What a penetration test costs, and what scope you're paying for
Understand what drives penetration test costs and what low quotes typically exclude. Compare scope, not just price, to avoid false economy.
A penetration test that comes in at a fraction of what others quoted often isn't a bargain—it's usually a narrower job wrapped in optimistic language. Understanding what scope you're actually paying for is the only way to compare quotes fairly and avoid discovering mid-project that critical systems fell outside the agreement.
The real problem happens when a business owner or IT manager accepts a low quote without clarifying what it covers, then halfway through finds out the tester won't touch the cloud infrastructure, won't test social engineering, or will only spend two days on a network that deserves five. By then, you've already signed, paid a deposit, and have a schedule to keep. The test proceeds anyway, delivers a report that says everything tested was secure (because barely anything was tested), and you've wasted money on false confidence.
What you're actually buying: the hidden scope drivers
Penetration testing doesn't have a per-hour flat rate the way a plumber does. The cost depends entirely on what the tester has to examine, how deeply they need to examine it, and how much time they need to do it properly. A cheap quote usually signals that one or more of these dimensions has been shrunk.
The size and complexity of your environment drives cost faster than anything else. A small office network with a few servers and 20 staff is a different job from a multi-site operation with hybrid cloud, third-party integrations, and hundreds of endpoints. The tester needs to map everything, understand dependencies, and identify attack paths—and that takes longer the bigger and messier your infrastructure is. Similarly, if you have legacy systems or custom applications, the tester may need to reverse-engineer how they work before they can test them. Off-the-shelf software is faster.
Scope definition is where quotes diverge most sharply. Will the tester attempt physical security (can they walk into your office and access a server room)? Will they use social engineering—phishing campaigns, pretexting, physical manipulation? Will they test remote access, APIs, databases, web applications, cloud services, or only internal network segments? Will they test third-party access or dependencies? A quote that omits "cloud infrastructure" or "social engineering" is cheaper because there's less work—not because the tester found a clever shortcut.
The depth of the test also matters. Some testers will run automated tools, document what they find, and call it done. Others will spend time manually verifying findings, chaining vulnerabilities together to show real-world attack chains, and testing compensating controls. A tester who spends two weeks on your environment will find more than one who spends three days, partly because they have more time and partly because they're doing work the cheaper option skipped.
Retesting is another cost that sometimes gets negotiated down or excluded. If you fix the vulnerabilities the tester found, will they come back to verify the fixes worked? A low quote might include only the initial test, leaving you to prove fixes yourself or pay extra for a retest. That's a false saving if you later discover something wasn't actually fixed.
Comparing quotes without getting lost in the fine print
When you collect quotes, ask each tester to state explicitly what's in and what's out. Not "we'll test your network"—specifically: internal network testing, external-facing systems, web applications, cloud services (and which ones), physical security attempts, social engineering, API testing, database testing, third-party integrations, and retesting. If a quote is silent on any of these, it's either excluded or the scope is ambiguous.
Ask how long they plan to spend on-site and how many testers will be involved. More time and more people usually mean more thorough testing, though efficiency varies. Ask whether they'll use automated scanning alone or combine it with manual testing. Ask what the report will include—vulnerability lists, proof-of-concept demonstrations, risk ratings, remediation steps, and retesting options.
When you find quotes at opposite ends of the price range, the difference almost never comes from one firm being more efficient. It comes from scope. The cheaper option is testing less, or testing less rigorously, or both. Whether that's acceptable depends on your risk tolerance and what you're trying to prove—to yourself, to a regulator, or to a client. A proof-of-concept test for a small app before launch is different from a comprehensive assessment of your entire operational technology. Name what you need, and the quotes will make sense.
When you're ready to move forward, look for providers on Strove who can explain exactly what their scope includes and why their approach fits your environment.
Common questions
- Why do penetration test quotes vary so widely?
- The biggest cost differences come from scope—what systems you're testing, how deeply, whether you include social engineering or physical security, and whether retesting is included. A low quote usually means narrower scope, not better pricing.
- What should I always ask about before accepting a quote?
- Ask exactly what is in scope (cloud, applications, social engineering, physical access, third-party systems) and what is excluded. Also ask about test duration, number of testers, and whether retesting of fixes is included.
- Is a cheaper penetration test ever a good choice?
- If it's a narrower scope that genuinely matches your needs—for example, testing a single web app before release—then yes. But if it's cheaper because the tester is omitting areas you care about, it's false economy.
- Does manual testing always cost more than automated scanning?
- Yes, usually. Manual testing takes longer because a person must understand your specific environment, chain findings together, and verify results. Automated scanning is faster but often misses context-dependent risks.
Find a verified provider on Strove
Compare vetted penetration testing providers, check their credentials, and book or request a quote — all in one place.
Find a Business