pentest cost · 2026

What a pentest actually costs.

A one-off web + API pentest for a startup runs €5,000–25,000 at a mid-market firm, and with retesting plus remediation the real number lands 40–60 % above the invoice. Below: the market ranges by type, and what the same coverage costs flat.

€5k–25k

one-off web + API pentest, mid-market firm, 2026

+40–60 %

hidden on top of the invoice: retest fees, remediation hours, re-runs

€9,900/yr

the same coverage as a flat standing hunt, retested after every release

What the market charges, by type

Ranges from public 2026 cost guides, mid-market boutique firms, converted to euros. Not the cheapest offshore quote, not the big four.

EngagementTypical scopeMarket rangeTesting
Web app1 app, roles + business logic€4,000 – 15,0003–5 days
APIREST/GraphQL, auth flows, BOLA€8,000 – 25,0004–8 days
Web + API + cloudfull SaaS stack, multi-tenant€25,000 – 80,0002–4 weeks
Internal networkVPN, AD, lateral movement€15,000 – 40,0005–10 days
Red teamadversary campaign, all vectors€30,000 – 150,000+4–12 weeks
Day rateconsultant, mid-market to big four€1,500 – 7,000per day

Market ranges aggregated from public 2026 cost guides (Lorikeet, Autonoma, StrikeHaven), converted to euros.

The invoice is not the cost

The quote covers a few days of testing. What happens after: fixing the findings, verifying the fixes, the audit the report feeds — that sits on your budget, not the vendor's.

30–50 %

a full retest cycle, billed again once your fixes are in

2–4 wks

of engineering time to remediate a typical 15–20 finding report

1 slip

a critical finding during an enterprise review costs the deal, not the invoice

Four red flags in a quote

01

€500–1,500 “pentest”: an automated scan in a report template, not manual testing.

02

Retest priced separately, so you pay again to verify your fix works.

03

No named tester: you scoped with one person, a pool runs the test.

04

Price only after three calls. Without a published number, the vendor prices the same scope off your budget, not the work.

the same coverage, flatMarket invoice vs standing hunt
one-off · marketstanding · rheono
One-off web + API€5,000–25,000 for a few days of coveragedeep audit from €3,500, one retest included
A year of coverage2–3 engagements, all-in €40,000–75,000€9,900 flat, every release, no high no pay

Cost questions, answered

What moves a pentest price?+

Scope first: how many apps, endpoints and roles. Then complexity (payments, multi-tenant), methodology (manual testing vs scan-driven), reporting depth, and whether retesting is included. Two quotes for the same scope can differ threefold on those alone.

One-off or standing — which do I need?+

A one-off report serves a deadline: SOC 2, an enterprise questionnaire, the board. If you ship weekly, the one-off goes stale at the first release after signing; that is what the standing hunt is for, retested after every release.

Is a €500 pentest a scam?+

It's an automated scan with a report template. Fine as a scan, useless as the evidence an auditor reads, and it misses the logic flaws a manual tester finds. The cost floor of real manual testing is simply higher.

Do I need a pentest for NIS2 or SOC 2?+

Both expect an independent, qualified test on a regular cadence. The auditor reads the report: signed, scope in writing, CVSS-scored findings with a working PoC. That is the shape of the sample report.

How do I compare two proposals?+

Fix the scope in writing and compare on four lines: what is included (retest, report, critical alerting), the named tester, the timeline, and a redacted sample report. Price is the last line, not the first.

free check

Price your own surface first.

20 minutes, read-only, a short written report. No call in between.