Home › Resources › Penetration testing › What does a penetration test cost?

What does a penetration test cost?

Penetration testing is priced in tester days: the time a skilled consultant needs to cover the agreed scope properly. Scope, rather than a day rate, is what really drives the number.

Why it matters

Two quotes for the same system can be thousands of dollars apart because they assume different depth. Knowing what moves the price lets you compare proposals on substance, and stops you paying test rates for what is really an automated scan.

What moves the price

  • Scope size and complexity: a single web application takes far less time than an entire network
  • Depth: authenticated testing across every user role takes longer than an anonymous outside view
  • Engagement type: a red team runs over weeks and costs more than a scoped single-system test
  • Reporting and retest: check whether verification of your fixes is included or charged separately
  • Constraints: testing inside maintenance windows or against production systems adds time

Comparing proposals fairly

Put the same three questions to every provider: how many tester days the price covers, how findings are validated and evidenced, and whether a retest of remediated issues is included. Comparing on those points, not on the headline figure, shows what each proposal actually buys you. A fixed price against a written scope protects both parties.

Getting an actual figure

A short conversation about what you run is usually all it takes to scope a test. Intelligence Group quotes a fixed price against a written scope, so the figure you sign off is the figure you pay.

Where Intelligence Group fits

Intelligence Group tests networks, applications, wireless and people across New Zealand and Australia, evidences every finding and retests once you have fixed it. See what we test or request a quote.