Penetration Test Scoping Calculator

Estimate penetration test hours, cost and timeline from your scope. Transparent hour rates per IP, web app and API, plus phase breakdown and PDF export.

Advertisement

Penetration Test Scoping and Cost Calculator

This penetration test scoping calculator turns a described attack surface into an hour estimate, a cost estimate, a phase breakdown, and a delivery timeline — then exports the whole thing as a statement-of-work-style PDF. It exists because the first honest answer to “what does a pen test cost?” is “how many hours of testing does your scope require?”, and most buyers have never seen that translation done in the open.

It is built for security buyers comparing proposals, MSPs and consultancies preparing estimates, and internal teams budgeting for an annual test. Every hour rate in the model is visible on screen, and the hourly cost is yours to set — so you can reproduce a vendor’s quote, or work out where it differs from the effort the scope implies.

The Effort Model

Base hours are built additively from the scope, then adjusted by methodology.

Base hours = Σ (scope item × its hour rate) × methodology multiplier

  • External IP addresses: 2 hours each black box, 1.5 gray box, 1 white box — reconnaissance effort falls as information is supplied up front.
  • Web applications: 16 hours simple, 32 hours medium, 60 hours complex. Complexity should reflect the number of roles, workflows, and integrations, not the page count.
  • API endpoints: 8 hours each, covering REST, GraphQL, and SOAP.
  • Mobile applications: 24 hours each, per platform — an iOS and Android pair is 48 hours, not 24.
  • Wireless networks: 8 hours each.
  • Social engineering: 16 hours plus half an hour per targeted employee, capped at 40 hours.
  • Physical security: 24 hours.

The methodology multiplier is 1.3× for black box, 1.0× for gray box, and 0.8× for white box. This surprises people who assume more access means more work. It reflects where testing time actually goes: black box testers spend it discovering what exists, while white box testers start with source code and architecture diagrams and spend their hours on depth of coverage instead. Gray box — typically credentials plus a network diagram — is the common middle ground and the model’s baseline.

Phase allocation

Total hours are distributed across five phases: reconnaissance 15%, scanning and enumeration 25%, exploitation 35%, post-exploitation 10%, reporting 15%. If a proposal you are reviewing allocates 5% to reporting, that is worth a question — the report is the deliverable, and a fifteen-percent allocation is what a genuinely useful remediation roadmap costs.

Add-ons and timeline

Three add-ons are calculated as percentages of base hours: retesting +15%, executive briefing +5%, remediation verification +10%. Total cost is total hours multiplied by your hourly rate, which defaults to $250 and is fully editable. Duration is total hours ÷ 40, rounded up, assuming one tester-equivalent of capacity per week; a firm assigning two testers will compress that.

A worked example

A typical mid-market external assessment: gray box, 10 external IP addresses, 2 medium-complexity web applications, 3 API endpoints, with retesting included.

  • External IPs: 10 × 1.5 = 15 hours.
  • Web applications: 2 × 32 = 64 hours.
  • APIs: 3 × 8 = 24 hours.
  • Subtotal 103 hours × 1.0 gray box multiplier = 103 base hours.
  • Phases: 15.5 recon, 25.8 scanning, 36.1 exploitation, 10.3 post-exploitation, 15.5 reporting.
  • Retesting: 103 × 0.15 = 15.5 hours. Total 118.5 hours.
  • At $250 per hour: $29,625, over 3 weeks.

Run the same scope as black box and the IP rate rises to 2 hours and everything is multiplied by 1.3: 108 raw hours become 140.4, or $35,100 and 4 weeks. The 18% premium buys you a more realistic simulation of an uninformed attacker. Whether that is worth $5,475 depends on whether you are testing your defences or testing your attack surface — for the latter, white box at 0.8× covers more ground for less money.

