Quick answer: Penetration testing is sold by the day, not by the hour, and the median published day rate is £1,000 (US$1,356) across 30 UK public-sector rate cards in Stingrai's Penetration Testing Price Index 2026, with a central band of £800 to £1,200 (US$1,084 to US$1,627). One supplier on the same framework publishes what its day actually contains, 7.5 hours exclusive of travel and lunch at £1,250 a day, so the index median derives to about £133 an hour (US$180), and the central band to £107 to £160 an hour. The clearest published hourly rate found anywhere in this pass belongs to Secure Ideas in the United States, which states plainly that it bills at US$340 per hour. In Germany, AWARE7 publishes EUR 1,350 net per day and mioso publishes EUR 1,200 to EUR 2,300 per day. Anything below roughly £500 a day is a warning sign rather than a saving, per SECFORCE.
Every figure on this page was read from a page or document that publishes it, on 1 September 2026, and links back to that source. Where a market publishes no rates at all, this page says so instead of filling the gap with an average.
Why an hourly rate is the wrong unit, and why buyers still search for it
The query "penetration testing cost per hour" is asked constantly and answered badly, usually with a made-up band and no source. It is asked for a good reason: a finance team approving a security budget wants a unit price it can compare against other professional services, and every other consultancy line in the budget has one.
The industry answers in a different unit. Almost every firm that publishes anything publishes a day rate, and then quotes a fixed fee for a scoped number of days. The reason is structural rather than evasive. An hourly meter pays a testing firm more for being slow, gives the buyer no ceiling on the invoice, and creates an argument about whether report writing, retesting and scoping calls are billable. A fixed fee against a stated number of days moves all of that risk to the supplier, which is where the buyer wants it.
So the useful answer to "what is the hourly rate" has three parts: the published day rate, the published number of hours in the day it buys, and the published number of days your scope needs. This page gives all three, from sources you can open.

The published numbers at a glance
Median published day rate (2026): £1,000, about US$1,356, across 30 UK public-sector rate cards (Stingrai Penetration Testing Price Index 2026).
Central published day-rate band (2026): £800 to £1,200, about US$1,084 to US$1,627 (same index, median floor to median ceiling).
Full published day-rate spread (2026): £480 to £1,600, low end Zoonou, high end Dionach.
Published length of a consultant day: 7.5 hours exclusive of travel and lunch, at a published rate of £1,250 a day exclusive of VAT, with a minimum contract of one day (Illume Security G-Cloud 14 pricing document).
Published length of a testing credit: 8 hours of offensive security testing per credit, with the price of a credit not published (Cobalt).
Implied hourly rate at the index median (derived): £133 over a 7.5-hour day, £125 over an 8-hour day.
Highest-confidence published hourly rate (2026): US$340 per hour, stated by the firm as its own billing rate (Secure Ideas).
Published German day rates (2026): EUR 1,350 net (AWARE7) and EUR 1,200 to EUR 2,300 (mioso).
Published Big Four framework day-rate bands (2026): £400 to £2,885 a day (KPMG LLP) and £500 to £3,500 a day (PricewaterhouseCoopers LLP).
Freelance marketplace hourly spread (2026): US$5 to US$900 an hour across 20 profiles, median US$15 (Guru, first page of listings sampled 1 September 2026).
UK contract pay for penetration testing roles (2026): median £564 a day, 10th percentile £421, 90th percentile £758, across 138 quoted daily rates in the six months to 1 September 2026 (ITJobsWatch). This is what a contractor is paid, not what a client is billed.
Key takeaways
The day rate is stable and the hourly rate is a derivation. Half the published UK market sits inside a £400-wide band, £800 to £1,200. Nobody publishes a per-hour price card for penetration testing, so every hourly figure in this post, including the £133 headline, is a division of a published day rate by a published day length. Treat it as a sanity check on a quote, never as a billing unit to ask for.
A "day" is 7.5 or 8 hours, and the difference is 6%. Illume publishes a 7.5-hour consultant day exclusive of travel and lunch. Cobalt publishes a credit worth 8 hours of testing. At the index median of £1,000, those two conventions give £133 and £125 an hour. Anyone quoting an hourly rate without stating which convention they use is quoting a number with a 6% ambiguity baked into it.
