Comparing pentest quotes: what to look for

You request three quotes for a pentest of the same application and get back €2,500, €6,000 and €14,000. All three are called "penetration test". The difference almost never lies in the name, but in three things that are not always clearly stated on a quote: how much gets tested, by whom, and what happens after the test. Below you can read how to make quotes comparable, and how to spot the quote that looks cheap but isn't.

The short answer

Don't compare the totals. Compare the number of testing days, who does the testing, how much manual work is involved, how precisely the scope is described and whether the retest is included. If one of those points is missing from the quote, ask about it. A quote that can't answer those questions can't be compared fairly.

Where the price difference comes from

A pentest is specialist work, and that work is expressed in time. Whether the quote is a fixed price or hourly, the price ultimately comes down to the number of testing days times a day rate. Three things explain most of the difference.

  • The number of testing days. A thorough test of an application with multiple roles typically takes four to five testing days. A €2,500 quote for the same application therefore assumes fewer days, or less manual work.
  • How much manual work is involved. An automated scan runs in an hour. A quote in which most of the "test" is done by a scanner can be cheap and still too expensive.
  • Overhead. At a large firm you help pay for account managers, offices and planning. That is not necessarily bad, because you get capacity in return. But it explains why the same testing day carries a different price tag at different providers.

The practical lesson: convert every quote into testing days. If the number isn't on it, ask. It is the figure that tells you most about what you are buying.

Ten questions to ask with every quote

Put these questions to every provider, and compare the answers instead of the totals.

QuestionWhy it matters
1. How many testing days are included?The number behind the price. Without it, you are comparing amounts, not work.
2. Which part is manual work and which part is scanner?A scanner finds known vulnerabilities. Logic flaws, authorisation problems and IDORs are only found by a human.
3. Who does the testing?Ask for a name and certifications, such as OSCP, OSWE or eWPTX. Is it the same person as in the intake, or does the work go to a junior?
4. What exactly is in scope?"Web application" is not a scope. Which URLs, APIs, roles and environments are tested, and which aren't?
5. Is the testing authenticated, and with which roles?Most of the risk sits behind the login. A test that only looks from the outside misses most of the application.
6. Is the retest included?Without a retest you have no proof that the problems are actually fixed. Some providers quote it separately.
7. Fixed price or time and materials?With time and materials you only know the cost afterwards. In that case, ask for a cap.
8. What does the report look like?Ask for a sample report. Does it include reproduction steps, concrete fixes, and a summary your board or customer can read?
9. When does the test start, and when is the report delivered?Important if an audit or customer is waiting. A low price with a three-month wait won't help you then.
10. How does the provider handle your data?NDA, where test data and findings are stored, and when they are deleted.

Question 3 is often skipped, even though it says a lot. The quality of a pentest depends largely on the person who carries it out. A firm with a strong name can send an experienced tester, or someone who has just started. You are entitled to know in advance who it will be.

Already have a quote and unsure whether it is reasonable? Bring it to a free intake. You get an honest answer, even if that answer is that the quote you have is fine.

Book a free intake →

Red flags in a pentest quote

Some quotes deserve an extra question before you sign.

  • No number of testing days and no name. You don't know how much work you are buying, or from whom.
  • "Automated pentest" or "pentest within 24 hours". That is a scan. Useful, but not a pentest, and it shouldn't be priced as one either.
  • A price per IP address or per endpoint, without questions about the application. The work in a pentest lies in the logic, the roles and the integrations, not in the number of endpoints. A provider that doesn't ask how your application works can't know how much time is needed.
  • No sample report. Providers who are proud of their reports are happy to show one, anonymised.
  • Guarantees such as "100% secure". A pentest shows what could be found within scope at the time of testing. Anyone who promises more is exaggerating.
  • A scope that only gets filled in during the test. Then you don't know in advance what you are getting, and afterwards you don't know what wasn't tested.

How to make quotes comparable

Three steps, and the comparison becomes a lot fairer.

Step 1: send every provider the same starting points. A short description is enough: which application, which environments, which user roles, how many customer environments for multi-tenant software, and what the reason is. Different starting points produce quotes you can't compare.

Step 2: put the answers side by side. Use the ten questions above and fill in for each provider:

Provider AProvider BProvider C
Testing days
Tester (name, certification)
Manual work or scanner
Authenticated, with which roles
Retest included
Sample report seen
Start and delivery
Price (excl. VAT)
Price per testing day

Step 3: look at the bottom line. If one provider's price per testing day is much lower, there is less manual work or less experience in it somewhere. If it is much higher, ask what you get extra for it. Sometimes that is worth it, sometimes you are paying for a logo.

Cheaper doesn't have to mean worse

A lower price is fine, as long as it is honest about what you get. Two days of testing on the highest-risk parts, such as login, authorisation between users and the most sensitive features, is money better spent than five days of scanner output. The problem is not a short test, but a short test that passes itself off as a thorough one. You can read more about how testing time and price relate in what a penetration test costs.

Large firm or independent tester?

Both have their place, and the choice depends on what you need.

  • A large firm is a good fit for large scopes that need to be finished quickly and require several testers at once, and for specialist work such as red teaming. You get capacity and often a broad range of services.
  • An independent tester is a good fit if you want to know who does the testing, want direct contact without an intermediary and want to be able to start quickly. You pay no overhead, and the person who does the intake also writes the report.

Whichever you choose, the ten questions above apply to both.

Conclusion

Pentest quotes seem hard to compare because they often describe different things under the same name. Make them comparable by asking about testing days, the tester, the manual work, the scope, the retest and the report, and convert everything into a price per testing day. You will quickly see which quote describes a thorough test, which an honest short test, and which a scan with a nice cover page. In doubt? A second opinion costs nothing.

Frequently asked questions

What does a pentest cost on average?

That depends on the scope. A thorough pentest of an application with multiple roles typically takes four to five testing days, around €5,000 to €6,000. Smaller scopes are shorter and cheaper. You will find a full explanation in what does a penetration test cost.

Is a cheap pentest always a bad pentest?

No. A shorter test that honestly focuses on the highest-risk parts can be perfectly fine. It only becomes a problem when a short test or a scan is presented as a thorough pentest.

Why does a pentester want an intake before sending a quote?

Because the time needed depends on how the application works: the roles, the logic, the integrations and the environment. Without that conversation a price is a guess, and a guess usually comes at the expense of coverage or of your budget.

How many testing days does my application need?

As a guideline: a simple application or API with limited roles about two to three testing days, a SaaS product or portal with multiple roles four to five, and a complex platform with several applications or a multi-tenant architecture six or more. The exact estimate follows after an intake.

Know what you are buying up front.

With Resync you know in advance who tests, what is in scope and what it costs. Always the same OSCP-certified tester, a fixed price and the retest included.

Book free intake →