Social engineering penetration testing: published prices and how to scope it
By The PenTest Index · Sources checked October 10, 2026
Social engineering penetration testing is an authorized attempt to trick your own staff by email, phone, text or in person, to see what a real attacker could get. Two providers publish figures of $2,750 and $3,600 for one small email campaign. Those figures cover different scopes. PEN Consultants says its assessment also tests technical controls and, after a successful compromise, lists the systems and data the user can reach.
So the first thing to settle is not the provider. It is the question you need answered.
What should social engineering penetration testing prove?
It should answer one stated question and show what was tried, what happened and where the tester stopped. Write the sentence "We need to know whether ___" before you ask anyone for a price. Then pick the narrowest row below that answers it.
A few terms, in plain words. Phishing is a trick by email. Vishing is a trick by phone. Smishing is a trick by text message. Pretexting is using a made-up identity or story, like "I'm from IT." The channel does not tell you how deep the test goes. A phone call can stop at "did they follow the script," or it can end with a reset password in the tester's hands.
Is our phishing simulation enough?
It is enough if your question is the first row. Many companies already own the tool. Microsoft states that Attack simulation training is included in Microsoft Defender for Office 365 Plan 2 and Microsoft 365 E5, and the techniques it lists are all email-based (Microsoft Learn, checked October 10, 2026).
It is not enough for rows two to four. A tool you run yourself does not phone your help desk, and it does not show what a stolen password opens. If you have an existing provider, ask them one thing before buying again: "Does our current scope test this question and report this evidence?"
How much does a social engineering test cost?
Four providers put something useful in public. Three publish figures, and those figures describe different purchases. None is a quote for your scope, and we are not turning them into a "typical range." Providers are listed A to Z. Everything below is what the provider's own page says. We read the pages. We did not buy or run these services.
Sources, all checked October 10, 2026: Bishop Fox service page · Invadel pricing and phishing testing cost page · PEN Consultants phishing assessment · Triaxiom cost article
Two things we worked out from those pages:
- PEN Consultants' three-campaign sample is $750 less than three single campaigns. Three times $2,750 is $8,250. The three-campaign sample is $7,500.
- Invadel's Medium starting figure is $1,900 above Small. Medium is $5,500 and Small is $3,600. If you need phone or text as well as email, Small does not cover it.
Which provider should you ask first?
Match the row to your question.
- You want click and reporting numbers from an outside party. Invadel's Small tier and PEN Consultants' single campaign are the two published figures. Check first whether a tool you already own answers the same question for nothing extra.
- You want a phone test of one process. Bishop Fox and Triaxiom both list phone work. Invadel's Medium tier can include voice, but its published report is click and reporting numbers, so ask whether it will document a process outcome.
- You want to know what a tricked employee's access opens. PEN Consultants and Bishop Fox both describe going past the first interaction. Neither is a confirmed fit until the proposal names how far the tester may go.
- You need someone on site. Of these four, Bishop Fox lists physical intrusion. A remote campaign is not a substitute.
The one question that settles most close calls: "After someone clicks or complies, do you stop and report numbers, or do you keep going to an agreed point and show what you reached?"
If one of these matches, go straight to the provider's page with your scope brief from the next section.
View Bishop Fox's social engineering service
View Invadel's phishing testing scopes and prices
View PEN Consultants' phishing assessment
Read Triaxiom's cost breakdown
Already holding a proposal? Compare what is in scope before you compare totals. Our quote check walks through that, and penetration testing cost covers budgeting for the rest of your testing.
What should you put in a social engineering scope brief?
Put the question, the people, the channels, the stopping point, the proof you want and the full price terms in one page, and send every provider the same page. That way their answers line up and you can compare them.
Copy this and fill in what you know. Leave the rest as "not confirmed" so the provider has to answer it.
Social engineering test: scope brief
What does a filled-in brief look like?
Here is a made-up example. Say you run an 80-person software company. You already send practice phishing emails. Last month someone phoned your support team pretending to be a customer and nearly got an account reset. Your manager wants to know if it would work next time.
- Question: Would our account-reset process hold up against a caller pretending to be a customer?
- Who needs the report: Our own security owner. No customer has asked.
- People and channels: The support team, by phone only.
- How far: Stop when the process either holds or fails. Use a test account. Do not reset a real customer's account.