The Big Four publish a band, not a rate, and the band is the whole story. KPMG LLP publishes £400 to £2,885 a day and PricewaterhouseCoopers LLP publishes £500 to £3,500 a day on the same public framework. A single band spanning a factor of seven is a grade ladder, not a price. The question to ask a large firm is not what the day rate is; it is which grades are actually on your engagement and for how many days each.
Marketplace hourly rates are self-declared and carry no information. Twenty penetration testing profiles on one marketplace page published rates from US$5 to US$900 an hour, with a median of US$15. That range is not a market; it is a list of asking prices with no methodology, no scope definition and no accountability attached to any of them.
A low day rate is usually a longer engagement, not a cheaper one. SECFORCE flags anything under £500 a day as unlikely to be genuine testing and anything over £2,000 a day as excessive outside specialised work. Between those two lines, the number that moves your invoice is the day count, not the rate.
Methodology
The verification pass for this post closed on 1 September 2026. Four kinds of source were accepted, in descending order of weight.
Public procurement rate cards. Penetration testing services listed on the UK Government's G-Cloud 14 framework carry a supplier-declared price with an explicit unit, usually "a unit a day". These carry the most weight because the rate was published to a government buyer under framework terms rather than to a marketing page. Every listing cited here was fetched individually during the pass and returned HTTP 200.
Published supplier pricing documents. The strongest single document in this post is a supplier's own G-Cloud pricing PDF, because it publishes the day rate and the number of hours in the day together. That combination is what makes an hourly derivation possible at all, and it is rare.
Vendor list prices. A price published on a vendor's own page, in a currency, attached to a defined unit. This is the category that supplies the US hourly rate and the two German day rates.
Published benchmarks. A figure where a firm states what it believes the market rate to be rather than what it charges. These are reported in their own section, labelled as benchmarks, and never mixed into the observed-price tables.
Inclusion and exclusion rules. A figure appears here only if it was read directly on the source page or document during this pass, in the currency the source used, attached to a stated unit. Search-result summaries were never accepted as evidence, even when they looked plausible. Where a figure existed only as a third-party paraphrase of another firm's claim, it was dropped rather than cited at second hand. Where a market publishes no rate data that could be retrieved, no rate is printed for that market.
Derived figures are labelled. Every hourly rate in this post is a division of a published day rate by one of the two published day-length conventions, and is marked as derived. Every project total is a published day rate multiplied by a published day count, and is marked the same way. Nothing here is modelled, interpolated or averaged across sources.
Currency. Conversions use US$1.3555 per GBP and US$1.1598 per EUR, the Federal Reserve H.10 observations dated 28 August 2026. USD figures are rounded to the nearest dollar and never printed without the original currency alongside them.
What was dropped. US General Services Administration awarded labour rates could not be retrieved: the CALC tool now redirects to a notice page carrying no data, and a GSA price list PDF returned HTTP 404. Upwork's published hourly bands returned HTTP 403 and a bot interstitial, so a different marketplace was sampled instead. Toptal publishes an annual salary figure rather than a rate. No Canadian or Australian public-sector penetration testing rate card could be retrieved, so neither market gets an observed day rate on this page. A widely repeated claim that large firms charge two to three times boutique rates had no traceable primary source and was dropped in favour of the two framework bands that can be read directly.
What a day actually contains
Two firms publish what a unit of testing time means, and they disagree by half an hour.
Published unit | Length | Publisher | What the definition excludes |
|---|---|---|---|
Consultant working day | 7.5 hours | Travel and lunch, both explicitly excluded. Travel, subsistence and VAT are billed separately, insurance is included, minimum contract is one day, and out-of-hours work carries an additional cost | |
Testing credit | 8 hours | The page does not publish what a credit costs, only what it is worth in testing time |
Those two conventions produce the following implied hourly rates from the published day rates. Every figure in this table is derived, not observed.
Published day rate | Publisher | Implied at 7.5 hours | Implied at 8 hours |
|---|---|---|---|
£800 (index median floor) | 30 G-Cloud 14 rate cards | £107 | £100 |
£1,000 (index median) | 30 G-Cloud 14 rate cards | £133 | £125 |
£1,200 (index median ceiling) | 30 G-Cloud 14 rate cards | £160 | £150 |
£1,250 | Illume Security | £167 | £156 |
£1,400 (red team median) | 3 G-Cloud 14 red team rate cards | £187 | £175 |
EUR 1,350 net | AWARE7 | EUR 180 | EUR 169 |
EUR 1,200 to EUR 2,300 | mioso | EUR 160 to EUR 307 | EUR 150 to EUR 288 |
Read the arithmetic in the other direction as well. Secure Ideas' published US$340 an hour becomes US$2,550 for a 7.5-hour day or US$2,720 for an 8-hour day. That sits far above the UK framework band, which is the clearest illustration in this post that an hourly number carries no meaning until you know the market, the seniority and the day convention behind it.
