M37
What a penetration test costs, and what the report contains
This is the material behind the video. Every figure below comes from a document anyone can open, and every row links to the document it came from. Nothing here is an estimate of ours, an average we computed from somebody else’s average, or a number a vendor gave us in private.
The numbers in the video
How this was put together
Three public records, kept separate because they are not the same kind of number. Sellers' own published prices, most of which exist because the UK government makes publishing one a condition of being listed on its buying framework. Awarded US federal contracts, read one description at a time: a keyword search returned 1,795 and only 157 survived reading, the rest being training courses, software licences, military red teams, soil tests and, in four cases, viral penetration tests on medical gowns. And penetration-test reports the firms published themselves, parsed for what each one contains. Every row links to the document it came from.
What these numbers cannot tell you
- A published price is an asking price. An awarded contract total is what was obligated on a whole agreement. A schedule labour rate is a ceiling, not what anyone was paid. None of the three is the price of one test, and averaging across them would be meaningless.
- The UK prices are framework prices: what a supplier is willing to have a public-sector buyer see before negotiating. There is no reason to assume a private buyer is quoted the same.
- Only five vendors publish a fixed per-test price. That median moved 40% when the fifth was added, so read the spread and not the midpoint.
- 42 bundled awards were caught by their own descriptions. An unknown number were not, and that error pushes the top of the range up rather than down.
- The reports are the ones firms chose to publish, almost always for open-source, grant-funded or crypto clients and at narrower scope than commercial work, and Trail of Bits is about 60% of the corpus. They support claims about what a published report contains and nothing about the typical private engagement.
- Severity words are not comparable between firms. Trail of Bits and iSEC Partners print no Critical tier at all; X41 print no Informational tier; Radically Open Security use a different ladder entirely. Counting 'criticals' across firms measures vocabulary.
What we could not get
- The G-Cloud service catalogue. buyer browse moved behind a login, so these documents are the search-indexed subset rather than the framework's full population. This is the biggest limit on the seller-price side.
- BreachLock, Probely, ImmuniWeb pricing. 403 to a plain request, or prices rendered by client-side script. Reachable with a browser; not escalated.
- Award line items. there is one free-text description per federal award and no line items published anywhere, which is why a bundle can only be caught when its own description happens to enumerate.
- 155 reports from 74 further firms. fetched, but with no machine-readable findings summary to parse. Doyensec, ConsenSys, Hacken, Securitum, Quarkslab and Bishop Fox are the largest losses.
- A price and a report for the same job. does not exist in public anywhere we could find, which is why this page cannot tell you whether price predicts what you get.
What it cost, where a record says so
217 rows. You can sort by any column heading, and the box below narrows the table to rows containing a word you type. Opening a row shows the scope in the record’s own words, and the document it came from.
Showing 25 of 217 rows. In the order the harvest produced them.
