“What does a pentest cost?” is the most common question after “what is a pentest?” – and it is a fair one. The honest answer up front: there is no serious fixed price. Anyone offering you pentests “from” a certain amount is calculating at a risk – yours. Here is how prices for security services actually come about, and how to recognise a good proposal.
Why there is no fixed price
A pentest (or a security audit) is not a standard product like a firewall license. The effort depends on things that differ completely from business to business:
- Scope: How many systems, networks, cloud subscriptions, and applications should be reviewed? A single server and a distributed cloud environment with dozens of services are not comparable effort.
- Complexity: Modern setups with containers, CI/CD pipelines, identity providers, and APIs require deeper understanding than a classic on-premise environment.
- Documentation: What do you need as the outcome? A compact finding, runbooks, evidence for auditors, or a complete list of issues with reproduction?
A provider who names a fixed price before clarifying the scope can only do one of two things: guess an average – and at the end either put too little work into the project or let the engagement fall short.
How does a pentest work?
- Intro call (free): 30 minutes in which you describe your situation. I ask about scope, systems, and goals.
- Written proposal: Based on the conversation, I define the scope and give you the expected frame – as an order of magnitude, not a fixed price.
- Billing: Only what was actually worked is billed. Documented and verifiable.
This shifts the risk distribution: the provider does not have to hope for a guessed price, and you do not pay for a flat rate that ends up above – or below – your actual needs.
What to look for in a proposal
Good signals:
- Scope is clarified before the price. Serious providers ask questions first, then name prices.
- The frame is justified understandably – not just “from X”, but with reference to your setup.
- The outcome is described: What form does the report take, what prioritisation, what handover?
- Follow-up questions are possible: A fix is verified, a finding is explained.
Warning signs:
- Fixed prices without scope clarification – calculated at a risk.
- No report promised, just “the list of found holes”.
- Pressure to close instead of room for your questions.
Audit or pentest: price is not the first criterion
Before you compare prices, you should have chosen the right service. A security audit – the technical assessment without an active attack – is the more sensible first step for most businesses and significantly less effort than a full pentest. My article Security Audit or Pentest? goes into the difference in detail.
The most common expensive mistake is not the high hourly rate, but the wrong project: a pentest on a system that was never audited before often does not find the biggest gaps – because nobody knew what to look for.
Clarity instead of guesswork
If you want to know a realistic frame for your business, the fastest way is a short conversation: describe your situation to me, I explain what needs to be reviewed, roughly how much time that costs – and which format makes the most sense for you. Free and non-binding for initial guidance.