Blog··7 min read

How much does a penetration test cost in 2026, and what €799 buys

The variables that move a penetration testing price (scope, surface types, depth, report, retest, legal overhead, human versus autonomous), what Darkmoon's €799 flat-rate engagement includes, and the four cases where a bespoke human engagement is still the right buy.

If you have asked three providers for a quote, you already know the honest answer to "how much does a penetration test cost": it depends, and the dependency is rarely explained. This article lists the variables that move a pen testing price, explains what the Darkmoon flat rate of €799 per engagement covers, and is explicit about the cases where a bespoke human engagement remains the right purchase. We quote no market averages. Published price surveys mix scopes that are not comparable, and a number without a scope attached is marketing, not information.

Why pentest quotes vary so much

A penetration test is priced as time multiplied by seniority, plus the overhead of the engagement itself. Five variables account for most of the spread between two quotes for what looks like the same job.

  • Scope size. The number of hosts, applications, API endpoints, user roles and cloud accounts drives the hours. A single login-protected web application and a forty-host estate with three cloud tenants are not the same product, even if both are called "a pentest" on the invoice.
  • Surface types. Web and API testing, Active Directory and identity, Kubernetes, cloud configuration, message brokers, mobile and firmware each need different skills and tooling. Multi-surface engagements cost more because a single tester rarely covers all of them well.
  • Depth and method. A black-box external test from the internet is cheaper than an authenticated grey-box test with test accounts, which is cheaper than a white-box review with source code. Business-logic abuse and chained attack paths take more time than enumeration.
  • Report and retest. A report that carries reproducible evidence, business impact and prioritised remediation takes longer to write than a tool export. A retest of fixed findings is sometimes included, sometimes billed separately. It is the first thing to check in a quote.
  • Legal and administrative overhead. Test authorisation, scope agreement, liability clauses, scheduling and a debrief are real work. In a traditional engagement they hide inside the day rate; a quote that looks cheap may simply have left them out.

Human, autonomous, or both: the driver that changes the economics

The newest price driver is who, or what, does the testing. A traditional engagement is a senior consultant's time. That time is scarce, so it is billed by the day and scheduled weeks out. An autonomous engine changes the cost structure: once the scope is set, enumeration, exploitation attempts and evidence collection run without an hourly meter, and they can be re-run on every change. Darkmoon's engine is open source under GPLv3 and self-hosted by default, so the engine itself costs nothing. What you pay for in a managed engagement is scoping, legal framing, human validation and the debrief.

This is not an argument that machines replace testers. It is an argument that the repeatable part of a test no longer needs to be priced like bespoke craft. The honest division of labour: an autonomous run finds and proves the exploitable paths across a defined scope, qualifying each finding as EXPLOITED, CONFIRMED or UNCONFIRMED with the request, payload or screenshot that backs it; a human sets the scope, reviews the evidence, judges business impact and explains the fixes. Pricing follows that split.

Price driverPushes the price up whenHow the flat rate handles it
ScopeMany hosts, applications, roles or tenantsDescribed in the guided order form; the €799 rate is indicative and adjusted to the final scope at the scoping call
Surface typesWeb, API, cloud, Active Directory and Kubernetes in one engagementWebsites, APIs, applications, network infrastructure, Active Directory, Kubernetes and CMS platforms are orderable target types
DepthAuthenticated testing, business logic, chained pathsTest accounts and constraints are collected at scoping; chained attack paths are what the engine is built to find and prove
ReportEvidence, business impact, remediation guidanceIncluded: vulnerabilities ranked by severity, technical evidence, business impact and prioritised remediation
RetestBilled as a second engagementDiscussed at the debrief; recurring campaigns are a Pro platform feature for teams that self-host
Legal overheadContract loops by email, printed and signed by handTest authorisation, scope and liability signed electronically inside the order flow

What €799 buys with Pentest on Demand

Darkmoon's managed service, Pentest on Demand, is priced as a flat rate of €799 per engagement, shown before you pay. The figure is indicative and adjusted to the final scope: if the scoping call reveals an estate three times the size described in the form, the price follows the scope, and you are told before anything starts. What the rate includes, as stated on the service page:

  • A full penetration test on the defined scope, run end to end by ASC-IT's security experts on the Darkmoon platform.
  • The legal framework and authorisations: test authorisation, scope and liability clauses, signed electronically as part of the order. No test is launched without the signed authorisation.
  • Personalised scoping by our team: after payment we contact you for access, test accounts, technical constraints and the intervention window.
  • A detailed report with evidence and recommendations: vulnerabilities ranked by severity, the technical proof behind each one, business impact and prioritised remediation guidance.
  • A secure client space, accessed by email and a single-use OTP code, where the contractual documents, the report and the exchanges are kept.
  • A video debrief meeting with an expert to walk through the findings, answer questions and guide you on the fixes.

Delivery time depends on the scope and is set in the contractual framework you sign at order time, typically a few business days after the scoping phase.

What a flat rate does not pretend to be

A flat-rate, autonomous-first engagement is the right buy for a defined perimeter: an external surface, a web application and its API, a cloud account, an Active Directory domain, a Kubernetes cluster, a CMS. It is the wrong buy, or only part of the buy, in four situations.

  • Supervised regulatory testing. DORA Article 26 threat-led penetration testing (TLPT) is a regime with authority-validated scope, external testers meeting Article 27 requirements and an attestation. Darkmoon supports a financial entity's general testing programme and its evidence, not the TLPT itself. For NIS2 entities, a validated test is one way to evidence Article 21(2)(f) (policies and procedures to assess the effectiveness of risk-management measures); see our NIS2 guide.
  • Red-team exercises with physical, social-engineering or long-dwell objectives. These are human engagements by definition and are priced in weeks.
  • Source-code review and threat modelling of a product still under design. Different deliverable, different pricing logic.
  • Very large or safety-critical estates, where the scoping itself is a project and the test plan needs sign-off from several owners. Here the €799 figure is a starting point, not the price.

In all four cases an autonomous run still has a place: it keeps the known surface honest between the human engagements, so the expensive hours go to what only humans can do.

Not legal advice

The regulatory references in this article (DORA, NIS2) are a security engineer's reading, not legal advice. Whether a given test satisfies a duty is a decision for your counsel, your auditor or your competent authority. Darkmoon does not certify compliance.

Questions to put to any provider before you compare prices

  • What exactly is in scope, counted in hosts, applications, roles and accounts, and what happens if the real estate turns out larger?
  • Is the test authenticated? Who provides test accounts, and when?
  • Is the retest of fixed findings included, and within what window?
  • Does every finding come with reproducible evidence, or with a scanner score?
  • Who signs the test authorisation, and what do the liability clauses say?
  • Is the report delivered with a debrief, or as an attachment?

If a quote cannot answer these in writing, the number on it is not comparable with any other number.

Where to start

If you want the engine, it is free: clone the GPLv3 Community edition from GitHub and run it against infrastructure you own. If you want the result without running anything, order a Pentest on Demand: describe the target, sign the framework, pay the flat rate, and our experts take it from there. Either way, the first question to answer is the one every price depends on: what, precisely, is in scope.

Next
Run it against your own lab

Darkmoon is open source (GPL-3.0) and self hosted. Clone it, point it at a target you own, and read every line.