~$ rebootworks
IT & security

how much does a pentest cost?

it's driven by the size of the attack surface: number of applications, roles, and integrations. a single web app with two user roles is a few days' work. we quote one fixed number after a short scoping call, and the retest is included.

there's no price list, because two companies asking for "a pentest" can be asking for a day of work or a month of it. what we can tell you is exactly what moves the number, so you can guess roughly where you land before we talk.

what drives the price

  • applications: one customer-facing app is one thing. an app, an admin panel, a public API and a mobile client that talks to all of them is four.
  • roles: each user type (visitor, customer, staff, admin) is another set of permissions to test against every other. access control between roles is where the serious findings usually are, so this scales the work more than people expect.
  • integrations: payment providers, single sign-on, third-party APIs, file storage. every boundary is a place for something to go wrong.

lines of code and traffic volume aren't on that list, which surprises people. a small app with six roles is more work than a large one with two.

how the quote works

a short scoping call, then one fixed number in writing. it covers the testing, both documents (the one-page summary and the developer detail), and a retest once you've fixed what we found. we don't bill by the hour, and the scoping call is free, the same as every first conversation we have. the number holds unless you add something to the scope, in which case you get the new number before we touch it, as with any fixed price.

when you write, list the applications, the user roles and the third-party services involved. that's enough for us to come back with a number instead of more questions.

read it in context