
If you are budgeting for a pen test, the first thing to know is that penetration testing cost is set almost entirely by scope. Two quotes for “a penetration test” can differ widely because one covers a single website for two days and the other covers your external network, internal network, three web applications and a cloud account. Until the scope is written down, the numbers are not comparable.
This guide explains what drives the price, how to scope a test, what the rules of engagement should say, what a good report contains and how often frameworks expect you to test. Our penetration testing service page explains how Honeybadger runs engagements. This article is general information, not legal advice; confirm framework requirements with your assessor or counsel.
Key takeaways
- Penetration testing cost tracks tester hours, and hours track scope: targets, applications, user roles, test type, testing window and retesting.
- Gray box testing usually gives the most findings per dollar; PCI SSC guidance says black box may need more time, money and resources.
- Nothing should be touched without a signed authorization and written rules of engagement.
- A real report has scope, methodology, limitations, an attack narrative and reproducible findings. Scanner output is not a pen test report.
- PCI DSS 11.4 and CMMC Level 3 call for testing at least every 12 months and after significant change.
Where this guidance comes from. We used NIST SP 800-115, the Penetration Testing Execution Standard (PTES), the OWASP Web Security Testing Guide v4.2, the PCI SSC Penetration Testing Guidance (v1.1, September 2017), PCI DSS Requirement 11, the FTC Safeguards Rule, the HIPAA Security Rule and its 2025 proposed update, and the CMMC rule in 32 CFR Part 170, along with our team’s field experience scoping security testing as a veteran-led firm.
What you are actually paying for
A penetration test is a person trying to reach an objective in your environment, such as a file server or another customer’s records, by chaining small weaknesses into a real path. NIST SP 800-115 describes four phases: planning, discovery, attack and reporting. Every phase consumes hours, and hours are the cost.
The PCI SSC guidance notes that scans take seconds to minutes per host, while penetration tests “may last days or weeks depending on the scope.” If you are still deciding which you need, read our comparison of penetration testing vs vulnerability scanning first.
What drives penetration testing cost
We do not quote price ranges here because we found no primary source that reports them reliably, and a range without your scope attached misleads. Use this table to see why quotes differ and where to trim without losing value.
| Cost driver | Why it changes the effort | How to scope it sensibly |
|---|---|---|
| Test type | External, internal, web app, API, cloud, wireless, social engineering and physical are separate disciplines | Start with the types tied to your biggest risk or compliance driver |
| Live external IPs and internal subnets | More reachable hosts means more services to probe | Count live hosts, not the size of the address block |
| Web applications and APIs | Each has its own logic, authentication and data flows | Prioritize apps handling payments, health data or customer accounts |
| User roles | Authorization flaws only appear when testing as each role | Name the roles that matter and provide test accounts |
| Knowledge level (black, gray, white box) | Black box spends paid hours rediscovering what you already know | Share diagrams and credentials unless stealth is the goal |
| Testing window and covert testing | Off-hours windows, fragile systems and stealth all slow the work | Allow business hours for low-risk targets; use covert testing only to measure detection |
| Retesting | Verifying fixes takes time after remediation | Confirm in writing whether a retest is included |
| Report depth | Executive summaries and attack narratives take time to write | Say who reads it: board, auditor, engineers |
Test types in brief
An external test covers what is reachable from the internet. An internal test assumes an attacker already has a foothold, such as a phished laptop, and measures how far it goes. Web application and API tests follow the OWASP Web Security Testing Guide, whose v4.2 categories include authentication, authorization, session management, business logic and API testing. Cloud testing focuses on identity policy, storage exposure and network boundaries, and wireless testing checks authentication and segmentation.
Social engineering measures how staff respond to phishing or pretext calls; see how social engineering bypasses your firewall. Physical testing checks whether someone can walk in, and pairs naturally with a physical security assessment.
Size, roles, window and retesting
Count the right things. A block with 12 live hosts is far less work than one with 200. A portal with customers, staff and administrators is more work than one login type, because the most damaging flaws are usually authorization flaws that show up only when you log in as the wrong user.
PTES tells testers to pad time estimates by 20 percent and warns that scope creep is a common way testing firms lose money, so vague scopes get padded quotes. Off-hours-only windows add calendar days. And if no retest is included, you pay again to prove the fixes work, even though PCI DSS Requirement 11.4.4 expects testing to be repeated to verify corrections.
Black box, gray box or white box?
The PCI SSC guidance defines the three by what the tester knows: nothing (black box), partial details (gray box) or full details (white box). It says PCI tests are typically white or gray box because they “yield more accurate results,” and that pure black box “may require more time, money, and resources.” That is the clearest lever you have on penetration testing cost.
