First, know what you are buying
Three different services get called a pen test, and they are priced worlds apart.
A vulnerability scan is automated software that checks your systems against a list of known weaknesses. It is cheap, fast, and shallow. Think of it as a smoke detector.
A penetration test is a person actively trying to break in, chaining weaknesses together the way a real attacker would, and documenting exactly how far they got. That human time is what you are paying for.
A security audit or assessment is a structured review of your settings, policies, and practices against a standard. It answers whether you are following good practice, not whether someone can break in today.
If a salesperson quotes you a few hundred dollars for a pen test, you are almost certainly buying a scan with a nicer report.
What penetration testing costs around here
Prices in Northern Virginia skew a little higher than the national average because so much local talent is absorbed by federal contracting. For a small business, these are the ranges I see in real proposals:
- External network test, meaning your internet-facing systems: roughly $4,000 to $8,000
- Web application test, for a custom site or portal with logins: roughly $6,000 to $20,000, driven by complexity
- Internal network test, meaning what an attacker can do once inside: roughly $5,000 to $15,000
- Add-ons like phishing campaigns or physical entry attempts: $2,000 to $10,000 more
A basic vulnerability scan, by contrast, runs anywhere from free to about $2,000 and is often included in a managed IT plan. Anyone quoting far below these ranges is probably running a scanner and calling it a pen test.
What drives the price
Four things move the number more than anything else.
- Scope. Ten external IP addresses cost less to test than a hundred. One web app with two user roles costs less than three apps with admin panels and payment flows.
- Manual effort. Real testing means a skilled person spending days probing your specific setup. More hours, more cost, and more findings a scanner would miss.
- Retesting. After you fix the findings, a good firm verifies the fixes. Some include one retest; others charge 20 to 30 percent extra. Ask up front.
- Reporting depth. A useful report explains each finding in plain English, ranks it by real-world risk, and tells you how to fix it. That writing time is part of the bill.
When you actually need one, and when you do not
You genuinely need a pen test when a contract, regulator, or insurer requires one, when you run a custom web application that handles payments or sensitive records, or when you have already done the basics and want them pressure-tested by a professional.
Here is the honest part: most small businesses I meet are not ready to get value from one. If you do not have multi-factor authentication everywhere, current updates, and tested backups, a $6,000 test will produce a report listing things you already suspected. You will have paid a professional to confirm the locks are unlocked.
In that case, spend a fraction of the money on a security review and fix the fundamentals first. Then a pen test tells you something you could not have guessed.
How to read a proposal
Before you sign anything, ask these questions and expect specific answers:
- What methodology do you follow, and how many hours are manual testing versus scanner time?
- Who exactly performs the test, and what certifications do they hold? OSCP is the respected hands-on credential for testers.
- Can I see a sanitized sample report before I commit?
- Is a retest of fixed findings included in the price?
- What happens if you knock something over? A serious firm carries insurance and agrees on testing windows and an emergency contact in advance.
Walk away from anyone who quotes a firm price before a scoping call, guarantees a clean result, or will not name the humans doing the work.
What to do next
- Write down why you want a test: a contract clause, an insurance form, a customer questionnaire, or plain peace of mind. The reason dictates the scope.
- If the fundamentals are shaky, book a security review first. It costs a fraction of a pen test and fixes the obvious gaps.
- Get two or three proposals and compare manual hours and retest terms, not just the bottom line.
- Budget for remediation. Findings you never fix are the most expensive kind.
At HashWhales I help Northern Virginia businesses figure out which of these they actually need, and I will tell you plainly if a pen test is premature. A short call costs nothing and usually saves the price of the wrong engagement.
