Penetration testing

Penetration Testing: What It Costs, and Whether You Need One

Last updated: July 2026

If you have started pricing a penetration test, you have probably found that quotes vary enormously and that every firm you ask says yes, you need one. Vintaris is independent, so the answer on this page is the straight one rather than a sales pitch: whether you actually need one yet, what drives the price, and what serves you better when the honest answer is not yet.

Most businesses pricing a test do not need one yet

A penetration test pays a skilled specialist to find the ways into your environment, which is worth real money when your obvious weaknesses are already closed. What the tester finds in that case will be things you could not have found yourself. When an estate has no reliable asset inventory and no patching discipline, a test mostly rediscovers missing patches and default configurations, which an inexpensive vulnerability scan would have listed in an afternoon.

A test is worth most when the rungs beneath it are solid.

The value of a test rises with the maturity of what is being tested. Spending the same money on knowing what you own and closing the known gaps will move your risk further, and it makes the eventual test worth the fee when you do buy one. Our vulnerability management page covers the rung most businesses are missing.

When a test is genuinely warranted

There are clear cases where the answer is yes and we will say so. The most common is compliance: if PCI DSS applies to your business, testing is explicitly required rather than advisable. The next most common is contractual, where an enterprise customer or a tender makes an annual test a condition of doing business, and the decision has been made for you.

A penetration test is warranted when

  • PCI DSS applies to you, which explicitly requires testing
  • A customer or contract makes it a condition
  • You have a specific high-value or internet-facing system worth adversarial testing
  • The fundamentals are in place and you want independent validation

If none of these apply, an assessment will tell you more for less.

Beyond those, a test earns its place when you have a specific application or internet-facing system carrying real value and real exposure, or when your fundamentals are in good order and you want independent validation of that. If none of those describe you, our honest answer is that a security assessment will tell you more about your risk for less money.

What a penetration test costs in Australia

Penetration testing is priced on tester days, so cost tracks scope and seniority more than anything else. A tightly scoped external test of a handful of internet-facing systems sits at the bottom of the Australian market, a broad engagement covering internal networks, multiple applications and segmentation testing sits well above it, and quotes for nominally the same job can differ several times over because the firms have scoped it differently.

01Scope sizeHow many systems, applications and IP ranges are in the engagement.
02Testing approachBlack box, grey box or white box, and how much internal knowledge the tester is given.
03Tester seniority and daysWho does the work and how many tester days the job is quoted at.
04Retest includedWhether a retest after remediation is part of the fee or billed separately.
05Report depth and formatHow detailed the findings, evidence and remediation guidance are.

A quote without a defined scope cannot be compared to another quote.

That last point matters more than the headline number. Before comparing quotes, get each provider to state the scope in writing, the approach they will use, how many tester days are included, whether a retest after you fix things is included or billed separately, and what the report will contain. Two quotes only become comparable once those five things are on the page.

How a test differs from a scan or a red team

These get used interchangeably in sales conversations and they buy you quite different things. A vulnerability scan is automated, runs continuously or on a schedule, and lists known weaknesses cheaply. A penetration test is expert-led and time-boxed, with a skilled tester using automated tooling and manual technique to exploit what they find and show you the chain of steps that got them there.

Vulnerability scanPenetration testRed team engagement
What it doesLists known weaknessesExploits and chains weaknesses to show real impactWorks towards an objective, testing detection and response too
How it is runAutomated and scheduledExpert-led and time-boxed, tools plus manual techniqueObjective-driven over a longer period
What it tells youWhat is exposedWhat an attacker could reach and howWhether you would detect and respond to a real intrusion
Relative costLowestModerateHighest
Who it suitsEvery business, as an ongoing baselineBusinesses with the fundamentals in placeOrganisations with a mature security function to test

A red team engagement goes further again, working towards a goal such as reaching a particular dataset, over a longer period, usually without the defending team being told. That suits organisations with a mature security function to test. For most mid-market businesses the useful comparison is the first two, and the scan is where the value per dollar sits until the basics are covered.

What each framework requires

Frameworks differ more than vendors tend to admit, so it is worth being exact. PCI DSS is the explicit one: requirement 11.4 in version 4.0 calls for internal and external penetration testing at least every twelve months and after significant change, with a documented methodology, and it expects testers to be qualified and organisationally independent from the people who run the systems. If you fall in scope, that is a requirement rather than a recommendation, and the independence expectation is the usual reason businesses engage an external firm.

FrameworkRequires a penetration test?What it says
PCI DSS v4.0Yes, explicitlyRequirement 11.4: internal and external testing at least every twelve months and after significant change, documented methodology, qualified and organisationally independent testers.
ISO 27001Not explicitlyOutcome-based. Auditors commonly accept or expect a test as evidence for technical vulnerability management.
SOC 2Not explicitlyOutcome-based. Commonly used as evidence, though not mandated.
ACSC Essential EightNoPenetration testing is not among the eight mitigation strategies.

Source: PCI DSS v4.0 requirement 11.4; ACSC Essential Eight Maturity Model, cyber.gov.au.

ISO 27001 and SOC 2 are commonly said to require testing, which overstates it. Neither mandates a penetration test in the explicit way PCI DSS does, though auditors frequently accept or expect one as evidence that technical vulnerabilities are being managed. The ACSC Essential Eight does not include penetration testing among its eight mitigation strategies at all, so if you are being pushed towards a test on Essential Eight grounds, the model itself does not ask for one.

