// uncategorised

How Much Does a Web Application Penetration Test Cost?

How Much Does a Web Application Penetration Test Cost?

“How much does a web application penetration test cost?” is the first question most buyers ask — and the honest answer is that it depends on scope. This guide explains what actually drives the price, typical ranges, and how to make sure you are paying for genuine manual testing rather than a scanner subscription.

What drives the price

Pentest pricing is effort-based: it scales with how much there is to test and how deeply. The main factors:

  • Size of the application — number of pages, endpoints, user roles and workflows.
  • Complexity — custom business logic, multi-tenancy, integrations and unusual tech stacks take longer.
  • Depth — a black-box perimeter check costs less than an authenticated, multi-role, logic-heavy assessment.
  • Type of target — a marketing site, an API, an e-commerce platform and a multi-tenant SaaS are very different jobs.
  • Compliance requirements — evidence for PCI DSS, SOC 2 or ISO 27001 adds formality and reporting.

Typical ranges

As a rough guide, a focused test of a small application typically starts in the low thousands, a standard business web app sits in the mid-range, and a large, complex or compliance-driven engagement costs more because it takes more senior tester-days. Because the variable is effort, the only accurate number comes from scoping your specific target — which is why reputable providers quote a fixed price after a short scoping call rather than publishing a flat rate.

Day-rate vs fixed-price

Some firms sell tester-days; others quote a fixed price for a defined scope. Fixed-price is usually better for buyers: you know the cost up front, and the incentive is to cover the agreed scope thoroughly rather than to bill more hours. Insist on a clear statement of work either way.

What should be included

A fair price should include all of the following — if any are “extra”, factor that in:

  • Manual testing by experienced testers, not just an automated scan.
  • A full report with executive summary, technical detail and reproductions.
  • CVSS risk ratings and business-impact context.
  • A remediation walkthrough and a complimentary retest after you fix.
  • An attestation letter for customers, auditors and insurers.

The false economy of cheap “pentests”

The cheapest quotes are almost always automated scans relabelled as penetration tests. They miss the exact issues that cause breaches — broken access control, business logic and chained exploits — because scanners cannot reason about them. Paying less for a scan you could run yourself is not a saving; it is a false sense of security. We explain the difference in penetration testing vs vulnerability scanning.

How to get an accurate quote

Provide the number of applications, roles and rough size; whether testing is authenticated; any compliance driver; and your ideal timeline. A good provider returns a fixed price and scope quickly.

Frequently asked questions

Why won’t you just publish a price? Because a flat rate either overcharges small apps or under-tests large ones. Effort-based pricing is fairer and more accurate.

Is a retest included? With us, yes — confirming your fixes actually close the attack path is part of the engagement.

Want a real number for your application? Tell us about your target and get a fixed-price quote — usually within one business day. Start with web application penetration testing.

// get started

Work with AgentOffense

Tell us about your target and goals. We’ll reply with scope and a fixed-price quote — usually within one business day.

./request_engagement