- Report: Which identity checks were asked for, whether they were followed, and what happened.
- Not confirmed yet: Number of calls, whether calls may be recorded, dates.
Now hold the four published offers up against that brief. Phone testing of one process is the must-have.
"Supported" here means the provider's page backs that one condition. It is not a verdict on quality and it is not a quote.
What this company should do: another email campaign does not answer its question, so it should skip the cheapest tier. It should send the brief to the two offers that list phone work and ask Invadel the Medium question. If the manager later asks "and what could the caller get into after the reset?", that is a bigger test. Change the brief and the written authorization before adding it.
If none of these four fits, or you are not sure which kind of testing you need, our Find My PenTest Match tool asks three short questions and gives you a scope checklist to copy or print. It is free and asks for no contact details. It does not have a social engineering option yet, so choose "Something else" and bring this brief with you.
Is social engineering testing required?
It depends on who is asking, and the two rule sets buyers ask about most say opposite things.
Sources, checked October 10, 2026: PCI SSC Penetration Testing Guidance v1.1, section 2.5 · FedRAMP Penetration Test Guidance v3.0, sections 1.0 and 3.1.1
We did not check SOC 2, ISO 27001, HIPAA or state rules for this page, so we are not saying what they require. Your auditor, assessor, customer or regulator decides what they accept. Send them this: "What exact scope and deliverables do you need, and is social engineering included?"
Buying for a card-data environment? See PCI penetration testing.
What should the report show beyond click rates?
It should prove the thing you asked about. A click rate tells you who clicked. It does not show that anyone got into anything.
Two questions worth asking any provider: "How do you tell a real person's click from an email filter opening the link?" and "Did you ask us to let your emails past our filters, and does that change what the result means?"
Is there a good phishing click rate?
No single number works, because an easy fake and a hard fake get very different results. NIST publishes a Phish Scale that rates how hard a phishing email is to spot, so you can read a click rate next to the difficulty of the email that produced it. Watch the share of people who report the message, too. That is the behavior you want more of.
For what a full test report should contain, see penetration testing report.
What needs approval before anyone tests your staff?
Agree the real targets, the real activities, the limits and how evidence is handled, in writing, before work starts. Fields 5 to 7 of the scope brief cover the main points. Three things deserve extra care.
It can upset people if it is used to catch them out. NIST's testing guide (SP 800-115, section 5.3) says that targeting individuals can embarrass them, and that results should be used to improve the organization's security and "not to single out individuals." It also says the final report should cover both the tactics that worked and the ones that did not (NIST SP 800-115, checked October 10, 2026). So ask for results by team and by pattern, and decide before the test how staff will be told afterward.
Your sign-off does not settle everything. Recording phone calls, walking into a building you lease, or contacting people at an outside company can raise legal questions that differ by place. Have your lawyer look at phone and in-person work before it is approved.
A real attack can arrive during the test. Agree how staff can check whether a strange call is the test, and who can pause the work.
For the full written agreement, see penetration testing rules of engagement.
Questions before you book
Can this replace a web application or network pentest?
No. A phishing campaign tells you nothing about systems it never touched. If a customer or auditor asked for an application or network test, keep that scope unless they tell you otherwise in writing. Penetration testing services explains the types.
How often should we repeat it?
No source we read sets a schedule for everyone. The PCI guidance leaves frequency to you. Let the request you are answering, your own risk and recent changes decide. Re-checking one fixed process is a small job. A fresh campaign is a new purchase, and both Invadel and PEN Consultants price it that way.
How long does it take?
The pages we read give few firm dates. Invadel says a campaign usually starts within a week of scoping. PEN Consultants' sample prices assume at least 60 days' notice. Ask for the start date, the testing window and the report date in writing.
Looking to learn social engineering yourself?
This page is for people buying a test for their company. For hands-on skills, look for a training provider.
How we checked this
We read each provider's public page on October 10, 2026 and compared what it says against a buyer's stated needs. That is our Purchase Check, and our methodology explains it. We did not purchase these services, test them, or confirm any provider's quality or availability. We have no paid relationship with any provider on this page. Providers appear A to Z.
Sources
Prices and terms change. Spot something out of date? Tell us and we will re-check it.
This brief helps you compare proposals. It does not authorize testing. Written authorization must cover the actual targets and activities.