VE MATPROOF EN TU STACK — RESERVA UNA DEMO DE 30 MINUTOS
securitySep 15, 202618 min read

Penetration Testing Cost USA 2026: Published Prices, Scope Ranges and What the Rules Actually Require

MW
Malte Wagenbach

Founder & CEO, Matproof

Este artículo aún no está disponible en español. Se muestra la versión en inglés.

Most US penetration testing firms will not print a price. You book a call, describe your estate, and wait.

This page prints what is already public. Every figure links to the page it came from and the date shown there. Where the record is thin or stale, we say so instead of filling the gap with a guess.

Vendor prices and ranges checked on 19 August 2026. Federal rates and rule texts checked on 15 September 2026. All figures in USD.

Prices US vendors publish on their own pricing pages

Only a handful of US vendors put a number on a pricing page. These are the ones we verified.

Vendor Product as listed Published price Source
Astra Security Pentest plan $1,999 per year Astra pricing
Astra Security Higher pentest plan $5,999 per year Astra pricing
Cobalt Autonomous Pentest $3,500 per test Cobalt pricing
Synack AI Sara Pentest Pricing starts at $4,181 Synack pricing
Synack Standard Pentest Pricing starts at $10,283 Synack pricing
Synack Synack14 Pentest Pricing starts at $27,120 Synack pricing
Sprocket Security Starter package $15,000 Sprocket pricing
Sprocket Security Internal network testing $13,000 add-on Sprocket pricing

Read these carefully.

  • None of these pages shows a publication or update date. Sprocket's footer carries a 2026 copyright.
  • Cobalt marks the $3,500 figure a limited time offer. It is not a standing list price, and it covers the autonomous AI test, not human-led work.
  • Sprocket does not state a billing period for the $15,000 figure. The page describes a subscription with continuous testing through the year.
  • Astra's pricing page is script-driven and the plan labels moved between our two fetches. The two prices held steady. Trust the prices, not the labels.

Vendors that publish nothing

¿Quiere un pentest externo gratuito de su dominio?

Ejecutar el chequeo de pentest gratuito

We checked and found no price on the pricing pages of BreachLock, HackerOne, Bishop Fox, Emagined Security and Red Sentry. All route to a sales conversation.

Red Sentry states its position openly: "No packages. No bait pricing. No arbitrary numbers." Source: Red Sentry, 17 August 2026.

Rhino Security Labs gives one directional figure and no list: "Penetration testing generally start around the $10,000 range, but can grow into six figures for large, in-depth projects." Source: Rhino Security Labs FAQ, no date shown.

Raxis describes the spread it sees in the market rather than its own price: "I know something is amiss when I see quotes range from $1,500 to $18,000 per week (and more)." Source: Raxis, content updated 16 June 2025.

Price ranges by scope

Two US firms publish a dated range table. We print both, because they disagree in places and you should see that.

Synack, dated 25 June 2026

Scope Published range
External network $4,000 – $12,000
Web application $5,000 – $30,000
API $5,000 – $30,000
Internal network $5,000 – $35,000
Mobile application $7,000 – $35,000
Cloud $10,000 – $50,000
Red team / adversary simulation $30,000 – $150,000+

Headline from the same page: "Penetration testing costs in 2026 range from $5,000 to over $100,000, with most organizations spending between $10,000 and $30,000 per engagement and an all-types average of around $18,300." Source: Synack pentest cost guide, 25 June 2026.

Compass IT Compliance, dated 3 June 2025

This table breaks the price by size rather than by type, which is closer to how a quote is actually built.

