarded or harder site, or two nearby sites. Up to 5 days on site and one after-hours attempt.SameSameSame
Schellman, physical penetration test"No less than $19,500 for a 1-week engagement"Covert entry aimed at getting in and gaining a foothold on the internal network. More sites or goals raise the price.Stated as included in the totalNot statedTeam size and on-site days are not stated.
Triaxiom Security, one office"Typically costs $10,800"One office. About 3 days: one of surveillance, two of entry attempts.Billed separately, except the Charlotte, NC areaRetest-policy post: one retest within 90 days of the assessment finishing. It does not mention a physical return visit or travel.An older post on its site shows a different price; see below.

See BreachPoint's physical testing prices See Invadel's physical testing prices See Schellman's physical test service See Triaxiom's physical test service

These links go to each provider's own page. This site may contain affiliate or referral links. If you buy through one, we may be compensated. See how we make money.

Secureworks and OnSecurity also describe physical tests but publish no price, so they are not in the table.

Three places where a provider's own pages disagree

We found these while reading. Each one is a question to put in writing before you sign.

  • Triaxiom's price. Its service page says a one-office test typically costs $10,800. A 2018 post still on its site says $4,800 for the same three days. We use $10,800 because it is on the current service page. Ask which applies to you.
  • BreachPoint's top price. Its service page gives the penetration test tier as $5,000 to $15,000. Its pricing page lists an Advanced option at $15,000 to $25,000. Don't treat $15,000 as a cap.
  • BreachPoint's final payment. One part of its pricing page says the balance is due within 15 days of the final report. Its FAQ on the same page says it is due on delivery. Ask which one the statement of work will say.

What the published prices leave out

Travel is the big one, and four providers handle it three ways: included (Schellman), included only near home (Invadel in New York, BreachPoint in Utah), or billed on top (Triaxiom outside Charlotte). An unknown travel bill makes your total incomplete. It does not make it zero.

Also check for after-hours attempts (in Invadel's Medium price, not its Small one), extra sites, and the return visit. Two nearby sites show why the tier matters: two of Invadel's Small tests would be $13,600, while its Medium tier covers two nearby sites for $10,500. That is $3,100 less, for up to five days on site instead of six.

For a wider budget, see our published penetration test prices.

What state price lists show

Mississippi's state IT agency publishes the most each approved vendor may charge state agencies for a "Physical Security Assessment." These are ceilings, not quotes. The size tiers are set by counts of devices and IP addresses, not buildings, and the line may not mean a covert test.

Table columns: Vendor; Smallest tier ceiling; Largest tier ceiling.
VendorSmallest tier ceilingLargest tier ceiling
Next Step Innovation$1,000$4,000
RSI Security$1,500$12,000
NTT Data Americas$20,811.13$318,758.72

Same line item, same smallest size, and the ceilings are about 21 times apart. That is the lesson: "physical security assessment" is a label, not a job description. Your scope has to say what you are buying.

Which offer fits which buyer?

Match the offer to your location and your goal first, then compare price. A low starting number is not clearance to book.

  • One office in the New York area, standard doors and reception. Invadel's Small price is the most complete published offer we read: fixed price, team size, days and a return visit are all stated. Confirm the return-visit deadline and strike the device step if you don't want it.
  • One office in Utah. BreachPoint's Comprehensive estimate carries no travel charge. Get the return visit and the payment date in writing.
  • Anywhere else, with a firm budget under $19,500. Ask BreachPoint and Triaxiom for an all-in number with travel listed line by line. Schellman's published floor rules it out.
  • Several sites, or you want the network included, and budget is not the limit. Schellman's week-long engagement and BreachPoint's Full-Scope Red Team are built for that.

This is about how the published terms fit a buyer. We have not bought or watched any of these tests, and we are not rating anyone's quality.

A worked example: one leased office in Denver

Say you run a 60-person company on one leased floor in Denver. This company is made up. Leadership wants to know if an outsider can reach the network closet. You want agreed, non-damaging entry attempts, no device plugged in and no network work. You need a report, a return visit you will request 60 days after the report, and a total of $15,000 or less including travel. No provider has quoted this.

