Independent research. Not affiliated with Cobalt, HackerOne, Bishop Fox, NCC Group, Trail of Bits, Synack, Bugcrowd, IOActive, or any other vendor named on this site. No vendor publishes a list price; dollar figures are buyer-marketplace estimates. Last verified June 2026.
pentestingcost.com
Updated June 2026 • Independent vendor pricing reference • pentestingcost.com

How much does a pentest cost? $4,000 to $50,000 depending on scope. (June 2026)

Buyer-side vendor pricing intelligence, fixed-price package guidance, and a scope estimator that maps your application to a realistic band — before the sales call.

$5k
Floor
Cobalt credit pack / Astra entry
$50k
Typical
Mid-market SOW or PTaaS annual
$200k+
Enterprise
Red team / full-stack boutique

No vendor publishes list prices • Cobalt publishes its credit model; all 8 are contact-sales • Dollar figures are buyer-marketplace estimates • Updated June 2026

Quick scope estimator
Estimated price band
$7,000$24,000
48 days • Mid-market consultancy or Cobalt Standard
Full estimator with methodology →
$5kFloor (Cobalt entry)
$50kTypical engagement
$200k+Enterprise red team
UpdatedJune 2026

What you actually get at $5k, $10k, $20k, and $50k

Buyers ask this exact question and get scattered answers across vendor blogs. One page, four columns.

$5,000
Entry tier
  • Scope: 1 small web app, ~10 endpoints
  • Method: OWASP Top 10, light manual
  • Report: Summary report
  • Retest: Basic, 30-day window
  • Vendors: Cobalt credit pack / Astra
$10,000
Mid-market
  • Scope: 1 mid-size app or API set, ~30 endpoints
  • Method: Full OWASP + auth bypass
  • Report: Technical + exec report
  • Retest: Included, 60-day window
  • Vendors: Mid-market consultancy
$20,000
Standard
  • Scope: Web + API + light cloud, 50-100 endpoints
  • Method: Business-logic depth, attack chains
  • Report: Full report + walkthrough
  • Retest: Included, 90-day window
  • Vendors: BSG / Bright Defense / Cobalt PTaaS
$50,000
Enterprise
  • Scope: Multi-app / cloud / mobile, 100+ endpoints
  • Method: Chained exploits, custom methodology
  • Report: Executive brief + full technical + walkthrough
  • Retest: Multiple retests, extended window
  • Vendors: Bishop Fox / NCC / Trail of Bits

Day-Rate Reference (2026)

Day-rate data sourced from BSG, Deepstrike, and Astra. PTaaS blended rate estimated from buyer-marketplace Cobalt credit data (Vendr, G2), not vendor-published prices.

CategoryHourly rateDay rateSource
Independent contractor$150-$250$1,200-$2,000Astra, Software Secured
Mid-market consultancy$200-$350$1,500-$3,500BSG, Deepstrike
Senior boutique / Big-4$350-$500$4,000-$7,000BSG, Bright Defense
PTaaS blended (Cobalt)$200-$280~$1,800/credit (est.)Vendr, G2
Day-rate vs project-fee crossover analysis →

PTaaS vs Traditional: 4-Question Filter

Answer the first question that matches your situation.

Annual compliance one-off?

Traditional SOW. One engagement, retest included, sign off.

Look at: Bishop Fox, NCC Group, BSG
Continuous code shipping?

PTaaS. Credits consumed as you ship, always current coverage.

Look at: Cobalt, Synack, HackerOne
Compliance trigger (SOC 2/PCI/ISO)?

Traditional with retest. Need a clean report with methodology attestation.

Look at: Bishop Fox, NCC, Trail of Bits
Have a bug bounty already?

PTaaS hybrid. Cobalt, Synack, or Bugcrowd extends your existing program.

Look at: Bugcrowd, Synack, HackerOne
Full cost-shape comparison: PTaaS vs traditional →

Why are you getting a pentest?

The answer determines which site helps you most and which vendor profile fits.

Customer security questionnaire

You need a pentest report to send to a customer or enterprise prospect. Start with the engagement tiers page to match your budget to what they'll accept.

See engagement tiers
SOC 2 / PCI / ISO 27001 compliance

You need a pentest that satisfies a compliance framework. The methodology and frequency requirements are covered on our sister site.

Visit penetrationtestingcost.com
Continuous security maturity

You're shipping continuously and want ongoing coverage. PTaaS is almost certainly the right model over traditional SOW engagements.

PTaaS vs traditional

Common Questions

How much does a pentest cost in 2026?

A pentest costs between $4,000 and $50,000 for most web application and API engagements. No major vendor publishes a list price; all are contact-sales. Buyer-marketplace estimates put Cobalt PTaaS around $2,500/month plus credits, HackerOne assessments at $15,000-$50,000 annually, and Bishop Fox boutique engagements from about $25,000. Enterprise red-team engagements (Trail of Bits, IOActive) reach $100,000-$200,000+.

Can I negotiate pentest pricing?

Yes. Multi-year commits unlock 20-30% off list pricing. Volume credit packs unlock 15-25%. Competing quotes from Cobalt, HackerOne, and Synack unlock 10-20%. Vendr and Spendflo buyer guides confirm these ranges as standard negotiation outcomes for PTaaS vendors.

What is the difference between a pentest and a vulnerability scan?

A scan is automated and finds known CVEs. A pentest is manual and finds business-logic flaws, authentication bypasses, and chained exploits. Anything labelled 'pentest' under $3,000 is almost certainly the former. Real pentests involve human testers who reason about your specific architecture.

How often should you do a pentest?

Annually at minimum for compliance (PCI 11.3, SOC 2, ISO 27001). After major releases or significant infrastructure changes. Continuously if you're a high-threat-profile company (fintech, healthtech, defence). For compliance-specific frequency guidance, see penetrationtestingcost.com.