Estimate penetration test hours, cost and timeline from your scope. Transparent hour rates per IP, web app and API, plus phase breakdown and PDF export.
This penetration test scoping calculator turns a described attack surface into an hour estimate, a cost estimate, a phase breakdown, and a delivery timeline — then exports the whole thing as a statement-of-work-style PDF. It exists because the first honest answer to “what does a pen test cost?” is “how many hours of testing does your scope require?”, and most buyers have never seen that translation done in the open.
It is built for security buyers comparing proposals, MSPs and consultancies preparing estimates, and internal teams budgeting for an annual test. Every hour rate in the model is visible on screen, and the hourly cost is yours to set — so you can reproduce a vendor’s quote, or work out where it differs from the effort the scope implies.
Base hours are built additively from the scope, then adjusted by methodology.
Base hours = Σ (scope item × its hour rate) × methodology multiplier
The methodology multiplier is 1.3× for black box, 1.0× for gray box, and 0.8× for white box. This surprises people who assume more access means more work. It reflects where testing time actually goes: black box testers spend it discovering what exists, while white box testers start with source code and architecture diagrams and spend their hours on depth of coverage instead. Gray box — typically credentials plus a network diagram — is the common middle ground and the model’s baseline.
Total hours are distributed across five phases: reconnaissance 15%, scanning and enumeration 25%, exploitation 35%, post-exploitation 10%, reporting 15%. If a proposal you are reviewing allocates 5% to reporting, that is worth a question — the report is the deliverable, and a fifteen-percent allocation is what a genuinely useful remediation roadmap costs.
Three add-ons are calculated as percentages of base hours: retesting +15%, executive briefing +5%, remediation verification +10%. Total cost is total hours multiplied by your hourly rate, which defaults to $250 and is fully editable. Duration is total hours ÷ 40, rounded up, assuming one tester-equivalent of capacity per week; a firm assigning two testers will compress that.
A typical mid-market external assessment: gray box, 10 external IP addresses, 2 medium-complexity web applications, 3 API endpoints, with retesting included.
Run the same scope as black box and the IP rate rises to 2 hours and everything is multiplied by 1.3: 108 raw hours become 140.4, or $35,100 and 4 weeks. The 18% premium buys you a more realistic simulation of an uninformed attacker. Whether that is worth $5,475 depends on whether you are testing your defences or testing your attack surface — for the latter, white box at 0.8× covers more ground for less money.
It is a planning estimate built from a transparent effort model. It is not a quote, and no testing firm is bound by it. Real pricing varies with tester seniority, geography, compliance requirements such as a PCI DSS-qualified assessor, retest windows, and how much of the scope turns out to be more complex than described. Its value is in making the effort assumptions explicit: if a proposal costs twice this estimate, the model tells you exactly which line to ask about.
On why the exercise is worth budgeting for at all: Verizon’s 2025 Data Breach Investigations Report found exploitation of vulnerabilities behind 20% of breaches, a 34% increase year on year, and third-party involvement in breaches doubling to 30%. IBM’s Cost of a Data Breach Report 2026 put the global average breach cost at $4.99M and the US average at $11.5M across 602 organisations. Against those figures, a five-figure annual test is a small line — but only if the scope actually covers the surface an attacker would use.
It depends almost entirely on scope. This calculator estimates hours from your attack surface and multiplies by an hourly rate you set. The worked example above — 10 IPs, 2 web apps, 3 APIs, gray box, with retesting — comes to roughly 119 hours. What that costs depends on the rate your chosen firm charges.
Because reconnaissance is expensive. Black box testers must discover the environment before they can test it, which the model prices at a 1.3× multiplier. White box testers start with source code and documentation and spend the same hours on depth instead, at 0.8×.
It is an editable default, not a market claim. Rates vary widely by region, firm size, and tester seniority. Enter the rate from a proposal you have actually received to see whether its hours are consistent with your scope.
The model divides total hours by 40 and rounds up, which assumes one tester-equivalent per week. The worked example gives three weeks. A firm assigning two testers may halve that, and scheduling and reporting turnaround add calendar time beyond testing hours.
