Penetration Test Scoping Calculator: Days and Cost by Scope Unit
This free penetration test scoping calculator estimates testing days and total project cost from the components that actually drive pentest pricing: external IP count, web applications, APIs, and internal network segments, adjusted by testing depth. It is built for IT directors and security leads who need to sanity-check a vendor proposal or build a budget estimate before requesting quotes. Enter your scope counts and preferred testing depth, and the tool returns a day estimate and total cost using industry-standard days-per-unit assumptions.
Your numbers
Discrete externally routable hosts to be tested, not the size of the full subnet.
Distinct web applications requiring manual testing, not just automated scanning.
Distinct API surfaces (internal or external-facing) requiring authenticated and unauthenticated testing.
Distinct internal VLANs or network zones requiring internal penetration testing.
Deeper manual testing and exploitation chaining takes longer than automated validation but finds issues scanners miss.
Blended senior penetration tester day rate; specialized skills (OT, embedded, cloud) run at the higher end.
Your results
Planning estimate only. Actual scoping depends on application complexity, authentication schemes, and whether social engineering or physical testing is included. Use this to sanity-check vendor proposals, not replace a formal scoping call.
Get your penetration test scope reviewed
We will email you a detailed scope and day estimate built from your actual asset inventory, plus a vendor proposal comparison checklist, and a Netray security architect will follow up with a 30-minute review.
No spam. Your results stay private. Unsubscribe anytime.
What actually drives penetration test cost
Penetration testing is priced almost entirely on tester days, and tester days scale with scope complexity, not just size. A web application with complex authentication flows and multiple user roles takes meaningfully longer to test thoroughly than a simple marketing site, even though both count as one application. The baseline assumptions in this calculator, roughly 50 external hosts per day, 3 days per web application, 2 days per API, and 2 days per internal segment, reflect typical mid-complexity scoping used by most reputable firms.
- External network testing scales sub-linearly with host count; scanning 500 hosts is not 10x the effort of 50.
- Web application complexity (authentication, roles, business logic) matters more than raw page count.
- API testing requires both authenticated and unauthenticated test passes, which is why it takes longer than a simple network host.
Testing depth: what you actually get for the extra days
Automated scanning with light manual validation catches known vulnerabilities and misconfigurations quickly but misses business logic flaws and multi-step exploitation chains. Standard manual testing adds structured attempts to chain lower-severity findings into meaningful impact. Deep manual testing with exploitation chaining is what most compliance frameworks and sophisticated attackers actually require you to defend against, since real breaches rarely rely on a single unpatched CVE.
- Automated-only testing is appropriate for low-risk internal tools, not customer-facing or regulated systems.
- Standard manual testing is the right default for most annual compliance-driven pentests.
- Deep exploitation-chaining engagements are worth the added cost for crown-jewel systems (ERP, PLM, production control).
Scoping mistakes that inflate cost or leave gaps
The most common scoping mistake is undercounting APIs, since many organizations do not maintain an accurate API inventory and end up adding scope mid-engagement at a premium rate. The second most common mistake is scoping only external testing when the actual risk (ransomware lateral movement, insider threat) lives on the internal network. Build your scope from an actual asset inventory, not a rough guess, before requesting quotes.
How Netray helps you scope and validate
Netray helps manufacturers and defense contractors build accurate penetration test scopes from real asset inventories, including OT and production network segments that generalist pentest firms frequently underscope, and reviews vendor proposals against your actual environment before you sign a statement of work.
Frequently Asked Questions
How much does a penetration test cost?
A typical mid-size scope, roughly 250 external hosts, 5 web applications, a handful of APIs, and a few internal segments, at standard manual testing depth runs $40,000 to $70,000 depending on consultant day rate and region. Smaller, focused engagements (a single web application) can run $12,000 to $25,000, while enterprise-wide engagements with OT or extensive internal scope can exceed $150,000.
How many days does a web application penetration test take?
A typical web application with standard authentication and moderate complexity takes 3 to 5 days of manual testing. Simple, low-functionality applications can be tested in 2 days; complex applications with multiple user roles, extensive business logic, and multiple authentication mechanisms often require 7 to 10 days for thorough coverage.
What is included in a standard penetration test versus a red team engagement?
A standard penetration test focuses on identifying and validating vulnerabilities within a defined, agreed scope over a set number of days, typically without evading detection. A red team engagement simulates a realistic adversary over a longer, often unannounced timeframe, testing detection and response capability alongside technical vulnerabilities, and generally costs significantly more due to its extended duration and specialized tradecraft.
How often should we conduct penetration testing?
Most compliance frameworks (PCI DSS, SOC 2, and many customer security requirements) require annual penetration testing at minimum, with additional testing after significant infrastructure or application changes. Organizations in higher-risk categories, including defense contractors and any business processing regulated data, commonly test semiannually or add continuous automated validation between formal annual engagements.
Get your penetration test scope validated against your actual asset inventory before requesting vendor quotes.
Related Tools
Vulnerability Remediation SLA Calculator
Estimate how many weeks it will take to burn down your priority vulnerability backlog given current findings volume, engineer capacity, and new findings arriving each week.
Aerospace & DefenseZero Trust Readiness Assessment
Answer 8 questions on identity, device posture, segmentation, and access policy to get a scored zero trust maturity band with a specific remediation roadmap.
ERP OperationsSIEM Sizing Calculator
Estimate annual SIEM license and storage cost from your events-per-second rate, daily ingest volume, and retention window split across hot and cold storage tiers.
Go Deeper
ERP Cloud Security: Best Practices for Manufacturers
Secure your cloud ERP deployment. Access controls, data encryption, compliance frameworks, and monitoring strategies for Infor CloudSuite environments.
The AI Incident Response Playbook
An AI incident response playbook: classify AI-specific incidents, contain a compromised agent, and run the postmortem that prevents a repeat.
ITAR and CMMC Handling of AI Workloads
How ITAR and CMMC apply to AI workloads: technical data boundaries, CUI handling, assessed environments, and where on-prem AI is the only option.