Scope Published range
External network, 1–25 IPs $5,000 – $10,000
External network, 25–50 IPs $10,000 – $15,000
External network, 50–100+ IPs $15,000 – $30,000+
Internal network, 1–2 VLANs $7,500 – $12,000
Internal network, 3–5 VLANs, 100–300 devices $12,000 – $20,000
Internal network, 300+ devices $20,000 – $40,000+
Web app, simple static, 1–5 pages $3,500 – $6,000
Web app, moderate dynamic $8,000 – $15,000
Web app, complex custom $15,000 – $35,000+
API $6,000 – $18,000
Cloud $10,000 – $25,000
Mobile $10,000 – $22,000
Red team, foundational, 2–4 weeks $40,000 – $65,000
Red team, advanced, 6–8+ weeks $70,000 – $120,000+
PCI DSS pentest $12,000 – $25,000
Consulting, hourly $250 – $400 per hour

Source: Compass IT Compliance, 3 June 2025.

One more dated point for external testing

Triaxiom Security publishes external network figures on a page dated 3 April 2026: about $5,000 for fewer than 10 hosts, $8,000 to $15,000 for 10 to 50 hosts, and $15,000 to $20,000 or more above 50 hosts. It also names the driver: "Scope (specifically, the number of IP addresses on your Internet perimeter with at least one open port accepting connections) is the biggest single cost driver." Source: Triaxiom Security, 3 April 2026.

Triaxiom's internal and web application price pages are dated 2018. We left those figures out.

A market benchmark

Packetlabs states that "the average cost of a penetration test in the United States in 2025 ranges from $10,000 to over $150,000". Source: Packetlabs, published 20 January 2024, last updated 20 October 2025. Packetlabs is a Toronto firm writing about the US market in USD.

What the federal price list says

The US government publishes the hourly rates its contractors were awarded. GSA's CALC+ labor rate data covers the Multiple Award Schedule. It is the closest US equivalent to the day rates UK suppliers declare on G-Cloud.

On 15 September 2026 we searched it for "penetration tester". It returned 394 labor rates, refreshed on 14 September 2026. The lowest was $57.34 an hour, the median $158.26 and the highest $320.56. At the median, an eight-hour tester day comes to about $1,266. That is our arithmetic, not a GSA figure.

Contractor, as GSA lists it Labor category Hourly rate
KAPU SOLUTIONS, INC. Penetration Tester 1 $57.34
FEDERAL INFORMATION SYSTEMS, INC Penetration Tester $90.07
CHENEGA SYSTEMS, LLC Penetration Tester, Mid $106.17
SCIENCE APPLICATIONS INTERNATIONAL CORPORATION Penetration Tester II $107.04
CGI FEDERAL INC. Penetration Tester 2 $126.45 (contract ends 18 October 2026)
BRAINGU LLC Penetration Tester III $281.40
FORTALICE SOLUTIONS LLC Penetration Tester 4 $297.35
ACCENTURE FEDERAL SERVICES LLC Vulnerability Assessment Analyst and Penetration Tester 4 $307.17

All eight rows sit on SIN 54151HACS, Highly Adaptive Cybersecurity Services. GSA sorts HACS vendors into six subgroups, and Penetration Testing is one of them. Sources: GSA CALC+ ceiling rates API, read 15 September 2026, and GSA Highly Adaptive Cybersecurity Services, page updated 17 August 2026.

How to read these numbers. Each is an awarded hourly rate for one person on a federal schedule contract. It is not the price of an engagement, and it is not what an agency finally paid. The Federal Acquisition Regulation says GSA has already found schedule rates "fair and reasonable", and that buyers "may seek additional discounts before placing an order". Source: FAR 8.404(d). One contractor often lists several rates for the same role, one per worksite, and the experience asked for differs by row: two years for the $57.34 row, five years for the $90.07 row.

Which US rules actually require a penetration test

Buyers get sold on the wrong requirement all the time. Here is what the text says.

PCI DSS v4.0 requires one at least every 12 months

Requirement 11.4.2 covers internal testing and 11.4.3 covers external testing. Both use the same wording: testing is performed "Per the entity's defined methodology", "At least once every 12 months", "After any significant infrastructure or application upgrade or change", "By a qualified internal resource or qualified external third-party", and "Organizational independence of the tester exists".