Day rates by market
United Kingdom
The UK is the only market in this pass with a genuine published rate-card population, because the Digital Marketplace requires suppliers to state a price and a unit. The aggregate view comes from Stingrai's penetration testing price index, which reads 30 of those listings. Individual listings verified during this pass:
Supplier | Published price | Unit | Source |
|---|---|---|---|
Armadillo Sec Ltd | £800 to £1,350 | a unit a day | |
Bulletproof Cyber | £1,400 | a unit a day | |
DigitalXRAID | £800 to £1,150 | a unit a day | |
Dionach | £1,600 | a unit a day | |
Illume Security | £1,250 | per consultant per day, 7.5 hours, excluding VAT | |
Indelible Data Limited | £1,050 | a unit a day | |
KPMG LLP | £400 to £2,885 | a unit a day | |
PricewaterhouseCoopers LLP | £500 to £3,500 | a unit a day | |
Zoonou | £480 | a unit a day |
Suppliers are listed alphabetically. Nothing in this table is a ranking, and position carries no meaning.
The specialist firms cluster tightly, £800 to £1,600, and the two large-firm entries do not so much sit above that band as swallow it whole. That is the difference between a rate card for one service and a rate card that covers a whole professional-services grade ladder.
For a shortlist of firms operating in this market, see the top penetration testing companies in the UK.
United States
No US public-sector penetration testing rate card could be retrieved in this pass, so the US evidence is vendor-published rather than framework-published.
The one unambiguous figure is Secure Ideas, which publishes its own billing rate in plain language: US$340 per hour. That is the only firm found in this pass that answers the question in the unit buyers actually search for.
Per-test list prices are the other US signal, and they price an outcome rather than an hour. Cobalt publishes US$3,500 per Autonomous Pentest and defines a credit as eight hours of testing without publishing the credit price. Intruder publishes US$3,500 per white-box web application test for platform subscribers and US$4,000 as a one-off. Stingrai publishes US$3,000 one-time for an autonomous test of one web application and its APIs and US$6,800 for the hybrid equivalent.
The US shortlist sits in the best penetration testing companies in the USA, and the scope-driven cost view in the penetration testing cost guide for 2026.
Germany and the wider EU
Germany is the second-best-documented market in this pass, because German providers publish a Tagessatz, a day rate, more readily than firms elsewhere.
Publisher | Published day rate | Stated basis |
|---|---|---|
EUR 1,350 net | The firm's own rate, used to build fixed-price quotes from a person-day count. Publishes 2 to 6 person-days for small web applications and for external network tests | |
EUR 1,200 to EUR 2,300 | The firm's own band, varying with requirements and complexity. States a typical engagement of about five days |
For the EU as a whole, SECFORCE publishes a benchmark rather than its own price: £1,200 (EUR 1,400) as a fair day rate, £1,000 to £1,500 (EUR 1,200 to EUR 1,800) as the typical range for thorough manual testing, under £500 (EUR 600) a day as unlikely to be genuine testing, and over £2,000 (EUR 2,300) a day as excessive outside highly specialised work. Those four lines are the most useful published guardrails in the European market, and the two German day rates above sit comfortably inside them.
Converting the UK index median into euros gives roughly EUR 1,167 a day, which is the anchor used in our guide to penetration testing companies in Germany. That guide also carries EUR project bands, from EUR 5,000 to EUR 14,000 for a small web application or single API up to EUR 45,000 to EUR 95,000 for red team and adversary simulation.
Canada
No Canadian public-sector penetration testing rate card could be retrieved in this pass. The federal procurement vehicles publish qualification categories rather than per-diem rates, and no provincial rate card surfaced.
What exists is a published benchmark. Traztech states that senior offensive security day rates in Canada sit roughly between CA$1,800 and CA$3,000. That is one firm's view of the market rather than its own price list, and it is reported here as such.
