aliteq.

Penetration Testing Cost (2026): Web App, API, Cloud, AI Features and SOC 2

Sellers publish $5,000 to $30,000 for a web or SaaS app test and $9,500 and up for an AI chatbot. Many firms print nothing at all. Here is what each firm's own page says, what moves the quote, and what a SOC 2 auditor looks for.

CipherUpdated 48m ago13 min readWeb story
Hand-drawn editorial illustration of a hand holding a magnifying glass over a house of cards, one card carrying a small teal padlock, on a near-black background in indigo-violet and off-white
Share

You have a customer asking for a recent pen test summary, or an auditor who mentioned one, and a search that returns nine articles by nine pen test firms. This page reads the firms' own pages and puts the numbers in one place, with the caveats the sellers leave out.

It does not teach testing techniques and never will. It covers scope, price and paperwork. For the audit itself, see what a SOC 2 audit costs. For the whole programme, see SOC 2 for AI startups: cost and timeline. The hub is Security & Compliance.

What do pen test firms publish for a web app, API, cloud or mobile test?

Firms that publish a figure put a web or SaaS app test at roughly $5,000 to $30,000, an API test at $5,000 to $20,000, mobile at $5,000 to $30,000 and cloud at $10,000 to $40,000 or more. These are planning ranges, not fixed prices.

Range bars of penetration test prices in USD published by sellers. Classic tests per Blaze: API $5k to $20k, web or SaaS app $5k to $30k, mobile app $5k to $30k, cloud $10k to $40k and up. AI features per Pentest Testing Corp: chatbot on a model API from $9.5k, RAG or plugin apps $15k to $35k, multi-agent platforms $35k to $75k. All are vendor planning ranges, not quotes.
Vendor-published planning ranges, read 3 Oct 2026. Not quotes, and not what clients paid. · aliteq research

The most detailed public table comes from Blaze Information Security, which says its ranges are "based on Blaze's own commercial data, including roughly 900 penetration testing quotes sent in 2025 alone." Its table:

SaaS or web app

Blaze's average 2026 range
$5,000 to $30,000
Blaze starting price
from $4,999
Typical duration
1 to 3 weeks

API

Blaze's average 2026 range
$5,000 to $20,000
Blaze starting price
from $4,999
Typical duration
1 to 2 weeks

Mobile app

Blaze's average 2026 range
$5,000 to $30,000
Blaze starting price
from $5,299
Typical duration
1 to 2 weeks

Cloud

Blaze's average 2026 range
$10,000 to $40,000+
Blaze starting price
from $7,500, varies
Typical duration
1 to 3 weeks

Network

Blaze's average 2026 range
$5,000 to $35,000+
Blaze starting price
from $4,999 (focused external)
Typical duration
1 to 3+ weeks

Blaze calls these "planning ranges, not fixed quotes" and says its overall average for a standard commercial engagement is "$10,000 to $35,000."

Other sellers land in the same neighborhood, with wider edges:

  • Astra (updated 19 Aug 2026): "The average cost of a penetration test ranges from $2500 to $50,000." Its table shows web apps at $5,000 to $50,000, mobile at $5,000 to $40,000, SaaS at $5,000 to $30,000, and APIs at $5,000 to $30,000 "per asset."
  • DeepStrike (updated 14 Sep 2026): "Professional pentests cost $5K to $50K; large enterprises often pay $100K+." It also says "Under $4K tests are usually just automated scans, not true pentests."
  • Autonoma puts a focused web app and API test for a Series A or B SaaS company at "$15,000 to $35,000," and day rates at "$1,500 to $3,500 per consultant day for mid-market firms."
  • Synack prints starting prices: "$4,181 (1 AI Sara Pentest)," "$10,283 (1 Standard Pentest)" and "$27,120 (1 Synack14 Pentest)." Its page adds that the Synack Platform "is required to purchase any of the testing products and is a separate line item."

Astra's pricing page also shows subscription-style plans. A plan described as "Offensive pentests by certified pentesters & autonomous agents" is listed at $5,999 a year, with a higher tier "$9999 /yr onwards." Its cheaper scanner plans ($69 to $499 a month) are vulnerability scanners, not pen tests.

