Ask five Australian firms what a penetration test costs and you will get five very different numbers for what sounds like the same job. That is not because the market is broken. It is because “a penetration test” describes everything from a two-day automated scan with a logo on it to a multi-week, senior-led assault on your entire environment.
This guide explains what actually drives penetration testing cost in Australia, how providers turn your scope into a quote, why fixed-price and day-rate models put the risk in very different places, and what the cheapest quotes quietly leave out.
What determines penetration testing cost in Australia
Every legitimate quote starts in the same place: scope. The price is a function of how much attack surface you are asking a tester to cover, how deeply you want it covered, and what happens after the report lands. Seven drivers do most of the work:
Number and complexity of applications
A brochure site with a contact form and a multi-tenant SaaS platform with payment flows are not the same test. What matters is not page count but functionality: authenticated workflows, APIs, file uploads, payment and integration points, and business logic a tester has to actually reason about. See what a thorough engagement covers on our web application penetration testing page.
IP count — live hosts, not allocated ranges
For infrastructure testing, the honest sizing unit is the number of live, responsive hosts and exposed services, not the size of the range on paper. A provider that prices purely per IP without asking what is actually running on them is telling you something about their method.
User roles and privilege levels
Every role in an application multiplies the access-control testing: can a standard user reach admin functions, can tenant A read tenant B’s data, can an unauthenticated visitor reach anything they should not? This is some of the highest-value work in a modern engagement, and it scales with the number of roles you want covered.
Testing depth: black box, grey box or white box
Black box (no credentials, no documentation) mimics an outside attacker but spends time on discovery. Grey box (credentials and context provided) is the pragmatic default — the tester spends the engagement finding flaws rather than finding the front door. White box (source code, architecture documentation, walkthroughs) covers the most ground per day but adds review effort per component. Depth changes both the day count and what those days are spent on.
Environment count
Testing production and staging, or the same platform across multiple regions or tenants, is not free duplication — configurations drift, and the differences are often where the findings live.
Retesting
After you remediate, someone has to verify the fixes actually hold. Some providers include that retest in the price; many bill it as a second engagement. It belongs in the cost comparison from the start, because a finding that was never retested is a finding you are still exposed to.
Compliance requirements
PCI DSS adds segmentation testing and an annual cadence for in-scope entities; APRA CPS 234 and ISO 27001/SOC 2 auditors shape the depth and reporting evidence an engagement has to produce — see our guide to penetration testing for Australian compliance.
Reporting effort rides on top of all of this: a report with reproduction steps, evidence and specific remediation for every finding takes meaningfully longer to produce than a reformatted scanner export.
How providers turn scope into a quote: engagement sizing
Behind every quote is the same calculation: scope is converted into tester-days. A scoper — ideally the person who will do the testing — enumerates the units of work, applies a depth assumption, and adds time for reporting and a debrief. The day count times seniority is the engagement; everything else is commercial packaging.
This is also why the “average cost of a penetration test” is the wrong question — averaging a small single-application test with a month-long objective-based operation produces a number that describes neither. The useful question is: what shape is my engagement, and what does that shape hinge on?
| Engagement shape | What the sizing hinges on | Effort profile |
|---|---|---|
| Single web application | Roles, authenticated functionality, API surface, business-logic complexity | The smallest common engagement — sized in days, growing with each role and workflow that needs authenticated coverage |
| External network / perimeter | Live hosts and exposed services, not allocated IP ranges | Discovery plus manual attack of each interesting service; a handful of live hosts sits at the short end |
| Cloud configuration review | Number of accounts or subscriptions, services actually in use, identity and network complexity | Scales with the breadth of the estate more than with data volume; multi-account setups add coordination and coverage time |
| Red-team style engagement | Objectives, permitted techniques, stealth requirements, duration of the operation | The largest shape — reconnaissance, tooling and persistence phases make it weeks, not days, before reporting starts |
Mixed engagements — an external test plus one application, say — are sized as the sum of their parts. A provider who can walk you through their day estimate, shape by shape, is showing you their working. One who quotes a flat figure without asking about roles, hosts or environments has not sized your engagement at all — they have guessed, and one of you is going to wear the difference.
Fixed price vs day rates: who carries the overrun risk
Once the days are estimated, the commercial model decides who pays when the estimate is wrong — and estimates are wrong regularly, because environments are always messier than the scoping call suggested.
Under an hourly or day-rate model, that risk is yours. If testing runs long, you pay more. The incentive problem is structural: a provider billing by the day has no commercial reason to be efficient, and every reason to interpret ambiguous scope generously. Mid-engagement variation requests — “we found more than expected, we need another week” — land when your negotiating position is weakest: half-tested, budget committed, deadline fixed.
Under a fixed-price model, the provider carries the overrun risk. If the engagement takes longer than estimated, that is their problem, not your invoice. This only works when scoping is done accurately by someone senior enough to see the traps in advance — which is precisely why fixed pricing and senior scoping tend to travel together.
| Fixed price | Hourly / day rate | |
|---|---|---|
| Testing runs long | The provider’s problem — the price holds | Your invoice grows |
| Mid-engagement “we need another week” | Absorbed by the provider | A variation request, landing when your leverage is weakest |
| Incentive to test efficiently | Built in — overruns cost the provider | Structurally absent — longer runs bill more |
| What to check before signing | That the scope is specific — read the exclusions | What happens to the estimate mid-engagement |
One caution: a fixed price attached to a vague scope is not risk transfer, it is a dispute deferred. Read the exclusions — a cheap fixed quote that quietly excludes authenticated testing, retesting, or half your roles has moved the cost, not removed it.
