Black Shard

Insights22 August 2026Updated 6 October 2026

Penetration testing cost in Australia, and how to get a quote

A penetration testing quote in Australia follows scope, and there is no standard rate card. Broad market prices start around $5,000 for a single web application or external network test and reach about $45,000 for a combined external and internal engagement. A larger environment pushes past the top of any band. Six scoping decisions move a quote within those bands, and the cheapest quote in your inbox is usually a vulnerability scan sold as a penetration test.

A brass balance scale weighing a stack of coins against a magnifying glass on dark slate, lit cold cyan

Why nobody can give you a number without a scope

A penetration test is skilled human time, and skilled human time is what you are pricing when you ask for a quote. Two requests that read identically on the surface, test our web app, can differ several times over in the tester-days behind them, depending on how many roles the application has, whether the tester works with credentials or without, and whether staging sits alongside production in scope. The word application hides all of that variation.

A published starting price is useful when it names exactly what it buys. A useful quote for the rest follows a conversation about your systems, because the scoping questions are what turn a starting price into a fixed one.

What actually moves the price

Strip away the marketing and a quote comes down to a small set of decisions, each of which changes how many tester-days the work actually takes. Ask a provider to walk through these before comparing any two numbers.

  • Attack surface: how many applications, APIs, hosts and live environments are in scope, and how many distinct user roles each application carries
  • Methodology depth: an unauthenticated surface sweep versus authenticated testing of every role, since almost everything that matters in a modern application sits behind the login
  • Environments: production alone, or production plus staging and development, each one adding testing time
  • Reporting depth: a findings list versus a ranked report with reproduction steps, business impact, and a specific fix for every issue
  • Retest: whether verifying that the fixes actually landed is inside the original price or billed again once the report is delivered
  • Delivery: remote scoping and testing, or on-site work with the travel and coordination that adds

Penetration testing prices in Australia, by engagement type

The figures below describe how the Australian market generally prices these engagements. They are not a quote, and every range can be pushed well past its top end by an environment that is larger, more tenanted or more regulated than the average, just as it can be undercut by a provider selling something narrower than the label on the invoice suggests. Treat them as a shape to sanity-check a quote against; they are not a number to hold anyone to.

A single small web application with a couple of user roles, tested by a provider actually issuing test credentials, tends to sit toward the bottom of its band. A multi-tenant platform with a dozen roles, an admin console and an API surface of its own pushes the same category well past the top. The pattern repeats across every row: scope decides where in the range you land far more than the category label does.

Engagement typeWhat it typically coversBroad market range (AUD)What pushes it toward the top
Vulnerability scan (included for contrast; it is not a penetration test)Automated, signature-based scanning of hosts and services, one-off or on a scheduleLow hundreds a month for continuous scanning; low thousands for a one-off pass across a modest estateHost count and how often it runs; there is no manual work to scale with depth
Web application penetration testOne application, tested authenticated across its roles, against the OWASP playbooksRoughly $5,000 to $20,000 per applicationExtra roles, an admin tier, an API of its own, or multi-tenancy that needs the tenant boundary tested
External network penetration testWhat an internet attacker can reach from outside the perimeterRoughly $5,000 to $15,000A larger internet-facing footprint and more discrete services exposed to it
Internal network penetration testAn assumed-breach foothold, measuring how far it goes: lateral movement, privilege escalation, Active DirectoryRoughly $10,000 to $30,000More sites, more segments, a larger directory, and on-site delivery
External and internal combinedBoth of the above run together as one engagement, priced as a packageRoughly $18,000 to $45,000Everything above, plus the coordination of running both in one window
Social engineering or phishing simulationA campaign against a defined user population, measuring what people click and reportRoughly $4,000 to $10,000 per campaignMultiple rounds, a larger user population, or pairing email with vishing or physical pretexting

Broad Australian market ranges by engagement type, indicative only

Why the cheapest quote in your inbox is usually a scan

A handful of tells separate a genuine penetration test quote from a vulnerability scan sold under that name, and none of them require reading the fine print. The price scales cleanly with a number typed into a form, IP count or page count, rather than following a conversation about what the business is actually trying to protect.

Turnaround is quoted in a day or two, which is enough time for a tool to run but not enough for a person to enumerate, chain and write up findings by hand. Nobody asks for test credentials, because there is no login to test from the inside, only a perimeter to sweep from outside it. The report, when a sample is offered, reads as a list with the same generic remediation text attached to every instance of the same finding, and no named tester is attached to the work.

None of that makes a scan a bad product. Automated scanning is cheap for a reason: it is software, it is fast, and it is worth running continuously rather than once. The problem is only the label.

A scan priced and delivered as a penetration test sells a buyer pentest expectations, human validation, chained findings, business-logic testing, at scan depth, and the gap only becomes visible when the report lands or when an auditor asks a question the document cannot answer. Our note on the difference between the two, and our guide to choosing the right assessment for where you actually are, cover the mechanics of what each instrument finds and what it structurally cannot.

Scoping is the one lever that makes any of these numbers real

Everything above is a market shape. The number that applies to your systems comes out of a scoping conversation, and three decisions inside that conversation move it more than anything else. Name the actual objective: the customer database, the tenancy boundary, the ability to reach production, so effort goes where compromise would actually hurt instead of spreading evenly across everything.

Decide upfront whether authenticated testing across every role is included, since a quote that withholds credentials is pricing a perimeter check and calling it an application test. And settle what a retest looks like before you sign anything: whether verifying the fixes is inside the fixed price or a second invoice once the report is in your hands.

The rest of a penetration test scope covers environments and exclusions, timing windows and rules of engagement, and the questions a competent provider asks before quoting anything at all.

How to get a penetration testing quote in Australia

Black Shard quotes every penetration test as a fixed scope, with the price and the timeframe set in writing before work starts. An external penetration test starts at $4,950 ex GST, with a written report and a re-test of the reported findings.

The quote names its drivers: the size of the attack surface, the number of environments in scope, tenancy count for multi-tenant products, and whether any of the work needs to run on-site. The re-test sits inside the fixed scope, and rules of engagement are agreed in writing before testing begins.

A free 30-minute scoping call produces the quote, or a brief through the contact form or to info@blackshard.com.au starts scoping from the detail you have and works out whichever of these details are still open.

  • The applications, APIs, networks or cloud environments in question, and whether each is internet-facing or internal
  • The user roles in each application, and whether test accounts can be issued for every role
  • The environments in scope: production, staging, or both
  • For a multi-tenant product, the tenancy count and whether the tenant boundary is in scope
  • Whether any of the work needs to run on-site
  • The deadline the report has to meet, such as an audit, a tender or a customer security review, and who will read it

The practical takeaway

Use the ranges above to sanity-check a quote. They are not a basis for negotiating one. If a number comes in well under its band, ask what is missing: credentials, a retest, a named tester, a report that goes beyond a findings list, a penetration test attestation letter you can hand to a customer.

If it comes in well over, ask what in your scope is driving that, and expect a specific answer rather than a shrug. Either way, the conversation that produces a real number is the same one that produces a useful test: it starts from what you are actually trying to protect and what it would cost you if someone reached it.

Tell us what you need tested.

Brisbane head office.

Open a briefinfo@blackshard.com.au