NIST SP 800-115 adds overt testing, where IT staff know, versus covert testing, where only upper management knows. NIST says overt testing “is less expensive, carries less risk than covert testing, and is more frequently used.” Choose covert when the question is whether monitoring would catch an attack; choose gray box, overt testing when the question is where you are weakest.
Not sure how to scope your first test? Send us your asset counts, applications and compliance driver and we will turn them into a written scope you can compare against any vendor. Request a penetration test scope online, or book a consultation online to talk it through first.
Rules of engagement and the authorization letter
Nothing should be touched until there is a signed authorization from someone entitled to approve testing and written rules of engagement. Federal law, 18 U.S.C. 1030, makes it a crime to access a computer “without authorization or exceeds authorized access” and obtain information. The letter separates a test from an intrusion.
PTES calls signed permission to test “critical” and notes that cloud providers, ISPs and managed security providers may need separate approval. For example, AWS lets customers test listed services without prior approval but prohibits denial-of-service and flooding. NIST SP 800-115 recommends involving legal advisors for intrusive tests. Drawing on NIST’s template and PCI SSC guidance, the rules of engagement should cover:
- Scope by address and application, plus an explicit out-of-scope list.
- Dates, hours, blackout periods and handling of fragile systems.
- Named contacts reachable in real time and an escalation path.
- Success criteria and stop conditions.
- Data handling: proof-of-concept only, and how any sensitive data seen is protected and destroyed.
- What happens if a real compromise is found. PCI SSC gives the example of stopping and activating incident response.
- Cleanup of test accounts and tools at the end.
That compromise clause matters. If a tester finds signs of a real intruder, the work should shift to cyber incident response so evidence is preserved.
What a good penetration test report contains
The PCI SSC guidance is blunt: “Merely reporting lists of vulnerabilities is not helpful.” Its suggested outline works for any test:
- Executive summary of scope and major findings.
- Scope, methodology and limitations, including what was not tested and why.
- Testing narrative showing the path an attacker could take.
- Segmentation results where segmentation reduces scope.
- Findings with affected targets, how each was exploited, a severity rating with traceable reasoning, references such as CVE or CWE, and a specific fix.
Ask every vendor for a redacted sample report before you sign. If it is mostly scanner output with a logo on the cover, the engagement will be too.
How often to test: compliance drivers
Most organizations test because a framework, customer or insurer asks. This reflects the text we reviewed as of October 2026; confirm with your assessor.
| Framework | What it says | Notes |
|---|---|---|
| PCI DSS v4.x, Req. 11.4 | Internal and external tests at least every 12 months and after significant change; fixes verified by repeat testing | Segmentation testing every 12 months, or six months for service providers |
| FTC Safeguards Rule, 16 CFR 314.4(d)(2) | Continuous monitoring, or annual penetration testing plus vulnerability assessments every six months | Not applicable under 5,000 consumers (314.6) |
| HIPAA, 45 CFR 164.308 | Thorough risk analysis and periodic technical evaluation; no explicit pen test | January 2025 proposed rule would add a 12-month test; still proposed as of late September 2026 |
| CMMC Level 2 (NIST SP 800-171 R2) | Periodic vulnerability scanning (3.11.2); no explicit pen test | Many contractors test anyway before assessment |
| CMMC Level 3 (32 CFR 170.14) | Penetration testing at least annually or after significant security changes (3.12.1e) | Applies to contracts requiring Level 3 |
| SOC 2 | No fixed frequency in text we could review | Ask your CPA firm what evidence they expect |
For healthcare, a penetration test is a practical way to support the “accurate and thorough” risk analysis HIPAA already requires. Our governance, risk and compliance service maps one control set to several frameworks so one test can serve more than one audit. Outside compliance, NIST SP 800-115 suggests annual testing may be sufficient when paired with regular scanning in between.
Red flags: when a cheap pen test is really a scan
A small, well-defined scope should cost less. The problem is a low penetration testing cost for a large scope, which usually means an automated scan with a new label. Watch for:
- A fixed price before anyone asks about your assets, applications or roles.
- No rules of engagement, authorization letter or emergency contact.
- One or two days for internal networks plus multiple applications.
- No authenticated testing across user roles.
- A sample report sorted by scanner severity with no narrative or reproduction steps.
- No named methodology, and no retest beyond another scan.
PCI SSC guidance also notes that qualifications “cannot be met by certifications alone,” so ask about experience with environments like yours. Buying a scan when you need a test produces a clean-looking report that falsely reassures leadership, auditors and insurers.
How to get an accurate penetration testing cost quote
- Name the driver: PCI, a customer, an insurer or your own risk concerns.
- List live external IPs and domains, internal subnets, cloud accounts and wireless networks.
- List applications and APIs with their user roles, and arrange test accounts.
- Choose the knowledge level and whether the test is announced.
- Set the testing window and flag fragile systems.