Our Essential Eight assessment covers what that model does ask for, and our PCI DSS guidance puts requirement 11.4 in context alongside the rest of the standard.

APIs, the narrower case

APIs are the one area where targeted testing often earns its place earlier than a general penetration test. A focused test of a customer-facing or partner-facing API can return more than a broad test of everything around it, because the exposure is concentrated and the review has usually not kept pace with the build.

APIs are the exception worth considering earlier

  • Exposed by design
  • Often carry data directly
  • Frequently built faster than they are reviewed
Where APIs fit in your security

Our API security page covers where APIs fit in your wider security picture. Where a hands-on API test is the right move, the advice on this page about scoping and buying it well applies unchanged.

How Vintaris helps

How we help

  • Advise whether a test is warranted
  • Help you define what to ask for
  • Point you towards specialist firms
  • Help you turn a report into a plan

What that gets you

  • An honest read on whether you need a test
  • A scope you can compare between quotes
  • A specialist firm suited to the job
  • A report turned into a plan you can action

Independent advice, so the only thing we are selling you is the right answer.

Because we are independent, we can answer the question straight. We will tell you whether a test is warranted for your business right now, and where it is not, we will tell you what will serve you better instead. Where a test is warranted, we will help you work out what to ask for and point you towards specialist firms that do this work properly.

We can also help you make sense of a report once you have one, which is where a lot of value goes unclaimed. A report is a list of findings, and turning it into a prioritised plan your team can work through is the part that reduces risk. If you would rather start with the cheaper and more informative step, our self-service assessment is $479 flat and includes a 45-minute walkthrough with an expert, credited in full toward an expert-led assessment within 30 days.

FAQ

Frequently asked questions

How does Vintaris help with penetration testing?

We are an independent advisor, so we help you decide whether you need a test, define the right scope if you do, and connect you with specialist firms who carry out the work well. We can also help you turn their report into a prioritised plan. Staying independent is what lets us give you a straight answer rather than a sales pitch.

How much does a penetration test cost in Australia?

Cost is driven by tester days, so it tracks scope and seniority. A tightly scoped external test of a few internet-facing systems sits at the bottom of the market and a broad internal and application engagement sits far above it. Quotes for nominally the same job often differ several times over because the scoping differs, so compare the scope before you compare the price.

Do I need a penetration test?

Probably not yet, if you do not have a reliable asset inventory and a working patching process. A test against an estate with known gaps tends to rediscover those gaps at a much higher price. If PCI DSS applies to you, or a customer or contract requires it, then yes.

What is the difference between a penetration test and a vulnerability assessment?

A vulnerability assessment identifies and prioritises known weaknesses, largely through automated scanning, and is inexpensive enough to run continuously. A penetration test is expert-led, using automated tools and manual technique, with a specialist attempting to exploit weaknesses and chain them together to show what an attacker could reach. The assessment tells you what is exposed and the test shows what someone could do with it.

What is the difference between a penetration test and a red team engagement?

A penetration test is time-boxed and scope-defined, aiming for coverage of an agreed set of systems. A red team engagement works towards a specific objective over a longer period, usually without the defending team knowing, and tests detection and response as much as the technical controls. Red teaming suits organisations with a mature security function already in place.

What is the difference between internal and external penetration testing?

External testing targets what an attacker can reach from the internet, such as your public applications and remote access. Internal testing starts from a position inside the network and looks at how far someone could move once they are in. PCI DSS requires both for organisations in scope.

Does the Essential Eight require a penetration test?

No. Penetration testing is not one of the eight mitigation strategies. The Essential Eight covers controls such as patching, application control, multi-factor authentication and backups, and a maturity assessment is the appropriate way to measure yourself against it.

Do ISO 27001 or SOC 2 require a penetration test?

Neither mandates one in the explicit way PCI DSS does. Both are outcome-based, and auditors commonly accept or expect a test as evidence that technical vulnerabilities are being identified and managed, so many organisations pursuing certification choose to run one.

What should a penetration test report contain?

An executive summary a non-technical reader can act on, the methodology used, each finding with a severity rating and the evidence behind it, clear remediation guidance, and confirmation of what was retested after fixes. Ask to see a sample report before you engage anyone.

What should I look for in a testing firm?

Ask about tester qualifications and independence from your systems, the methodology they follow, whether a retest is included, what the report looks like, and how they scope the engagement. A firm that scopes carefully before quoting is usually a better sign than a firm that quotes immediately.

What is pentesting?

Penetration testing is expert-led security testing in which a specialist, drawing on both automated tools and manual technique, attempts to break into systems the way an attacker would, then reports what they reached and how. The balance of automated tooling and hands-on work varies with the engagement, from largely manual to heavily tool-assisted. It is one validation technique among several rather than a security program in itself.

Vintaris provides cyber security assessment and advisory services. Where penetration testing is warranted, Vintaris advises on scope and can introduce you to specialist testing firms; any firms suggested are suggestions only and Vintaris makes no warranty as to their work. General information on this page is not legal, financial or insurance advice.

Prepared and reviewed by the Vintaris security team.

Not sure whether a penetration test is the right spend for your business yet? Find out where you stand in two minutes.

Start the free 2-minute check