Skip to content
Selva Ops

How much does a penetration test cost?

Short answer: for a single web or API application of moderate complexity, manual penetration testing in the North American and LATAM markets typically lands between $8,000 and $25,000 USD. Larger applications, multi-platform mobile, LLM/agent systems, and compliance-heavy reporting push higher. Sub-$3,000 "pentests" are usually scans.

Pricing

Let's talk about your engagement

Every quote is scoped privately to the target, timeline, and compliance driver — reach out and we reply within 1 business day with real numbers, not a table.

Prefer email? Write to info@selvaops.com.

What drives cost

  • Application complexity — number of user roles, distinct workflows, third-party integrations, and custom business logic.
  • Attack surface size — endpoints, screens, trust boundaries (especially RAG corpora and agent tools for LLM apps).
  • Environment and access — grey-box with docs and accounts is more efficient per day than pure black-box discovery.
  • Compliance reporting — SOC 2 / PCI / ISO evidence packs, attestation letters, and auditor Q&A add overhead beyond the technical test.
  • Retest inclusion — a free retest window (often 30 days) is standard at the mid/high end; excluding it lowers the quote and the value.

Low-end vs high-end: what you actually get

Low-end of the market often means fewer testing days, limited authenticated testing, thin remediation advice, and little or no retest. Useful for a narrow smoke-check; insufficient for most auditor or customer questionnaires.

High-end means more days with a senior tester, systematic authorization matrices, business-logic abuse cases, clear evidence, engineer-ready remediation, and a closed remediations loop. That is what the upper half of the ranges above usually buys.

Why unusually cheap tests are cheap

Automated scanners are valuable in CI. They are not a penetration test. A $1,500–$4,000 offering that promises "OWASP Top 10 coverage" in a few days is typically a scan export with light triage. It will not find IDOR across tenants, workflow bypasses, or LLM tool-abuse chains — and those are the findings that matter.

Vulnerability scan vs penetration test vs red team

Vulnerability scanPenetration testRed team
GoalKnown weaknesses, breadthExploit real attack paths in scopeTest detection & response org-wide
MethodMostly automatedManual + toolingAdversary simulation, stealth
Typical cost bandHundreds – low thousandsHigh thousands – tens of thousandsTens – hundreds of thousands
Best forHygiene, CI regressionRelease / audit evidenceMature security programs

Selva Ops performs penetration tests and manual code audits — not network/infrastructure red teaming. If you need a red team, ask for a referral rather than a stretched "pentest" quote.

How to use this page

Compare quotes against the bands above. Ask who performs the work, how many days are allocated, whether authorization testing is systematic, and whether a retest is included. Then request a scoping call with the details of your target — you will get a private proposal, not a copy-paste of this table.

FAQ

Why do some vendors quote a few thousand dollars for a "full pentest"?

Often that price buys an automated vulnerability scan with a templated report. Manual authorization testing, business-logic review, and a retest cycle are what move an engagement into five figures for non-trivial applications.

Is a more expensive test always better?

Not always. Price correlates with tester experience, days of effort, and report quality — but you should evaluate sample reports, methodology, and who actually performs the work. A senior solo practitioner and a junior team at a large firm can land in similar bands for different reasons.

Do these numbers include a retest?

Market practice varies. Many mid-to-high-end engagements include one retest window for fixed findings. Confirm this in writing — a report without a closed remediation loop is incomplete for most compliance uses.

Ready to scope an engagement?

Describe the target and we reply within 1 business day with scoping questions or a proposed approach — no sales layer in between.

Request a scoping call