Project-level Canadian pricing is far better documented than rate-level pricing, and our guide to the average cost of a penetration test in Canada breaks it into scope bands: CA$5,000 to CA$12,000 for a small single-role web application, CA$12,000 to CA$25,000 for a standard multi-role SaaS application, CA$15,000 to CA$35,000 for an external network test at standard scope, and CA$40,000 to CA$120,000 for an annual continuous testing subscription.
Australia
No Australian public-sector rate card could be retrieved either; the government seller catalogue sits behind a login. No Australian firm found in this pass publishes a day rate.
What Australian firms do publish is indicative project pricing. Intrix publishes ranges of A$3,000 to A$6,000 for a small web application, A$7,000 to A$15,000 for a large or complex one, A$3,000 to A$10,000 for external network testing, A$5,000 to A$15,000 for internal, A$6,000 to A$20,000 for a cloud assessment and A$15,000 to A$100,000 or more for a red team engagement, with an explicit note on the page that the figures are indicative only. Our own Australian market guide carries comparable bands.
Deriving an Australian day rate from those project ranges would require a published day count that no Australian source in this pass provides, so this page does not print one.
Day rates by provider type
Provider type explains more of the variance than geography does.
Provider type | What is published | Rate | Implied hourly at 7.5 hours (derived) |
|---|---|---|---|
Freelance marketplace profile | Self-set asking rate, no scope definition | US$5 to US$900 an hour, median US$15 (Guru, n = 20) | Already hourly |
Independent contractor (pay, not billing) | Contract role pay rate | £564 a day median, £421 to £758 across the 10th to 90th percentile (ITJobsWatch, n = 138) | £75 |
Specialist testing firm | Framework rate card | £800 to £1,200 central band, median £1,000 (price index, n = 30) | £107 to £160 |
Named published consultant rate | Pricing document with a day length attached | £1,250 a day, 7.5 hours (Illume Security) | £167 |
US consultancy publishing an hourly rate | Its own billing rate | US$340 an hour (Secure Ideas) | US$2,550 a day, derived in reverse |
Big Four entity | Framework rate card spanning grades | £400 to £2,885 (KPMG LLP); £500 to £3,500 (PricewaterhouseCoopers LLP) | £53 to £385 and £67 to £467 |
Four notes belong on that table.
The marketplace row is not a market rate. A US$5 asking rate and a US$900 asking rate on the same page tell you that nothing on that page has been validated. Marketplace profiles publish what a person would like to be paid, with no scope definition, no methodology statement and no accountability if the test misses something. Treat the row as evidence about the marketplace, not evidence about the price of testing.
The contractor row is pay, not billing. ITJobsWatch measures the day rate quoted in UK contract job advertisements for penetration testing roles. That is what a firm pays a contractor, before the firm's own overhead, scoping, quality review, reporting, retesting, insurance and margin. The gap between the £564 median pay rate and the £1,000 median client-billed rate is the firm, and buying "direct" mostly means buying the pay rate without the things the gap funds.
The Big Four row is a ladder, not a rate. Neither published band is wrong; both simply cover every grade a large firm might staff, from a junior analyst to a partner. A £400 day and a £2,885 day both exist inside KPMG's published band. What matters on a large-firm quote is the grade mix and the day count per grade, and that is a question you have to ask explicitly.
Only two of the Big Four appear. No G-Cloud 14 penetration testing listing was located for Deloitte or Ernst & Young during this pass, so neither is represented. The band above describes KPMG LLP and PricewaterhouseCoopers LLP, and nothing more.
What a tester is paid against what you are billed
Two published pay figures sit alongside the billing rates, and printing them next to each other is the fastest way to see what a day rate actually pays for.
Measure | Figure | Source | What it is |
|---|---|---|---|
UK contract role, median day rate | £564 | ITJobsWatch, 138 quoted rates in the six months to 1 September 2026, up 2.50% year on year from £550 | What a contractor is paid |
UK contract role, 10th to 90th percentile | £421 to £758 | ITJobsWatch, same sample | What a contractor is paid |
US penetration testing skill, average hourly pay | US$29.79 | PayScale, 255 respondents, page updated 13 July 2026 | What an employee is paid |
UK client-billed day rate, median | £1,000 | Price index, 30 rate cards | What a buyer is billed |
The PayScale figure is employee pay for a skill rather than contractor pay for an engagement, so it is not directly comparable to a billing rate and should never be used as one. It is included because it is the most common number that gets misquoted as a US hourly penetration testing rate, and seeing it next to Secure Ideas' published US$340 an hour makes the distinction obvious.

