Penetration Testing Cost Calculator
Quick Answer
A penetration test published here ranges from €539 (Vulnerability Assessment) to €8,000–€12,000 (Enterprise SaaS), depending mainly on application size, user roles, authentication complexity, and API surface. Answer 7 questions below and the price updates immediately — nothing is hidden behind a form. What prompted the test (a customer questionnaire, an audit, or a regulation) can raise the recommended tier, because a Vulnerability Assessment isn't accepted evidence everywhere a penetration test is required.
How This Calculator Works
The methodology is open — nothing is hidden to make the tool look smarter than it is. Five questions are scored and summed; two questions (what prompted the test, and whether AI is in scope) change the result a different way.
| Question | Weight range |
|---|---|
| What are we testing? | 0 – 7 |
| How many user roles sit behind the login? | 0 – 5 |
| How does authentication work? | 0 – 4 |
| What API surface is exposed? | 0 – 5 |
| Roughly how large is it? | 0 – 6 |
The five weighted answers are summed into a scope score out of a maximum of 27, which maps to one of four published tiers:
- 0–3 → Vulnerability Assessment (€539)
- 4–9 → Focused Web App Penetration Test (from €1,800)
- 10–17 → Standard Web App + API Penetration Test (from €4,500)
- 18–27 → Enterprise SaaS Penetration Test (from €8,000)
The driver question doesn't add points — it can raise the tier. If your score lands in the Vulnerability Assessment range but the engagement is driven by a customer questionnaire, a SOC 2/ISO 27001 audit, NIS2/DORA/CRA, or investor due diligence, the recommended tier is raised to Focused Penetration Test. A vulnerability assessment normally isn't accepted evidence in those situations, and the result explains why.
AI/LLM functionality adds a separate line item, not extra points — prompt injection and agent-hijacking testing is a distinct engagement (AI Red Team Pentest, €990) on top of whichever tier your score recommends.
Published Price Table
| Tier | Price (EUR, excl. VAT) | Delivery |
|---|---|---|
| Web App Vulnerability Assessment SEC-PENT-01 | €539 | 5 business days |
| Focused Web App Penetration Test SEC-PENT-02 | from €1,800 | 1.5–2 weeks |
| Standard Web App + API Penetration Test SEC-PENT-03 | from €4,500 | ~3 weeks (8–12 person-days) |
| Enterprise SaaS Penetration Test SEC-PENT-04 | from €8,000 | 4–5 weeks (15–22 person-days) |
| AI Red Team Pentest Add-on, not a tier | + €990 | 10–14 business days |
What Changes the Price
What you're testing
A marketing site, a single logged-in app, an app with an API, a multi-tenant SaaS platform, or a mobile app + backend — each has a very different attack surface.
Roles behind the login
Each additional role (admin, standard user, guest, partner) is tested separately, and cross-role access is where most real findings come from.
Authentication complexity
Email/password is cheap to test. SSO/OAuth and especially SAML/MFA/custom flows have to be exercised end to end.
API surface
REST, GraphQL, and webhooks each add dedicated test time — including undocumented endpoints.
Application size
Distinct screens plus API endpoints. More surface area means more manual testing hours.
What prompted the engagement
A customer questionnaire, SOC 2/ISO 27001 audit, or NIS2/DORA/CRA readiness can require a full penetration test even where your raw score would suggest a smaller tier.
Price Your Engagement
Seven questions, published prices, no call required. The figure below updates as you answer.
Published price. Confirmed after a short scoping review.
Why this tier
- TargetMarketing site, no login
- RolesNone — no login
- AuthNo authentication
- APINone
- SizeUnder 20
- DriverInternal, no external driver
- Score0 of 27
- Duration5 business days
You receive
- Automated discovery (Burp Suite Professional, Nuclei, OWASP ZAP)
- Manual validation of all Critical/High findings
- CVSS v3.1 vectors + CWE classification
- OWASP Top 10:2025 mapping
- Signed Attestation Letter
- One round of clarification questions
- Deep manual exploitation — not included
- Business-logic testing — not included
- Remediation retest (available as add-on, +€200) — not included
Indicative only. Final scope is agreed in writing before any testing begins. Prices exclude VAT. Not a CREST-accredited test — Moldova has no CREST accreditation path.
Want it as a document?
The price is above — you don't need to give us anything for it. If you want this scope summary emailed so you can forward it to your auditor or your buyer, we'll send it.
Indicative only. Final scope is agreed in writing before any testing begins. A Vulnerability Assessment (€539) is not a full penetration test — most auditors and enterprise vendor security reviews specifically requiring "penetration test" evidence will not accept it as a substitute. All prices exclude VAT. Optimum Web is not CREST-accredited.
Frequently Asked Questions
How accurate is the price this calculator shows?
It's a published starting point, not a placeholder. The four prices and duration ranges match what we publish on each tier's own page. The exact figure within a tier's range is confirmed after a short scoping review — but the tier and the floor price are real, not "contact us for pricing."
Why do you ask what prompted the test (question 6)?
Because it changes what the report has to contain, and sometimes the tier itself. A customer questionnaire, a SOC 2 / ISO 27001 audit, or NIS2/DORA/CRA readiness normally requires evidence of an independent penetration test — a Vulnerability Assessment usually isn't accepted as a substitute. If your answers score low but your driver requires a real pentest, we raise the recommended tier and explain why.
Is a €539 result a real penetration test?
No — and we say so on the result. €539 buys a Vulnerability Assessment: automated discovery plus manual validation of the high-severity findings. It's a legitimate, audit-recognised deliverable for some controls (ISO 27001 Annex A.8.8), but it does not include deep manual exploitation or business-logic testing. Where a customer or auditor specifically asks for "a penetration test," start from the Focused tier instead.
What if my score lands right on a tier boundary?
Treat the calculator as a starting point for a conversation, not a binding quote. If your scope is close to a boundary, book a 30-minute scoping call — we'll confirm the tier and the exact number in writing before anything is agreed.
Do these prices include VAT?
No. All prices shown are fixed prices excluding VAT, consistent with the rest of our security pricing.
Is a remediation retest included?
It depends on the tier. The Vulnerability Assessment and Focused Penetration Test tiers do not include a retest by default — it's a paid add-on (+€200 / +€500). The Standard and Enterprise tiers include a remediation retest as standard.
What if my platform has AI or LLM features?
Prompt injection, data leakage, and agent-hijacking testing aren't covered by a standard web/API penetration test. If you flag AI/LLM functionality in scope, the calculator adds our AI Red Team Pentest (€990, 10–14 business days) as a separate line item on top of the recommended tier.
Will you always sell me the tier the calculator recommends?
No. The calculator is a scoping starting point, not a sales script. If your driver is purely internal (or a cyber insurance renewal) and the calculator recommends a tier above the Vulnerability Assessment, the result shows a smaller first-step option at €539 — with an honest note that it isn't a substitute for a penetration test where an auditor or customer specifically requires one.
