Skip to content
Zyberum Cyber Security Firm
Menu
Free toolPenetration testing

Pentest Cost Estimator

Estimate how many days a penetration test takes and what it typically costs: pick the target, its size, the approach and a retest. Market ranges for Germany and the EU.

Updated This page as Markdown

In short

This estimator gives a typical effort range in person-days and a price range in euros for a penetration test, based on the type of target (web app, API, mobile app, cloud, network, hardware, IoT product, automotive ECU, OT), its size, the test approach (black, grey or white box) and whether a retest is included. The ranges are market-typical for Germany and the EU and not an offer.

What should be tested?
How big is it?
Test approach

How it works

The estimator starts from the typical day ranges on our pentest cost page, one per target type. Size scales the range: a small target takes about 70 percent of the typical effort, a large or complex one about 150 percent. The approach scales it again: black-box testing needs about 20 percent more time for discovery, white-box testing saves about 10 percent because the tester reads code instead of guessing. A retest adds about 20 percent. The price multiplies the days by a daily rate band of 1,200 to 1,500 euros.

How to read the result

Use the lower end when the target is well documented, test accounts and environments are ready on day one and you can answer questions quickly. Use the upper end when the tester has to discover the attack surface alone, when environments are shared with production or when there are many roles, tenants or hardware variants.

If the range looks too high for your budget, narrowing the scope is better than compressing the time. A thorough test of the three most exposed components beats a shallow pass over thirty.

Limits

The estimator does not know your application, your network or your device. It cannot see how many user flows exist, whether the firmware is encrypted, how many interfaces the ECU has or how an OT plant can be tested without downtime. Those questions take a 15-minute call, after which the range becomes a fixed price.

FAQ

Frequently asked questions

Why a range and not a price?

Because the effort depends on things the four questions cannot capture: the number of roles and user flows in an application, the number of interfaces on a device, how much documentation and access you can provide. After a 15-minute scoping call we turn the range into a fixed price.

What is included in the days?

Preparation and kick-off, the testing itself, writing the report with a reproduction and a fix recommendation for every finding, and a results call. The retest option adds a verification of your fixes a few weeks later, with an updated report.

Are the prices realistic for Germany?

The daily rate band of 1,200 to 1,500 euros excluding VAT is what specialised security firms in Germany and the EU typically charge for senior testers. Cheaper offers usually mean juniors or a scanner with a report; more expensive ones usually buy brand, not findings.

Related pages

Get started

The tool gave you a result. Now what?

Discuss your result with a security engineer in 15 minutes and find out what the practical next step is.

  • Your result, interpreted for your situation
  • What to do first
  • Free and without obligation
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usTalk to an expert

Pick a time that suits you

Open in a new tab