Testing
Penetration testing pricing in Europe: what actually drives the number
Penetration testing is priced on time, and time is driven by a small number of factors that buyers can influence. Understanding them is the difference between negotiating a discount and negotiating a better test.

Ask five European providers to quote the same web application and you can reasonably receive proposals ranging from a few thousand euros to well into five figures. That spread is not primarily greed. It reflects genuinely different amounts of work being proposed under the same word.
The pricing model, stated plainly
Essentially all penetration testing is priced as tester-days multiplied by a day rate, with some allowance for reporting and project management. Everything else is presentation. So there are exactly two questions when comparing proposals: how many days, and doing what?
What genuinely drives the day count
| Driver | Effect on effort | Can you influence it? |
|---|---|---|
| Number of distinct authorisation roles | Large — each role pair multiplies access control testing | Sometimes: test the risky pairs, not all combinations |
| Distinct business workflows | Large — logic testing is per-workflow and manual | Yes: prioritise the workflows that move money or data |
| Quality of documentation provided | Moderate — poor docs add discovery time | Yes, and this is the cheapest saving available |
| Authenticated vs unauthenticated | Increases effort, and increases value more | Yes — supply accounts, do not remove the scope |
| Environment stability | Moderate to large — a broken staging environment burns days | Yes: verify it works before the window opens |
| Raw host count | Small beyond a point — identical hosts are near-free | Yes: group identical builds explicitly |
| Report depth and mapping to frameworks | Small but real | Yes: ask for what you need, not everything |
| Retest | Typically 10–20% of the original effort | Include it — it is the highest-value line item |
Rough European ranges
These are indicative, vary considerably by country and provider profile, and should be treated as sanity checks rather than benchmarks. Rates in Western and Northern Europe generally sit at the higher end; Baltic and Central European providers frequently deliver comparable senior work at lower rates because their cost base differs, not their competence.
| Engagement | Typical effort | Indicative range |
|---|---|---|
| Small web application, 2 roles, authenticated | 5–8 days | €4,000 – €10,000 |
| Complex multi-tenant platform with API | 15–25 days | €12,000 – €35,000 |
| External infrastructure, moderate estate | 4–7 days | €3,000 – €9,000 |
| Internal assumed-breach assessment | 8–15 days | €7,000 – €20,000 |
| Objective-led red team | 25–60 days | €30,000 – €120,000+ |
| Retest of prior findings | 1–3 days | €1,000 – €4,000 |
Where the cheap quotes save money
A quote at a third of the market rate is not usually fraudulent. It is usually honest about a smaller scope in language the buyer does not decode. The savings almost always come from the same places.
- Automated tooling with a human writing the summary, rather than manual business logic testing.
- Junior testers with limited senior review. Ask who reviews findings before delivery.
- Reporting compressed to a template with minimal per-finding analysis.
- No retest, so the engagement ends at the least useful moment.
- Unauthenticated only, which removes the most productive part of the test.
- A short window that cannot accommodate the discovery that testing produces — the interesting path is usually found on day four.
How to reduce cost without reducing value
- Provide good documentation up front: architecture diagram, API specification, role matrix, and a list of the workflows that matter commercially. This can remove one to two days of discovery.
- Have accounts provisioned and verified before the window opens. Credential problems on day one are extremely common and directly waste billed time.
- Confirm the environment is stable and populated with representative test data.
- Group identical assets explicitly rather than listing 200 hosts that are three builds.
- Prioritise honestly. Ask the provider to spend the budget on your two most valuable workflows rather than covering everything shallowly.
- Bundle retesting into the original contract rather than mobilising a separate engagement later.
- Book outside peak periods if your timeline allows. Capacity pricing is real.
Guarantees and what they mean
Some providers offer a no-findings or validated-findings guarantee: if the engagement produces no decision-useful outcome within the agreed scope, the fee is waived. Structured properly this is a genuine risk-sharing mechanism. Structured loosely it creates an incentive to inflate low-severity issues into findings.
If you are offered one, read the definition. A guarantee tied to validated, reproducible findings or a documented improvement plan against an agreed scope is meaningful. A guarantee tied to finding something is an invitation to pad the report.
Frequently asked questions
How much does a penetration test cost in Europe?
Most engagements are priced as tester-days times a day rate. A small authenticated web application test commonly falls in the €4,000–€10,000 range, a complex platform €12,000–€35,000, and an objective-led red team €30,000 and upward. Rates vary considerably by country and provider profile, so treat any range as a sanity check rather than a benchmark.
Why do penetration test quotes vary so much?
Because the same word covers very different amounts of work. The main variables are tester-days, whether testing is manual or largely automated, whether it is authenticated across multiple roles, the seniority of the testers, and whether reporting and retesting are included. Asking every provider to state tester-days makes proposals comparable.
Is retesting worth paying for?
It is usually the highest-value line item in the engagement. Retesting typically costs 10–20% of the original effort and converts an unverified remediation claim into evidence — which is what compliance frameworks, auditors and customers actually want. Bundle it into the original contract rather than mobilising separately.
Talk to the team
Need this tested rather than described?
QuietHours is a European cybersecurity practice operated by the securIT team. Send us the system, service, or control you are concerned about and we will help turn it into a workable scope.
Discuss your scope