🛡️ Pentest from €539 · Compliance from €89. See All Services →
Optimum Web
Free Tool · Scoping Worksheet

Penetration Testing Cost Calculator

Quick Answer

A penetration test published here ranges from €539 (Vulnerability Assessment) to €8,000–€12,000 (Enterprise SaaS), depending mainly on application size, user roles, authentication complexity, and API surface. Answer 7 questions below and the price updates immediately — nothing is hidden behind a form. What prompted the test (a customer questionnaire, an audit, or a regulation) can raise the recommended tier, because a Vulnerability Assessment isn't accepted evidence everywhere a penetration test is required.

How This Calculator Works

The methodology is open — nothing is hidden to make the tool look smarter than it is. Five questions are scored and summed; two questions (what prompted the test, and whether AI is in scope) change the result a different way.

QuestionWeight range
What are we testing?0 – 7
How many user roles sit behind the login?0 – 5
How does authentication work?0 – 4
What API surface is exposed?0 – 5
Roughly how large is it?0 – 6

The five weighted answers are summed into a scope score out of a maximum of 27, which maps to one of four published tiers:

  • 0–3 → Vulnerability Assessment (€539)
  • 4–9 → Focused Web App Penetration Test (from €1,800)
  • 10–17 → Standard Web App + API Penetration Test (from €4,500)
  • 18–27 → Enterprise SaaS Penetration Test (from €8,000)

The driver question doesn't add points — it can raise the tier. If your score lands in the Vulnerability Assessment range but the engagement is driven by a customer questionnaire, a SOC 2/ISO 27001 audit, NIS2/DORA/CRA, or investor due diligence, the recommended tier is raised to Focused Penetration Test. A vulnerability assessment normally isn't accepted evidence in those situations, and the result explains why.

AI/LLM functionality adds a separate line item, not extra points — prompt injection and agent-hijacking testing is a distinct engagement (AI Red Team Pentest, €990) on top of whichever tier your score recommends.

Published Price Table

TierPrice (EUR, excl. VAT)Delivery
Web App Vulnerability Assessment
SEC-PENT-01
€5395 business days
Focused Web App Penetration Test
SEC-PENT-02
from €1,8001.5–2 weeks
Standard Web App + API Penetration Test
SEC-PENT-03
from €4,500~3 weeks (8–12 person-days)
Enterprise SaaS Penetration Test
SEC-PENT-04
from €8,0004–5 weeks (15–22 person-days)
AI Red Team Pentest
Add-on, not a tier
+ €99010–14 business days

What Changes the Price

What you're testing

A marketing site, a single logged-in app, an app with an API, a multi-tenant SaaS platform, or a mobile app + backend — each has a very different attack surface.

Roles behind the login

Each additional role (admin, standard user, guest, partner) is tested separately, and cross-role access is where most real findings come from.

Authentication complexity

Email/password is cheap to test. SSO/OAuth and especially SAML/MFA/custom flows have to be exercised end to end.

API surface

REST, GraphQL, and webhooks each add dedicated test time — including undocumented endpoints.

Application size

Distinct screens plus API endpoints. More surface area means more manual testing hours.

What prompted the engagement

A customer questionnaire, SOC 2/ISO 27001 audit, or NIS2/DORA/CRA readiness can require a full penetration test even where your raw score would suggest a smaller tier.

Price Your Engagement

Seven questions, published prices, no call required. The figure below updates as you answer.

01What are we testing?

Pick the closest match. If several apply, choose the largest.

02How many user roles sit behind the login?

Each role is tested separately, and cross-role access is where most real findings come from.

03How does authentication work?

Federated login and MFA add real testing time — the flows have to be exercised end to end.

04What API surface is exposed?

Undocumented endpoints count. If you are not sure, pick the option above your guess.

05Roughly how large is it?

Distinct screens plus API endpoints. An estimate is fine.

06What prompted this?

This changes what the report has to contain, and sometimes the tier.

