The request usually comes from outside. Your cyber insurance renewal asks for the date of your last penetration test. A big customer's security questionnaire wants one before they'll sign. Or you've just cleaned up after an incident and want to know what else is open. So you ask for quotes — and get numbers from $500 to $30,000 for what sounds like the same service.
It is not the same service. "Pentest" is the most abused word in security sales, and the cheap version is usually not a penetration test at all. Here is what the real thing includes, what it costs, and how to avoid paying pentest money for a scan.
A penetration test is not a vulnerability scan
A vulnerability scan is software. It probes your systems, compares what it finds against a database of known flaws, and prints a report. It is automated, cheap and repeatable — running one quarterly is genuinely good hygiene, and some insurers expect exactly that.
A penetration test is a person. A tester tries to break in the way a real attacker would: chaining small weaknesses together, abusing misconfigurations, seeing whether your login page can be talked into things it shouldn't do. A scanner will tell you a server is running an old version of something. A tester will use that old version, plus a password someone reused, plus a shared folder nobody remembered, to end up reading your payroll — then show you the path so you can close it.
The industry blurs the two because scans cost almost nothing to run and "penetration test" is what buyers search for. The order-of-magnitude price gap between them is your first clue about which one a quote actually covers.
What a real engagement includes
- Scoping. A call to agree what gets tested — your public-facing systems, a web application, the internal network, sometimes your staff via a phishing exercise — what is off-limits, and when testing happens. It ends in a written rules-of-engagement document. No scoping conversation, no real pentest.
- The testing window. Days of human-led work, supported by tools but driven by judgment. As a benchmark, 2026 industry guides put a proper test of even a modest application at five to ten tester days.
- The report. This is the product you are actually buying: findings ranked by severity, evidence of how each was exploited, and a concrete fix for each — written so your IT person can act on it and you can understand it.
- A debrief. A walkthrough of the findings where you ask what is urgent and what can wait.
- A retest. After you fix the findings, the tester verifies the fixes worked. Confirm up front whether this is included or billed separately — it varies.
What it costs
The ranges below come from published 2026 pricing guides — treat them as the shape of the market, not a quote.
- A small, tightly scoped engagement — one web application, or a small external network — generally runs $5,000 to $15,000.
- Standard commercial engagements average $10,000 to $35,000. A web application test spans roughly $5,000 to $30,000 and an external network test $5,000 to $20,000, depending on size and depth.
- The driver is labour: skilled testers bill around $1,500 to $2,500 a day, and the work takes days, not hours.
- Compliance-specific reporting — PCI DSS, HIPAA, SOC 2 — pushes any of these upward, because the framework paperwork adds billable hours.
Which brings us to the most useful number here: as of 2026, a "web application penetration test" priced under about $3,000 is almost always an automated scan with a human's name on the cover. That is not a bargain. It is the cheap product at ten times the price.
When a small business actually needs one
- Your insurer asks. As of 2026, many cyber insurance carriers require an annual penetration test for policies above $1 million in coverage. Read the application literally — attesting to a pentest when you ran a scan is exactly the gap carriers use to deny claims.
- Compliance asks. PCI DSS if you take card payments, SOC 2 if you sell to bigger companies, HIPAA if you touch health data.
- A customer asks. Landing a large client increasingly means a security questionnaire with a pentest question on it.
- You just had an incident. Once you have worked through the first 24 hours of a ransomware attack and rebuilt, a test tells you whether the door is actually closed — and whether there are others.
- You are about to launch something. A new portal or app that will hold other people's data should be tested before it goes live, not after.
And the honest counterpoint: if you have not done the basics — two-factor everywhere, tested backups, patching, a properly configured firewall — a pentest will spend thousands of dollars telling you what you already know. Work through the small business cybersecurity checklist first, then pay a human to find what a checklist can't.
Red flags when you're buying
- The quote arrives instantly, with no scoping questions. Testers cannot price what they have not scoped.
- The price is a fraction of everyone else's. See above — you are buying a scan.
- The sample report is raw scanner output: fifty pages of vulnerability IDs, no narrative of what was exploited, no prioritised fixes.
- Nobody will say who does the testing or what their qualifications are. OSCP is the certification you will hear most; the willingness to answer matters more than the acronym.
- No retest is offered at any price.
- The deliverable includes a "certified secure" badge for your website. No serious firm certifies anything as secure.
What to do with the report
A surprising number of pentest reports get filed as proof of purchase and never opened again, which turns the whole exercise into an expensive receipt. The report is a work list. Most findings are ordinary IT tasks — patch this, disable that, retire the forgotten server, tighten a firewall rule. Your own IT person can work through them, or you can post the remediation list as a job and have a vetted technician close the findings one by one.
Then schedule the retest, and keep the report and the retest letter together — that pair is what your insurer or your customer's auditor actually wants to see. Put next year's test in the calendar while you remember.
If you'd rather have one team run the whole thing
Koadi delivers VAPT — vulnerability assessment and penetration testing — end to end: scoping, testing, and a report ranked by what to fix first, then support for the fixing itself. For the remediation work, the marketplace takes over: post the problem free, set a fixed price or take bids from vetted, identity-verified technicians, and the money sits in escrow until you approve the work. Remote help covers every US state; on-site visits come through local techs. Call (848) 266-6363 or write help@koaditech.com with what your insurer or customer is asking for, and we'll turn it into a scope.