Fixed scope, fixed price
What a penetration test
actually costs.
Most firms in this category will not print a number, which wastes the time of everyone who has a budget and wants to know whether it is the right order of magnitude. Here are ours. They are the same prices we transact at on Azure Marketplace, and they include the retest that most vendors charge for.
Pricing
Three sizes, and an honest fourth
Prices are per engagement, in US dollars, and include the report, the debrief and the retests. What moves a system between tiers is almost always the role model and the tenancy, not the number of pages.
Focused
$6,900
One application
A single web application or API, one or two roles, no multi-tenancy. The usual first engagement, and the usual answer to a customer or auditor asking for a current test.
- One application or API, one environment
- Up to two user roles tested against each other
- The full published catalogue, scoped to what applies
- Report written for the engineers who will fix it
- Retest of every finding, included
- Findings live in your workspace as they are confirmed
Most engagements
Professional
$14,500
A real product
An application with a role model worth attacking: several roles, an API behind it, integrations, and business logic that means something. Where most of our work sits.
- Application and its API together
- Several roles, tested in every direction
- Business-logic and workflow abuse, not just the catalogue
- Authorization tested object by object
- Report, debrief, and retest of every finding
- Priority on scheduling
Platform
$32,000
Multi-tenant, or several systems
A multi-tenant platform, or a set of systems that only make sense tested together. Tenant isolation is the organising question and it is the one that cannot be answered by testing a single account.
- Multi-tenant isolation across real tenants
- Several applications, APIs and back-office surfaces
- Full role and permission matrix
- Chained findings across system boundaries
- Report per system plus one consolidated view
- Retests across the whole engagement
Custom
Quoted
Anything the three above do not describe
Mobile, embedded and IoT, source-code-assisted review, an unusual environment, a programme across a year, or a scope that simply does not fit a box. Priced from the same rate card, agreed before anything is issued.
- Mobile (Android and iOS) and embedded devices
- Source-assisted and white-box engagements
- Recurring or programme-based testing
- Procurement through Azure Marketplace as a private offer
Every tier includes the retest of every reported finding. That is not a line we add to look generous: we have retested 1,237 fixes and 26.5% of the verdicts were not a clean fix, so an engagement that ends at the report ends before the part that decides whether anything actually got safer.
How buying works
Four steps, and none of them is a shopping cart
Pick the tier that looks right
You do not have to be sure. It anchors the conversation, and if the fit is wrong we will say so before anything is issued — including telling you a smaller tier is enough.
We confirm the scope, in writing
A short call or a form. What the system does, how many roles, whether it is multi-tenant, what environment we get and when you need it finished. This is what turns a tier into a real price.
You get the offer
Fixed scope, fixed price, a start date and the terms. Directly, or as an Azure Marketplace private offer if you would rather buy on your Microsoft agreement.
Testing starts on the agreed date
The engagement opens on CybeRapid, your workspace goes live, and findings appear as they are confirmed rather than at the end.
There is deliberately no card checkout on this page. A penetration test cannot be honestly sold before the scope is agreed — and we would rather lose the impulse purchase than issue you an engagement that turns out to be the wrong one. Steps two and three usually take a day.
Before you ask
What actually drives the number
What moves the price
- Roles. Every additional role multiplies the authorization surface, and authorization is the largest class of serious finding we report.
- Tenancy. Multi-tenant isolation cannot be tested from one account; it needs real tenants and a real matrix.
- API surface. Endpoints behind the interface, not screens in it.
- Environment readiness. Working credentials and a stable environment on day one buy you depth; chasing access spends the days you paid for.
What does not
- How many pages the site has. Fifty near-identical screens behind one role are cheaper to test than three behind six.
- Urgency. We will tell you whether a date is achievable; we do not price a deadline as a surcharge.
- How many findings we produce. The price is agreed in advance. 234 of our 890 projects produced no findings at all — that is a legitimate result, and it costs what it costs.
- Whether you buy directly or through Microsoft. Same engagement, same price.
Tell us what the system does, and we will tell you the tier.
If a smaller one is enough, that is what we will say. Scoping costs you a conversation, not a commitment.