Why nobody can give you a number without a scope
A penetration test is skilled human time, and skilled human time is what you are pricing when you ask for a quote. Two requests that read identically on the surface, test our web app, can differ several times over in the tester-days behind them, depending on how many roles the application has, whether the tester works with credentials or without, and whether staging sits alongside production in scope. The word application hides all of that variation.
That is why a published number with no scoping conversation behind it is a guess wearing a price tag. A useful quote follows a conversation about your systems; it does not arrive before one. What follows is the shape of that conversation: the handful of decisions that move the price, broad ranges the Australian market currently charges by engagement type, and the tell that separates a real quote from a relabelled scan.
What actually moves the price
Strip away the marketing and a quote comes down to a small set of decisions, each of which changes how many tester-days the work actually takes. Ask a provider to walk through these before comparing any two numbers.
- Attack surface: how many applications, APIs, hosts and live environments are in scope, and how many distinct user roles each application carries
- Methodology depth: an unauthenticated surface sweep versus authenticated testing of every role, since almost everything that matters in a modern application sits behind the login
- Environments: production alone, or production plus staging and development, each one adding testing time
- Reporting depth: a findings list versus a ranked report with reproduction steps, business impact, and a specific fix for every issue
- Retest: whether verifying that the fixes actually landed is inside the original price or billed again once the report is delivered
- Delivery: remote scoping and testing, or on-site work with the travel and coordination that adds
What the Australian market charges, broadly
The figures below describe how the Australian market generally prices these engagements. They are not a quote, they are not Black Shard's pricing, and every range can be pushed well past its top end by an environment that is larger, more tenanted or more regulated than the average, just as it can be undercut by a provider selling something narrower than the label on the invoice suggests. Treat them as a shape to sanity-check a quote against, not a number to hold anyone to.
A single small web application with a couple of user roles, tested by a provider actually issuing test credentials, tends to sit toward the bottom of its band. A multi-tenant platform with a dozen roles, an admin console and an API surface of its own pushes the same category well past the top. The pattern repeats across every row: scope decides where in the range you land far more than the category label does.
| Engagement type | What it typically covers | Broad market range (AUD) | What pushes it toward the top |
|---|---|---|---|
| Vulnerability scan (for contrast, not a penetration test) | Automated, signature-based scanning of hosts and services, one-off or on a schedule | Low hundreds a month for continuous scanning; low thousands for a one-off pass across a modest estate | Host count and how often it runs, not depth, since there is no manual work to scale |
| Web application penetration test | One application, tested authenticated across its roles, against the OWASP playbooks | Roughly $5,000 to $20,000 per application | Extra roles, an admin tier, an API of its own, or multi-tenancy that needs the tenant boundary tested |
| External network penetration test | What an internet attacker can reach from outside the perimeter | Roughly $5,000 to $15,000 | A larger internet-facing footprint and more discrete services exposed to it |
| Internal network penetration test | An assumed-breach foothold, measuring how far it goes: lateral movement, privilege escalation, Active Directory | Roughly $10,000 to $30,000 | More sites, more segments, a larger directory, and on-site delivery |
| External and internal combined | Both of the above run together as one engagement, priced as a package | Roughly $18,000 to $45,000 | Everything above, plus the coordination of running both in one window |
| Social engineering or phishing simulation | A campaign against a defined user population, measuring what people click and report | Roughly $4,000 to $10,000 per campaign | Multiple rounds, a larger user population, or pairing email with vishing or physical pretexting |
Broad Australian market ranges by engagement type, indicative only
Why the cheapest quote in your inbox is usually a scan
A handful of tells separate a genuine penetration test quote from a vulnerability scan sold under that name, and none of them require reading the fine print. The price scales cleanly with a number typed into a form, IP count or page count, rather than following a conversation about what the business is actually trying to protect. Turnaround is quoted in a day or two, which is enough time for a tool to run but not enough for a person to enumerate, chain and write up findings by hand. Nobody asks for test credentials, because there is no login to test from the inside, only a perimeter to sweep from outside it. The report, when a sample is offered, reads as a list with the same generic remediation text attached to every instance of the same finding, and no named tester is attached to the work.
None of that makes a scan a bad product. Automated scanning is cheap for a reason: it is software, it is fast, and it is worth running continuously rather than once. The problem is only the label. A scan priced and delivered as a penetration test sells a buyer pentest expectations, human validation, chained findings, business-logic testing, at scan depth, and the gap only becomes visible when the report lands or when an auditor asks a question the document cannot answer. Our note on the difference between the two, and our guide to choosing the right assessment for where you actually are, cover the mechanics of what each instrument finds and what it structurally cannot.
Scoping is the one lever that makes any of these numbers real
Everything above is a market shape. The number that applies to your systems comes out of a scoping conversation, and three decisions inside that conversation move it more than anything else. Name the actual objective: the customer database, the tenancy boundary, the ability to reach production, so effort goes where compromise would actually hurt instead of spreading evenly across everything. Decide upfront whether authenticated testing across every role is included, since a quote that withholds credentials is pricing a perimeter check and calling it an application test. And settle what a retest looks like before you sign anything: whether verifying the fixes is inside the fixed price or a second invoice once the report is in your hands.
That is the short version. Our note on scoping a penetration test properly covers the full list: environments and exclusions, timing windows and rules of engagement, and the questions a competent provider asks before quoting anything at all.
The practical takeaway
Use the ranges above to sanity-check a quote, not to negotiate one. If a number comes in well under its band, ask what is missing: credentials, a retest, a named tester, a report that goes beyond a findings list. If it comes in well over, ask what in your scope is driving that, and expect a specific answer rather than a shrug. Either way, the conversation that produces a real number is the same one that produces a useful test: it starts from what you are actually trying to protect and what it would cost you if someone reached it.