Which firms print no price?

Cobalt, Bugcrowd and HackerOne show no dollar figures on the pages we read. Cobalt explains a credit model: "A Cobalt Credit represents the equivalent of 8 hours of offensive security testing," sold in annual packages. Bugcrowd lists what each tier includes and sends you to a quote. HackerOne's pricing URL redirects to a platform page. Pentest-Tools.com publishes self-service scanning plans (from $95 a month) but its managed tests are an "estimate" request. "No price on the page" is not the same as "expensive." It means you must ask.

What moves a pen test quote?

The price follows the number of days a skilled tester needs, so anything that adds surface adds cost. The firms name the same handful of drivers on their own pages.

Scorecard of what moves a penetration test quote and the question to ask: number of targets, user roles, endpoints and pages, mobile platforms, cloud accounts, depth of testing (scan only versus manual), retesting, and report type. Retesting is included by some firms such as Cobalt and Bugcrowd and billed by others.
Drivers as listed on the firms' own pages, read 3 Oct 2026. · aliteq research
  • Targets. Astra defines a target as a URL. Its pricing page says "Mobile is per platform, so an Android app and an iOS app are two targets," and "Networks, cloud, IPs and standalone APIs are 1 target each." Ask every firm what counts as one.
  • User roles. Blaze lists "the number of user roles, endpoints, applications, cloud accounts or IPs in scope" and contrasts a simple site with "a multi-tenant SaaS platform with APIs, SSO, admin roles, payment flows, cloud infrastructure." A customer role, an admin role and a read-only role are three things to test.
  • Endpoints and pages. Astra's decision variables are "unique dynamic and static pages" for web apps and "unique APIs and end-points" for API tests. Autonoma's table ties a narrow web test to 3 to 5 test days and a full multi-role one to 5 to 10.
  • Depth. A scan is cheap. A manual test is not. Blaze warns that "Low-cost offers are often automated vulnerability scans marketed as manual penetration testing."
  • Retesting. Astra says "Many providers charge extra for retesting, while others include a limited number of rescans." Cobalt says its model provides "unlimited on-demand retesting throughout your contract term." Bugcrowd lists "12 months of retesting (with 1 report update)." Autonoma says retesting "is usually billed separately." Retesting matters because you will fix findings and need proof that you did.
  • Who tests. Astra: "Companies with skilled pentesters will quote more." Blaze says providers commonly charge "$250 to $300 per hour for standard professional services" for hourly work.

For a stack like a Next.js front end on Supabase with Stripe and one AI feature, the practical way to cut a quote is to cut scope, honestly. List the apps, APIs, roles and third-party services in plain text before the call. Then ask which of those the firm would test and which it would only review. If you built the app with an AI coding tool, our vibe-coded app security checklist is a cheaper first pass, and a pen test is the independent check on top of it, not a replacement.

What does it cost to test AI and LLM features?

The firms that publish AI testing prices put a chatbot on a third-party model API at about $9,500 and up, an app with plugins, tools or retrieval at $15,000 to $35,000, and multi-agent platforms at $35,000 to $75,000 or more. This is a young market and the only public numbers come from sellers.

  • Pentest Testing Corp (guide dated 28 Jun 2026) lists fixed-price tiers: "Starter" at "$9,500+" for a single chatbot on a third-party model API with limited backend integration; "Professional" at "$15,000 to $35,000" for an app "with active plugins, internal tool access, and/or a RAG pipeline"; and "Enterprise" at "$35,000 to $75,000" for a multi-agent platform or fine-tuned models. It says these are "fixed-price ranges, not hourly estimates."
  • AI Vyuh Security (7 Apr 2026) gives a different cut, for red teaming: a simple chatbot "$8K to $15K," a retrieval pipeline "$15K to $35K," a tool-using agent "$25K to $60K," and multi-agent systems "$50K to $150K+." It notes that "The jump from 'chatbot' to 'tool-using agent' is where costs accelerate."

