What penetration testing costs
Every engagement is a fixed fee after a free scoping call.
Starting prices are for the smallest common scope of each service; your proposal prices your exact scope.
Starting prices in US dollars for the smallest scope of each service, reviewed October 2026. Your price is a fixed fee, set in a written proposal after a free scoping call. One retest of reported findings within 90 days of the final report is included.
Where common projects start
Pick the situation closest to yours.
-
An audit or a customer’s security review
For SOC 2, ISO 27001, HIPAA, or an enterprise customer’s questionnaire, we test the system they’re asking about. For a SaaS product, that usually means the web application, its API, and the cloud account it runs in.
- Web application, including its own API From $5,000 per application
- Separate public or partner API From $8,000 per API
- Cloud environment From $10,000 per environment
Reports document the scope, methodology, and dates that assessors typically look for.
Get a quote for audit testing Get a quote for a customer review
-
A cyber insurance application or renewal
If your insurer asks for an external penetration test, start there. Need a phishing test too? We quote both in one proposal.
- External network test From $5,000
- Phishing campaign Quoted for your scope. Minimum project $5,000.
You get a letter you can give your broker or insurer.
-
An AI feature about to ship
Chatbots, copilots, RAG pipelines, or agents that take actions. Testing one AI feature is also a low-risk way to see how we work.
- AI and LLM penetration testing From $5,000
-
Your internal network and Active Directory
How far could an attacker get from one compromised laptop? We follow the paths to your critical systems.
- Internal network and Active Directory From $15,000 per network
Starting prices in US dollars for the smallest scope of each service, reviewed October 2026. Your price is a fixed fee, set in a written proposal after a free scoping call.
Starting prices by service
Each price is for the smallest scope of that service. Your proposal is a fixed fee for your exact scope.
Penetration testing
-
Web application penetration testing
- From $5,000 per application
The price covers the app and its own API. Fixed fee after a free scoping call. Retest included. Attestation letter included.
Depends on the number of user roles and tenants, the size of the app, and the API behind it.
-
API penetration testing
- From $8,000 per API
Fixed fee after a free scoping call. Retest included. Attestation letter included.
Depends on the number of endpoints and user roles and whether you have an OpenAPI spec, Postman collection, or schema.
-
Network penetration testing
- External networkFrom $5,000
- Internal network and Active DirectoryFrom $15,000 per network
- WirelessFrom $5,000 per site
Fixed fee after a free scoping call. Retest included. Attestation letter included.
Depends on the number of live hosts and sites and the size of Active Directory.
-
Cloud penetration testing
- From $10,000 per environment
An environment is one AWS account, Azure subscription, or Google Cloud project. Fixed fee after a free scoping call. Retest included. Attestation letter included.
Depends on the number of accounts, subscriptions, or projects and the Kubernetes clusters and identity providers in scope.
-
Mobile application penetration testing
- From $10,000 per app
Fixed fee after a free scoping call. Retest included. Attestation letter included.
Depends on the platforms (iOS, Android, or both), the size of the app, and its backend API.
-
AI and LLM penetration testing
- From $5,000
Fixed fee after a free scoping call. Retest included. Attestation letter included.
Depends on the number of AI features, the tools the model can use, and the data it can retrieve.
Adversary simulation
-
Red team and assumed-breach testing
- From $30,000
Phishing and phone pretexting are included when in scope. Fixed fee after a free scoping call.
Depends on your objectives, the length of the engagement, and the access paths in scope.
-
Phishing and social engineering testing
- Quoted for your scope. Minimum project $5,000.
Fixed fee after a free scoping call.
Depends on the number of people in scope, the channels (email, phone, or text), and the number of campaigns.
Assessment and training
-
Secure code review and threat modeling
- Quoted for your scope. Minimum project $5,000.
Fixed fee after a free scoping call.
Depends on the size of the codebase, the languages, and the areas you want reviewed most closely.
-
Vulnerability assessments and scanning
- One-time assessmentFrom $5,000
- Recurring scanningQuoted for an ongoing term
One-time work is a fixed fee after a free scoping call. Recurring scanning is quoted for an ongoing term after a free scoping call.
Depends on the number of hosts and web apps, internal or external coverage, and how often you scan.
-
Security training and hands-on labs
- Custom lab environmentsFrom $10,000
- Workshops and coursesQuoted per session
Fixed fee after a free scoping call.
Depends on the number of attendees, the length of the course, remote or on-site delivery, and any custom labs.
Starting prices in US dollars for the smallest scope of each service, reviewed October 2026. Your price is a fixed fee, set in a written proposal after a free scoping call. One retest of reported findings within 90 days of the final report is included.
What moves the price
- The number of applications, user roles, and API endpoints
- Live IP addresses, internal sites, and wireless locations
- Cloud accounts, subscriptions, or projects
- Platforms: iOS, Android, or both
- Codebase size and languages, for code review
Included in every penetration test
Part of the fixed fee, not add-ons.
- Manual testing by our own US-based testers, backed by tooling.
- Critical findings are reported within 24 hours of confirmation, not held for the report.
- Executive summary and technical findings with severity ratings, evidence, and reproduction steps.
- Final report delivered within 5 business days after testing ends.
- A walkthrough call with your team after the report.
- An attestation letter you can share with customers, auditors, and insurers.
- One retest of reported findings within 90 days of the final report, included in the price.
- Every engagement is a fixed fee after a free scoping call.
Engagement commitments apply to work under a signed HackNow proposal.
Pricing questions
Anything else? Ask us directly.
What does “fixed fee” mean?
Your proposal states one price for the agreed scope. It changes only if the scope changes, for example if you add an application or more user roles.
What changes the price?
Scope and complexity: how many applications, user roles, API endpoints, IP addresses, cloud accounts, or sites are in scope. Each service above lists what its price depends on.
Do you charge by the hour?
No. Every engagement is a fixed fee for the scope in your written proposal.
How long does a penetration test take?
Most web app, API, and network tests take one to three weeks of testing, and the final report is delivered within 5 business days after testing ends. Red team engagements take three to eight weeks. Testing can usually start within 5 business days of signing.
Is there a minimum?
Yes. The minimum project is $5,000. Ongoing services are quoted for their term.
Is the retest extra?
No. One retest of reported findings within 90 days of the final report is included in the price.
Want a number for your scope?
We reply to every request within one business day. Every engagement is a fixed fee after a free scoping call.