Requirement 11.4.5 adds segmentation testing at least once every 12 months. Requirement 11.4.4 says exploitable findings must be corrected and "Penetration testing is repeated to verify the corrections".

Source: PCI SSC, PCI DSS v4.0 SAQ D for Merchants, publication date April 2022. The standard itself sits behind a licence click-through, so we quote the openly published SAQ. Check the requirement numbers against the version your QSA assesses you on.

Note what PCI does not say. It names no tester certification at all. Not OSCP, not CREST, not GPEN. It asks for a qualified party and for organizational independence. Your QSA decides what qualified means.

CMMC Level 3 requires a penetration test at least annually

32 CFR 170.14(c)(4) lists requirement CA.L3-3.12.1e: "Conduct penetration testing at least annually or when significant security changes are made to the system, leveraging automated scanning tools and ad hoc tests using subject matter experts." Source: 32 CFR 170.14 on eCFR.

The "at least annually" comes from the CMMC rule. The NIST requirement behind it, SP 800-172 3.12.1e, leaves the frequency to the organization. NIST withdrew that February 2021 edition on 13 May 2026 and replaced it with Revision 3. The CMMC rule still incorporates the 2021 edition, so the text above is the one that applies. Source: NIST SP 800-172.

CMMC Level 1 has no penetration testing requirement. Level 2 is built on NIST SP 800-171 Rev. 2. Its requirements 3.11.2 (scan for vulnerabilities) and 3.12.1 (periodically assess security controls) do not name penetration testing. Source: NIST SP 800-171 Rev. 2.

NYDFS Part 500 requires an annual penetration test

Section 500.5(a)(1) requires "penetration testing of their information systems from both inside and outside the information systems' boundaries by a qualified internal or external party at least annually". Source: NYDFS Second Amendment to 23 NYCRR 500, dated 1 November 2023. The Section 500.5 compliance date was 1 May 2025.

Again, the rule asks for "a qualified internal or external party" and names no certification.

The section is now titled "Vulnerability management". Small covered entities are exempt from 500.5 under section 500.19(a): fewer than 20 employees and independent contractors, or less than $7,500,000 gross annual revenue in each of the last three fiscal years, or less than $15,000,000 in year-end total assets. Source: DFS consolidated text of Part 500, which DFS marks as not an official version.

The FTC Safeguards Rule requires one, unless you monitor continuously

For financial institutions under the FTC's jurisdiction, 16 CFR 314.4(d)(2) says: "Absent effective continuous monitoring or other systems to detect, on an ongoing basis, changes in information systems that may create vulnerabilities, you shall conduct: (i) Annual penetration testing of your information systems determined each given year based on relevant identified risks in accordance with the risk assessment". It also requires vulnerability assessments "at least every six months". Source: 16 CFR 314.4 on eCFR.

Two limits matter. Continuous monitoring is written into the rule as the alternative, so the annual test is not absolute. And 16 CFR 314.6 lists paragraph (d)(2) among the provisions that "do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers". Source: 16 CFR 314.6. Whether a given tool counts as effective continuous monitoring is a judgement for you and your advisers. We make no such claim for Sentinel.

FedRAMP requires one, and it must be a 3PAO

FedRAMP publishes dedicated penetration test guidance for cloud service providers. Source: FedRAMP Penetration Test Guidance version 3, dated 30 June 2022. The assessment must come from an accredited third-party assessment organization.

We could not source an "at least annually" cadence from a fedramp.gov page. The FedRAMP Rev5 control CA-08 leaves the frequency as an organization-defined parameter. We are not going to print a cadence we cannot cite.

HIPAA does not require a penetration test today. A proposed rule would.

The current Security Rule asks for "an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information" (45 CFR 164.308(a)(1)(ii)(A)) and "a periodic technical and nontechnical evaluation" (164.308(a)(8)). Neither names penetration testing. Source: 45 CFR 164.308 on eCFR.

