Live from ThreatFeed

Fixed-Price Testing

Penetration Testing Costs, Published in Full

Fixed scope, fixed price, published. If your environment fits one of the tiers below, you can book a penetration test without a sales conversation and know the number before you start.

Why These Numbers Are Public

A lower price, not a shorter test.

Penetration testing is usually quoted privately because scope genuinely varies, and for unusual environments it should be. But most engagements are not unusual. An external estate of thirty hosts, or a web application with three roles, is a known quantity, and treating it as a mystery mostly serves to keep the price negotiable.

The difference is structural. Engagements are delivered by a principal consultant working directly with you: there is no sales organization to fund, no bench to keep occupied, and no project management layer sitting between the testing and the report. Scopes are repeatable rather than reinvented for every client, so the hours in an engagement go into testing instead of into deciding how the engagement will run.

The result is a lower published price that reflects a lower cost of delivery, not a shallower test. The sample report is there so you can check that claim rather than take it on faith.

What a fixed price does not change. Scope, rules of engagement, testing windows, and escalation contacts are still agreed in writing before any testing begins. A published price sets the cost, not the care.

No penetration test identifies every vulnerability, and no test makes an organization secure. What a well-executed one produces is evidence-based prioritization: a shorter list of things genuinely worth your engineering time, with proof of why each one belongs on it.

Each tier below names its limits explicitly. Scope inside those limits is the published price. Scope past them is quoted against the same rates, with the triggers listed further down so nothing arrives as a surprise at invoice time.

Published Tiers

Four scopes, four prices

Three tiers each cover a single domain; the fourth runs both network domains as one engagement. Application testing attaches to any of them for $4,500. Every tier is a complete engagement including the report, the attestation letter, the remediation walkthrough, and one retest.

Perimeter Test

$5,500 fixed, all inclusive

External network penetration test of your Internet-facing estate. The common answer to an insurance renewal, a customer security questionnaire, or a first independent test.

Scope limits

  • Up to 32 live external hosts
  • One testing window
  • Unauthenticated perspective

Testing performed

  • Attack surface discovery and service enumeration
  • Manual validation of every reported finding
  • Controlled exploitation within the agreed rules of engagement
  • Credential attacks against exposed authentication
  • Attack-path narrative for anything chainable

Commonly bought for: Cyber insurance renewals, vendor questionnaires, annual due diligence.

Internal Test

$7,500 fixed, all inclusive

Internal network penetration test from an assumed foothold. Answers what an attacker reaches after a phished user, a compromised laptop, or a third party gets inside — which is where most real incidents are actually decided.

Scope limits

  • One internal network segment, up to 512 hosts
  • One testing window
  • Delivered through a shipped appliance or your VPN

Testing performed

  • Active Directory configuration and trust abuse
  • Credential exposure, reuse, and harvesting
  • Privilege escalation to domain and local administrator
  • Lateral movement between hosts and segments
  • Network segmentation validation
  • Attack-path analysis from foothold to critical asset

Commonly bought for: Segmentation validation, insurer or board requirements, assurance after an incident.

Application Test

$9,500 fixed, all inclusive

Authenticated web application and API penetration test against a single application. The scope most SOC 2 auditors and enterprise customers are actually asking for.

Scope limits

  • One application and its supporting API
  • Up to 3 authenticated roles
  • Up to roughly 40 distinct endpoints or screens

Testing performed

  • Authenticated testing from every provided role
  • Access control and authorization boundary testing
  • Injection, deserialization, and business logic abuse
  • API-specific testing, including undocumented endpoints
  • Session management and authentication flow review

Commonly bought for: SOC 2 Type II, enterprise customer security review, pre-launch assurance.

Full Network

$12,000 fixed, all inclusive

External and internal network penetration testing in one coordinated engagement, with the external result feeding the internal phase. This is the scope most compliance frameworks mean by a network penetration test. Application testing is added separately.

Scope limits

  • Up to 32 live external hosts
  • One internal network segment, up to 512 hosts
  • One testing window covering both phases

Testing performed

  • Everything in Perimeter and Internal
  • External findings carried forward into the internal phase
  • End-to-end attack paths from Internet-facing entry to critical asset
  • Segmentation validation against the external perspective
  • A single report, attestation letter, and retest covering both

Commonly bought for: SOC 2 Type II, PCI DSS, insurer and board-facing programs.

Prices are in USD and cover testing performed remotely from the United States. Travel, if you require on-site testing, is quoted separately at cost.

