Business

What a Penetration Test Costs, and What Actually Changes the Number

Quotes for the same scope routinely differ by a factor of three. Here is what the number is made of, which variables move it most, and how to tell a cheap quote from a small one.

Pental4

Ask four firms to price the same web application and you will get four numbers, sometimes spanning a factor of three. That is not because three of them are wrong. It is because "a penetration test" describes an activity, not a quantity, and the quote is really a bid on how many days it takes.

The number is days multiplied by a rate

Almost every quote in this industry decomposes the same way: a day rate, and an estimate of days. The rate varies less than people expect. The days vary enormously, and that is where the difference lives.

So the useful question when comparing quotes is never "why is this one more expensive". It is "how many days is each of you proposing, and what are you doing with them". Two firms at the same rate quoting six days and two days are not competing on price. They are proposing different pieces of work.

What moves the day count

  • Roles, not pages. An application with one kind of user is a fraction of the work of one with four. Every additional role multiplies the authorisation testing, because each pair of roles is a boundary somebody has to try to cross.
  • Whether state changes. A read-only reporting tool is quicker than something that moves money, provisions access or writes to another system. The risk is in the writes.
  • How much of it is bespoke. A standard framework with a familiar authentication library is understood in an hour. A hand-rolled session mechanism is where the days go, and it is also where the findings usually are.
  • Integrations. Every external system reached from the application is a boundary, and boundaries are where assumptions differ.
  • Whether credentials arrive on day one. This is the single most common cause of an overrun that neither side planned for.

How many distinct user roles are there, and can a tester have a working account for each of them before the engagement starts? A firm that cannot answer the second half is quoting for an unknown.

What a cheap quote usually leaves out

A low number is not automatically bad. It becomes bad when it is low because something is missing, and the things that go missing are consistent enough to check for.

  • The report. Writing a good one takes real time. A quote with no reporting days is quoting for the testing and delivering you a tool output.
  • The retest. Fixing what was found and proving it is fixed is the point of the exercise. Ask whether a retest is included, how long after the test it is valid for, and whether it covers everything or only the highs.
  • The debrief. An hour on a call explaining the findings to the people who have to fix them changes how much of the report gets actioned.
  • Authorisation depth. The quickest way to save two days is to test each role in isolation and never try to cross between them, which skips the class of finding that matters most in a multi-tenant application.

Fixed price against day rate

A fixed price moves the risk of an overrun onto the tester, which sounds attractive until you notice what it does to their incentives on day five of a four-day job. It works well where the scope is genuinely well understood and badly where it is not.

A day rate with a stated estimate and an agreement about what happens if the estimate is wrong is usually the more honest arrangement, and it forces the scoping conversation to be real rather than optimistic. Whichever you choose, get the estimate in days written down beside the money, because that is the number you will want when comparing next year.

Where the range actually sits

Published day rates in the UK market for application and infrastructure testing generally sit in the several-hundreds to low-thousands per tester per day, and most external application tests land somewhere between three and ten days once reporting is counted. A single small marketing site is at the bottom of that. A multi-tenant platform with an API, four roles and a payments integration is not, and a quote that puts it there is quoting for something narrower than what you asked for.

Treat any quote that arrives without questions with suspicion. A firm that can price your environment without asking about roles, integrations or environments has either done this exact system before or is guessing, and one of those is much more common than the other.

How to compare two quotes properly

  1. Put the day counts side by side, not the totals.
  2. Ask each firm what they would do with the extra days the other one is not proposing.
  3. Check whether reporting, retest and debrief are inside the number or outside it.
  4. Ask what happens if they find something critical on day two. A firm that says they would carry on to the end of the schedule before telling you has answered a different question from the one you asked.
  5. Ask who writes the report. On some engagements it is not the person who did the testing, and it shows.

A proposal carries the scope it was priced against, so the days quoted and the work delivered stay attached to the same record rather than drifting into three documents. When the scope moves, it moves on the proposal, and the invoice follows from that rather than from somebody remembering what was agreed on a call in March.


Pental Is Built by the People Writing This

Engagement management for testing firms, on a database you own, under your brand, with the AI running on your key.

Common questions

How much does a penetration test cost in the UK?

Most quotes decompose into a day rate and a number of days. Day rates for application and infrastructure testing generally sit in the several hundreds to low thousands per tester per day, and a typical external application test runs three to ten days once reporting is counted. A single small site sits at the bottom of that range. A multi-tenant platform with an API, several roles and a payments integration does not.

Why do quotes for the same system differ so much?

Because they are quoting different numbers of days, not different rates. Two firms at the same rate proposing six days and two days are proposing different pieces of work. Compare the day counts rather than the totals, and ask each what they would do with the days the other is not proposing.

What is usually missing from a cheap quote?

Reporting days, the retest, the debrief, and depth of authorisation testing. The quickest way to save two days is to test each user role in isolation and never attempt to cross between them, which skips the class of finding that matters most in a multi-tenant application.

Related reading

Business · 4 min read
How Long a Penetration Test Takes, and Why Estimates Vary So Much
From first call to final report, with the parts nobody counts. What drives the testing days, how long reporting really takes, and where the calendar time goes that is not testing at all.
Business · 4 min read
Penetration Testing for a SaaS Startup: When to Start and What to Buy
The first test is usually bought because a customer asked. Here is when it is genuinely worth doing sooner, what to spend on it, and what enterprise buyers will ask for next.
Business · 4 min read
Choosing a Penetration Testing Provider: The Questions That Separate Them
Certifications and logos tell you less than eight specific questions do. What to ask, what a good answer sounds like, and the two answers that should end the conversation.