| Row detail | Record | |||||
|---|---|---|---|---|---|---|
| PTaaS infrastructure, one-off test, up to 5 IPs | $941fixed | fixed | AMICIS GROUP LIMITED | 2026-09-01 | source | |
| PTaaS infrastructure, one-off test, up to 100 IPs | $5,176fixed | fixed | AMICIS GROUP LIMITED | 2026-09-01 | source | |
| PTaaS infrastructure, one-off test, up to 500 IPs | $9,693fixed | fixed | AMICIS GROUP LIMITED | 2026-09-01 | source | |
| PTaaS web application, one-off test, up to 1 app | $1,255fixed | fixed | AMICIS GROUP LIMITED | 2026-09-01 | source | |
| Work outside the PTaaS packages | $1,129daily | daily | AMICIS GROUP LIMITED | 2026-09-01 | source | |
| External Infrastructure / Web Application Assessment / API / Internal Infra (and 9 more) | $1,506daily | daily | PEN TEST PARTNERS LLP | 2026-09-01 | source | |
| IT Health Check | $1,631daily | daily | PEN TEST PARTNERS LLP | 2026-09-01 | source | |
| Hardware / IOT Testing | $1,757daily | daily | PEN TEST PARTNERS LLP | 2026-09-01 | source | |
| Application Penetration Test - Entry or Compliance (5-8 days) | $8,988fixed | fixed | IBM UNITED KINGDOM LIMITED (X-Force Red) | 2026-09-01 | source | |
| Application Penetration Test - Standard (12-18 days) | $15,819fixed | fixed | IBM UNITED KINGDOM LIMITED (X-Force Red) | 2026-09-01 | source | |
| Application Penetration Test - Advanced (17-25 days) | $21,571fixed | fixed | IBM UNITED KINGDOM LIMITED (X-Force Red) | 2026-09-01 | source | |
| External Network Penetration Test (up to 4 Class C segments) | $8,449fixed | fixed | IBM UNITED KINGDOM LIMITED (X-Force Red) | 2026-09-01 | source | |
| Internal Network Penetration Test (up to 4 Class C segments) | $12,403fixed | fixed | IBM UNITED KINGDOM LIMITED (X-Force Red) | 2026-09-01 | source | |
| Cloud Penetration Test - Small (2 accounts / 100 assets) | $10,798fixed | fixed | IBM UNITED KINGDOM LIMITED (X-Force Red) | 2026-09-01 | source | |
| Cloud Penetration Test - Large (10 accounts / 600 assets) | $30,850fixed | fixed | IBM UNITED KINGDOM LIMITED (X-Force Red) | 2026-09-01 | source | |
| Hardware Penetration Test - Advanced | $49,484fixed | fixed | IBM UNITED KINGDOM LIMITED (X-Force Red) | 2026-09-01 | source | |
| Application Vulnerability Scan (DAST) - Initial Scan | $1,749fixed | fixed | IBM UNITED KINGDOM LIMITED (X-Force Red) | 2026-09-01 | source | |
| Penetration Testing (CHECK ITHC, web app, cloud, AD, wireless...) FY25, Team Member | $1,355daily | daily | QINETIQ LIMITED | 2026-09-01 | source | |
| Penetration Testing FY25, Team Leader | $1,568daily | daily | QINETIQ LIMITED | 2026-09-01 | source | |
| Red Team Cyber Attacks / High Assurance Engagements FY25, Team Leader | $1,882daily | daily | QINETIQ LIMITED | 2026-09-01 | source | |
| Web Application and API / External / Internal Pen Testing / ITHC | $1,600daily | daily | CYBER SECURITY ASSOCIATES LTD | 2026-09-01 | source | |
| Red Teaming | $2,196daily | daily | CYBER SECURITY ASSOCIATES LTD | 2026-09-01 | source | |
| Web penetration test, CMS, one-off | $1,882fixed | fixed | ISOTOMA LIMITED | 2026-09-01 | source | |
| Web penetration test, transactional application, one-off | $3,137fixed | fixed | ISOTOMA LIMITED | 2026-09-01 | source | |
| Web penetration test, CMS, continuous/ongoing | $5,019fixed | fixed | ISOTOMA LIMITED | 2026-09-01 | source |
What the reports contain
501 reports the firms published themselves. Severity words are not comparable between firms, so each row carries the ladder its own firm used. Open the row to see it.
Showing 25 of 501 reports. In the order the harvest produced them.
