Your first penetration test, explained.
A customer, auditor, or insurer wants a pen test, and you’ve never bought one. Here’s what to test, how to prepare, what it costs, and what you get.
Last reviewed October 2026
Pen test or vulnerability scan?
A vulnerability scan runs automated tools that look for known issues. A penetration test adds people who try to break in the way an attacker would, including the authorization and business-logic flaws that automated tools often miss. NIST SP 800-53 Rev. 5 (CA-8) says penetration testing “goes beyond automated vulnerability scanning.”[1] OWASP’s Web Security Testing Guide says business-logic flaws “cannot be detected by a vulnerability scanner.”[2] If the request you received asks for a penetration test, a scan report won’t answer it.
Read the full comparison: penetration test vs. vulnerability scan
What to test first
For a typical SaaS product, the first test covers the web application and the API behind it, with two test accounts for each user role. If your product serves many customers from one system, we also check whether one customer can reach another’s data. If you run on AWS, Azure, or Google Cloud, consider adding a cloud configuration review.
What it costs
Every engagement is a fixed fee after a free scoping call. Starting prices for the smallest scope: web applications from $5,000 per application, external network tests from $5,000, APIs from $8,000 per API, and cloud environments from $10,000 per environment. The web application price covers the app’s own API. Your price depends on the applications, user roles, API endpoints, IP addresses, or cloud accounts in scope, and it won’t change once testing starts unless the scope does. One retest of reported findings within 90 days of the final report is included.
Starting prices in US dollars for the smallest scope of each service, reviewed October 2026. Your price is a fixed fee, set in a written proposal after a free scoping call.
See starting prices for every service
How long it takes
- We reply to every request within one business day and set up a free scoping call.
- You get a fixed-fee proposal and rules of engagement to sign. Testing can usually start within 5 business days of signing.
- Testing takes one to three weeks for most web applications. Critical findings are reported within 24 hours of confirmation, not held for the report.
- Final report delivered within 5 business days after testing ends. We walk your team through the findings on a call.
- When you’ve fixed the findings, one retest of reported findings within 90 days of the final report is included in the price, with an updated report and attestation letter.
Start dates are agreed during scoping, so tell us your deadline when you ask for a quote.
How to prepare
- The web addresses and API base URLs in scope
- Two test accounts for each user role, so we can test access between users
- API documentation, such as an OpenAPI spec or Postman collection
- A technical contact and an emergency contact for the testing window
- Anything that’s off limits
See the full scoping checklist
No staging environment?
That’s workable. We can test production inside agreed testing windows, after agreeing on source IP addresses and emergency contacts. We never run denial-of-service or destructive tests without your written approval, and you can pause testing at any time with one message.
What you’ll get
- An executive summary for leadership
- Technical findings with evidence, reproduction steps, and specific fixes
- A walkthrough call with your team
- An attestation letter you can share
- One retest of reported findings within 90 days of the final report, included in the price
See an example report and attestation letter
What to send your customer
Send the attestation letter. It confirms the test dates, scope, method, and results without exposing your vulnerabilities. Keep the full report for your engineers and your auditor.
Why customers ask
Verizon 2026 DBIR: “breaches with third-party involvement have increased by 60% from last year’s dataset, reaching 48% of total breaches.”[3]
Ready for your first test?
We reply to every request within one business day. Every engagement is a fixed fee after a free scoping call.