Our finding: buy an active entry test of one site. Ask BreachPoint (Comprehensive) and Triaxiom for written quotes. Neither is ready to book on its published terms alone. Schellman's offer fails on budget. Invadel's published price fails on location, though it will quote Denver separately.

Table columns: What you need; BreachPoint Comprehensive; Invadel Small; Schellman; Triaxiom.
What you needBreachPoint ComprehensiveInvadel SmallSchellmanTriaxiom
Test in DenverUnresolved: travel is agreed separatelyMismatch: the $6,800 price covers New York metroUnresolved: confirm Denver coverage; travel stated as includedUnresolved: travel billed on top
Total of $15,000 or lessUnresolved: $8,000 to $12,000 leaves $3,000 to $7,000 for travel and a return visitUnresolved until a Denver quote existsMismatch: floor is $19,500Unresolved: $10,800 leaves $4,200 for travel and a return visit
No device, no network workUnresolved: must be written into scopeMismatch as packaged: one device attempt is included by defaultUnresolved: the service aims at a network footholdUnresolved: must be written into scope
Return visit requested on day 60Unresolved: not statedUnresolved outside New YorkUnresolved: not statedUnresolved: see below

"Supported" means that one condition is backed by the page we read. It is not a verdict on the provider. A mismatch on something you must have removes that offer as published. "Unresolved" means you need an answer in writing.

The Triaxiom return visit turns on one date. Its retest-policy post counts 90 days from the end of the assessment. You plan to ask 60 days after the report. Under that wording, your request lands inside the window only if the report arrives within 30 days of the test ending. Ask this: "Does the included retest cover an on-site return visit to Denver, is travel extra, and is the 90 days counted from the last test day or from the report?"

What would change the finding: a written Denver quote that lists the test, travel, report and return visit, with your exclusions spelled out.

Who has to sign before a physical penetration test?

TrustedSec recommends a company officer, and if you don't own and solely occupy the building, the building owner too. A signature from IT alone may not be enough.

This is the part of the purchase that goes wrong in public. In September 2019, two testers hired by Iowa's State Court Administration were arrested inside a county courthouse, held nearly 24 hours and released on $100,000 bail. They carried an authorization letter. According to Krebs on Security, one listed contact did not answer the deputies' calls, another said he didn't believe they had permission for physical entry, and the testing firm's CEO later said it had not understood that the county, not the state, owned the building. Charges were dropped on January 30, 2020.

After that case, the security firm TrustedSec published its legal templates for physical testing for anyone to use. Its notes, and the providers' own terms, give you this map.

Table columns: Your situation; Who should agree in writing; Ask the provider.
Your situationWho should agree in writingAsk the provider
You own the building and are the only occupantA company officer. TrustedSec notes that directors and people in IT or security "might not always have the authorization.""Who on our side has to sign your letter?"
You lease a floor or suite in a shared buildingYour officer and the building owner or authorized manager. TrustedSec says the customer and building owner should both sign. Invadel treats landlord consent as a scoping step."Does the test wait until building consent is in hand?"
The lobby has guards or a guard contractorThe same, plus a decision on whether the guard company is told"Who do your testers call if a guard stops them?"
Co-working space or serviced officeThe operator. Shared areas are theirs to authorize."What can you test if the operator says no?"
Your servers sit in someone else's data centerThe data center operator, who may refuse"Have you tested at this operator before?"
A government or public buildingThe body that owns and runs that building, which may not be the one hiring the tester"Whose signature covers each address?"

Leave any area out of scope until its owner has agreed.

