Assessment Pricing
Typical Engagement Pricing
These examples are provided as starting points for budgetary purposes. Every project is uniquely scoped to your specific environment, objectives, and requirements.
All scoping and testing is performed by senior consultants with 10+ years of experience, with a heavy focus on manual, hands-on testing.
Typical pricing examples
Common assessment scopes and starting points
Select a size below to see how pricing scales with complexity and environment size.
External Penetration Test
Testing of internet-facing systems to identify exploitable weaknesses before attackers do.
Limited external footprint or single IP range
Internal Penetration Test
Testing from inside the network to identify chains attackers could use after gaining initial access.
Up to 500 assets
Web Application Security Assessment
Manual testing of web applications, authentication, authorization, and business logic.
Up to 2 user roles, basic functionality
Active Directory Security Assessment
Assessment of Active Directory attack chains, misconfigurations, privilege exposure, AD CS risks, and identity security weaknesses from various perspectives.
Single domain, <500 users
Social Engineering Assessment
Phishing, vishing, smishing, or multi-vector campaigns designed to evaluate user awareness and defensive response.
Single whitelisted phishing campaign
Security Control & Readiness Assessment
Lightweight to comprehensive reviews of security controls, governance, and readiness against practical or formal frameworks.
Readiness Snapshot
Custom scope
Need Something Else Scoped?
We also perform assessments that vary widely based on objectives and environment complexity. These engagements are scoped individually to fit your unique needs.
Mobile Application Assessment
Deep-dive manual testing of iOS and Android applications and their backend APIs.
API Security Assessment
Comprehensive testing of REST, GraphQL, and other APIs for logic flaws and authorization bypasses.
Cloud Security Audit
Review of AWS, Azure, or GCP environments for misconfigurations and identity risks.
Cloud Penetration Test
Exploitation-focused assessment of cloud-native infrastructure and services.
Red Team Assessment
Objective-based simulation of real-world adversaries to test your detection and response.
Purple Team Exercise
Collaborative testing to tune SIEM/EDR alerts and improve defensive capabilities.
Custom Security Review
Tailored assessments for unique environments, physical security, or specialized hardware.
Pricing FAQ
Answers to common questions about penetration testing pricing, assessment scope, timelines, and deliverables.
How much does a penetration test cost?▾
How much does an Active Directory security assessment cost?▾
Why isn't pricing fixed?▾
What factors influence penetration testing pricing?▾
What is the minimum engagement size?▾
How long does a typical assessment take?▾
Do you offer nonprofit, education, or public sector pricing?▾
Do you offer fixed-price assessments?▾
How do I get an exact quote?▾
What if my assessment doesn't fit one of the examples shown?▾
What is included with an assessment?▾
Ready to define scope
Get pricing based on your environment
Share your objectives, environment details, and timing so we can provide a scoped proposal with clear assumptions and predictable pricing.