// buying guide

Asking what a penetration test costs is like asking what a renovation costs: the honest answer starts with "it depends", but that is not a useful place to leave you. These are the bands we see in the Australian market and the bands we quote ourselves, in AUD excluding GST.

The short answer: a focused test of a small web application typically starts around $6,000 to $8,000. Most single-application engagements land between $10,000 and $25,000. Large or multi-target programs run $30,000 and up. Almost everything else about pricing is an explanation of why a given engagement sits where it does in that range.

Typical prices by engagement type

EngagementTypical effortIndicative range (AUD, ex GST)
Small web app (one role, few screens)3–5 days$6,000 – $10,000
Standard web app + API (2–3 roles)5–10 days$10,000 – $20,000
Mobile app (iOS + Android + backend)7–12 days$14,000 – $25,000
External network (modest perimeter)3–5 days$6,000 – $12,000
Internal network / Active Directory5–10 days$10,000 – $22,000
Cloud security review (one platform)4–8 days$8,000 – $18,000
Multi-target annual programvaries$30,000+

Treat these as calibration, not a menu. A quote outside these bands is not automatically wrong, but the vendor should be able to explain why, specifically, in terms of your scope.

The four levers

Size of the surface. Roles, screens, APIs, hosts. This is the obvious one and still the one people under-count.

Complexity. Custom workflows, payments, multi-tenant, SSO, mobile plus API. Complexity is why two 'web apps' are not the same quote.

Depth and access. Grey-box with accounts finds more than black-box in the same number of days. You are buying coverage, not mystery.

Reporting burden. A letter for a customer is cheap. A mapped pack for APRA or ISO, with a debrief to a risk committee, is a different document.

How to compare quotes

Ignore day-rate theatre. Compare: who actually tests, whether findings are verified, whether retest is included, whether the scope lists roles, and whether the report has an executive summary. The cheapest scan with a pentest label is the most expensive when you have to buy a second test for the auditor.

Ready to get a number for your scope? Ask for a quote.