| Row detail | Report | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| 7ASecurity | 7ASecuritypentest-logback-RC1.1 | not stated | 34 | 5 | 1 | 0 | 1 | 1 | 2 | open | |
| 7ASecurity | 7ASecuritypentest-report-amneziavpn | not stated | 36 | 16 | 3 | 1 | 6 | 4 | 2 | open | |
| 7ASecurity | 7ASecuritypentest-report-amneziavpn2 | not stated | 25 | 10 | 0 | 0 | 6 | 2 | 2 | open | |
| 7ASecurity | 7ASecuritypentest-report-amneziavpn3-RC1.1 | not stated | 41 | 6 | 2 | 1 | 1 | 2 | 0 | open | |
| 7ASecurity | 7ASecuritypentest-report-argovpn | not stated | 46 | 13 | 0 | 1 | 5 | 2 | 5 | open | |
| 7ASecurity | 7ASecuritypentest-report-bridgefy | not stated | 133 | 44 | 4 | 12 | 9 | 13 | 6 | open | |
| 7ASecurity | 7ASecuritypentest-report-conda-forge-RC1.0 | not stated | 53 | 13 | 1 | 2 | 4 | 4 | 2 | open | |
| 7ASecurity | 7ASecuritypentest-report-coverdrop | not stated | 84 | 33 | 0 | 0 | 11 | 15 | 7 | open | |
| 7ASecurity | 7ASecuritypentest-report-defo-2 | not stated | 28 | 10 | 0 | 0 | 0 | 3 | 7 | open | |
| 7ASecurity | 7ASecuritypentest-report-freebrowser-RC1.4 | not stated | 87 | 27 | 3 | 6 | 6 | 6 | 6 | open | |
| 7ASecurity | 7ASecuritypentest-report-leavehomesafe | not stated | 59 | 12 | 1 | 2 | 4 | 2 | 3 | open | |
| 7ASecurity | 7ASecuritypentest-report-litmuschaos | not stated | 50 | 16 | 1 | 3 | 4 | 5 | 3 | open | |
| 7ASecurity | 7ASecuritypentest-report-nvm | not stated | 29 | 4 | 0 | 2 | 0 | 0 | 2 | open | |
| 7ASecurity | 7ASecuritypentest-report-opentelemetry | not stated | 21 | 7 | 0 | 2 | 2 | 1 | 2 | open | |
| 7ASecurity | 7ASecuritypentest-report-securedrop | not stated | 70 | 18 | 0 | 0 | 7 | 9 | 2 | open | |
| 7ASecurity | 7ASecuritypentest-report-thunderbird-send-RC1.2 | not stated | 71 | 22 | 1 | 8 | 6 | 5 | 2 | open | |
| 7ASecurity | 7ASecuritypentest-report-tor2-RC1.2 | not stated | 41 | 17 | 1 | 4 | 8 | 3 | 1 | open | |
| 7ASecurity | 7ASecuritypentest-report_groundtruth | not stated | 69 | 20 | 3 | 4 | 5 | 7 | 1 | open | |
| 7ASecurity | 7ASecuritypentest-report_psiphon-e | not stated | 22 | 5 | 0 | 0 | 0 | 3 | 2 | open | |
| 7ASecurity | 7ASecuritypentest-report_wepn | 17 | 68 | 31 | 2 | 0 | 7 | 13 | 9 | open | |
| Cure53 | Cure53audit-report_coinbase-kms | not stated | 21 | 9 | 0 | 1 | 1 | 1 | 6 | open | |
| Cure53 | Cure53audit-report_distrust-toolkit | not stated | 22 | 7 | 0 | 0 | 0 | 3 | 4 | open | |
| Cure53 | Cure53audit-report_ente-crypto | not stated | 15 | 4 | 0 | 1 | 2 | 1 | 0 | open | |
| Cure53 | Cure53audit-report_micro-btc-signer | 11 | 16 | 4 | 0 | 1 | 1 | 0 | 2 | open | |
| Cure53 | Cure53audit-report_nip44-implementations | 10 | 18 | 10 | 0 | 0 | 2 | 2 | 6 | open |
Ask us to run something
If you want this rerun against your own market, your own corpus of reports, or a record your organisation keeps, say so here. We read everything and we answer, including when the answer is no. If we take something on, the protocol is written down before the run starts and published with the result, whichever way the result goes.
9592 Solutions UG (haftungsbeschränkt), Fährstr. 217, 40221 Düsseldorf, Germany is the controller for what you send here. Your address and your message are used to answer you and to work out whether we take the request on, under Art. 6(1)(b) and Art. 6(1)(f) GDPR. They go to nobody else and they are not used for advertising. Write to christo@9592.tech for a copy or a deletion at any time. The longer version is on the privacy page.