What the rules of engagement should settle

The rules of engagement are the written list of what testers may and may not do. Before the first site day they should name:

  1. The exact addresses, floors and rooms, and any that are off limits.
  2. The hours. Business hours only, or after hours too. In the Iowa case, court officials later said they had not expected testing outside business hours.
  3. Methods allowed and banned. Lock picking, forced entry, damage, who testers may pretend to be, and whether anything gets plugged into your network.
  4. Two named contacts who will answer the phone during every test window. Schellman lists two; check the numbers work before day one.
  5. Whether police or the alarm company are told first. TrustedSec recommends the customer notify law enforcement. Schellman suggests routing the alarm call list to someone who knows about the test.

We are not lawyers and this is not legal advice. Have your counsel read the authorization letter. Nothing on this page, and no checklist of ours, authorizes anyone to test anything. We cover the document itself in our guide to penetration testing rules of engagement.

What should you send providers before asking for a price?

Send every provider the same one-page brief. It asks each of them the same question, so the answers line up. It does not make unlike offers equal.

Physical assessment buying brief

Don't put door codes, alarm codes or badge numbers in a brief. Agree how to share access details with the provider you hire.

  • Purpose and reader: What decision will the result support? Who receives the report?
  • Site and goal: Address, the areas you control, and the room or asset to reach.
  • Authority: Who controls each area? Which permissions are still open? Leave open areas out.
  • Route: Walkthrough, active entry attempts, or entry plus network work.
  • Attempts: Entry points, dates, hours, who inside will know, how many testers and site days to quote.
  • Limits: What is allowed and what is banned. Our default: no damage, no device plugged in, no network work, nothing touching another tenant, unless you agree otherwise in writing.
  • Contacts and stops: Main and backup contact for every test window. Who can pause or stop the test.
  • Evidence and report: Each attempt that worked or was blocked, photos you permit, what was out of scope, the risk to the business, the fix and its owner. Findings written by control, not by employee name.
  • Dates: Approvals, site days, report date, your fix deadline, return-visit deadline.
  • Return visit: Which controls, on site or not, how many visits, what starts the clock, and who pays travel.
  • Full cost: Test, travel, report, return visit, taxes, deposit, when the balance is due, and what it costs to cancel or move dates.
  • What you already have: Could a current provider or contract cover this?

This brief prepares a request for quotes. It does not authorize testing.

Prepared with The PenTest Index: https://thepentestindex.com/physical-penetration-testing/

Filled in for the Denver example

  • Purpose and reader: Can an outsider reach our network closet? Report goes to the CEO and the IT lead.
  • Site and goal: One leased floor, [fictional address], Denver. Goal: reach the closet door and, if possible, enter.
  • Authority: Our COO for our suite. Building manager consent for the lobby and stairwells is still open, so those areas are out for now.
  • Route: Active entry attempts.
  • Attempts: Our suite's entrance and reception, from authorized areas only. Business hours. Only the COO and IT lead know. Quote for two testers.
  • Limits: No damage, no forced entry, no device plugged in, no network work, no other tenant's space.
  • Contacts and stops: COO and IT lead, both on call all test days. Either can stop the test.
  • Evidence and report: Photos of each attempt, no employee names.
  • Dates: Report within two weeks of the last site day. Fixes within 60 days of the report.
  • Return visit: One on-site visit to re-check fixed controls, requested 60 days after the report.
  • Full cost: $15,000 or less for everything, travel included.
  • What we already have: No current provider.

Can't fill in the first three lines yet? That usually means the request behind the test is still fuzzy. Our scoping tool has questions for specialist work like this and a checklist you can copy or print. It is free, needs no email, and sends nothing to providers. It does not list physical testing providers, so use it to sharpen the request, then come back to the table above.

Build your scope checklist

Already holding a quote? Check it against the same lines with our Quote Check.

Does getting in include testing the network?

Only if you say so. Entering a room, plugging in a device, and attacking systems from that device are three separate permissions.

Offers differ here by default. Invadel's package includes one attempt to place a device and sells the network test from that device as a paired service. Schellman's stated end goal includes a foothold on the internal network. BreachPoint includes network work in its red team tier and also sells a network testing add-on. If you want doors only, write "no device, no network work" in the brief. If you want the full path, scope the internal penetration test alongside it.