Both sources say the same thing about scope: what the AI feature can reach matters more than the model it calls. An assistant that only answers questions is cheaper to test than one that can read another customer's records or call your internal tools. Expect the firm to ask how many models and agents are in scope and what each is allowed to do.

Two cautions. First, "AI pen test" can mean two things. Synack's "AI Sara Pentest" (from $4,181) is an AI-led test of ordinary systems, not a review of your LLM feature. Astra lists "AI" and "MCP" among supported targets on its $5,999 plan. Ask which one you are buying. Second, a buyer's security questionnaire may ask whether your AI feature has been tested at all. Our guide to AI security questionnaire answers shows where that question appears and what evidence to attach.

What do SOC 2 auditors accept?

SOC 2 does not require a penetration test, but most auditors expect one, and the sources we read agree on that. What an auditor actually accepts is a question for your own audit firm.

Scorecard on SOC 2 and penetration tests. SOC 2 does not require one but most auditors expect it. It fits under monitoring evaluations, CC4.1. A scan does not replace a test because it lacks manual validation. Auditors look for scope, fixes for critical and high findings, and a retest. A cheap compliance test may cost around $5,000 and be thin. Sources are a consultancy and pen test sellers.
What the sources we read say. Your own auditor has the last word. · aliteq research
  • Not mandated. Fractional CISO, a consultancy: "No, SOC 2 does not require penetration testing, but most organizations will get one as part of their compliance with the standard." Astra: SOC 2 "doesn't explicitly mandate penetration testing, but most auditors expect it." Drata's own guide, which we read in February and could not reload on 3 October because its site blocks scripted requests, also says a pen test is not required.
  • Where it fits. The consultancy ties it to the criterion CC4.1: "The entity selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning." A pen test is one way to do a separate evaluation. It is not the only one.
  • Scans are not tests. Astra says scans "lack the manual exploitation and validation that pentests provide," and that auditors look for "proof that tests covered in-scope systems, documentation of remediation efforts for critical and high-risk findings, and evidence of retesting to confirm fixes were effective." That is a pen test seller's view, but it matches the checklist every firm sells against.
  • A cheap compliance test exists. Fractional CISO says tests that "get organizations 'compliant' can be done for around $5,000," while "Quality penetration testing (with actionable results) often costs $15,000 to $30,000." Blaze's figure for a standard SaaS scope is "$8,000 to $25,000."

Put it in budget terms. Our audit-cost guides use about $5,000 to $15,000 as the typical pen test line inside a first-year SOC 2 budget, and the seller ranges above show why it can go higher. See what a SOC 2 audit costs for the lines around it, and vanta vs drata vs secureframe if you are also choosing a compliance platform. If a buyer is waiting on you now, start with what to do when a customer asks for SOC 2: a recent pen test summary is one of the things it suggests sending while the report does not yet exist.

Before you buy, email your auditor three questions: do you expect a pen test for our scope, how recent must it be, and would you accept a summary letter or do you need the full report? Get the answer in writing.

PTaaS, a one-off test or a bug bounty?

A one-off test is a fixed project with a report at the end. PTaaS (pen testing as a service) is a platform subscription where tests launch on demand and retesting sits inside the plan. A bug bounty pays outside researchers for findings and is a different thing, not a substitute for either.

  • One-off. Fixed price, 1 to 3 weeks of testing per Blaze's table, a report, usually a retest window. Best when you need a single dated report for an audit or a customer.
  • PTaaS. Bugcrowd's page describes launching tests "within 3 business days" with a "PTaaS Dashboard" and "12 months of retesting." Cobalt sells annual credit packages with retesting inside. Better if you ship often and want to retest as you fix, but you pay for the platform and the term.
  • Bug bounty. Bugcrowd says its managed bug bounty finds "hidden vulnerabilities that are beyond the reach of automated tools or traditional pen testing," continuously, and prices it by quote. It is not scoped like a test and does not produce a fixed-date report in the same way. Most small teams meet an auditor's expectation with a scoped test first.
  • Scan subscriptions. Astra's scanner plans and Pentest-Tools.com's plans are tools you run yourself. They are a cheap regular check, not a pen test report.

What should the report contain?