How to convert a day rate into a project estimate
This is the arithmetic that turns an hourly or daily figure into a number you can put in a budget line. Multiply a published day rate by a published day count. Every total below is a derivation, not a quoted price, and both inputs are named.
Step 1. Pick a day rate. Use £1,000, the median published rate, unless you have a specific reason to use another. Use £1,400 for red team work, which is the published red team median.
Step 2. Take the day count from a published source, not from a guess. The counts below all come from published price lists.
Step 3. Multiply, then add the things day counts exclude. Retesting, report reformatting for an audit, out-of-hours testing, travel and subsistence are the five line items most often outside the day count. Illume's pricing document, for instance, states plainly that travel, subsistence and VAT sit outside the day rate and that out-of-hours work carries an additional cost.
Worked examples
Scope | Published day count | Publisher of the day count | Derived at the published day rate |
|---|---|---|---|
Small web application | 3 to 5 days | £3,000 to £5,000 (US$4,067 to US$6,778) | |
Web application, deeper scope | 6 to 12 days | £6,000 to £12,000 (US$8,133 to US$16,266) | |
Multi-role SaaS platform | 5 to 7 days | £5,000 to £7,000 (US$6,778 to US$9,489) | |
API | 4 to 9 days | £4,000 to £9,000 (US$5,422 to US$12,200) | |
External infrastructure | 3 to 5 days | both of the above | £3,000 to £5,000 (US$4,067 to US$6,778) |
Internal network, up to about 150 hosts | 1 to 3 days | £1,000 to £3,000 (US$1,356 to US$4,067) | |
Internal network, larger estate | 5 to 8 days | £5,000 to £8,000 (US$6,778 to US$10,844) | |
Cloud review, single platform | 4 to 5 days | £4,000 to £5,000 (US$5,422 to US$6,778) | |
Red team, at the £1,400 red team median | 10 to 15 days | EJN Labs, published as 2 to 3 weeks | £14,000 to £21,000 (US$18,977 to US$28,466) |
Full-scope assessment | 10 to 20 days | £10,000 to £20,000 (US$13,555 to US$27,110) |
The same arithmetic works in euros. AWARE7 publishes 2 to 6 person-days for a small web application and a EUR 1,350 net day rate, which derives to EUR 2,700 to EUR 8,100. mioso publishes a typical engagement of about five days against a EUR 1,200 to EUR 2,300 band, which derives to EUR 6,000 to EUR 11,500. SECFORCE publishes a worked example of a six-day web application assessment at £6,000, which lands exactly on the index median rate.
Two things fall out of the table. The internal network rows differ by a factor of five on total price and a factor of five on days, at almost the same rate, which is the cleanest evidence in this post that quote variance is scope variance. And the smallest engagements are short enough that a minimum contract length matters: Illume publishes a one-day minimum, so a half-day of work still bills a full day.
If you would rather not do the arithmetic, the pentest cost calculator turns a scope into a point estimate in about two minutes with its assumptions shown.
What a day of testing actually produces
A rate is only meaningful next to an output. Stingrai's State of Penetration Testing 2026 analysed 1,206 verified findings from 55 penetration tests run between October 2024 and August 2026, which is the closest thing in this post to a measure of what the days you are buying return.
The median test produced 8 findings, with the middle half of tests returning 5 to 15. The mean was 21.9, dragged there by a single engagement that produced 223 findings, which is exactly why the median is the number to plan against. 67.2% of all verified findings were rated High or Critical. The mix moves sharply with test type: internal network testing returned a median of 11 findings per test with 92% rated High or Critical, while web application testing returned a median of 8 with 54% High or Critical.
Set that against the day counts above. A published 3 to 5 day web application test, at the index median rate, is roughly £3,000 to £5,000 for a median of 8 findings, more than half of which will be High or Critical. Remediation is the other half of the budget: across findings with a tracked resolution time, the median Critical took 10.5 days to fix. Buying the test without funding the fix window is the most expensive mistake available in this budget line.
