ERP OperationsFree Interactive Tool

Penetration Test Scoping Calculator: Days and Cost by Scope Unit

This free penetration test scoping calculator estimates testing days and total project cost from the components that actually drive pentest pricing: external IP count, web applications, APIs, and internal network segments, adjusted by testing depth. It is built for IT directors and security leads who need to sanity-check a vendor proposal or build a budget estimate before requesting quotes. Enter your scope counts and preferred testing depth, and the tool returns a day estimate and total cost using industry-standard days-per-unit assumptions.

Your numbers

IPs

Discrete externally routable hosts to be tested, not the size of the full subnet.

apps

Distinct web applications requiring manual testing, not just automated scanning.

APIs

Distinct API surfaces (internal or external-facing) requiring authenticated and unauthenticated testing.

segments

Distinct internal VLANs or network zones requiring internal penetration testing.

Deeper manual testing and exploitation chaining takes longer than automated validation but finds issues scanners miss.

$/day

Blended senior penetration tester day rate; specialized skills (OT, embedded, cloud) run at the higher end.

Your results

Estimated project cost
$129,800
Total consulting cost at your chosen day rate and testing depth.
External network testing days
6 days
Baseline days to test the external attack surface at roughly 50 hosts per day.
Web application testing days
15 days
Baseline days for manual web application testing at roughly 3 days per application.
API testing days
12 days
Baseline days for API security testing at roughly 2 days per API surface.
Internal network testing days
6 days
Baseline days for internal network penetration testing at roughly 2 days per segment.
Total testing days at chosen depth
59 days
Combined baseline days adjusted by your selected testing depth multiplier.

Planning estimate only. Actual scoping depends on application complexity, authentication schemes, and whether social engineering or physical testing is included. Use this to sanity-check vendor proposals, not replace a formal scoping call.

Get your penetration test scope reviewed

We will email you a detailed scope and day estimate built from your actual asset inventory, plus a vendor proposal comparison checklist, and a Netray security architect will follow up with a 30-minute review.

No spam. Your results stay private. Unsubscribe anytime.

What actually drives penetration test cost

Penetration testing is priced almost entirely on tester days, and tester days scale with scope complexity, not just size. A web application with complex authentication flows and multiple user roles takes meaningfully longer to test thoroughly than a simple marketing site, even though both count as one application. The baseline assumptions in this calculator, roughly 50 external hosts per day, 3 days per web application, 2 days per API, and 2 days per internal segment, reflect typical mid-complexity scoping used by most reputable firms.

  • External network testing scales sub-linearly with host count; scanning 500 hosts is not 10x the effort of 50.
  • Web application complexity (authentication, roles, business logic) matters more than raw page count.
  • API testing requires both authenticated and unauthenticated test passes, which is why it takes longer than a simple network host.

Testing depth: what you actually get for the extra days

Automated scanning with light manual validation catches known vulnerabilities and misconfigurations quickly but misses business logic flaws and multi-step exploitation chains. Standard manual testing adds structured attempts to chain lower-severity findings into meaningful impact. Deep manual testing with exploitation chaining is what most compliance frameworks and sophisticated attackers actually require you to defend against, since real breaches rarely rely on a single unpatched CVE.

  • Automated-only testing is appropriate for low-risk internal tools, not customer-facing or regulated systems.
  • Standard manual testing is the right default for most annual compliance-driven pentests.
  • Deep exploitation-chaining engagements are worth the added cost for crown-jewel systems (ERP, PLM, production control).

Scoping mistakes that inflate cost or leave gaps

The most common scoping mistake is undercounting APIs, since many organizations do not maintain an accurate API inventory and end up adding scope mid-engagement at a premium rate. The second most common mistake is scoping only external testing when the actual risk (ransomware lateral movement, insider threat) lives on the internal network. Build your scope from an actual asset inventory, not a rough guess, before requesting quotes.

How Netray helps you scope and validate

Netray helps manufacturers and defense contractors build accurate penetration test scopes from real asset inventories, including OT and production network segments that generalist pentest firms frequently underscope, and reviews vendor proposals against your actual environment before you sign a statement of work.

Frequently Asked Questions

How much does a penetration test cost?

A typical mid-size scope, roughly 250 external hosts, 5 web applications, a handful of APIs, and a few internal segments, at standard manual testing depth runs $40,000 to $70,000 depending on consultant day rate and region. Smaller, focused engagements (a single web application) can run $12,000 to $25,000, while enterprise-wide engagements with OT or extensive internal scope can exceed $150,000.

How many days does a web application penetration test take?

A typical web application with standard authentication and moderate complexity takes 3 to 5 days of manual testing. Simple, low-functionality applications can be tested in 2 days; complex applications with multiple user roles, extensive business logic, and multiple authentication mechanisms often require 7 to 10 days for thorough coverage.

What is included in a standard penetration test versus a red team engagement?

A standard penetration test focuses on identifying and validating vulnerabilities within a defined, agreed scope over a set number of days, typically without evading detection. A red team engagement simulates a realistic adversary over a longer, often unannounced timeframe, testing detection and response capability alongside technical vulnerabilities, and generally costs significantly more due to its extended duration and specialized tradecraft.

How often should we conduct penetration testing?

Most compliance frameworks (PCI DSS, SOC 2, and many customer security requirements) require annual penetration testing at minimum, with additional testing after significant infrastructure or application changes. Organizations in higher-risk categories, including defense contractors and any business processing regulated data, commonly test semiannually or add continuous automated validation between formal annual engagements.

Get your penetration test scope validated against your actual asset inventory before requesting vendor quotes.