What does a penetration test cost in 2026?
Short answer: between $2,500 and $50,000 for a one-shot engagement, or $2,999+/year per target on a continuous platform — unless your threat model fits a $149 verified audit. Here are the real ranges, what drives them, and a calculator for your own numbers.
The honest price ranges
| Who | Model | Price | What that buys |
|---|---|---|---|
| One-shot consultancy | Per engagement | $5,000–$15,000 typical | Full market spans $2,500 for a scoped 1–2 day test to $50,000+ for large, multi-target engagements. |
| Astra Security | Continuous hybrid, per target | $2,999–$9,999 / yr | Pentest Auto $2,999/yr per target; Expert plans $5,999–$9,999/yr. |
| Aikido Security | Pentest add-on | ~$4,000+ | Sold as an add-on on top of their platform plans. |
| Beagle Security | Per-app subscription | $99–$299 / mo | Per-app monthly subscriptions; automated testing with human review at the top tiers. |
| Notra | One-time, per audit | $149 | Flat, published, no sales call. Re-tests cost the same $149. |
Platform prices (Astra, Aikido, Beagle) are their public pricing as of September 2026 — check their sites for current terms; quotes vary with scope. Consultancy ranges reflect common market quotes, not a published list.
What actually drives the price
Number of targets
Most engagement quotes are per app or per target. Three web apps roughly triples a one-shot price — which is also why per-target subscriptions get expensive fast.
Depth
A scoped external scan costs a fraction of weeks-long testing with authenticated sessions, multiple roles, and business-logic hunting. Authenticated testing alone moves quotes up a tier.
Human attestations
If your deliverable is a signed letter for SOC 2 or an enterprise reviewer, you're paying for a certified human to sign their name. That's a large slice of what consultancies charge.
Re-tests
You fixed the findings — now prove it. Consultancies often charge for a re-scan or put you back in the queue. Re-test frequency is where annual costs quietly double.
Where Notra fits — and what you give up
| Notra | Price | What it covers |
|---|---|---|
| Free scorecard | $0 | Grades your site in about a minute. No card, no sales call. |
| First verified audit | $0 | Free trial Deep Audit after you prove domain ownership. |
| Deep Audit | $149 one-time | Full unauthenticated deep budget; report in ~35–60 minutes with per-finding exploit evidence. |
| Deep+ | $299 one-time | Adds authenticated testing with your session cookie and an extended request ceiling. |
| Monitor | $49 / domain / mo | Daily re-scans with email on every change — between full audits. |
The honest rows: a Notra audit comes with no attestation letter — it's evidence, not a signed assurance from a certified assessor — and no human chaining of novel multi-step, business-logic attacks. If either of those is the deliverable you need, a manual engagement is the right buy and the ranges above are what it costs. Where Notra wins is the verified-evidence slice, same-day, at a price that makes re-testing after every release affordable. The full trade-off is laid out in Notra vs manual penetration testing.
Price your own year
Pick your app count and re-test cadence. The comparison uses the consultancy math from the table above ($5,000 per app per engagement, ~$1,500 per re-test, attestation included) against Notra's flat $149 per audit.
Signed letter from a certified assessor, for auditors.
2 × $5,000 + 2 × $1,500 re-tests · attestation included in the quote
| Free scorecard | $0 |
| 2 apps × 2 re-tests × Deep Audit | $596 |
| Human attestation | $0 (not offered) |
per year, vs the consultancy math above
Cost questions, answered straight
Why is there such a huge range — $2,500 to $50,000?
You're buying different amounts of human time and different deliverables. A $2,500 test is usually one tester for a couple of days on one app. A $50,000 engagement is weeks of multi-role testing with re-tests and an attestation letter your auditor accepts. The number mostly tracks targets × depth × human attestations × re-tests — which is what the calculator above lets you price out.
Is a $149 audit a 'real' penetration test?
It is a real test with a narrower slice: Notra autonomously verifies the exploit classes it has proofs for — injection, exposed secrets and files, JWT and auth weaknesses, CVE-exposed components — and ships the exact request/response evidence for every finding. What it does not do is human creativity (novel multi-step chaining, business-logic abuse) or a signed attestation letter. See the honest side-by-side with manual pentests below.
Can I use the results for SOC 2 or a customer security review?
You can share a Notra report as evidence of proactive testing — every finding carries its own proof, and runs are manifest-pinned. But it is not a signed attestation from a certified assessor, and some auditors specifically want that letter. If the letter is the deliverable, budget for a manual engagement; the consultancy quotes in the table above are what that costs.
How often should I re-test?
Every time your attack surface meaningfully changes: a major release, a new auth flow, a new integration. With one-shot consultancies that means re-entering their queue and paying again; with Notra a re-test is another flat $149 credit you can run the same day. Continuous monitoring at $49/domain/month catches regressions daily in between.
Run the free scorecard first — it grades your site in about a minute and tells you whether a $149 verified audit is worth it.
Next steps: the full pricing page, a sample verified report, the honest manual-pentest comparison, and continuous monitoring for between-audits coverage. Competitor prices referenced from public sources as of September 2026 — if something here is out of date, tell us.