How to Use It

  1. Choose a methodology. Black box for adversary simulation, white box for maximum coverage, gray box for the usual balance.
  2. Enumerate the scope honestly. Under-scoping is the most common cause of a mid-engagement change order. Count every live external IP, every distinct application, and both mobile platforms.
  3. Set web application complexity carefully. The gap between simple and complex is 44 hours per application, the single largest lever in the model.
  4. Review the phase breakdown. Use it to sanity-check vendor proposals against a normal distribution of effort.
  5. Set your hourly rate. The $250 default is an editable placeholder, not a market quote. Use a rate from an actual proposal to reproduce and interrogate it.
  6. Add the extras that matter. Retesting is the one most often cut and most often regretted — a finding is not closed until someone has verified the fix.
  7. Export the PDF. It contains methodology, scope table, phase breakdown, cost summary, timeline, and deliverables, in a shape you can send to procurement.

What This Estimate Is and Is Not

It is a planning estimate built from a transparent effort model. It is not a quote, and no testing firm is bound by it. Real pricing varies with tester seniority, geography, compliance requirements such as a PCI DSS-qualified assessor, retest windows, and how much of the scope turns out to be more complex than described. Its value is in making the effort assumptions explicit: if a proposal costs twice this estimate, the model tells you exactly which line to ask about.

On why the exercise is worth budgeting for at all: Verizon’s 2025 Data Breach Investigations Report found exploitation of vulnerabilities behind 20% of breaches, a 34% increase year on year, and third-party involvement in breaches doubling to 30%. IBM’s Cost of a Data Breach Report 2026 put the global average breach cost at $4.99M and the US average at $11.5M across 602 organisations. Against those figures, a five-figure annual test is a small line — but only if the scope actually covers the surface an attacker would use.

Frequently Asked Questions

How much does a penetration test cost?

It depends almost entirely on scope. This calculator estimates hours from your attack surface and multiplies by an hourly rate you set. The worked example above — 10 IPs, 2 web apps, 3 APIs, gray box, with retesting — comes to roughly 119 hours. What that costs depends on the rate your chosen firm charges.

Why does black box testing cost more than white box?

Because reconnaissance is expensive. Black box testers must discover the environment before they can test it, which the model prices at a 1.3× multiplier. White box testers start with source code and documentation and spend the same hours on depth instead, at 0.8×.

Is the $250 hourly rate a real market rate?

It is an editable default, not a market claim. Rates vary widely by region, firm size, and tester seniority. Enter the rate from a proposal you have actually received to see whether its hours are consistent with your scope.

How long does a penetration test take?

The model divides total hours by 40 and rounds up, which assumes one tester-equivalent per week. The worked example gives three weeks. A firm assigning two testers may halve that, and scheduling and reporting turnaround add calendar time beyond testing hours.

What is included in retesting?

Verification that reported vulnerabilities were actually fixed, priced at 15% of base hours. Remediation verification, at 10%, is a more detailed evidence-backed validation of the full remediation effort. They are separate line items because they are different depths of work.

How should I judge web application complexity?

By roles, workflows, and integrations, not pages. A single-page marketing site is simple. An application with several user roles, payment processing, and third-party integrations is complex, and the 44-hour gap between the two ratings reflects genuinely different testing depth.

Does this cover compliance-mandated testing?

The effort model is generic. Compliance-driven tests may need a qualified assessor, prescribed methodology, or specific reporting formats that change the price. Map your obligations first with the NIST CSF mapper or the SOC 2 gap analysis tool.

Is my scope data sent anywhere?

No. The calculation and the PDF generation both run entirely in your browser.

What Is Penetration Test Scoping

Penetration test scoping defines the boundaries, objectives, targets, and constraints of a security assessment before testing begins. Proper scoping ensures that the test covers the right assets, uses appropriate methodologies, stays within legal and ethical boundaries, and provides actionable results that justify the investment.

Underscoped tests miss critical attack surfaces. Overscoped tests waste budget on low-value targets. Effective scoping requires collaboration between the security team requesting the test and the testers performing it to align expectations, define success criteria, and establish rules of engagement.