Why Stingrai publishes fixed package prices rather than an hourly rate
Stingrai does not sell penetration testing by the hour, and does not publish an hourly rate. The pricing page carries fixed package prices instead: an Autonomous Pentest from US$3,000 one-time, driven by Snipe, and a Hybrid Pentest at US$6,800 one-time where certified penetration testers work alongside Snipe throughout the engagement, both covering one web application and its APIs. The same two tiers are available continuously at US$450 and US$1,275 per month on a 12-month engagement, so a buyer can fund an annual point-in-time test or year-round coverage from the same published price list. The Autonomous tier carries a published No High or Critical Finding, Don't Pay guarantee.
Three reasons that model is better for the buyer than an hourly meter.
Predictability. A fixed package price is the invoice. There is no day-count negotiation, no argument about whether scoping calls and report writing are billable, and no change order when reconnaissance takes longer than expected.
No incentive to pad. An hourly meter pays the supplier more for working slowly. A fixed price for a defined scope pays the supplier for finishing, which aligns the supplier with the buyer on the only thing that matters, which is depth of coverage inside the scope.
Retesting is included rather than metered. Retesting is the most common gap between a quoted number and a paid invoice across this whole market. Under an hourly model it is billable time; under a fixed package it is part of what was bought.
Deliberately, this post does not convert Stingrai's packages into an implied hourly rate. Doing so would invent a day count nobody published, and the whole point of the arithmetic above is that derived numbers are only as good as the published inputs behind them. For scopes larger than one application, request a quote and the number comes back scoped rather than metered.
What this means for buyers
Ask for the fee, the day count and the grade mix in the same sentence. A fee alone is not comparable between suppliers. A fee plus days plus seniority is comparable in a spreadsheet, and it is the only way to read a band like KPMG's £400 to £2,885.
Sanity-check any quote against £800 to £1,200 a day. Materially below that band, ask who is doing the testing and how much of it is automated. Materially above it, ask for the specific reason, which is usually a regulated framework or a named specialist.
Ask which day convention a supplier uses. Seven and a half hours or eight changes an implied hourly rate by 6% and changes a ten-day engagement by five hours of testing.
Never buy on an hourly rate alone. An hourly meter with no ceiling is the worst structure available to a buyer in this market. If a supplier will only quote hourly, ask for a not-to-exceed figure and a scope statement, in writing.
Budget the retest and the fix window. Retesting sits outside many published prices, and the median Critical finding in our own dataset took 10.5 days to close. Both are real costs that a day rate does not cover.
Use published rate cards as leverage. Framework listings are published, competed and public. They are the cleanest negotiating reference available in this market, and most private-sector buyers never look at them.
Frequently Asked Questions
What is the hourly rate for penetration testing in 2026?
There is no published hourly price card for penetration testing, because the market sells days rather than hours. Derived from the median published day rate of £1,000 across 30 UK public-sector rate cards and the 7.5-hour consultant day that Illume Security publishes on the same framework, the implied rate is about £133 an hour (US$180), with the central band running £107 to £160. The clearest firm-published hourly rate found in this pass is US$340 an hour at Secure Ideas in the United States. Treat any hourly figure as a sanity check on a quote rather than a billing unit to request.
What is a normal penetration testing day rate?
£800 to £1,200 (US$1,084 to US$1,627) covers the middle half of the published UK market, with a median of £1,000 and a full published spread of £480 to £1,600, per Stingrai's price index across 30 rate cards. SECFORCE publishes a compatible benchmark: £1,200 as a fair day rate, £1,000 to £1,500 as typical for thorough manual testing, under £500 as unlikely to be genuine testing, and over £2,000 as excessive outside specialised work.
What is the penetration testing day rate in the UK?
The median published UK day rate is £1,000, measured across 30 penetration testing listings on the G-Cloud 14 framework, with a central band of £800 to £1,200. Individual verified listings range from £480 at Zoonou to £1,600 at Dionach, with Illume Security at £1,250 for a 7.5-hour consultant day and Indelible Data at £1,050.
What is the penetration testing day rate in the US and Canada?
No US or Canadian public-sector penetration testing rate card could be retrieved during this pass, so neither market has an observed day rate on this page. What is published: Secure Ideas bills at US$340 an hour, which derives to US$2,550 over a 7.5-hour day, and Traztech publishes a benchmark of CA$1,800 to CA$3,000 a day for senior offensive security work in Canada, which is one firm's view of the market rather than a rate card. Canadian project bands sit in our guide to the average cost of a penetration test in Canada.
Why do penetration testing firms quote per project instead of per hour?
