Pricing a penetration test comes down to the number of hours worked multiplied by an hourly rate. In practice every conversation about price is therefore a conversation about one question: how much work does a thorough test of this particular target require.

The answer starts with the type of test, because differences between types are larger than differences within a single type.

Ranges by type of test

Type of testTypical effortWhat moves the effort most
External network, perimeter2-5 daysnumber of addresses and exposed services
Web application or API3-10 daysnumber of roles, features and endpoints
Mobile app with backend4-8 daystwo platforms, app hardening mechanisms
Internal network, Active Directory5-12 daysnumber of sites, segments and systems
IoT or embedded device5-15 daysnumber of layers: hardware, firmware, radio, cloud
OT and ICS systems5-15 dayscaution, maintenance windows, passive work
Social engineering, phishing3-7 daysnumber of scenarios and size of target group
Automotive, in-vehicle busesquoted individuallyaccess to a vehicle or bench, equipment required

Ranges assume a single tester, grey box mode and a single target. Large engagements sit outside that scale: the shortest project I have run closed in two weeks, the longest ran for three months. Treat the table as a starting point for a conversation, not as a price list.

Automotive deliberately carries no range in that table. Work on in-vehicle components and buses needs a bench, access to a vehicle or a module, and equipment that does not fit into a single day rate. Such work runs as a separate project, quoted individually.

My specialisation is devices, industrial systems and infrastructure. I do take web and mobile application tests as well, although they are not my main area, and I say so upfront rather than after you ask for a quote.

Why devices and OT come out more expensive

Testing a network concerns essentially one layer. Testing a device concerns several, and each is separate work:

Device layerScopeEffort
Hardwarediagnostic interfaces, memory dump, enclosure protection1-3 days
Firmwareimage analysis, secrets, secure boot, logic2-5 days
CommunicationWi-Fi, BLE, LoRa, cloud protocol1-4 days
App and backendauthentication, authorisation, tenant isolation2-5 days
Update processsignatures, rollback, distribution channel1-2 days
Effort spreads across layers. The lighter bar is the lower bound, the darker one completes the upper.
Effort spreads across layers. The lighter bar is the lower bound, the darker one completes the upper.

A sensor with no app and no cloud component fits into a few days. A camera with a mobile app, a backend and OTA updates takes a dozen or more, even though both products fall under the term IoT device.

With OT, effort grows for a different reason. A large share of the work happens passively or on a twin rig, because the test must not stop production. What you pay for there is caution, not a larger number of findings.

Factors common to every type

Test mode

Black box means working without documentation or accounts. It sounds realistic, costs more and delivers less, because a significant part of the budget goes into reconstructing knowledge the client already holds.

Grey box assumes test accounts and basic documentation. It is the most common choice and usually the optimal one.

White box includes full documentation and sometimes source code. Measured per vulnerability found, it is the most economical.

In practice clients mostly choose grey or white box, and the choice is rational: less time on the same scope means a lower invoice. An attacker has unlimited time; a tester typically has two weeks, so closing that gap with documentation is in the client's interest.

Retest

A retest means verifying the vulnerabilities found and described in the report, not re-examining everything. Going through the whole target again is another penetration test and is priced as one.

Ordered together with the pentest it comes as a discounted package, which is cheaper than commissioning it separately after the fact. Without a retest you hold a list of vulnerabilities but no confirmation that the fixes work, and it is that confirmation which goes into documentation and to the end customer.

Engagement size

My rate sits between PLN 150 and 250 net per hour, roughly EUR 35 to 60 at current rates, and it is not flat. The larger the engagement, the lower it goes:

Engagement sizeRate
around 20 hoursPLN 250/h
around 100 hoursPLN 200/h
around 300 hoursPLN 150/h

The reason is mundane: a longer project carries less overhead per hour spent on onboarding, scoping and reporting.

In practice this means that splitting one large scope into several small engagements costs more than commissioning it as a whole.

Number of environments

The same application in three variants for three clients is not one test. The same applies to a device shipped in several hardware revisions.

Estimating the order of magnitude

  1. Identify the type of test and read the range from the first table.
  2. For a device, list the layers from the second table and add them up.
  3. Adjust upwards for black box mode, downwards for full documentation.
  4. Add the retest.
  5. Convert days to hours and multiply by the rate from the table above.

What to watch for in offers

The first warning sign is an automated scan presented as a penetration test. A quote corresponding to a few hours of work almost always describes a tool rather than a specialist. One question about proof of exploitation settles it. The differences are covered in pentest, audit or scan.

The second is a report without recommendations. A list of problems with no guidance on remediation order shifts the entire analytical effort back onto your team.

How to reduce the cost

  • Provide documentation and test accounts. This is the most effective way to shorten a project, set out in the preparation checklist.
  • Narrow the scope deliberately rather than diluting quality across everything.
  • Order the retest together with the pentest; the package is cheaper.
  • Schedule the test before the project is frozen. Fixes at that stage cost a fraction of changes made after deployment.

How I quote

A quote is built from scope and the rate table above. There is no minimum project size: a short, well defined job gets quoted as readily as a multi-month engagement. In practice one conversation and a completed preparation checklist are enough to give an effort range.

Get in touch and describe the target in a few sentences. I usually send back a scope estimate within one business day. Individual services are described under services.