Independent research. Not affiliated with Cobalt, HackerOne, Bishop Fox, NCC Group, Trail of Bits, Synack, Bugcrowd, IOActive, or any other vendor named on this site. Prices change. Last verified April 2026.
pentestingcost.com
Updated April 2026 • Independent vendor pricing reference • pentestingcost.com

How much does a pentest cost? $4,000 to $50,000 depending on scope. (April 2026)

Public vendor pricing, fixed-price packages, and a scope estimator that maps your application to a realistic band — without a sales call.

$5k
Floor
Cobalt credit pack / Astra entry
$50k
Typical
Mid-market SOW or PTaaS annual
$200k+
Enterprise
Red team / full-stack boutique

2 vendors with public pricing (Cobalt, HackerOne) • $5k floor: Cobalt entry • $50k ceiling: HackerOne annual packs • Updated April 2026

Quick scope estimator
Estimated price band
$7,000$24,000
48 days • Mid-market consultancy or Cobalt Standard
Full estimator with methodology →
$5kFloor (Cobalt entry)
$50kTypical engagement
$200k+Enterprise red team
UpdatedApril 2026

What you actually get at $5k, $10k, $20k, and $50k

Buyers ask this exact question and get scattered answers across vendor blogs. One page, four columns.

$5,000
Entry tier
  • Scope: 1 small web app, ~10 endpoints
  • Method: OWASP Top 10, light manual
  • Report: Summary report
  • Retest: Basic, 30-day window
  • Vendors: Cobalt credit pack / Astra
$10,000
Mid-market
  • Scope: 1 mid-size app or API set, ~30 endpoints
  • Method: Full OWASP + auth bypass
  • Report: Technical + exec report
  • Retest: Included, 60-day window
  • Vendors: Mid-market consultancy
$20,000
Standard
  • Scope: Web + API + light cloud, 50-100 endpoints
  • Method: Business-logic depth, attack chains
  • Report: Full report + walkthrough
  • Retest: Included, 90-day window
  • Vendors: BSG / Bright Defense / Cobalt PTaaS
$50,000
Enterprise
  • Scope: Multi-app / cloud / mobile, 100+ endpoints
  • Method: Chained exploits, custom methodology
  • Report: Executive brief + full technical + walkthrough
  • Retest: Multiple retests, extended window
  • Vendors: Bishop Fox / NCC / Trail of Bits

Day-Rate Reference (2026)

Day-rate data sourced from BSG, Deepstrike, and Astra. PTaaS blended rate calculated from Cobalt credit pricing.

CategoryHourly rateDay rateSource
Independent contractor$150-$250$1,200-$2,000Astra, Software Secured
Mid-market consultancy$200-$350$1,500-$3,500BSG, Deepstrike
Senior boutique / Big-4$350-$500$4,000-$7,000BSG, Bright Defense
PTaaS blended (Cobalt)$200-$280~$1,800/creditCobalt.io, Vendr
Day-rate vs project-fee crossover analysis →

PTaaS vs Traditional: 4-Question Filter

Answer the first question that matches your situation.

Annual compliance one-off?

Traditional SOW. One engagement, retest included, sign off.

Look at: Bishop Fox, NCC Group, BSG
Continuous code shipping?

PTaaS. Credits consumed as you ship, always current coverage.

Look at: Cobalt, Synack, HackerOne
Compliance trigger (SOC 2/PCI/ISO)?

Traditional with retest. Need a clean report with methodology attestation.

Look at: Bishop Fox, NCC, Trail of Bits
Have a bug bounty already?

PTaaS hybrid. Cobalt, Synack, or Bugcrowd extends your existing program.

Look at: Bugcrowd, Synack, HackerOne
Full cost-shape comparison: PTaaS vs traditional →

Why are you getting a pentest?

The answer determines which site helps you most and which vendor profile fits.

Customer security questionnaire

You need a pentest report to send to a customer or enterprise prospect. Start with the engagement tiers page to match your budget to what they'll accept.

See engagement tiers
SOC 2 / PCI / ISO 27001 compliance

You need a pentest that satisfies a compliance framework. The methodology and frequency requirements are covered on our sister site.

Visit penetrationtestingcost.com
Continuous security maturity

You're shipping continuously and want ongoing coverage. PTaaS is almost certainly the right model over traditional SOW engagements.

PTaaS vs traditional

Common Questions

How much does a pentest cost in 2026?

A pentest costs between $4,000 and $50,000 for most web application and API engagements. Cobalt PTaaS starts at approximately $2,500/month. HackerOne assessment products run $15,000-$50,000 annually. Bishop Fox boutique engagements start at $25,000. Enterprise red-team engagements (Trail of Bits, IOActive) reach $100,000-$200,000+.

Can I negotiate pentest pricing?

Yes. Multi-year commits unlock 20-30% off list pricing. Volume credit packs unlock 15-25%. Competing quotes from Cobalt, HackerOne, and Synack unlock 10-20%. Vendr and Spendflo buyer guides confirm these ranges as standard negotiation outcomes for PTaaS vendors.

What is the difference between a pentest and a vulnerability scan?

A scan is automated and finds known CVEs. A pentest is manual and finds business-logic flaws, authentication bypasses, and chained exploits. Anything labelled 'pentest' under $3,000 is almost certainly the former. Real pentests involve human testers who reason about your specific architecture.

How often should you do a pentest?

Annually at minimum for compliance (PCI 11.3, SOC 2, ISO 27001). After major releases or significant infrastructure changes. Continuously if you're a high-threat-profile company (fintech, healthtech, defence). For compliance-specific frequency guidance, see penetrationtestingcost.com.