Skip to content
Commercial transparency

How we price a project

We don't publish fixed price lists. Every organization has a different perimeter, risk profile, and timeline — your quote reflects what actually needs to be tested, not a generic package.

Why no public prices

Penetration testing isn't off-the-shelf

A displayed price without context sets wrong expectations: you either overpay for a small scope or underbuy for a complex environment.

1

Perimeters differ radically

An internal app, 500 users, and a hybrid datacenter can't cost the same — in effort or risk.

2

Testing depth is negotiated

Black-box, grey-box, or white-box, with or without exploitation, with retest — each changes team effort.

3

Compliance adds deliverables

NIS2, GDPR, or auditor requirements mean extra documentation, not just a standard technical report.

Cost drivers

What shapes the final quote

In the initial consultation we map these parameters together — you get a clear estimate, not a number from a table.

Attack surface

Number of apps, IPs, domains, environments (prod, staging), external integrations.

Type of testing

Network, web/API, mobile, cloud, social engineering — standalone or combined.

Access and context

Credentials, documentation, VPN, on-site: more context means more efficient testing, sometimes lower cost.

Rules of engagement

Test windows, DoS restrictions, critical systems — they define how we work and how long it takes.

Deliverables and retest

Executive report, board briefing, retest included or separate, post-remediation support.

Urgency and schedule

Standard timeline (2–4 weeks) vs. accelerated project with dedicated resources.

Process

From first contact to quote

You won't see "from X €" on the site. You'll see exactly what your organization buys before you sign.

1

Discovery call (30–45 min)

We understand goals: audit, incident, contract, NIS2. No obligation.

2

Documented scoping

Perimeter, exclusions, ROE, deliverables — everything in writing before start.

3

Commercial proposal

Estimate in person-days, schedule, total price. Typical response within one business day.

4

Refinement and kickoff

We adjust scope if budget is fixed — prioritize what matters most.

What you get

Included in every standard project

Regardless of quote size, deliverable structure stays predictable.

  • Technical report with severities (CVSS) and reproduction steps
  • Executive summary for leadership
  • Findings prioritized by business impact
  • Actionable remediation guidance
  • Clarification support during the project
  • Retest for critical vulnerabilities (as agreed in scope)

Clarity

What we don't promise at a bargain market price

  • Automated scans sold as a full pentest
  • Reports without manual validation
  • No remediation or retest support
  • Vague scope that expands without agreement

Questions

About quotes and budget

Do you have a minimum or ballpark price?

We can indicate a range after the scoping call, based on complexity. Without a defined perimeter, any figure would be misleading.

Can we get multiple vendor quotes?

Yes. For a fair comparison, ensure scope, deliverables, and retest are identical across quotes.

Do you work with a fixed budget?

Yes. Tell us your limit — we'll propose a realistic scope that maximizes risk coverage within available budget.

B2B invoicing and contracts?

Contract, NDA, invoice in USD or EUR. Milestone payments for larger projects.

Get a quote based on your context

Send a short perimeter description or book a call — we'll respond with a clear proposal, no billing surprises.