Who Performs the Testing

The same tester, start to finish

Every engagement on this page is scoped, tested, written up, and walked through by the same principal consultant, who has held offensive security certifications for 16 years, since 2010. Work is never subcontracted and never handed to a rotating bench. The price reflects how the practice is structured, not who is doing the work.

Certifications held

  • CISSP badge CISSP — Certified Information Systems Security Professional ISC2 · Issued 2017 · Valid through 2027
  • GCFE badge GCFE — GIAC Certified Forensic Examiner GIAC · Issued 2012 · Valid through 2028
  • GSEC badge GSEC — GIAC Security Essentials GIAC · Issued 2010 · Valid through 2030
  • GPEN badge GPEN — GIAC Penetration Tester GIAC · Issued 2010 · Valid through 2030

Education

  • Harvard University logo Master of Liberal Arts (ALM), Information Management Systems Harvard University · 2024
  • Harvard Extension School logo Graduate Certificate in Cybersecurity Harvard Extension School · 2022

The platform is public. Go and look at it. Craft Consulting Solutions builds and runs ThreatFeed, a live threat-intelligence platform: executive briefings from daily to quarterly, CVE and breach search, MITRE ATT&CK and ATLAS technique ranking, and current adversary and tooling analysis. It is open to read, with nothing to sign up for. A practice this size running a live intelligence platform is also the answer to whether a lower price means a smaller capability.

Certifications are verifiable with the issuing body. Any certification past its expiry is removed from this site automatically rather than left to be noticed.

Included at Every Tier

The things usually billed separately

Each of the following is included in the published price. Several of them are the reason an engagement that looks cheaper on the quote turns out not to be.

One free retest within 90 days

Fix the findings and we verify them, once, at no charge. The retest produces an updated report showing each finding as resolved or still present, which is the document an auditor or customer actually wants to see.

Letter of attestation

A signed summary letter suitable for auditors, customers, and insurers, stating what was tested, when, by whom, and against what methodology. Issued with the report, not on request.

Report within 7 business days

The written report is delivered within seven business days of the testing window closing, and usually sooner. Reporting is where most engagements quietly slip, so seven is a committed date rather than an estimate.

Critical findings sent same day

Anything critical is reported the day it is confirmed, with enough detail to act on immediately. Nothing severe waits in a queue for the final document.

No discovery call required

If your scope fits a published tier, you can book and pay without a sales conversation. A scoping call is available if you want one, but it is not a gate.

Remediation walkthrough

A working session with your engineers to go through the findings, the reproduction steps, and the fixes. Held after delivery, included in the price.

Add-Ons

Common scope changes, also published

Applied on top of any tier. These cover the changes that come up most often, so a second application or a fourth role is a number rather than a negotiation.

Penetration testing add-on pricing
Add-on Price Notes
Add an application $4,500 Application Test depth, attached to any tier. Also the price of each application beyond the first.
Additional authenticated role $750 Per role beyond the first three.
Additional internal segment $3,500 Per segment beyond the first.
Rush scheduling +20% Testing begins within 10 business days.

What Drives the Cost

What makes a penetration test cost more, or less

If you are comparing quotes rather than buying today, these are the variables that actually move the number — on this page and on anyone else’s.

What increases it

  • Live host count on the perimeter, and host count inside each internal segment
  • Number of applications, and authenticated roles within each one, since every role is a separate pass through the same functionality
  • Additional internal segments or physical sites, each needing its own access and its own pass
  • Testing type: red team and assumed-breach work is open-ended pursuit rather than bounded coverage
  • Evidence requirements, where a framework or a customer asks for artifacts beyond the standard report
  • Compressed timelines, which cost more because they displace work already scheduled

What does not, here

  • Account management, project coordination, and the sales process that produced the quote
  • A bench of consultants who have to stay billable between engagements
  • Offices and the fixed overhead a firm carries whether or not it is testing that week
  • The retest, which is included within 90 days rather than sold afterward
  • The attestation letter your auditor needs, which is issued with the report rather than on request
  • The remediation walkthrough, which is part of the engagement rather than follow-on consulting

Why the published numbers are what they are. The practice is deliberately small: one experienced tester working directly with you, with the overhead of a larger firm removed rather than passed along. This is not an introductory rate, a discount, or a shorter engagement. It is the same work without the structure that usually surrounds it.

What Gets Quoted Instead

When a published price stops being honest

A fixed price only works when the scope is bounded. The following fall outside the published tiers and are quoted individually, against the same rates and the same inclusions. Quoting them is not an upsell; it is the alternative to a fixed price that quietly stops covering the work.

