Pentest Scoping
and Pricing Cheatsheet

The reference you pull up on every scoping call. Eight questions, a decision matrix, testing effort in days, published starting prices, and a SOW checklist.

Published
Updated Sept 2026
Format
Quick Reference
Author
Louis Sanchez

Most pentest scoping conversations go sideways for the same reason: the wrong questions get asked, or the right questions get asked too late. This cheatsheet exists so that does not happen. It covers the eight questions you need answered before you can write a meaningful SOW, the pentest type that maps to each scenario, how many testing days each engagement actually takes, what it costs, and the mistakes that blow up budgets or leave gaps in coverage. The prices are Voke Cyber's own published starting figures, not market averages. Built from 1,000+ engagements.

8 Questions to Ask on Every Scoping Call

Get these answered before you quote. Each one directly affects the engagement type, the number of testing days, and the cost — the effort and price table further down turns the answers into a number.

1
What is the primary driver?
Compliance (SOC 2, PCI, HIPAA), due diligence (M&A, investor), incident response (post-breach validation), or client requirement (contractual obligation). The driver determines the methodology, the report format, and who the audience is.
2
What assets are in scope?
Web applications, APIs, internal network, external perimeter, cloud infrastructure, mobile apps. Get specific. "Our web app" could mean one login page or a 200-endpoint SaaS platform.
3
How many applications, IPs, or endpoints?
This is the sizing question. For web apps: number of roles, forms, and pages. For networks: number of live IPs or subnets. For APIs: number of endpoints. Vague answers here mean vague estimates later.
4
Authenticated or unauthenticated testing?
Authenticated testing (with valid credentials) finds more. It also takes longer. If the app has multiple user roles, each role adds complexity. Most compliance frameworks expect authenticated testing at minimum.
5
Production or staging environment?
Production testing is more realistic but riskier. Staging avoids business disruption but may not reflect the real attack surface. Some clients need both. Know which before scoping starts.
6
Any off-limits systems or time windows?
Payment processors, medical devices, production databases with no backup, or third-party hosted systems may be out of scope. After-hours-only testing affects scheduling and cost.
7
When is the compliance deadline?
Auditors do not care that the pentest was "almost done." Know the hard deadline. Work backward: testing time + remediation time + retest time. If the deadline is in three weeks and the client has not started, say so.
8
Who receives the report?
Technical team, the board, auditors, or the client's clients. This determines the report format. Auditors need attestation letters. Boards need executive summaries. Developers need proof-of-concept details.

Pentest Type Decision Matrix

Match the client's situation to the right engagement type. Getting this wrong wastes budget and leaves real gaps untested.

Web Application Pentest

Custom web applications, SaaS products, customer portals, internal tools with a browser interface. Covers OWASP Top 10, business logic, authentication, and authorization flaws.

API Pentest

REST or GraphQL APIs, microservices, mobile app backends, third-party integrations. Tests authentication, input validation, rate limiting, and data exposure. Often scoped alongside web app testing.

External Network Pentest

Internet-facing infrastructure: firewalls, VPN gateways, mail servers, DNS, web servers. Tests what an attacker sees from the outside. Required by most compliance frameworks.

Internal Network Pentest

Assume-breach scenario or insider threat simulation. Tests Active Directory, lateral movement, privilege escalation, network segmentation. Starts from a foothold inside the network.

Cloud Security Assessment

AWS, Azure, or GCP configuration review. Tests IAM policies, storage permissions, network controls, logging gaps, and serverless security. Scope per provider and per account.

Mobile Application Pentest

iOS or Android native apps. Tests local storage, certificate pinning, API communication, reverse engineering protections, and platform-specific vulnerabilities.

Phishing Simulation

Human-layer testing. Measures click rates, credential submission, and reporting behavior. Best used to establish a baseline or validate security awareness training effectiveness.

Red Team Engagement

Full-scope adversary simulation with minimal rules. Combines phishing, network exploitation, physical access, and social engineering. Tests detection and response, not just prevention. Reserve for mature security programs.

5 Scoping Pitfalls That Burn VCISOs

These are the mistakes that lead to change orders, missed findings, or clients who feel like they wasted money.

How Long Each Pentest Takes, and What It Costs

Effort is testing days, not calendar days. Engagements at the same price point take the same effort — a web application and an API test are the same size of job. Specialist work (red team, LLM/AI, IoT, thick client) runs longer because the tooling and the skill set are narrower.

Prices are Voke Cyber's published starting figures: the low end of the day range is the floor scope.

Engagement Type Testing Effort Starting Price What Moves It
Vulnerability Assessment 1 – 2 days $1,250 Number of live hosts and subnets, depth of manual validation
Phishing Simulation 2 – 3 days $2,000 Number of targets, pretexts, delivery window
Web Application 3 – 5 days $3,000 Number of roles, forms, pages, and API endpoints
API 3 – 5 days $3,000 Number of endpoints, authentication complexity
Cloud Security Review 3 – 5 days $3,000 Number of accounts, services in use, IaC maturity
PCI Scanning 3 – 5 days $3,000 Number of in-scope IPs, remediation re-scan cycles
External Network 3 – 5 days $3,500 Number of live IPs, services exposed
LLM / AI 5 – 8 days $4,500 Model count, agent tooling, RAG pipeline complexity
Internal Network 5 – 10 days $5,000 Number of subnets, AD complexity, segmentation
Mobile Application 5 – 7 days per platform $5,500 iOS vs. Android, API backend included or separate
Thick Client 7 – 10 days $7,000 Source code availability, platforms in scope
Red Team 10 – 20 days $8,000 Objective complexity, rules of engagement, detection maturity
IoT & Embedded 10 – 15 days $10,000 Hardware teardown, firmware extraction, radio protocols
EU AI Act Assessment 10 – 15 days $10,000 Number of high-risk systems, Annex IV evidence depth

Retesting is included free for a minimum of 30 days after delivery, so remediation verification does not need its own engagement window or a separate line in the budget.

Why two quotes for the same scope can differ by double

The variable that moves price most is authenticated testing. One user role on a web application is the floor. Five roles with different permission levels across multiple modules is a different engagement — each role multiplies the testing surface, and the effort scales close to linearly with it. The second biggest variable is whether the API behind the application is in scope. A web application quoted without its API is a cheaper number for a smaller job, not a better deal.

A quote that comes back at half the going rate is usually one of three things: an automated scan with a report template, a single unauthenticated pass, or a scope that quietly excluded the API. Ask which, and ask how many tester-days are budgeted. If they cannot answer in days, that is your answer.

SOW Checklist

Every penetration testing statement of work should cover these items. Missing any of them creates ambiguity that leads to disputes, scope creep, or incomplete testing.

Louis Sanchez - Offensive Security Consultant at Voke Cyber

About the Author

Louis is a penetration tester and the founder of Voke Cyber. He has scoped and delivered over 1,000 penetration testing engagements across web applications, networks, cloud environments, and mobile platforms. This cheatsheet reflects the scoping process he uses with every client.

Ready to Scope an Engagement?

Skip the back-and-forth. Our scoping process takes one call. You get a fixed-price estimate and a clear SOW within 24 hours.