- Confirm who signs the authorization and which providers need notice.
- Ask each vendor for a written scope, methodology, sample report and retest terms.
Want a quick read on your biggest gaps first? Our free cyber risk check reviews email security, identity, devices and backups and returns three priority fixes.
How Honeybadger scopes and prices penetration testing
Honeybadger Solutions is a veteran-owned SDVOSB delivering cyber services remotely, nationwide. Every test is scoped in writing first: objective, systems in scope, rules of engagement, windows, data handling, escalation contact and stop condition. Authorization comes from someone entitled to give it, and hosting approval is checked rather than assumed.
We follow PTES and NIST SP 800-115 for process, OWASP for applications and MITRE ATT&CK for describing what was done. Findings include reproduction steps, realistic impact and a specific fix, with an executive summary and an attack narrative. Retesting is included. If we find evidence of a real intrusion, we stop, notify your contact and shift to incident response and forensics.
Penetration testing cost is quoted per engagement from environment size, application count and complexity, whether social engineering or physical testing is included, and whether the test is announced. Red team work, remediation engineering and ongoing scanning are quoted separately, and testing fits within our managed cyber security (MSSP) service for year-round coverage.
Ready to scope a test? Send your asset counts, applications and compliance driver through our online service request form, or book a consultation online to discuss scope first.
Why the online intake is faster than a phone call: it takes about two minutes, and your answers are routed straight to the specialist team that handles your kind of matter, whether that is cyber and forensics, investigations or field security. That team sees the full picture before it replies, so you skip phone tag and get a real answer and next steps sooner. If it cannot wait for business hours, use the urgent intake form, which is read seven days a week.
Frequently asked questions
How much does a penetration test cost?
There is no honest single number. Penetration testing cost follows tester time, and tester time follows scope: targets, applications, user roles, test type, knowledge level, testing window and retesting. A flat price quoted before anyone asks about your scope is usually pricing an automated scan.
Is a vulnerability scan enough for compliance?
Usually not where a framework names penetration testing. PCI DSS treats quarterly scans (Requirement 11.3) and annual penetration tests (Requirement 11.4) as separate requirements, and the FTC Safeguards Rule lists them as separate activities too.
How often should we run a penetration test?
A common baseline is at least once every 12 months and after any significant change, the cadence in PCI DSS Requirements 11.4.2 and 11.4.3 and CMMC Level 3 requirement 3.12.1e. Test sooner after a migration, a merger or a new internet-facing application.
Does HIPAA require penetration testing?
As of October 2026, the HIPAA Security Rule in the eCFR requires a thorough risk analysis and periodic technical evaluation but does not use the word penetration. A January 6, 2025 proposed rule would require testing at least every 12 months. Confirm current status with counsel.
Should we choose black box or gray box testing?
For most budgets, gray box. PCI SSC guidance says PCI tests are typically white or gray box because they give more accurate results, and that pure black box testing may require more time, money and resources.
What should be in the authorization letter?
The organization, the testing firm, the systems and addresses in scope, the dates and hours of testing, and a signature from someone with authority over those systems. Keep it with the rules of engagement, and get approval from any hosting provider whose terms require it.
Sources and further reading
- NIST SP 800-115 (2008) — Testing phases, overt vs covert testing and the rules of engagement template.
- PTES: Pre-engagement — Scoping, time padding and permission to test.
- OWASP Web Security Testing Guide — V4.2 web application and API methodology.
- PCI SSC Penetration Testing Guidance v1.1 (2017) — Box types, rules of engagement, retesting and report outline.
- Microsoft Learn: PCI DSS Requirement 11 — Reproduces PCI DSS v4 Requirement 11.3 and 11.4 text.
- eCFR: 16 CFR 314.4 (FTC Safeguards Rule) — Annual penetration testing and six-month assessments.
- eCFR: 16 CFR 314.6 — Small-institution exception.
- eCFR: 45 CFR 164.308 (HIPAA) — Current risk analysis and evaluation requirements.
- Federal Register: HIPAA Security Rule proposed rule (2025) — Proposed 12-month penetration testing.
- eCFR: 32 CFR 170.14 (CMMC) — Level 2 and Level 3 requirements, including 3.12.1e.
- NIST SP 800-171 Rev. 2 — Requirement 3.11.2 on vulnerability scanning.
- AWS penetration testing policy — Cloud provider testing rules.
- 18 U.S.C. 1030 (Cornell LII) — Why written authorization is required.
Written and reviewed by the Honeybadger Solutions security and investigations team, a veteran-led Arizona firm (Arizona DPS private investigation agency license No. 1759795). Facts checked against the cited sources on October 2, 2026. This article is general information, not legal advice.
Browse by topic
Security guard services · Private investigations · Cybersecurity · Digital forensics · Financial fraud investigation · Executive protection · All articles