How Much Does a Penetration Test Cost in 2026?
Short answer: web application tests generally start around $500, network and Active Directory assessments around $1,500 — but the honest answer is "it depends on scope," and here's exactly what scope means in practice.
Why there's no single number
Anyone who quotes you a fixed price without asking what you're testing is either guessing or padding the number to cover the risk of not knowing. A penetration test's cost is driven almost entirely by how much has to be manually tested, and that varies enormously even within one category — a 3-endpoint internal tool and a 40-endpoint multi-role SaaS platform are both "a web app," but they're not the same job.
What actually drives the price
For web applications
- Number of user roles — each role needs its own authorization testing pass
- Endpoint / page count — more surface area, more manual testing hours
- API presence — a REST or GraphQL API adds a distinct testing surface
- Business logic complexity — multi-step checkout flows, payment logic, and file handling all add depth
Starting price: from $500 for a focused single-role application, scaling from there.
For network and Active Directory
- Host count — more systems, more enumeration and validation time
- Domain complexity — number of domains, forests, and trust relationships
- Segmentation testing — validating network isolation adds scope
Starting price: from $1,500 for a single-domain environment, scaling with size and trust complexity.
Compliance-driven tests (SOC 2, PCI DSS)
These generally follow the same underlying pricing as a standard web or network test — the compliance framework changes how the report is formatted for your auditor or QSA, not the base cost structure. A SOC 2 or PCI DSS pentest scoped like a standard application test costs about the same as one; what changes is report format and evidence mapping.
What a cheap quote usually means
If a quote is dramatically below these ranges, it's worth asking exactly what's included. Common ways prices get pushed artificially low: automated-scan-only "testing" with no manual verification, a fixed number of hours regardless of actual scope (so testing stops when the clock runs out, not when the work is done), or a report that's a re-branded scanner output. None of those catch the business-logic and chained-attack-path findings that manual testing is actually for.
How pricing works here
Every engagement starts with a free 30-minute scoping call, then a written proposal with a fixed price and exact timeline within 24 hours — no hourly billing, no surprise add-ons once testing starts. See the full pricing breakdown or jump straight to a specific service to see what's included.
Want an exact number for your environment?
Free scoping call, fixed-price proposal within 24 hours.