Verification that reported vulnerabilities were actually fixed, priced at 15% of base hours. Remediation verification, at 10%, is a more detailed evidence-backed validation of the full remediation effort. They are separate line items because they are different depths of work.
By roles, workflows, and integrations, not pages. A single-page marketing site is simple. An application with several user roles, payment processing, and third-party integrations is complex, and the 44-hour gap between the two ratings reflects genuinely different testing depth.
The effort model is generic. Compliance-driven tests may need a qualified assessor, prescribed methodology, or specific reporting formats that change the price. Map your obligations first with the NIST CSF mapper or the SOC 2 gap analysis tool.
No. The calculation and the PDF generation both run entirely in your browser.
Penetration test scoping defines the boundaries, objectives, targets, and constraints of a security assessment before testing begins. Proper scoping ensures that the test covers the right assets, uses appropriate methodologies, stays within legal and ethical boundaries, and provides actionable results that justify the investment.
Underscoped tests miss critical attack surfaces. Overscoped tests waste budget on low-value targets. Effective scoping requires collaboration between the security team requesting the test and the testers performing it to align expectations, define success criteria, and establish rules of engagement.
| Dimension | Options | Considerations |
|---|---|---|
| Test Type | External, Internal, Web App, API, Mobile, Wireless, Social Engineering, Physical | Match to your threat model and compliance requirements |
| Approach | Black Box (no info), Gray Box (partial), White Box (full access) | Gray box offers the best balance of realism and coverage |
| Methodology | OWASP, PTES, NIST SP 800-115, OSSTMM | Choose based on asset type and compliance framework |
| Duration | Days to weeks | Depends on scope size, test type, and depth required |
| Targets | IP ranges, domains, applications, APIs, users | Define explicitly to prevent scope creep |
| Exclusions | Production data modification, DoS testing, specific IPs | Protect business operations from test impact |
| Factor | Low Effort | Medium Effort | High Effort |
|---|---|---|---|
| Web application complexity | 5-10 pages, basic forms | 20-50 pages, auth, roles | 100+ pages, complex workflows, APIs |
| Network size | /28 (16 IPs) | /24 (256 IPs) | /16 (65K IPs) |
| API endpoints | 5-10 endpoints | 20-50 endpoints | 100+ endpoints |
| Authentication complexity | Single role | 3-5 roles | Complex RBAC, federation, MFA |
| Technology stack | Single language/framework | 2-3 technologies | Microservices, multiple languages |
Black box testing simulates an external attacker with no prior knowledge. White box testing provides full access to source code, architecture diagrams, and credentials. Gray box testing offers partial knowledge like user-level credentials or network diagrams. Each methodology requires different time and produces different findings.
A typical pentest follows these phases: Reconnaissance (information gathering), Scanning (network and vulnerability scanning), Exploitation (attempting to gain access), Post-Exploitation (privilege escalation and lateral movement), and Reporting (documenting findings and remediation). This tool estimates hours for each phase.
Duration varies significantly by scope. A small web application might take 40-80 hours, while a large enterprise network assessment could take 200-400+ hours. Factors include the number of IPs, applications, APIs, wireless networks, and whether social engineering or physical testing is included.
Social engineering testing (phishing, vishing, physical intrusion) tests the human element of security and is highly recommended for comprehensive assessments. It typically adds 20-40 hours depending on the campaign complexity. CISSP Domain 6 emphasizes that security assessments should cover people, processes, and technology.
A professional SOW should include: scope definition (in-scope and out-of-scope targets), methodology, rules of engagement, timeline, deliverables (executive summary, technical findings, remediation guidance), emergency contacts, legal authorization, and data handling procedures. This tool generates a SOW estimate covering these elements.
Visual Nmap command generator with preset templates and results parser. Build nmap scan commands and analyze output for security insights.
Visual Metasploit command generator with module presets, payload selector, and msfconsole reference. Build msf commands for penetration testing.
Calculate CVSS v3.1 vulnerability severity scores with Base, Temporal, and Environmental metrics. Generate vector strings and severity ratings.