Scoping Dimensions

DimensionOptionsConsiderations
Test TypeExternal, Internal, Web App, API, Mobile, Wireless, Social Engineering, PhysicalMatch to your threat model and compliance requirements
ApproachBlack Box (no info), Gray Box (partial), White Box (full access)Gray box offers the best balance of realism and coverage
MethodologyOWASP, PTES, NIST SP 800-115, OSSTMMChoose based on asset type and compliance framework
DurationDays to weeksDepends on scope size, test type, and depth required
TargetsIP ranges, domains, applications, APIs, usersDefine explicitly to prevent scope creep
ExclusionsProduction data modification, DoS testing, specific IPsProtect business operations from test impact

Effort Estimation Factors

FactorLow EffortMedium EffortHigh Effort
Web application complexity5-10 pages, basic forms20-50 pages, auth, roles100+ pages, complex workflows, APIs
Network size/28 (16 IPs)/24 (256 IPs)/16 (65K IPs)
API endpoints5-10 endpoints20-50 endpoints100+ endpoints
Authentication complexitySingle role3-5 rolesComplex RBAC, federation, MFA
Technology stackSingle language/framework2-3 technologiesMicroservices, multiple languages

Common Use Cases

  • Annual penetration test planning: Scope the required annual pen test for PCI DSS, SOC 2, HIPAA, or CMMC compliance with appropriate coverage
  • Vendor comparison: Generate consistent scoping documents to request comparable proposals from multiple penetration testing firms
  • New application assessment: Scope a pre-launch security assessment for a new web application or API before production deployment
  • Red team exercise planning: Define objectives, rules of engagement, and success criteria for adversary simulation exercises
  • Budget planning: Estimate penetration testing costs based on scope to allocate appropriate security budget

Best Practices

  1. Start with business risk — Scope the test around your most valuable and exposed assets. A penetration test of 10 critical applications is more valuable than a surface-level scan of 100 low-risk systems.
  2. Define rules of engagement clearly — Document what testers can and cannot do: can they use social engineering? Can they test during business hours? Can they access production data? Put this in writing before testing begins.
  3. Choose gray box for best ROI — Gray box testing (testers receive credentials, documentation, and architecture diagrams) covers more ground than black box in the same time while still identifying real vulnerabilities.
  4. Include retesting — Budget for a retest engagement 30-60 days after the initial test to verify that critical findings have been properly remediated.
  5. Scope for quality, not just compliance — A compliance-driven pen test checks boxes. A risk-driven pen test finds vulnerabilities. Include time for manual testing beyond automated scanning.

Frequently Asked Questions

What is the difference between black box, white box, and gray box testing?+

Black box testing simulates an external attacker with no prior knowledge. White box testing provides full access to source code, architecture diagrams, and credentials. Gray box testing offers partial knowledge like user-level credentials or network diagrams. Each methodology requires different time and produces different findings.

What phases are included in a penetration test?+

A typical pentest follows these phases: Reconnaissance (information gathering), Scanning (network and vulnerability scanning), Exploitation (attempting to gain access), Post-Exploitation (privilege escalation and lateral movement), and Reporting (documenting findings and remediation). This tool estimates hours for each phase.

How long does a typical penetration test take?+

Duration varies significantly by scope. A small web application might take 40-80 hours, while a large enterprise network assessment could take 200-400+ hours. Factors include the number of IPs, applications, APIs, wireless networks, and whether social engineering or physical testing is included.

Should I include social engineering in my pentest scope?+

Social engineering testing (phishing, vishing, physical intrusion) tests the human element of security and is highly recommended for comprehensive assessments. It typically adds 20-40 hours depending on the campaign complexity. CISSP Domain 6 emphasizes that security assessments should cover people, processes, and technology.

What should a pentest Statement of Work include?+

A professional SOW should include: scope definition (in-scope and out-of-scope targets), methodology, rules of engagement, timeline, deliverables (executive summary, technical findings, remediation guidance), emergency contacts, legal authorization, and data handling procedures. This tool generates a SOW estimate covering these elements.

Related tools

This tool is provided for informational and educational purposes only. All processing happens in your browser — no data is sent to or stored on our servers. While we strive for accuracy, we make no warranties about the completeness or reliability of results.