Pentest cost · pricing · quotes

What a penetration test actually costs — no calculator fantasy.

An external penetration test in Germany typically costs €7,000 to €16,000 for a single application or API. Larger engagements — network with Active Directory, a cloud landing zone, SAP — tend to run €12,000 to €30,000. These figures are indicative and depend on actual scope, not on the sales conversation.

Indicative price ranges·Senior-led·Retest itemised in quote
Price ranges by engagement type

Typical scope, typical duration, typical price range.

All figures are indicative orientation only — the binding quote always follows the scoping conversation about your actual environment.

EngagementTypical scopeTester-daysIndicative range
Web application / API
One application with a standard feature set, one role set, one or two environments.5–10 7.000 € – 16.000 €
External perimeter / network
Publicly reachable IP ranges, exposed services, VPN / email gateways.4–8 6.000 € – 13.000 €
Internal network / Active Directory
Assumed-breach starting point, AD domain with a few thousand objects, Tier-0 paths.8–15 12.000 € – 24.000 €
Cloud (Azure / AWS / M365)
One or two subscriptions/accounts, IAM review, landing zone, CI/CD integration.8–14 12.000 € – 22.000 €
Mobile app (iOS/Android)
One platform, backend API included, reversing and runtime analysis.6–10 8.000 € – 15.000 €
SAP
SAP authorisations, RFC gateway, SAProuter, selected BTP integrations.10–18 16.000 € – 30.000 €
AI / LLM
One LLM-powered assistant or agent including RAG pipeline and tool calls.7–12 10.000 € – 19.000 €

A focused red team or a DORA TLPT format under TIBER-EU runs over weeks and typically sits between €35,000 and €85,000 — see our red teaming page for detail.

What drives the price

Seven factors that determine the day count.

  • 01Scope: number of applications, roles, environments, IP ranges or AD objects.
  • 02Authenticated vs. unauthenticated: multi-role testing needs more days than an outside-in view alone.
  • 03Compliance evidence: structured evidence for ISO 27001, DORA, NIS2 or TISAX adds documentation and mapping work.
  • 04Remediation support: a remediation call or several alignment rounds with your engineering team.
  • 05Retest scope: verification of individual findings versus a full re-scan after fixes.
  • 06Staffing: senior operators throughout vs. junior offshore teams with a senior review at the end.
  • 07Reporting depth: an executive summary alone, or an additional technical report with CVSS, PoC and ticket export.
What's always included

Whatever the scope — these are standard.

Senior operators

No junior team with a senior signature at the end — a senior operator runs the test.

Manual depth per OWASP WSTG/ASVS

Scanners are used only as mapping aids — business logic and chained attacks are manually verified.

Executive and technical report

Management-ready summary plus a technical write-up with CVSS and proof-of-concept.

Remediation call

One session with your team to prioritise findings and clarify open questions.

Retest itemised in the quote

A verification retest is a standard line item in every quote — scope and window are stated explicitly.

Why cheaper isn't cheaper

A scanner report with a cover page doesn't solve a security problem.

Quotes well below the ranges above almost always come from the same place: automated scans, little to no manual verification, and a report that copies findings from tool output instead of exploiting and assessing them. That may be enough for a first glance — not for evidence you can show an auditor, customer or supervisor.

Senior-led, manual work costs more per day but needs fewer days for the same outcome — and finds business-logic flaws and chained attacks no scanner sees. The price gap is rarely margin; it's the time actually spent on the system.

FAQ

Frequently asked questions about pentest cost

What does a penetration test cost?

An external penetration test in Germany typically costs €7,000 to €16,000 for a single application or API, depending on scope, roles and required compliance evidence. Larger engagements — internal network with Active Directory, a cloud landing zone or SAP — tend to run €12,000 to €30,000. A focused red team or a DORA TLPT sits well above that, usually in the €35,000 to €85,000 range.

Why are there no fixed prices?

Every environment is different: the number of roles, environments, integrations and compliance requirements drives the day count. A serious quote follows a short scoping conversation, not a price calculator — otherwise you end up either over- or under-tested.

Is a retest included?

A verification retest is itemised in the quote as its own line — scope and timing are agreed during scoping, not billed as a hidden add-on after the project closes.

What does a pentest for ISO 27001 cost?

The test itself sits in the same ranges as above. On top comes effort for structured evidence — mapping to A.8.29, CVSS scoring, hand-off into your risk register — typically a 10–20% premium over a test with no audit requirement.

How quickly can I get a quote?

After a short scoping call, usually within 3–5 business days. Start is typically possible within 2–4 weeks.

Do red team / TIBER / DORA TLPT engagements cost more?

Yes, considerably. A scenario-based red team or a TLPT format under TIBER-EU / DORA Article 26 runs over weeks rather than days, requires separated threat-intelligence and attack roles, and typically sits between €35,000 and €85,000.

Clarify scope, get a binding quote.

In a short scoping call we pin down scope, roles and compliance requirements — and you get a price range that matches your actual environment.

Pentest cost & scoping updates

Short updates on pricing trends, scoping practice and compliance requirements.

For CISOs and procurement teams planning pentest budgets. Kept short, no marketing.

Subscribe to cost updates

Concise, infrequent, opt out any time.