How much does a penetration test cost in 2026?

The honest answer to "how much does a pentest cost" is a range wide enough to be useless until you understand what moves it. So here is the range, and then the part that actually matters: the levers that decide where in the range you land, most of which are yours to pull.
The ranges, plainly
For a single web application in 2026, industry pricing guides land in roughly the $5,000 to $30,000 range for a typical engagement, with simpler apps at the lower end and complex multi-tenant SaaS platforms higher. Invicti's pricing guide puts web application testing at about $4,000 to $20,000 and up, and Bright Defense puts the web app range at $5,000 to $30,000, with both noting that once you add network, cloud, and red-team work the broad span runs from a few thousand dollars to well over $100,000. The spread is enormous because the word "pentest" covers a one-app check and a month-long red-team exercise equally.
What you are actually paying for
Traditional pentest pricing is, at its core, the price of expert time. You are buying a fixed number of senior tester-hours, and the quote is mostly an estimate of how many days those testers need. That single fact explains every line item below, because each one is really a question of how many expert-days the engagement will take.
What drives the number
- 01Scope and complexity: the number of applications, user roles, endpoints, APIs, cloud accounts, and integrations in scope. A single-role brochure site and a multi-tenant platform with SSO and payments are not the same job.
- 02Depth of testing: a light surface check versus a thorough test of authorization logic, business workflows, and chained attack paths.
- 03Level of access: how much you grant the testers, which changes how many days are spent reaching the interesting surface versus testing it.
- 04Compliance requirements: a test that must map to SOC 2 or another framework, with a report an auditor will scrutinize, carries more reporting overhead.
- 05Retest: whether confirming your fixes actually worked is included, or billed separately.
- 06Tester seniority: who is actually doing the work, which is the largest hidden variable in any human-hours quote.
Why access changes the bill
Here is the counterintuitive lever. A pure black-box test, where the testers start from nothing, spends a large share of its days on discovery, the slow work of mapping your system from the outside. As Cobalt notes, granting more access skips that overhead and spends the same days finding vulnerabilities instead. Giving the testers accounts and context does not just improve the test, it can lower the cost per real finding, because fewer hours are burned getting in. We made the full case for this in our guide to how much access to give a pentester.
How long it takes
Timeline tracks cost because both track tester-days. A standard web-app engagement is commonly a few days of active testing, then a few days of report writing, then internal review before delivery, so calendar time of one to two weeks is normal even when active testing is short. A larger or more complex target stretches every phase.
The number that actually matters
Price is the wrong thing to optimize. The cheapest option in this market is usually an automated scan dressed up as a report, and it is cheap precisely because no one proved anything. What you want to compare is value: how much of your real attack surface was tested, how many findings came with a working exploit rather than a guess, and whether the serious ones were retested closed. A test that proves three exploitable issues and confirms the fixes is worth more than a far pricier report full of unverified maybes.
This is also where the economics are shifting. When the exhaustive work is done at machine scale, the price stops being a variable five-figure consulting estimate and becomes a flat, predictable line item that can run on every release instead of once a year. That is the model Uvy is built on: proof-backed testing at a flat, predictable price, run on every release rather than booked once a year. See how it works.