  • Scope beyond the published limits for a tier
  • Multiple physical sites or more than one internal segment
  • Cloud configuration review, wireless, or physical testing
  • Red team, assumed-breach, or social engineering engagements
  • Environments requiring cleared, escorted, or on-site testing
  • Retesting requested more than 90 days after delivery

If you are not sure which side of the line you are on, send the scope. Determining that is free and usually takes one message.

Ongoing security leadership is priced separately, as a monthly retainer rather than an engagement. Those rates are published on the security leadership page.

How It Runs

From booking to report

  1. Scope confirmation You send host counts, application URLs, and role descriptions. We confirm in writing that it fits the tier, or tell you what it would be quoted at.
  2. Rules of engagement Testing windows, escalation contacts, out-of-scope systems, and limits on disruptive activity are agreed and signed before anything starts.
  3. Testing Performed by hand within the agreed window. Critical findings are sent the day they are confirmed rather than held for the report.
  4. Report and attestation Delivered within seven business days of the window closing, usually sooner, with the signed attestation letter for your auditor, customer, or insurer.
  5. Walkthrough and retest A working session with your engineers, then one free retest within 90 days producing an updated report showing what is resolved.

Security Leadership

Ongoing advisory is published too

Testing is bought as an engagement. Security leadership is bought as time, so it is priced as a set number of days each month rather than per engagement. The full terms and what each retainer covers are on the security leadership page.

Fractional security leadership retainer pricing
Retainer Commitment Monthly Commonly bought by
Advisory 1 day per month $2,500 Organizations with competent IT and no security owner.
Fractional 2 days per month $4,500 Companies in a SOC 2 or PCI cycle, or answering enterprise customers.
Embedded 4 days per month $8,500 Regulated environments, or bridging a security leadership gap.

Three-month minimum, then month to month with 30 days notice. Retainer clients get priority on the testing calendar rather than a different rate, so the prices above stand either way.

Questions

Before you book

How much does a penetration test cost?

Here, between $5,500 and $12,000 for a standard scope: $5,500 for an external network test, $7,500 for an internal test, $9,500 for a web application and its API, and $12,000 for external and internal network testing together. Those are fixed prices for the scopes published on this page, not estimates, and they include the report, the attestation letter, and one retest.

How much does a SOC 2 penetration test cost?

Most SOC 2 programs need either application testing at $9,500 or external and internal network testing at $12,000, depending on what your auditor put in scope. Both include the signed letter of attestation auditors ask for, at no extra cost. If you are not sure which your auditor means, send us the scope language and we will tell you.

What does a web application penetration test cost?

$9,500 for one application and its supporting API, tested from up to three authenticated roles. Additional applications are $4,500 each and additional roles are $750. Testing covers access control, injection, business logic abuse, and the API endpoints behind the interface, including undocumented ones.

Why is this less than the quotes I have received elsewhere?

Lower cost of delivery, not less testing. There is no sales organization to fund, no bench to keep occupied, and no layer of project management between the testing and the report. The hands-on testing time is comparable to any other credible engagement.

Is a fixed-price test a shallower test?

It is a bounded one, which is different. The limits on each tier are published precisely so that depth is not the variable that quietly absorbs a scope change. Environments past those limits are quoted rather than squeezed into a price that no longer fits them.

Who performs the testing?

The same consultant who writes your report and runs the walkthrough. Engagements are not staffed out to a rotating bench, and the report is not assembled by someone who was not present for the test.

What do my auditors and customers actually receive?

A full technical report with reproduction steps and evidence, and a signed letter of attestation stating what was tested, when, by whom, and against what methodology. The attestation letter is the document most auditors and enterprise customers want; it is included, not billed on request.

How does the free retest work?

Once your team has remediated, request the retest any time within 90 days of delivery. We verify each finding and reissue the report showing it as resolved or still present. One retest per engagement is included; further retests, or requests past 90 days, are quoted.

How soon can testing start?

Typically two to five weeks out, depending on the calendar. Rush scheduling begins testing within ten business days for an additional 20 percent.

Is testing performed remotely?

Yes. External and application testing are performed remotely. Internal testing is performed through a shipped appliance or your VPN, which is why an internal test does not require travel. On-site testing is available where you require it, with travel quoted separately at cost.

Do I have to take a sales call first?

No. If your scope fits a published tier, send it and we return the scoping document and a start date. A call is available whenever you want one, but it is not a gate in front of the price.

Book a test, or check a scope

If your environment fits a published tier, say which one and we will send the scoping document and a start date. If it does not, describe it and we will quote it against the same rates.