All posts

What a penetration test costs, according to three public records

The quoted average is $18,300 and traces to a 2023 page that names none of its sources. Sellers who publish put a fixed test at $4,655. The US government paid a median of $39,146 for short engagements. All three are real, and the dataset is public.

security public-records m37

Hardly anyone publishes what a penetration test costs. Most vendors quote in private, reports go out under NDA, and the “average cost” figures that circulate on vendor blogs rarely say where they came from. I wanted to know what the public record says, so I had it read. The harvest, the reading and the video were done by the AI agents that produce my channel, M37; I picked the question and checked the receipts. The video below is the result, and this post is the same material as text, with the sources.

Three public records answer the question, and they answer it with three different numbers.

The number that gets quoted

Search for the cost of a penetration test and you will find $18,300 quoted as the current average, by vendor after vendor. Almost none of them say where it came from. One, Cybersecurity Ventures, does. It points at an article on eSecurity Planet from June 2023, which is honest about its method: the figure comes from “polling ten different penetration testing information sources”. The article does not name any of them. Its own metadata says it was last modified in December 2023, and the sentence carrying the number is byte-identical in an archive copy from June 2023 and one from November 2025.

I have no evidence the number is wrong. What I can say is that its support is ten sources that were never named, on a page that stopped being maintained in 2023, quoted back as this year’s figure.

What the sellers publish

Most security firms do not publish a price. The UK government runs a buying framework, G-Cloud, and to be listed on it a supplier has to upload a pricing document. So there is a public web server holding rate cards from firms whose own websites will not quote you anything. The catalogue’s own browse moved behind a login, so I could reach only the 17 pricing documents that search engines had indexed. Between those, a few cloud marketplaces and the handful of vendors who put prices on their sites, I found 60 published prices from 20 named vendors. Pounds are converted to dollars at 1.2547, the ECB reference rate on the day the G-Cloud pricing documents were filed.

Published day rates in those documents, 15 line items across 8 vendors, run from £900 to £1,750 with a median of £1,250. A wider harvest would find rates outside that band; this one is what I could reach.

Fixed per-test prices are thinner. Only 5 vendors publish one. Their vendor medians run from $2,509 to $16,720, and the median of those medians is $4,655. That last number moved by 40% when the fifth vendor turned up late in the harvest, so read the spread, not the midpoint.

What a government actually paid

Governments have to publish what they bought. I asked the US federal award database, USAspending.gov, for every contract award mentioning penetration testing and got 1,795 matches. Most are not what I was looking for: 85 are training courses, 27 are software licences, 12 are soil tests (a cone penetration test is how you check the ground under a dam), and 4 are viral penetration tests on stockpiled medical gowns.

Reading every description, with the reason for each exclusion logged, leaves 157 contracts. Their median value is $133,213, which is not useful, because the same two words cover a two-week job and a five-year programme. So I split them by how long the work ran, which is a field in the data. The cut at 200 days is my choice, a proxy for a scoped engagement rather than a guarantee of one. For the 37 contracts that ran 200 days or less, the median award is $39,146, with the middle half between $23,600 and $76,551.

An awarded contract total is not the price of one test. It is the closest thing to a transacted price that the public record contains.

Three answers, eight times apart

The sellers who publish say $4,655, the industry’s quoted figure says $18,300, and a government paying for a short engagement says $39,146. None of them is lying. They are three different objects wearing the same two words: a shop-window price, an unaudited average of other people’s asking prices, and an obligated federal award.

What the report contains

The other half of the question is what arrives when you pay. Some security firms publish their assessment reports: penetration tests, code reviews, audits. I fetched 873 of them and could parse the findings tables of 501, from seven firms, dated 2014 to 2026. Of the rest, 311 had no findings table a parser could read with confidence, 41 were not assessments (threat models, fix reviews, summary letters), and the remainder were duplicates, self-inconsistent or marketing samples. Trail of Bits alone is 303 of the 501.

The median report has 10 findings over 39 pages. Across 478 reports with a severity breakdown, 5,754 findings in total, critical and high together are 15.3%. 211 of those 478 reports, 44%, contain no critical or high finding at all. The largest single category, a third of everything reported, is informational, which the firms’ own scales define as not posing an immediate risk.

I merged critical and high because the firms’ scales do not line up. Trail of Bits, 60% of the corpus, has no Critical tier at all; High is the top of its scale, so for most of these reports “no critical or high” means nothing at the top of the ladder. Counting criticals alone across firms would measure vocabulary, not risk.

And these are the reports firms chose to publish. Almost all of them are for open-source, grant-funded or crypto clients, at narrower scope than commercial work. They support claims about what a published report contains, and nothing about the private engagement you would buy.

What the record cannot tell you

The record cannot tell you whether the price predicts what you get. I could not find anyone who publishes a price and a report for the same job, so the two populations never meet. I ran the search and it returned nothing, which is why the video says so rather than guessing.

The data

Everything above, every contract, every rate card, every report, is on one page, sorted however you want it, with each row linking to the document it came from: apps.9592.tech/m37/pentest. The page’s sources are all free and public: USAspending.gov, the GSA pricing API, UK Contracts Finder, the G-Cloud supplier documents, and the firms that publish their reports.

The video is an M37 episode. Every episode on that channel is built on something that was actually measured, and this one took a day of harvesting public documents and reading 1,795 contract descriptions one at a time. If you have bought or sold a penetration test and the numbers look wrong to you, I would rather hear it than not.

Have a market or a dataset you want read this way?

I build evidence pieces like this one: harvest the public record, measure it, and publish the numbers with every source attached. If there is a question in your field that the public record could answer, write to me and tell me what it is.

Get in touch

Or just email me at [email protected]