Because an hourly meter misaligns everyone. It pays the supplier more for working slowly, gives the buyer no ceiling on the final invoice, and creates a recurring argument about whether scoping, report writing and retesting are billable time. A fixed fee for a scoped number of tester days moves the delivery risk to the supplier and gives the buyer a number that does not move. It also makes quotes comparable: divide the fee by the stated day count and two very different-looking quotes usually turn out to sit on the same day rate.
Is hourly billing cheaper than a fixed-price penetration test?
Rarely, and it is always riskier. A low hourly rate usually buys a longer engagement rather than a cheaper one: in the published fixed-fee data, internal network testing quotes that differ by a factor of five on price differ by the same factor on days, at almost identical day rates. Hourly billing also leaves retesting, report reformatting and out-of-hours work as metered extras. If you are quoted hourly, ask for a not-to-exceed total and a written scope before you sign.
Is it cheaper to hire a freelance penetration tester than a firm?
The headline number is lower and the comparison is not like for like. On one marketplace page sampled on 1 September 2026, 20 penetration testing profiles published self-set rates from US$5 to US$900 an hour with a median of US$15 (Guru), with no scope definition or methodology attached to any of them. UK contract pay data tells the same story from the other side: the median advertised contract rate for a penetration testing role is £564 a day (ITJobsWatch, 138 rates), against a £1,000 median client-billed day rate. The gap funds scoping, quality review, reporting, retesting, insurance and accountability. A freelancer can be the right answer for a narrow, well-understood scope; they are rarely the right answer where a report has to stand up to an auditor or a customer security review.
How many hours does a penetration test take?
Published day counts run from 1 to 3 days for an internal network of up to about 150 hosts, 3 to 5 days for a small web application or an external network test, 4 to 9 days for an API, 5 to 10 days for one mobile platform, and 10 to 20 days for a full-scope assessment, per the published price lists at Precursor Security and EJN Labs. At the 7.5-hour day that Illume publishes, a 5-day web application test is 37.5 hours of testing. Red team engagements run 2 to 3 weeks.
How much does a retest cost?
It depends entirely on whether it was included in the original scope, which is why it is the most common gap between a quoted number and a paid invoice. Some published prices bundle retesting and some bill it as additional days at the same day rate, so a retest of a 5-day engagement can be anything from zero to a further 1 to 2 days. Stingrai includes retesting in its published packages on the pricing page. Ask the question in writing before you compare two quotes.
Which is more expensive, a boutique firm or the Big Four?
The two Big Four entities publishing penetration testing rates on the UK framework publish bands rather than rates: KPMG LLP at £400 to £2,885 a day and PricewaterhouseCoopers LLP at £500 to £3,500 a day. Both bands run from below the specialist median to well above the specialist ceiling, because they cover an entire grade ladder rather than one service. Specialist testing firms on the same framework cluster at £800 to £1,200. The comparison that matters is not firm type but grade mix: ask which grades are on your engagement, for how many days each, and who writes the report.
Where can I get the latest penetration testing rate data?
Public procurement frameworks are the only large, comparable, published rate population in this market. Stingrai's Penetration Testing Price Index 2026 reads 30 of those listings quarterly and links every price to the page it was read from. For a number against your own scope rather than a market band, the pentest cost calculator shows its assumptions alongside its output.
Related reading
Penetration Testing Price Index 2026, the published-price dataset behind the day-rate figures on this page.
Best penetration testing companies in 2026, the global shortlist.
Penetration testing cost in 2026, the scope-driven cost guide.
Pentest cost calculator, a scope-to-estimate model with its assumptions published.
References
UK Government Digital Marketplace. G-Cloud 14 penetration testing service listings. Retrieved 1 September 2026. https://www.applytosupply.digitalmarketplace.service.gov.uk/g-cloud/services/266289063333452. Supplier-declared day rates published under a public procurement framework, each carrying an explicit price unit.
Illume Security Ltd. Penetration Testing Pricing, G-Cloud 14, version 1.0. Retrieved 1 September 2026. https://assets.applytosupply.digitalmarketplace.service.gov.uk/g-cloud-14/documents/716841/286888045662029-pricing-document-2024-05-02-1454.pdf. Publishes a £1,250 consultant day rate, a 7.5-hour working day exclusive of travel and lunch, a one-day minimum contract, and the exclusions that sit outside the rate.