On 6 January 2025 HHS proposed a new 164.312(h). It says "Penetration testing must be performed at least once every 12 months" by "a qualified person", and that automated vulnerability scans run "at least once every six months", or more often where the risk analysis says so. Source: HHS proposed rule, 90 FR 898.

Status on 15 September 2026: the Federal Register lists only the proposed rule under RIN 0945-AA22, with no final rule and no withdrawal, and eCFR shows 164.308 and 164.312 unchanged. We could not reach the federal regulatory agenda, so we print no target date. Do not let a vendor tell you HIPAA mandates a pentest today.

SOC 2: ask your auditor

A SOC 2 report is an auditor's opinion against the AICPA Trust Services Criteria. The AICPA publishes the criteria behind a free account login, and we did not read that document for this update, so we do not quote it. We cannot confirm or deny the claim you will see on vendor blogs that a point of focus under CC4.1 names penetration testing. Points of focus are guidance, not requirements, either way.

Auditors and enterprise customers commonly ask for a pentest report, usually filed as evidence for CC4.1 and CC7.1. Read your auditor's request list, not a vendor's blog, ours included.

Accreditation in the US

There is no US equivalent of the UK CHECK scheme for general commercial work.

The closest thing is FedRAMP 3PAO accreditation, and it applies only to federal cloud work. 3PAOs are accredited by A2LA against ISO/IEC 17020 and the A2LA R311 requirements. Source: A2LA FedRAMP accreditation.

OSCP, GIAC GPEN and CREST are market signals in the United States. No US regulation we checked names any of them. CREST does operate an Americas chapter and some US firms hold it. Source: CREST.

What we could not source

  • No US vendor publishes a day rate. Not one. Hourly figures of $200 to $400 appear in vendor blog posts only, never on a pricing page.
  • Cobalt's State of Pentesting report carries no cost data. We checked. Eight editions, no dollar figures.
  • BreachLock publishes no price. Per-service figures circulating online come from a third-party buyer-data site, not from BreachLock. We did not print them.
  • Bishop Fox publishes nothing. The page that reportedly carried a range now returns a 404.
  • We could not fetch the PCI DSS v4.0.1 master document. It sits behind a click-through licence. We cited the Council's own SAQ D, which carries the same requirement text.
  • We could not source the FedRAMP annual cadence from an official page.
  • We could not read the AICPA Trust Services Criteria. They sit behind a login. An earlier version of this page said the criteria do not name penetration testing. We removed that sentence because we cannot source it.
  • We could not confirm a target date for the proposed HIPAA rule. The federal regulatory agenda did not load for us.
  • GSA's own wording on what a ceiling rate means sits on buy.gsa.gov, which did not load for us. We cite the FAR instead.

Where Matproof Sentinel fits, and where it does not

Matproof Sentinel is an AI penetration testing platform. Pricing is public, in euros, with no sales call: €149 per single run, €299 per month, €1,490 per month, and Custom for enterprise. See pricing. We do not publish a USD price list.

Sentinel runs ten specialised AI agents in stages. Recon maps the surface with nmap, amass and httpx. Web, API, Infra, Cloud and Mobile agents run in parallel with nuclei, sqlmap, OWASP ZAP, testssl.sh, Prowler and MobSF. Source-code and supply-chain agents read your repositories with Semgrep, Gitleaks and Trivy. A ValidatorAgent re-runs every finding and stamps it VALIDATED, UNVERIFIED or FALSE_POSITIVE. Reports export as PDF, JSON and SARIF 2.1.0. The full method is public at docs.matproof.com.

What Sentinel is not

  • There is no human penetration tester. AI agents find the issues. Another AI agent checks them.
  • Matproof holds no CREST accreditation, no NCSC CHECK approval and no FedRAMP 3PAO accreditation.
  • Sentinel does no social engineering, no physical intrusion and no zero-day research.
  • Sentinel cannot sign a report as an accredited assessor.

