“What does a pentest cost?” is the most common question after “what is a pentest?” – and it is a fair one. The honest answer up front: there is no serious fixed price. Anyone offering you pentests “from” a certain amount is calculating at a risk – yours. Here is how prices for security services actually come about, and how to recognise a good proposal.


Why there is no fixed price

A pentest (or a security audit) is not a standard product like a firewall license. The effort depends on things that differ completely from business to business:

  • Scope: How many systems, networks, cloud subscriptions, and applications should be reviewed? A single server and a distributed cloud environment with dozens of services are not comparable effort.
  • Complexity: Modern setups with containers, CI/CD pipelines, identity providers, and APIs require deeper understanding than a classic on-premise environment.
  • Documentation: What do you need as the outcome? A compact finding, runbooks, evidence for auditors, or a complete list of issues with reproduction?

A provider who names a fixed price before clarifying the scope can only do one of two things: guess an average – and at the end either put too little work into the project or let the engagement fall short.


How does a pentest work?

Penetration Test Workflow

  1. Intro call (free): 30 minutes in which you describe your situation. I ask about scope, systems, and goals.
  2. Written proposal: Based on the conversation, I define the scope and give you the expected frame – as an order of magnitude, not a fixed price.
  3. Billing: Only what was actually worked is billed. Documented and verifiable.

This shifts the risk distribution: the provider does not have to hope for a guessed price, and you do not pay for a flat rate that ends up above – or below – your actual needs.


What to look for in a proposal

Good signals:

  • Scope is clarified before the price. Serious providers ask questions first, then name prices.
  • The frame is justified understandably – not just “from X”, but with reference to your setup.
  • The outcome is described: What form does the report take, what prioritisation, what handover?
  • Follow-up questions are possible: A fix is verified, a finding is explained.

Warning signs:

  • Fixed prices without scope clarification – calculated at a risk.
  • No report promised, just “the list of found holes”.
  • Pressure to close instead of room for your questions.

Audit or pentest: price is not the first criterion

Before you compare prices, you should have chosen the right service. A security audit – the technical assessment without an active attack – is the more sensible first step for most businesses and significantly less effort than a full pentest. My article Security Audit or Pentest? goes into the difference in detail.

The most common expensive mistake is not the high hourly rate, but the wrong project: a pentest on a system that was never audited before often does not find the biggest gaps – because nobody knew what to look for.


Clarity instead of guesswork

If you want to know a realistic frame for your business, the fastest way is a short conversation: describe your situation to me, I explain what needs to be reviewed, roughly how much time that costs – and which format makes the most sense for you. Free and non-binding for initial guidance.