How we price a project
We don't publish fixed price lists. Every organization has a different perimeter, risk profile, and timeline — your quote reflects what actually needs to be tested, not a generic package.

Why no public prices
Penetration testing isn't off-the-shelf
A displayed price without context sets wrong expectations: you either overpay for a small scope or underbuy for a complex environment.
Perimeters differ radically
An internal app, 500 users, and a hybrid datacenter can't cost the same — in effort or risk.
Testing depth is negotiated
Black-box, grey-box, or white-box, with or without exploitation, with retest — each changes team effort.
Compliance adds deliverables
NIS2, GDPR, or auditor requirements mean extra documentation, not just a standard technical report.
Cost drivers
What shapes the final quote
In the initial consultation we map these parameters together — you get a clear estimate, not a number from a table.
Attack surface
Number of apps, IPs, domains, environments (prod, staging), external integrations.
Type of testing
Network, web/API, mobile, cloud, social engineering — standalone or combined.
Access and context
Credentials, documentation, VPN, on-site: more context means more efficient testing, sometimes lower cost.
Rules of engagement
Test windows, DoS restrictions, critical systems — they define how we work and how long it takes.
Deliverables and retest
Executive report, board briefing, retest included or separate, post-remediation support.
Urgency and schedule
Standard timeline (2–4 weeks) vs. accelerated project with dedicated resources.
Process
From first contact to quote
You won't see "from X €" on the site. You'll see exactly what your organization buys before you sign.
Discovery call (30–45 min)
We understand goals: audit, incident, contract, NIS2. No obligation.
Documented scoping
Perimeter, exclusions, ROE, deliverables — everything in writing before start.
Commercial proposal
Estimate in person-days, schedule, total price. Typical response within one business day.
Refinement and kickoff
We adjust scope if budget is fixed — prioritize what matters most.
What you get
Included in every standard project
Regardless of quote size, deliverable structure stays predictable.
- Technical report with severities (CVSS) and reproduction steps
- Executive summary for leadership
- Findings prioritized by business impact
- Actionable remediation guidance
- Clarification support during the project
- Retest for critical vulnerabilities (as agreed in scope)
Clarity
What we don't promise at a bargain market price
- Automated scans sold as a full pentest
- Reports without manual validation
- No remediation or retest support
- Vague scope that expands without agreement
Questions
About quotes and budget
Do you have a minimum or ballpark price?
We can indicate a range after the scoping call, based on complexity. Without a defined perimeter, any figure would be misleading.
Can we get multiple vendor quotes?
Yes. For a fair comparison, ensure scope, deliverables, and retest are identical across quotes.
Do you work with a fixed budget?
Yes. Tell us your limit — we'll propose a realistic scope that maximizes risk coverage within available budget.
B2B invoicing and contracts?
Contract, NDA, invoice in USD or EUR. Milestone payments for larger projects.
Get a quote based on your context
Send a short perimeter description or book a call — we'll respond with a clear proposal, no billing surprises.