What determines the price of your pentest?
The price of a pentest depends on four factors: the scope of the assessment, technical complexity, the risk profile, and your reporting needs and applicable standards. More user roles, integrations and environments generally require more investigation. Together, we determine the coverage needed and which plan is suitable.
Scope of the test
The number of applications, IP addresses, APIs and user roles defines the scope of the test. An application with two roles and no integrations generally requires less investigation than a platform with ten roles and multiple integrations. We also test whether users can perform actions beyond the permissions of their role.
Technical complexity
Integrations, login processes and functions such as ordering and payment require targeted manual testing. Automated scans help identify known vulnerabilities, but investigating business process abuse also requires an understanding of how your application works. We therefore test how components interact and which actions users can perform. More complex scenarios require more testing time.
Risk profile and coverage
We tailor coverage to the risk profile of your application or environment. Components handling sensitive data or with serious consequences if compromised receive extra attention. By identifying risks together in advance, we focus testing on the most important attack scenarios. The depth of testing required helps determine how much investigation time is needed.
Reporting and standards
We agree in advance which standards and reporting requirements apply to your application, network or other environment. For compliance engagements, we map findings to the applicable framework and make clear what was tested. Additional coverage or evidence requirements may require more testing and reporting time. That is why we discuss them before testing begins.
What is included?
The Quick Pentest, Expert Pentest and Extensive Pentest include:
- Manual testing by certified ethical hackers at DongIT, a pentest company holding the CCV Keurmerk Pentesten and ISO 27001 certifications
- Review of findings by a second pentester
- Reporting through our Security Reporter platform, with online access and PDF and CSV exports
- Notification of critical findings through the platform, followed up by phone
When is the price confirmed?
The Basic Scan and Quick Pentest have the fixed prices shown in the table. For the Expert Pentest, Extensive Pentest and tailored assessments, we first discuss what you need tested in a free scoping call. You then receive a quotation with the final price before testing begins.
The Quick, Expert and Extensive Pentest are performed and reported in accordance with the quality requirements of the CCV Keurmerk Pentesten certification scheme. The Basic Scan is not a pentest and is not covered by this certification: it combines an automated scan with a limited manual check. The stars in the comparison table indicate the different levels of manual testing.
Additional services
Request these services alongside a pentest or separately. They are not included in the plan price.
Frequently asked questions about pentest costs
More about choosing a plan, additional costs and how we work.
What does a web application pentest cost?
The Quick Pentest costs €2,960 excluding VAT and is intended for a straightforward web application with a limited scope. For applications with multiple user roles, APIs or integrations, the Expert Pentest from €5,040 excluding VAT is usually a better fit. We confirm the final price after discussing the scope with you. Read about web application pentesting and pentesting mobile apps and APIs.
What does a network or cloud pentest cost?
The Expert Pentest from €5,040 excluding VAT is usually the starting point for a network or cloud pentest. For more complex infrastructure, such as multiple network segments or cloud environments, the Extensive Pentest from €7,200 excluding VAT is a better fit. We confirm the final price once we have agreed the scope with you. Read about our network and cloud pentests.
Can the Quick Pentest assess my external attack surface?
Yes. The Quick Pentest at €2,960 excluding VAT can be used for a focused assessment of your external attack surface. Within the agreed scope, we identify subdomains, publicly accessible IP addresses, services and identifiable software versions. Our pentesters then perform targeted manual testing for potential vulnerabilities and assess the risks. The assessment therefore goes beyond an inventory or automated scan.
We agree in advance which domains and IP ranges are in scope and which manual tests we will perform. This is one possible use of the Quick Pentest, not an additional assessment included by default alongside a web application pentest. If a broader scope or more in-depth testing is needed, we discuss a suitable plan and its price before testing begins.
Which plan fits a DigiD, NIS2 or ISO 27001 assessment?
For a compact DigiD environment, the Expert Pentest from €5,040 excluding VAT may be suitable. For more extensive environments, such as those with multiple applications or complex integrations, we offer the Extensive Pentest from €7,200 excluding VAT. With either plan, we align the DigiD pentest with the applicable Logius framework and the evidence your auditor needs. We agree which plan fits the scope, risk profile and reporting requirements in advance, then confirm the final price.
For NIS2 and ISO 27001 assessments, we offer the Extensive Pentest from €7,200 excluding VAT. The report includes a management summary and maps findings to relevant standards and controls. We discuss the systems to be tested and the reporting requirements in advance.
Can I request a plan directly without a quotation?
You can request the Basic Scan and Quick Pentest directly at the fixed plan price. We then confirm what we will test and when. For the Expert Pentest, Extensive Pentest and tailored assessments, we first discuss your requirements and scope in a free call. You receive a quotation within three business days of that conversation.
What if a pentest does not fit my budget?
Then we reverse the approach. Normally, we first determine the scope based on what needs to be tested, and the price follows from that. If your budget is fixed, we time-box the assessment: we agree on the available testing time and focus it on the highest-risk areas. We document what falls outside that coverage in the report, so you know what has not yet been tested.
Why is the Basic Scan cheaper than a pentest?
The Basic Scan costs €1,480 excluding VAT and is a vulnerability scan with a limited manual check. This requires less manual investigation than a pentest. The Quick Pentest costs €2,960 excluding VAT and includes manual testing of a straightforward web application, including user permissions and business logic. A Basic Scan is therefore a different type of assessment, not a lower-priced pentest plan.
Does a white box pentest cost extra?
No. We do not charge extra for a white box pentest. With this approach, our pentesters receive relevant information in advance, such as credentials, source code and documentation. This helps them use their time more effectively, investigate more and reduce blind spots. That is why we generally recommend a white box pentest.
The price depends on the scope, complexity and required coverage of the assessment, not on providing this information. A full source code review is a separate service. Read about black box, grey box and white box testing.
What does a retest cost?
A retest is not included in the plan price. It checks whether previously identified vulnerabilities have been fixed. The price depends on the number of findings that need to be tested again. We discuss the cost when delivering the pentest report.
Is red teaming part of a plan?
No. Red teaming is a separate, tailored assessment with its own quotation. We simulate a realistic attack on your organisation and agree the objectives and scope with you in advance.
What does an AI or LLM application pentest cost?
Testing AI and LLM applications is a separately priced module available with the Expert Pentest and Extensive Pentest. The cost depends on the number of models and interfaces, connected data sources and tools, user roles and AI agent permissions. The abuse scenarios to be investigated also affect the price. Discuss your AI application with us; we provide a quotation after a free scoping call.
Do you use AI in pentesting, and what does that mean for the cost?
Yes. We use AI selectively to improve the quality of our testing, not to replace experienced pentesters. This requires expert direction: the right instructions, technical context and a critical assessment of the results. Our pentesters check every finding and determine the final risk assessment. Manual testing and review by a second pentester remain part of our approach.
AI therefore does not automatically make a pentest cheaper. The price depends on the scope, complexity and required depth of testing.
Need a tailored pentest?
Need to test multiple environments or meet specific testing and reporting requirements? We will discuss what you need and prepare a tailored quotation. You receive a response within one business day and a quotation within three business days of the scoping call.
Nederlands