€5k–25k
one-off web + API pentest, mid-market firm, 2026
+40–60 %
hidden on top of the invoice: retest fees, remediation hours, re-runs
€9,900/yr
the same coverage as a flat standing hunt, retested after every release
Ranges from public 2026 cost guides, mid-market boutique firms, converted to euros. Not the cheapest offshore quote, not the big four.
| Engagement | Typical scope | Market range | Testing |
|---|---|---|---|
| Web app | 1 app, roles + business logic | €4,000 – 15,000 | 3–5 days |
| API | REST/GraphQL, auth flows, BOLA | €8,000 – 25,000 | 4–8 days |
| Web + API + cloud | full SaaS stack, multi-tenant | €25,000 – 80,000 | 2–4 weeks |
| Internal network | VPN, AD, lateral movement | €15,000 – 40,000 | 5–10 days |
| Red team | adversary campaign, all vectors | €30,000 – 150,000+ | 4–12 weeks |
| Day rate | consultant, mid-market to big four | €1,500 – 7,000 | per day |
Market ranges aggregated from public 2026 cost guides (Lorikeet, Autonoma, StrikeHaven), converted to euros.
The quote covers a few days of testing. What happens after: fixing the findings, verifying the fixes, the audit the report feeds — that sits on your budget, not the vendor's.
30–50 %
a full retest cycle, billed again once your fixes are in
2–4 wks
of engineering time to remediate a typical 15–20 finding report
1 slip
a critical finding during an enterprise review costs the deal, not the invoice
€500–1,500 “pentest”: an automated scan in a report template, not manual testing.
Retest priced separately, so you pay again to verify your fix works.
No named tester: you scoped with one person, a pool runs the test.
Price only after three calls. Without a published number, the vendor prices the same scope off your budget, not the work.
Scope first: how many apps, endpoints and roles. Then complexity (payments, multi-tenant), methodology (manual testing vs scan-driven), reporting depth, and whether retesting is included. Two quotes for the same scope can differ threefold on those alone.
A one-off report serves a deadline: SOC 2, an enterprise questionnaire, the board. If you ship weekly, the one-off goes stale at the first release after signing; that is what the standing hunt is for, retested after every release.
It's an automated scan with a report template. Fine as a scan, useless as the evidence an auditor reads, and it misses the logic flaws a manual tester finds. The cost floor of real manual testing is simply higher.
Both expect an independent, qualified test on a regular cadence. The auditor reads the report: signed, scope in writing, CVSS-scored findings with a working PoC. That is the shape of the sample report.
Fix the scope in writing and compare on four lines: what is included (retest, report, critical alerting), the named tester, the timeline, and a redacted sample report. Price is the last line, not the first.