How much does a penetration test cost?
Short answer: for a single web or API application of moderate complexity, manual penetration testing in the North American and LATAM markets typically lands between $8,000 and $25,000 USD. Larger applications, multi-platform mobile, LLM/agent systems, and compliance-heavy reporting push higher. Sub-$3,000 "pentests" are usually scans.
Pricing
Let's talk about your engagement
Every quote is scoped privately to the target, timeline, and compliance driver — reach out and we reply within 1 business day with real numbers, not a table.
Prefer email? Write to info@selvaops.com.
What drives cost
- Application complexity — number of user roles, distinct workflows, third-party integrations, and custom business logic.
- Attack surface size — endpoints, screens, trust boundaries (especially RAG corpora and agent tools for LLM apps).
- Environment and access — grey-box with docs and accounts is more efficient per day than pure black-box discovery.
- Compliance reporting — SOC 2 / PCI / ISO evidence packs, attestation letters, and auditor Q&A add overhead beyond the technical test.
- Retest inclusion — a free retest window (often 30 days) is standard at the mid/high end; excluding it lowers the quote and the value.
Low-end vs high-end: what you actually get
Low-end of the market often means fewer testing days, limited authenticated testing, thin remediation advice, and little or no retest. Useful for a narrow smoke-check; insufficient for most auditor or customer questionnaires.
High-end means more days with a senior tester, systematic authorization matrices, business-logic abuse cases, clear evidence, engineer-ready remediation, and a closed remediations loop. That is what the upper half of the ranges above usually buys.
Why unusually cheap tests are cheap
Automated scanners are valuable in CI. They are not a penetration test. A $1,500–$4,000 offering that promises "OWASP Top 10 coverage" in a few days is typically a scan export with light triage. It will not find IDOR across tenants, workflow bypasses, or LLM tool-abuse chains — and those are the findings that matter.
Vulnerability scan vs penetration test vs red team
| Vulnerability scan | Penetration test | Red team | |
|---|---|---|---|
| Goal | Known weaknesses, breadth | Exploit real attack paths in scope | Test detection & response org-wide |
| Method | Mostly automated | Manual + tooling | Adversary simulation, stealth |
| Typical cost band | Hundreds – low thousands | High thousands – tens of thousands | Tens – hundreds of thousands |
| Best for | Hygiene, CI regression | Release / audit evidence | Mature security programs |
Selva Ops performs penetration tests and manual code audits — not network/infrastructure red teaming. If you need a red team, ask for a referral rather than a stretched "pentest" quote.
How to use this page
Compare quotes against the bands above. Ask who performs the work, how many days are allocated, whether authorization testing is systematic, and whether a retest is included. Then request a scoping call with the details of your target — you will get a private proposal, not a copy-paste of this table.
FAQ
Why do some vendors quote a few thousand dollars for a "full pentest"?
Often that price buys an automated vulnerability scan with a templated report. Manual authorization testing, business-logic review, and a retest cycle are what move an engagement into five figures for non-trivial applications.
Is a more expensive test always better?
Not always. Price correlates with tester experience, days of effort, and report quality — but you should evaluate sample reports, methodology, and who actually performs the work. A senior solo practitioner and a junior team at a large firm can land in similar bands for different reasons.
Do these numbers include a retest?
Market practice varies. Many mid-to-high-end engagements include one retest window for fixed findings. Confirm this in writing — a report without a closed remediation loop is incomplete for most compliance uses.