On PCI DSS specifically

PCI DSS 11.4 asks for a qualified party and organizational independence. It names no certification, and an independent platform can satisfy the independence part. Whether your QSA accepts an AI-only test as the 11.4 penetration test is your QSA's call, not ours. Ask your QSA before you rely on it. We will not tell you it is settled.

Hire a US firm instead when

  • You are in a FedRAMP process. You need a 3PAO.
  • A customer contract or a federal tender names an accreditation.
  • You need social engineering, physical entry or a full red team.
  • Your QSA has told you an AI-only test will not satisfy 11.4.
  • You run OT, SCADA or mainframe systems.

Use Sentinel when

  • You ship code weekly and an annual test leaves the rest of the year untested.
  • Your auditor wants evidence that testing ran all year, not once.
  • You want a price without a sales call.
  • You want findings in your issue tracker and SARIF in your pipeline, not a PDF in a shared drive.

Most mature teams do both. One accredited engagement a year for the signature. Continuous automated testing for the evidence in between.

Frequently asked questions

How much does a penetration test cost in the US?
Synack's dated guide puts most engagements at $10,000 to $30,000, with an all-types average near $18,300 (25 June 2026). Compass IT Compliance breaks it down by size, from $3,500 for a simple static web app to $40,000 or more for a large internal network (3 June 2025). Published vendor prices start at $1,999 per year for Astra and $3,500 per autonomous test at Cobalt.

What is the hourly rate for a US penetration tester?
Two vendor blogs publish a figure: $250 to $400 per hour (Compass IT Compliance, June 2025) and $200 to $400 per hour (Software Secured, no date shown). No US vendor pricing page publishes a rate. The federal schedule does: see the GSA figures above.

Does PCI DSS require a penetration test?
Yes. Requirements 11.4.2 and 11.4.3 require internal and external testing at least once every 12 months and after significant change, plus segmentation testing under 11.4.5 and a re-test to verify fixes under 11.4.4.

Does SOC 2 require a penetration test?
Ask your auditor. We could not read the AICPA criteria, which sit behind a login, so we make no claim that they name or omit a penetration test. Auditors and customers commonly ask for a pentest report, usually as evidence for CC4.1 and CC7.1.

Does HIPAA require a penetration test?
Not today. 45 CFR 164.308(a)(8) requires a periodic evaluation and does not name penetration testing. An HHS proposed rule of 6 January 2025 would require one at least every 12 months. As of 15 September 2026 it is not final.

Does the FTC Safeguards Rule require a penetration test?
Yes, annually, unless you run effective continuous monitoring, under 16 CFR 314.4(d)(2). Institutions holding customer information on fewer than 5,000 consumers are exempt from that paragraph under 314.6.

What does the federal government pay a penetration tester per hour?
GSA's CALC+ data listed 394 awarded hourly rates for penetration tester labor categories on 15 September 2026, from $57.34 to $320.56, with a median of $158.26. These are rates for one person on a federal schedule contract, not engagement prices.

Do I need an OSCP or CREST certified tester in the US?
No US rule we checked names a certification. PCI DSS asks for a qualified party with organizational independence. NYDFS asks for a qualified internal or external party. Certifications are how firms signal quality, not how regulators define it.

Related reading


Ready to act on this? Matproof runs continuous AI penetration testing with public pricing. Book a demo.

penetration testing cost usapentest cost united stateshow much does a penetration test costpenetration testing pricing 2026pci dss penetration testing costweb application penetration testing cost usa

Pentest externo gratuito

Analizamos su dominio en busca de las vulnerabilidades más explotadas y le enviamos un informe priorizado por correo electrónico en un plazo de 24 horas.

Realizar comprobación gratuita

Stop guessing. Start testing.

Run a free 3-minute scan now, or start a full Matproof Sentinel pentest from €299/mo. Audit-ready report with proof of exploit, no procurement loop.