Penetration testing pricing varies more than vulnerability assessment pricing, because the methodology, depth, and target system type can vary so much from one engagement to the next.
Methodology is one of the biggest cost factors. Black box testing simulates a real outsider with zero knowledge, which takes longer since testers have to do their own reconnaissance before they can even start looking for weaknesses. White box testing, with full access and documentation provided upfront, tends to move faster and surface more findings per hour.
Scope obviously matters too — a single web application test is a much smaller engagement than a full network penetration test, and both are smaller than an engagement that includes embedded hardware or firmware.
Reverse engineering hardware layouts and firmware code takes specialized tooling, equipment, and time that standard web or network testing doesn't require. Testers often need to physically handle devices, extract and analyze firmware images, and work without the kind of documentation that's readily available for standard software.
If your scope includes embedded devices, IoT hardware, or custom firmware, expect that portion of the engagement to be priced and scoped separately from any software or network components.
Rules of engagement and scope get defined in writing before any pricing is finalized. That scoping conversation — what's in scope, what techniques are acceptable, what testing windows work for you — is what makes the resulting quote accurate instead of a rough guess.
Be upfront during scoping about any systems that are particularly fragile or business-critical. It doesn't reduce the thoroughness of testing, but it does affect timing and technique choices, which can affect the final price.
The methodology stays the same, but the report format is tailored to satisfy PCI DSS 11.3 documentation requirements, which we account for during scoping rather than treating as a separate add-on.
Not inherently more expensive, but production testing often requires more careful scheduling and communication to avoid disrupting live operations, which gets factored into the timeline during scoping.
If testing surfaces a critical issue mid-engagement, we flag it immediately rather than waiting for the final report — the goal is to get you information you can act on as soon as it's found, not sit on it until a deadline.