What happens during the test, and how long does it take?

Expect a day of watching, two or so days of attempts, and a written report. For one office, the calendar runs three to five weeks from signing to report on the one published timeline we found.

Table columns: Stage; What providers state; Get in writing.
StageWhat providers stateGet in writing
Paperwork and consentInvadel allows 2 to 4 weeks from signing to the site daysThe date all signatures are due
On siteAbout 3 days for one office (Invadel, Triaxiom). 1 to 2 days for BreachPoint Comprehensive.Number of testers, days and attempts
ReportInvadel: within 5 business days of the last site dayYour report date
FixesYours to scheduleWho owns each fix
Return visitVaries; see the price tableThe deadline and what starts it

On site, testers use the low-drama ways a real intruder would: tailgating (walking in behind staff), copying a badge, slipping a poorly fitted latch, a delivery or contractor story at reception. Then they see what they can reach, such as unlocked computers, papers left out, or the server room.

Will anything get broken? It should not, unless you approve it. Invadel's terms ban forced entry and damage outright. Put the same ban in your rules of engagement.

What if testers are caught or stopped? That is a result, and a good one. Testers show the letter and call your named contacts. Triaxiom says that if its team is caught early it may switch the work to an audit so you still get findings. A blocked attempt shows that control held that day. It does not prove every route is safe.

Who should know? Usually only your named contacts, so staff and guards react as they normally would. Those contacts can stop the test at any time.

Will staff be named in the report? Ask for findings by control, not by person. The point is the door and the procedure, not the receptionist. Our guide to the penetration testing report covers what else to check.

Is physical penetration testing required for your audit or contract?

Usually not by name. In the two official texts we read for this page, one applies only where a program has chosen it, and the other says the related testing is not required. Ask whoever is requesting evidence exactly what they need.

Table columns: Source we read; What the text says.
Source we readWhat the text says
NIST SP 800-53 Rev. 5, control enhancement CA-8(3), "Facility Penetration Testing""Employ a penetration testing process that includes [Assignment: organization-defined frequency] [Selection: announced; unannounced] attempts to bypass or circumvent controls associated with physical access points to the facility." The frequency and the announced-or-not choice are left to the organization. It applies where your program has selected that enhancement.
The same document, CA-8 discussionPenetration testing "can exercise both physical and technical controls."
PCI SSC Penetration Testing Guidance, March 2015, section 2.5"PCI DSS does not require use of social-engineering techniques." It lists persuading someone to hold a door open as one example of such an optional test. This is 2015 guidance, not the text of the current standard.

We did not read the current PCI DSS, SOC 2, ISO 27001 or HIPAA texts for this page, so we make no claim about them. If a customer or auditor says "pentest" or "physical security," send this: "Do you need active entry attempts, a review of our physical controls, or technical testing? What must the report show, and by when?" They decide what they accept. No provider can promise that for them.

Questions before you book

How often should you repeat it?

There is no universal schedule in what we read. NIST leaves frequency to the organization. Schellman and OnSecurity each suggest at least yearly or after changes, which is their advice, not a rule. A sensible trigger is a move, a new badge system or a change of guard company.

Can your own team do it?

For a walkthrough, often yes. For an entry test, an employee already has a badge and a familiar face, so the result says little about a stranger. Check whether the person asking for evidence accepts internal work.

What is the difference between a physical penetration test and a physical security assessment?

An assessment or audit looks and lists. A penetration test tries. Providers use the words loosely, so go by what the scope says testers will do.

Is this page about becoming a physical penetration tester?

No. It is for organizations buying a test. It does not cover training or jobs.

Sources and how we checked

We read each page below on October 10, 2026 and compared the published terms. We did not buy, commission or observe any of these tests, and we inspected no physical-test sample report. Prices and terms change; ask for yours in writing. Our method explains how we apply a buyer's requirements to a specific offer, and you can send a correction.

None of these organizations endorses this page. The templates and standards belong to their publishers; we link to them and do not reproduce them.