07Anything AI-powered in scope?

LLM features need prompt-injection and data-leakage testing, which is a separate engagement.

SCOPE-260803-403 Aug 2026
PENT 01
Web App Vulnerability Assessment
Automated discovery + manual validation of a small, low-complexity target
€539

Published price. Confirmed after a short scoping review.

Why this tier

  • TargetMarketing site, no login
  • RolesNone — no login
  • AuthNo authentication
  • APINone
  • SizeUnder 20
  • DriverInternal, no external driver
  • Score0 of 27
  • Duration5 business days

You receive

  • Automated discovery (Burp Suite Professional, Nuclei, OWASP ZAP)
  • Manual validation of all Critical/High findings
  • CVSS v3.1 vectors + CWE classification
  • OWASP Top 10:2025 mapping
  • Signed Attestation Letter
  • One round of clarification questions
  • Deep manual exploitation — not included
  • Business-logic testing — not included
  • Remediation retest (available as add-on, +€200) — not included
Book this engagement Or book a 30-min scoping call

Indicative only. Final scope is agreed in writing before any testing begins. Prices exclude VAT. Not a CREST-accredited test — Moldova has no CREST accreditation path.

Want it as a document?

The price is above — you don't need to give us anything for it. If you want this scope summary emailed so you can forward it to your auditor or your buyer, we'll send it.

Indicative only. Final scope is agreed in writing before any testing begins. A Vulnerability Assessment (€539) is not a full penetration test — most auditors and enterprise vendor security reviews specifically requiring "penetration test" evidence will not accept it as a substitute. All prices exclude VAT. Optimum Web is not CREST-accredited.

Frequently Asked Questions

How accurate is the price this calculator shows?

It's a published starting point, not a placeholder. The four prices and duration ranges match what we publish on each tier's own page. The exact figure within a tier's range is confirmed after a short scoping review — but the tier and the floor price are real, not "contact us for pricing."

Why do you ask what prompted the test (question 6)?

Because it changes what the report has to contain, and sometimes the tier itself. A customer questionnaire, a SOC 2 / ISO 27001 audit, or NIS2/DORA/CRA readiness normally requires evidence of an independent penetration test — a Vulnerability Assessment usually isn't accepted as a substitute. If your answers score low but your driver requires a real pentest, we raise the recommended tier and explain why.

Is a €539 result a real penetration test?

No — and we say so on the result. €539 buys a Vulnerability Assessment: automated discovery plus manual validation of the high-severity findings. It's a legitimate, audit-recognised deliverable for some controls (ISO 27001 Annex A.8.8), but it does not include deep manual exploitation or business-logic testing. Where a customer or auditor specifically asks for "a penetration test," start from the Focused tier instead.

What if my score lands right on a tier boundary?

Treat the calculator as a starting point for a conversation, not a binding quote. If your scope is close to a boundary, book a 30-minute scoping call — we'll confirm the tier and the exact number in writing before anything is agreed.

Do these prices include VAT?

No. All prices shown are fixed prices excluding VAT, consistent with the rest of our security pricing.

Is a remediation retest included?

It depends on the tier. The Vulnerability Assessment and Focused Penetration Test tiers do not include a retest by default — it's a paid add-on (+€200 / +€500). The Standard and Enterprise tiers include a remediation retest as standard.

What if my platform has AI or LLM features?

Prompt injection, data leakage, and agent-hijacking testing aren't covered by a standard web/API penetration test. If you flag AI/LLM functionality in scope, the calculator adds our AI Red Team Pentest (€990, 10–14 business days) as a separate line item on top of the recommended tier.

Will you always sell me the tier the calculator recommends?

No. The calculator is a scoping starting point, not a sales script. If your driver is purely internal (or a cyber insurance renewal) and the calculator recommends a tier above the Vulnerability Assessment, the result shows a smaller first-step option at €539 — with an honest note that it isn't a substitute for a penetration test where an auditor or customer specifically requires one.