A useful report names the scope, the dates, each finding with a severity rating and the evidence for it, how to fix it, and the retest result. Blaze describes the weak version: "Provides only scanner output with a light narrative. Does not test authenticated areas. Does not include evidence, reproduction steps, and remediation guidance. Does not offer retesting or fix validation."

Ask for a sample report before you sign. Check these items:

  1. An executive summary a customer can read, separate from the technical detail.
  2. The scope: which apps, APIs, roles, environments and dates.
  3. Each finding with severity, evidence and fix guidance.
  4. A retest section showing which findings were verified as fixed.
  5. A statement of what was not tested.

Customers and auditors usually want a summary they can keep on file. Ask the firm in advance whether you may share it, and whether they offer a shorter letter for customers.

How to read a pen test quote

A good quote says what is tested, by whom, for how long, and what happens after the report. A vague one, or one that is far below the others, usually leaves something out. Ask the same questions of every firm and write the answers down.

  1. What exactly is in scope: which URLs, apps, APIs, roles, cloud accounts and mobile platforms?
  2. Is it manual testing by named people, or a scan with a report? Who is the tester?
  3. How many days of testing, and how many calendar weeks until I have the report?
  4. Is retesting included, how many rounds, and for how long?
  5. Does the report suit a SOC 2 audit, and can I see a sample?
  6. Is there a platform fee on top (as Synack's page says for its platform)?
  7. What changes the price if scope grows mid-test?
  8. For an AI feature, is the model, the app around it, or both in scope, and what tool or data access will be tested?
  9. Do you test against a staging copy, and how is my production data protected?
  10. What does next year's test cost, and is there a discount for a renewal?

If two quotes differ by 3x, do not pick the lower one first. Compare their scope lines.

Quick answers

How much does a penetration test cost?
Firms that publish figures put a web or SaaS app test at about $5,000 to $30,000, an API test at $5,000 to $20,000 and a cloud test at $10,000 to $40,000 or more. Blaze says the average standard commercial engagement is $10,000 to $35,000. These are seller planning ranges, not quotes. Cobalt, Bugcrowd and HackerOne publish no price.
Does SOC 2 require a penetration test?
No. The sources we read say SOC 2 does not require one, but most auditors expect one, and it can serve as an evaluation under criterion CC4.1. Ask your own audit firm what it will accept, how recent the test must be and whether a summary letter is enough.
How much does it cost to pen test an AI or LLM feature?
Vendor-published ranges start around $9,500 for a chatbot on a third-party model API and run $15,000 to $35,000 for an app with plugins or retrieval. Multi-agent platforms are quoted from $35,000 to $75,000 or more. This is a young market and the only public numbers come from sellers.
Is a vulnerability scan the same as a pen test?
No. A scan checks for known weaknesses automatically. A pen test adds manual testing and validation by a person. Blaze warns that very cheap offers are often scans sold as manual tests, and DeepStrike says tests under about $4,000 are usually just automated scans.
Is retesting included in the price?
It depends on the firm. Cobalt and Bugcrowd say retesting is included in their plans. Astra says some providers charge extra and others include limited rescans. Autonoma says it is usually billed separately. Ask how many retest rounds you get and for how long.
Should I buy a pen test, PTaaS or a bug bounty first?
For a small team that needs a dated report for an auditor or a customer, a scoped one-off test is the usual first step. PTaaS suits teams that ship often and want retesting built in. A bug bounty is a continuous program priced by quote and does not replace a scoped test.

A pen test is one line in a larger bill, and the number you can control is scope. Write it down before the first call, ask every firm the same questions, and let your auditor tell you what they accept. The rest of the compliance map is on the Security & Compliance hub.

Found this useful? Share it

Share
Cipher

Security & Compliance Editor

Cipher

I'm US-based and I read security the way an attacker would — follow the incentives, find where it breaks. I write for the founder whose first enterprise customer just sent a security questionnaire: what SOC 2 really costs, what an auditor will ask about your AI feature, and which 'compliance' promises are marketing.

The Aliteq brief

The tech worth knowing — hardware, AI, gaming, deals. No spam, unsubscribe anytime.

Keep reading