What a cheap pen test actually cuts
Penetration testing has three real inputs: senior time, manual effort, and verification. A quote significantly below the market for a given scope has cut at least one of them — the price pressure has to come out somewhere. The usual cuts:
The junior bench
A principal consultant scopes the work and wins the deal; the testing lands with whoever is free — often a junior running a standard toolkit against a checklist. The proposal was senior. The hands on your systems were not.
Scan-and-send
An automated vulnerability scan, lightly reformatted and rebadged as a penetration test. The “findings” are unverified signatures — heavy on false positives, blind to business logic and anything requiring judgement. It is the cheapest product in the market because it involves almost no human testing at all.
No manual exploitation
Findings are listed as theoretical severities rather than exploited to demonstrate impact — so you never learn what an attacker could actually achieve, and your engineers burn remediation sprints triaging issues nobody proved were real.
Paid retests
The headline price excludes verifying your fixes. The retest arrives later as a second invoice — at which point the “cheap” engagement has quietly caught up to the quotes it undercut.
Templated reports
Boilerplate findings with generic remediation advice, recycled across clients. If the guidance could apply to any company in the country, it was not written about your environment.
None of this means the most expensive quote wins. It means the number at the bottom of a quote is unreadable without knowing what sits behind it — which is what the next section is for.
Eight questions to ask a penetration testing provider before you sign
- Who, exactly, will be hands-on-keyboard during our test — and what are their certifications? Not the company’s badges: the individual’s. This is the question that exposes the bait-and-switch org chart. At Core Sentinel the answer is the senior tester who scoped your engagement, holding current OSCE and OSCP among 30+ professional certifications, with 20+ years in offensive security; our founder has also completed CREST certification.
- What proportion of the testing is manual? If the honest answer is “mostly automated with manual review”, you are buying a scan with supervision. Tools should assist a human tester, not replace one.
- Will you actually exploit what you find? Exploitation — safely, under agreed rules of engagement — is what separates proven impact from theoretical severity. If exploitation is out of scope by default, ask why.
- Is the remediation retest included in the price? If not, add it to the quote before you compare providers. A test without a retest leaves you with a list of holes and no evidence any of them were closed.
- Is this a fixed price, and what happens if testing runs long? Get the overrun answer in writing. “We’ll discuss it if it comes up” means the risk is yours.
- Can we see a sanitised sample report? Two minutes with a real report tells you more than any capability deck: reproduction steps and evidence, or paragraphs of boilerplate?
- How are findings risk-rated? A raw CVSS copy-paste treats every environment identically. Good providers rate findings by real impact in your context — because that ordering is what your remediation budget will follow.
- What is excluded from scope — in writing? Cheap quotes are frequently narrow quotes. Unauthenticated-only testing, capped host counts and excluded roles or environments are all legitimate scoping decisions — but only if you made them knowingly.
A provider worth engaging will answer all eight without flinching. Evasion on any of them — particularly the first — is your answer.
Frequently asked questions
How much does a penetration test cost in Australia?
There is no honest single figure, because the cost is a function of scope: how many applications and live hosts, how many user roles and environments, the depth of testing (black, grey or white box), and whether the remediation retest is included. A provider quotes by converting that scope into senior tester-days. Any flat number offered before those questions are asked is a guess — and averages published online blend incomparable engagements into a figure that describes none of them. Define your scope, then get fixed quotes against it: that is the only comparison that means anything.
Why do penetration testing quotes vary so much between providers?
Because the same words cover different products. One quote is priced for a senior tester manually exploiting your systems for days, with an evidence-backed report and an included retest. Another is priced for an automated scan, a junior operator and a templated report. The scope on paper looks identical; the inputs — seniority, manual effort, verification — are not. Large price gaps between quotes for the same scope almost always trace back to one of those three inputs being cut.
Is penetration testing mandatory in Australia?
There is no single law that mandates penetration testing for every Australian organisation, but for many it is effectively required. PCI DSS explicitly requires penetration testing at least annually for in-scope entities, APRA CPS 234 requires regulated entities to systematically test their information-security controls, and ISO 27001 and SOC 2 auditors expect independent testing evidence in practice. Customer contracts and vendor security questionnaires impose the same requirement commercially. Our guide to penetration testing for Australian compliance breaks down which frameworks require what, and how often.
Is the retest included in the price, or billed separately?
It varies by provider, and it materially changes the true cost of the engagement — always ask before comparing quotes. At Core Sentinel the remediation retest is included in the fixed price: once your team has fixed the findings, we verify every fix at no extra cost and issue a letter of attestation you can share with customers and auditors.
Does a longer penetration test cost more?
Yes — duration is an output of scope, and price follows the tester-days. Every additional application, role, environment or live host adds days of senior time, so a broader engagement costs more because it buys more actual testing, not because the meter runs. What matters commercially is whether the day count is fixed before you sign: under a fixed-price model, extra time uncovered mid-engagement is the provider’s cost, not a variation on your invoice.
What is the difference between a penetration test and a vulnerability scan?
In cost terms, almost everything. A scan is the cheapest product on the market because it involves almost no human effort: an automated tool lists potential issues, many of them false positives, with no exploitation and no business-logic reasoning. A penetration test is priced in senior tester-days precisely because a skilled human does what the tool cannot. So when a “penetration test” quote comes in at scan money, it is usually a scan — the human testing has been priced out, not the need for it.
Get a fixed-price penetration testing quote
Tell us your scope — applications, hosts, roles, environments — and a senior OSCE/OSCP-certified tester will return a fixed quote before you commit, with the remediation retest included.
Prefer to talk it through first? Call 1300 859 443 — you will be speaking with someone who actually does the testing.