Pricing a penetration test comes down to the number of hours worked multiplied by an hourly rate. In practice every conversation about price is therefore a conversation about one question: how much work does a thorough test of this particular target require.
The answer starts with the type of test, because differences between types are larger than differences within a single type.
Ranges by type of test
| Type of test | Typical effort | What moves the effort most |
|---|---|---|
| External network, perimeter | 2-5 days | number of addresses and exposed services |
| Web application or API | 3-10 days | number of roles, features and endpoints |
| Mobile app with backend | 4-8 days | two platforms, app hardening mechanisms |
| Internal network, Active Directory | 5-12 days | number of sites, segments and systems |
| IoT or embedded device | 5-15 days | number of layers: hardware, firmware, radio, cloud |
| OT and ICS systems | 5-15 days | caution, maintenance windows, passive work |
| Social engineering, phishing | 3-7 days | number of scenarios and size of target group |
| Automotive, in-vehicle buses | quoted individually | access to a vehicle or bench, equipment required |
Ranges assume a single tester, grey box mode and a single target. Large engagements sit outside that scale: the shortest project I have run closed in two weeks, the longest ran for three months. Treat the table as a starting point for a conversation, not as a price list.
Automotive deliberately carries no range in that table. Work on in-vehicle components and buses needs a bench, access to a vehicle or a module, and equipment that does not fit into a single day rate. Such work runs as a separate project, quoted individually.
My specialisation is devices, industrial systems and infrastructure. I do take web and mobile application tests as well, although they are not my main area, and I say so upfront rather than after you ask for a quote.
Why devices and OT come out more expensive
Testing a network concerns essentially one layer. Testing a device concerns several, and each is separate work:
| Device layer | Scope | Effort |
|---|---|---|
| Hardware | diagnostic interfaces, memory dump, enclosure protection | 1-3 days |
| Firmware | image analysis, secrets, secure boot, logic | 2-5 days |
| Communication | Wi-Fi, BLE, LoRa, cloud protocol | 1-4 days |
| App and backend | authentication, authorisation, tenant isolation | 2-5 days |
| Update process | signatures, rollback, distribution channel | 1-2 days |
A sensor with no app and no cloud component fits into a few days. A camera with a mobile app, a backend and OTA updates takes a dozen or more, even though both products fall under the term IoT device.
With OT, effort grows for a different reason. A large share of the work happens passively or on a twin rig, because the test must not stop production. What you pay for there is caution, not a larger number of findings.
Factors common to every type
Test mode
Black box means working without documentation or accounts. It sounds realistic, costs more and delivers less, because a significant part of the budget goes into reconstructing knowledge the client already holds.
Grey box assumes test accounts and basic documentation. It is the most common choice and usually the optimal one.
White box includes full documentation and sometimes source code. Measured per vulnerability found, it is the most economical.
In practice clients mostly choose grey or white box, and the choice is rational: less time on the same scope means a lower invoice. An attacker has unlimited time; a tester typically has two weeks, so closing that gap with documentation is in the client's interest.
Retest
A retest means verifying the vulnerabilities found and described in the report, not re-examining everything. Going through the whole target again is another penetration test and is priced as one.
Ordered together with the pentest it comes as a discounted package, which is cheaper than commissioning it separately after the fact. Without a retest you hold a list of vulnerabilities but no confirmation that the fixes work, and it is that confirmation which goes into documentation and to the end customer.
Engagement size
My rate sits between PLN 150 and 250 net per hour, roughly EUR 35 to 60 at current rates, and it is not flat. The larger the engagement, the lower it goes:
| Engagement size | Rate |
|---|---|
| around 20 hours | PLN 250/h |
| around 100 hours | PLN 200/h |
| around 300 hours | PLN 150/h |
The reason is mundane: a longer project carries less overhead per hour spent on onboarding, scoping and reporting.
In practice this means that splitting one large scope into several small engagements costs more than commissioning it as a whole.
Number of environments
The same application in three variants for three clients is not one test. The same applies to a device shipped in several hardware revisions.
Estimating the order of magnitude
- Identify the type of test and read the range from the first table.
- For a device, list the layers from the second table and add them up.
- Adjust upwards for black box mode, downwards for full documentation.
- Add the retest.
- Convert days to hours and multiply by the rate from the table above.
What to watch for in offers
The first warning sign is an automated scan presented as a penetration test. A quote corresponding to a few hours of work almost always describes a tool rather than a specialist. One question about proof of exploitation settles it. The differences are covered in pentest, audit or scan.
The second is a report without recommendations. A list of problems with no guidance on remediation order shifts the entire analytical effort back onto your team.
How to reduce the cost
- Provide documentation and test accounts. This is the most effective way to shorten a project, set out in the preparation checklist.
- Narrow the scope deliberately rather than diluting quality across everything.
- Order the retest together with the pentest; the package is cheaper.
- Schedule the test before the project is frozen. Fixes at that stage cost a fraction of changes made after deployment.
How I quote
A quote is built from scope and the rate table above. There is no minimum project size: a short, well defined job gets quoted as readily as a multi-month engagement. In practice one conversation and a completed preparation checklist are enough to give an effort range.
Get in touch and describe the target in a few sentences. I usually send back a scope estimate within one business day. Individual services are described under services.