QuietHours by securITDiscuss your scope

Testing

Penetration testing pricing in Europe: what actually drives the number

Penetration testing is priced on time, and time is driven by a small number of factors that buyers can influence. Understanding them is the difference between negotiating a discount and negotiating a better test.

Minimalist bar composition representing cost drivers

Ask five European providers to quote the same web application and you can reasonably receive proposals ranging from a few thousand euros to well into five figures. That spread is not primarily greed. It reflects genuinely different amounts of work being proposed under the same word.

The pricing model, stated plainly

Essentially all penetration testing is priced as tester-days multiplied by a day rate, with some allowance for reporting and project management. Everything else is presentation. So there are exactly two questions when comparing proposals: how many days, and doing what?

What genuinely drives the day count

DriverEffect on effortCan you influence it?
Number of distinct authorisation rolesLarge — each role pair multiplies access control testingSometimes: test the risky pairs, not all combinations
Distinct business workflowsLarge — logic testing is per-workflow and manualYes: prioritise the workflows that move money or data
Quality of documentation providedModerate — poor docs add discovery timeYes, and this is the cheapest saving available
Authenticated vs unauthenticatedIncreases effort, and increases value moreYes — supply accounts, do not remove the scope
Environment stabilityModerate to large — a broken staging environment burns daysYes: verify it works before the window opens
Raw host countSmall beyond a point — identical hosts are near-freeYes: group identical builds explicitly
Report depth and mapping to frameworksSmall but realYes: ask for what you need, not everything
RetestTypically 10–20% of the original effortInclude it — it is the highest-value line item

Rough European ranges

These are indicative, vary considerably by country and provider profile, and should be treated as sanity checks rather than benchmarks. Rates in Western and Northern Europe generally sit at the higher end; Baltic and Central European providers frequently deliver comparable senior work at lower rates because their cost base differs, not their competence.

EngagementTypical effortIndicative range
Small web application, 2 roles, authenticated5–8 days€4,000 – €10,000
Complex multi-tenant platform with API15–25 days€12,000 – €35,000
External infrastructure, moderate estate4–7 days€3,000 – €9,000
Internal assumed-breach assessment8–15 days€7,000 – €20,000
Objective-led red team25–60 days€30,000 – €120,000+
Retest of prior findings1–3 days€1,000 – €4,000

Where the cheap quotes save money

A quote at a third of the market rate is not usually fraudulent. It is usually honest about a smaller scope in language the buyer does not decode. The savings almost always come from the same places.

  • Automated tooling with a human writing the summary, rather than manual business logic testing.
  • Junior testers with limited senior review. Ask who reviews findings before delivery.
  • Reporting compressed to a template with minimal per-finding analysis.
  • No retest, so the engagement ends at the least useful moment.
  • Unauthenticated only, which removes the most productive part of the test.
  • A short window that cannot accommodate the discovery that testing produces — the interesting path is usually found on day four.

How to reduce cost without reducing value

  1. Provide good documentation up front: architecture diagram, API specification, role matrix, and a list of the workflows that matter commercially. This can remove one to two days of discovery.
  2. Have accounts provisioned and verified before the window opens. Credential problems on day one are extremely common and directly waste billed time.
  3. Confirm the environment is stable and populated with representative test data.
  4. Group identical assets explicitly rather than listing 200 hosts that are three builds.
  5. Prioritise honestly. Ask the provider to spend the budget on your two most valuable workflows rather than covering everything shallowly.
  6. Bundle retesting into the original contract rather than mobilising a separate engagement later.
  7. Book outside peak periods if your timeline allows. Capacity pricing is real.

Guarantees and what they mean

Some providers offer a no-findings or validated-findings guarantee: if the engagement produces no decision-useful outcome within the agreed scope, the fee is waived. Structured properly this is a genuine risk-sharing mechanism. Structured loosely it creates an incentive to inflate low-severity issues into findings.

If you are offered one, read the definition. A guarantee tied to validated, reproducible findings or a documented improvement plan against an agreed scope is meaningful. A guarantee tied to finding something is an invitation to pad the report.

Frequently asked questions

How much does a penetration test cost in Europe?

Most engagements are priced as tester-days times a day rate. A small authenticated web application test commonly falls in the €4,000–€10,000 range, a complex platform €12,000–€35,000, and an objective-led red team €30,000 and upward. Rates vary considerably by country and provider profile, so treat any range as a sanity check rather than a benchmark.

Why do penetration test quotes vary so much?

Because the same word covers very different amounts of work. The main variables are tester-days, whether testing is manual or largely automated, whether it is authenticated across multiple roles, the seniority of the testers, and whether reporting and retesting are included. Asking every provider to state tester-days makes proposals comparable.

Is retesting worth paying for?

It is usually the highest-value line item in the engagement. Retesting typically costs 10–20% of the original effort and converts an unverified remediation claim into evidence — which is what compliance frameworks, auditors and customers actually want. Bundle it into the original contract rather than mobilising separately.

Talk to the team

Need this tested rather than described?

QuietHours is a European cybersecurity practice operated by the securIT team. Send us the system, service, or control you are concerned about and we will help turn it into a workable scope.

Discuss your scope

Related reading