Pentest Scoping
and Pricing Cheatsheet
The reference you pull up on every scoping call. Eight questions, a decision matrix, testing effort in days, published starting prices, and a SOW checklist.
Most pentest scoping conversations go sideways for the same reason: the wrong questions get asked, or the right questions get asked too late. This cheatsheet exists so that does not happen. It covers the eight questions you need answered before you can write a meaningful SOW, the pentest type that maps to each scenario, how many testing days each engagement actually takes, what it costs, and the mistakes that blow up budgets or leave gaps in coverage. The prices are Voke Cyber's own published starting figures, not market averages. Built from 1,000+ engagements.
8 Questions to Ask on Every Scoping Call
Get these answered before you quote. Each one directly affects the engagement type, the number of testing days, and the cost — the effort and price table further down turns the answers into a number.
Pentest Type Decision Matrix
Match the client's situation to the right engagement type. Getting this wrong wastes budget and leaves real gaps untested.
Web Application Pentest
Custom web applications, SaaS products, customer portals, internal tools with a browser interface. Covers OWASP Top 10, business logic, authentication, and authorization flaws.
API Pentest
REST or GraphQL APIs, microservices, mobile app backends, third-party integrations. Tests authentication, input validation, rate limiting, and data exposure. Often scoped alongside web app testing.
External Network Pentest
Internet-facing infrastructure: firewalls, VPN gateways, mail servers, DNS, web servers. Tests what an attacker sees from the outside. Required by most compliance frameworks.
Internal Network Pentest
Assume-breach scenario or insider threat simulation. Tests Active Directory, lateral movement, privilege escalation, network segmentation. Starts from a foothold inside the network.
Cloud Security Assessment
AWS, Azure, or GCP configuration review. Tests IAM policies, storage permissions, network controls, logging gaps, and serverless security. Scope per provider and per account.
Mobile Application Pentest
iOS or Android native apps. Tests local storage, certificate pinning, API communication, reverse engineering protections, and platform-specific vulnerabilities.
Phishing Simulation
Human-layer testing. Measures click rates, credential submission, and reporting behavior. Best used to establish a baseline or validate security awareness training effectiveness.
Red Team Engagement
Full-scope adversary simulation with minimal rules. Combines phishing, network exploitation, physical access, and social engineering. Tests detection and response, not just prevention. Reserve for mature security programs.
5 Scoping Pitfalls That Burn VCISOs
These are the mistakes that lead to change orders, missed findings, or clients who feel like they wasted money.
- Scoping too narrow. The web app talks to three APIs, a payment gateway, and a cloud storage bucket. If those are out of scope, the tester cannot follow the attack chain. Interconnected systems need to be in scope or explicitly acknowledged as a coverage gap.
- Scoping too broad. "Test everything" sounds thorough. It produces a 200-page report where critical findings get buried next to informational noise. Focused scoping with clear objectives produces better outcomes than trying to boil the ocean.
- Forgetting the APIs behind the web app. The front end gets tested. The API it calls does not. Attackers do not use the front end. They call the API directly. If the web app has an API, it needs to be in scope.
- Underestimating authenticated testing complexity. One user role is straightforward. Five roles with different permission levels across multiple modules is a different engagement entirely. Each role multiplies the testing surface. Price accordingly.
- Scheduling during code freeze or peak traffic. A pentest during Black Friday or a code freeze creates friction with every stakeholder. Ask about deployment schedules, traffic patterns, and change windows before locking in dates.
How Long Each Pentest Takes, and What It Costs
Effort is testing days, not calendar days. Engagements at the same price point take the same effort — a web application and an API test are the same size of job. Specialist work (red team, LLM/AI, IoT, thick client) runs longer because the tooling and the skill set are narrower.
Prices are Voke Cyber's published starting figures: the low end of the day range is the floor scope.
| Engagement Type | Testing Effort | Starting Price | What Moves It |
|---|---|---|---|
| Vulnerability Assessment | 1 – 2 days | $1,250 | Number of live hosts and subnets, depth of manual validation |
| Phishing Simulation | 2 – 3 days | $2,000 | Number of targets, pretexts, delivery window |
| Web Application | 3 – 5 days | $3,000 | Number of roles, forms, pages, and API endpoints |
| API | 3 – 5 days | $3,000 | Number of endpoints, authentication complexity |
| Cloud Security Review | 3 – 5 days | $3,000 | Number of accounts, services in use, IaC maturity |
| PCI Scanning | 3 – 5 days | $3,000 | Number of in-scope IPs, remediation re-scan cycles |
| External Network | 3 – 5 days | $3,500 | Number of live IPs, services exposed |
| LLM / AI | 5 – 8 days | $4,500 | Model count, agent tooling, RAG pipeline complexity |
| Internal Network | 5 – 10 days | $5,000 | Number of subnets, AD complexity, segmentation |
| Mobile Application | 5 – 7 days per platform | $5,500 | iOS vs. Android, API backend included or separate |
| Thick Client | 7 – 10 days | $7,000 | Source code availability, platforms in scope |
| Red Team | 10 – 20 days | $8,000 | Objective complexity, rules of engagement, detection maturity |
| IoT & Embedded | 10 – 15 days | $10,000 | Hardware teardown, firmware extraction, radio protocols |
| EU AI Act Assessment | 10 – 15 days | $10,000 | Number of high-risk systems, Annex IV evidence depth |
Retesting is included free for a minimum of 30 days after delivery, so remediation verification does not need its own engagement window or a separate line in the budget.
Why two quotes for the same scope can differ by double
The variable that moves price most is authenticated testing. One user role on a web application is the floor. Five roles with different permission levels across multiple modules is a different engagement — each role multiplies the testing surface, and the effort scales close to linearly with it. The second biggest variable is whether the API behind the application is in scope. A web application quoted without its API is a cheaper number for a smaller job, not a better deal.
A quote that comes back at half the going rate is usually one of three things: an automated scan with a report template, a single unauthenticated pass, or a scope that quietly excluded the API. Ask which, and ask how many tester-days are budgeted. If they cannot answer in days, that is your answer.
SOW Checklist
Every penetration testing statement of work should cover these items. Missing any of them creates ambiguity that leads to disputes, scope creep, or incomplete testing.
- Engagement type and methodology (OWASP, PTES, NIST SP 800-115)
- Specific assets in scope (URLs, IP ranges, cloud accounts, app names)
- Assets explicitly out of scope
- Testing approach: black box, gray box, or white box
- Authenticated vs. unauthenticated testing
- User roles and credential requirements for authenticated testing
- Testing environment: production, staging, or both
- Testing window: dates, hours, time zone
- Point of contact for emergency stop or escalation
- Rules of engagement: what the tester can and cannot do
- Denial-of-service testing: included or excluded
- Social engineering: included or excluded
- Report deliverables: executive summary, technical detail, attestation letter
- Report delivery timeline after testing ends
- Retesting: included, and if so, within what window
- Data handling and destruction policy
- Compliance requirements the engagement must satisfy
- Communication cadence during testing (daily updates, Slack channel, etc.)
Ready to Scope an Engagement?
Skip the back-and-forth. Our scoping process takes one call. You get a fixed-price estimate and a clear SOW within 24 hours.