Asking what a penetration test costs is like asking what a renovation costs: the honest answer starts with "it depends", but that is not a useful place to leave you. These are the bands we see in the Australian market and the bands we quote ourselves, in AUD excluding GST.
The short answer: a focused test of a small web application typically starts around $6,000 to $8,000. Most single-application engagements land between $10,000 and $25,000. Large or multi-target programs run $30,000 and up. Almost everything else about pricing is an explanation of why a given engagement sits where it does in that range.
Typical prices by engagement type
| Engagement | Typical effort | Indicative range (AUD, ex GST) |
|---|---|---|
| Small web app (one role, few screens) | 3–5 days | $6,000 – $10,000 |
| Standard web app + API (2–3 roles) | 5–10 days | $10,000 – $20,000 |
| Mobile app (iOS + Android + backend) | 7–12 days | $14,000 – $25,000 |
| External network (modest perimeter) | 3–5 days | $6,000 – $12,000 |
| Internal network / Active Directory | 5–10 days | $10,000 – $22,000 |
| Cloud security review (one platform) | 4–8 days | $8,000 – $18,000 |
| Multi-target annual program | varies | $30,000+ |
Treat these as calibration, not a menu. A quote outside these bands is not automatically wrong, but the vendor should be able to explain why, specifically, in terms of your scope.
The four levers
Size of the surface. Roles, screens, APIs, hosts. This is the obvious one and still the one people under-count.
Complexity. Custom workflows, payments, multi-tenant, SSO, mobile plus API. Complexity is why two 'web apps' are not the same quote.
Depth and access. Grey-box with accounts finds more than black-box in the same number of days. You are buying coverage, not mystery.
Reporting burden. A letter for a customer is cheap. A mapped pack for APRA or ISO, with a debrief to a risk committee, is a different document.
How to compare quotes
Ignore day-rate theatre. Compare: who actually tests, whether findings are verified, whether retest is included, whether the scope lists roles, and whether the report has an executive summary. The cheapest scan with a pentest label is the most expensive when you have to buy a second test for the auditor.
Ready to get a number for your scope? Ask for a quote.