Skip to main content

Assessment Pricing

Typical Engagement Pricing

These examples are provided as starting points for budgetary purposes. Every project is uniquely scoped to your specific environment, objectives, and requirements.

All scoping and testing is performed by senior consultants with 10+ years of experience, with a heavy focus on manual, hands-on testing.

Typical pricing examples

Common assessment scopes and starting points

Select a size below to see how pricing scales with complexity and environment size.

External Penetration Test

Testing of internet-facing systems to identify exploitable weaknesses before attackers do.

Small
Starting at $4,200

Limited external footprint or single IP range

Internal Penetration Test

Testing from inside the network to identify chains attackers could use after gaining initial access.

Small
Starting at $6,000

Up to 500 assets

Web Application Security Assessment

Manual testing of web applications, authentication, authorization, and business logic.

Small
Starting at $5,200

Up to 2 user roles, basic functionality

Active Directory Security Assessment

Assessment of Active Directory attack chains, misconfigurations, privilege exposure, AD CS risks, and identity security weaknesses from various perspectives.

Small
Starting at $8,000

Single domain, <500 users

Social Engineering Assessment

Phishing, vishing, smishing, or multi-vector campaigns designed to evaluate user awareness and defensive response.

Small
Starting at $3,600

Single whitelisted phishing campaign

Security Control & Readiness Assessment

Lightweight to comprehensive reviews of security controls, governance, and readiness against practical or formal frameworks.

Small
Starting at $2,400

Readiness Snapshot

Custom scope

Need Something Else Scoped?

We also perform assessments that vary widely based on objectives and environment complexity. These engagements are scoped individually to fit your unique needs.

Mobile Application Assessment

Deep-dive manual testing of iOS and Android applications and their backend APIs.

API Security Assessment

Comprehensive testing of REST, GraphQL, and other APIs for logic flaws and authorization bypasses.

Cloud Security Audit

Review of AWS, Azure, or GCP environments for misconfigurations and identity risks.

Cloud Penetration Test

Exploitation-focused assessment of cloud-native infrastructure and services.

Red Team Assessment

Objective-based simulation of real-world adversaries to test your detection and response.

Purple Team Exercise

Collaborative testing to tune SIEM/EDR alerts and improve defensive capabilities.

Custom Security Review

Tailored assessments for unique environments, physical security, or specialized hardware.

Pricing FAQ

Answers to common questions about penetration testing pricing, assessment scope, timelines, and deliverables.

How much does a penetration test cost?
Penetration testing costs vary based on the size of the environment, testing objectives, complexity, and scope. Most Vilkas Cybersecurity penetration testing engagements start at $6,000, with larger assessments increasing based on the amount of testing required.
How much does an Active Directory security assessment cost?
Active Directory (AD) security assessments typically start around $8,000 for smaller single-domain environments and increase based on the number of domains, forests, users, and complexity of the environment being assessed. All AD security assessments are performed from an unauthenticated standpoint, standard user, and Domain Admin or additional role of your choosing.
Why isn't pricing fixed?
Every environment differs in complexity, size, testing objectives, and risk profile. The examples shown represent common engagement sizes, but final pricing is based on scope and requirements.
What factors influence penetration testing pricing?
Pricing is influenced by factors such as the size of the environment, number of assets, number of user roles, application complexity, testing objectives, cloud footprint, and overall engagement duration.
What is the minimum engagement size?
Most technical assessments have a minimum engagement size of three testing days, which typically starts at $6,000. Smaller advisory or readiness engagements may start lower.
How long does a typical assessment take?
Smaller assessments may require only a few testing days, while larger environments, applications, and enterprise networks may require multiple weeks of testing. Assessment duration is determined during the scoping process.
Do you offer nonprofit, education, or public sector pricing?
Yes. Reduced pricing may be available for qualifying nonprofit, educational, and public sector organizations.
Do you offer fixed-price assessments?
Most engagements are provided as fixed-price projects based on an agreed-upon scope. This gives clients predictable costs while ensuring the assessment receives the appropriate level of effort. We typically do not offer Time and Materials or Hourly pricing models.
How do I get an exact quote?
Complete our scoping questionnaire or schedule a consultation. Most assessments can be scoped and quoted quickly once we understand the environment and objectives. Our detailed scoping and in-house proposal building process allows us to return a comprehensive proposal in 24 hours, or same day if required.
What if my assessment doesn't fit one of the examples shown?
The pricing examples on this page represent common engagement types and sizes. We also perform mobile application security assessments, API security assessments, cloud security audits, cloud penetration tests, purple team exercises, red team assessments, and custom security reviews. We are happy to work with you to develop a tailored scope and quote based on your organization's unique requirements.
What is included with an assessment?
Every assessment includes hands-on manual testing performed by experienced security consultants, along with both executive and technical reporting. Our reports include identified findings, supporting evidence, risk explanations, an attack chain walkthrough where applicable, and actionable remediation guidance. All assessments include built-in post-remediation validation testing to confirm corrective actions have been implemented successfully. To maintain independence and objectivity, Vilkas Cybersecurity does not perform remediation services for findings identified during an assessment. Optional deliverables such as letters of attestation and executive readout presentations are also available upon request at no extra charge.

Ready to define scope

Get pricing based on your environment

Share your objectives, environment details, and timing so we can provide a scoped proposal with clear assumptions and predictable pricing.