KPMG LLP. Cyber Security Penetration Testing and Continuous Security Testing and Assurance, G-Cloud 14. Retrieved 1 September 2026. https://www.applytosupply.digitalmarketplace.service.gov.uk/g-cloud/services/813866545819939. Published framework day-rate band of £400 to £2,885.
PricewaterhouseCoopers LLP. PwC Ethical Hacking Services, G-Cloud 14. Retrieved 1 September 2026. https://www.applytosupply.digitalmarketplace.service.gov.uk/g-cloud/services/145105421679159. Published framework day-rate band of £500 to £3,500.
Secure Ideas. What is the Cost of a Penetration Test? Retrieved 1 September 2026. https://www.secureideas.com/knowledge/how-much-does-a-penetration-test-cost. The firm's own published billing rate of US$340 per hour.
AWARE7 GmbH. Penetrationstest Kosten 2026. Retrieved 1 September 2026. https://a7.de/penetrationstest-kosten/. Published day rate of EUR 1,350 net with person-day counts per engagement type.
mioso. Pentest Kosten: Preisstruktur. Retrieved 1 September 2026. https://security.mioso.com/pentest/preisstruktur/. Published day-rate band of EUR 1,200 to EUR 2,300 and a stated typical engagement of about five days.
SECFORCE. Pen Testing Price List UK and EU Guide. Retrieved 1 September 2026. https://www.secforce.com/the-blog/pen-testing-price-list-uk-and-eu-guide-2025/. Published day-rate benchmark with upper and lower credibility thresholds and a worked engagement example.
Precursor Security. Penetration Testing Cost. Retrieved 1 September 2026. https://www.precursorsecurity.com/services/offensive-security/penetration-testing/cost. Published fixed-fee table with tester-day counts attached to each engagement type.
EJN Labs. Penetration Testing Cost UK. Retrieved 1 September 2026. https://ejnlabs.com/penetration-testing-cost-uk/. Published fixed-fee table covering twelve engagement types with day counts.
Cobalt. Pricing. Retrieved 1 September 2026. https://www.cobalt.io/pricing. Defines one credit as the equivalent of eight hours of offensive security testing and publishes a per-test price without publishing a credit price.
Intruder. Pentest pricing. Retrieved 1 September 2026. https://www.intruder.io/pentest-pricing. Published per-test prices for platform subscribers and one-off purchasers.
ITJobsWatch. Penetration Testing contract rates, UK. Six months to 1 September 2026, retrieved 1 September 2026. https://www.itjobswatch.co.uk/contracts/uk/penetration%20testing.do. Median £564 daily rate across 138 quoted rates, with 10th and 90th percentiles.
PayScale. Penetration Testing skill, hourly rate, United States. Page updated 13 July 2026, retrieved 1 September 2026. https://www.payscale.com/research/US/Skill=Penetration_Testing/Hourly_Rate. Average hourly pay of US$29.79 across 255 respondents. Employee pay, not a billing rate.
Guru. Penetration Testing freelancers. First page of listings sampled 1 September 2026. https://www.guru.com/d/freelancers/skill/penetration-testing/. Twenty self-set hourly rates from US$5 to US$900, median US$15.
Traztech. How Much Does Penetration Testing Cost in Canada? Retrieved 1 September 2026. https://traztech.ca/blog/penetration-testing-cost-canada. Published benchmark of CA$1,800 to CA$3,000 per day for senior offensive security work.
Intrix. Penetration Testing Cost Australia. Retrieved 1 September 2026. https://intrix.com.au/blog/how-much-does-a-penetration-test-cost-in-australia/. Published indicative AUD project ranges by assessment type, with no day rate.
Board of Governors of the Federal Reserve System. H.10 Foreign Exchange Rates. Observation dated 28 August 2026, retrieved 1 September 2026. https://www.federalreserve.gov/releases/h10/current/. Source of the US$1.3555 per GBP and US$1.1598 per EUR rates used for every conversion on this page.
Stingrai. Penetration Testing Price Index 2026. https://www.stingrai.io/blog/penetration-testing-price-index-2026. Median published day rate and central band across 30 public-sector rate cards.
Stingrai. The State of Penetration Testing 2026. https://www.stingrai.io/blog/state-of-penetration-testing-2026. 1,206 verified findings across 55 penetration tests, median findings per test, severity mix by test type, and remediation timing.
Stingrai. Pricing. Retrieved 1 September 2026. https://www.stingrai.io/pricing. Published one-time and continuous package prices for one web application and its APIs.



