FD Solutions Security testing

Guide

How much does a penetration test cost in 2026?

Published prices, what actually drives them, and how to tell an expensive quote from an overpriced one.

Short answer

A web application penetration test costs $5,000–$35,000 from a traditional consultancy, $69–$499 a month from an automated scanning platform, and $50–$1,450 for a fixed-scope engagement from a small independent firm. Price is driven by scope, whether testing is authenticated, and whether a person verifies each finding by hand.

Almost nobody publishes a price, which is why you are reading this. The honest answer is that a web application penetration test in 2026 costs between $5,000 and $35,000 from a traditional consultancy, $69 to $499 a month from an automated scanning platform, and very little in between — and the gap in the middle is where most companies actually live.

Below is what those numbers are made of, so you can read a quote rather than just react to it.

The three markets, and why they price so differently

Automated scanners — $69 to $499 a month. You point them at a domain and they run signature checks. There is no person, so there is no judgement: you get candidates, including false ones, and no auditor treats the output as evidence of a penetration test. Useful as a monitor. Not an answer to "has this been tested".

Consultancies and PTaaS — $5,000 to $35,000 for one web application. Two testers for one to three weeks, a threat model, a written report, a retest. This is the real thing, and if your budget reaches it you should buy it. Expect two to four weeks between signing and starting.

Freelance marketplaces — $15 to $1,560. Sometimes excellent, often a scanner run by somebody who did not read the output, and structurally hard to check. No company behind it means no contract worth enforcing, no NDA with a counterparty, no insurance and no recourse.

What actually drives the number

Not the number of pages. This is the single most common misunderstanding, and it makes people over-buy and under-buy in equal measure.

Cost tracks user roles and privilege boundaries. Authorisation testing does not scale with how much content you have; it scales with how many directions one kind of user could try to reach another kind of user's data. A hundred-page brochure site with no login is a small job. A three-role, multi-tenant platform that moves money is not, even if it has twelve screens.

After that: how many APIs and how well documented, whether money moves and therefore needs a sandbox, how complex the workflows are, whether source code is available, whether a compliance framework imposes extra reporting, and whether retesting is inside the fee or billed later.

Questions worth asking before you sign anything

Is the retest included? If not, budget for it — you will need it, and buying it separately is always dearer.

Who writes the report, and can I see a redacted sample? The report is the deliverable. A vendor who will not show you one is telling you something.

Is every finding verified by a person? Ask directly. "AI-powered" and "continuous" are not answers to it.

What exactly is in scope, and who signs the authorisation? A test without a written authorisation letter naming the systems is not a test you want your name on.

What happens if you find a Critical on day one? The right answer is that you hear immediately, not in three weeks when the document is ready.

Published 2026 market prices, checked September 2026
PriceHuman verificationReport an auditor acceptsLead time
Automated scanner$69–$499 / moNoNoInstant
FD Solutions$50–$4,000YesYes2–5 days
Consultancy / PTaaS$5,000–$35,000YesYes2–4 weeks
Freelance marketplace$15–$1,560VariesRarelyVaries

Published 2026 market prices, checked September 2026

Questions

Is a cheap test worse than no test?
Only if it makes you think you are covered when you are not. A small, honestly-scoped test that says exactly what it did and did not cover is useful at any price. A cheap test that implies full coverage is worse than nothing, because you stop looking.
How often should we test?
Annually as a floor, and after any significant change to authentication, authorisation or payments. If you deploy weekly, a point-in-time test is stale within a month and a retainer makes more sense than a bigger one-off.
Does the price include fixing what you find?
Almost never, and you should be suspicious when it does — a vendor whose fee grows with the length of its own findings list has a conflict of interest. Get the testing and the fixing priced separately, even if the same firm does both.

Next step

Send us a URL. Get a price today.

One reply from the engineer who would run the test — the engagement that fits, the fixed price, and the earliest window.

WhatsApp Get a price