How Security Assessments Are Priced & How to Run a Better RFP

How Security Assessments Are Priced & How to Run a Better RFP

How Security Assessments Are Priced & How to Run a Better RFP 1200 630 Andrew Heller

"What does a pen test cost?"

The honest answer is: it depends on what you're actually buying. Which sounds like a dodge. It isn't. It's the most important thing to understand about buying security assessments, because the buyers who understand it get better tests for less money, and the ones who don't end up comparing numbers that mean nothing.

A "pen test" is not a unit of work

Here's where most pricing conversations go sideways. "Pen test" gets used as if it's a standard product, like buying a laptop. It isn't. It's a label that covers wildly different engagements.

A vulnerability scan is automated and cheap. A penetration test is human-driven and time-boxed. A red team engagement simulates a full adversary campaign. Purple teaming pairs testers with your defenders to validate detection, not just find holes. TTX and TTP replay exercises test whether your people and processes hold up under pressure, then prove the fixes worked.

These are different amounts of labor, different skill sets, and different outcomes. When your RFP just says "pen test," every vendor prices a different thing, and you end up choosing between a cheap automated scan and a deep human-led engagement as if they're the same purchase. They're not.

So the real question isn't "what does it cost?" It's "what drives the cost?" Six things, in practice.


What actually drives the price

1. Environment complexity. This is the biggest lever. How many applications, APIs, hosts, and cloud accounts are in scope? How much code? How many user roles? A single marketing site and a sprawling SaaS platform with ten microservices, three mobile apps, and a pile of third-party integrations are not the same test. More attack surface means more time, full stop.

2. Test depth. Is it authenticated or unauthenticated? White box, grey box, or black box? Does the tester stop at the first finding, or chain vulnerabilities to show real impact? Depth is labor. A shallow "did anyone leave the door open" pass takes days. A deep "show me the blast radius" engagement takes weeks. Both are legitimate. They just answer different questions and cost accordingly.

3. Operator time. Who's doing the work matters. Senior operators who've seen hundreds of environments find things junior testers miss, and they cost more. Continuous validation (purple teaming, ongoing TTP replay) means more hours spread across the year instead of a one-time burst. If a quote seems suspiciously cheap, ask who's staffing it.

4. On-site versus remote. Travel, shipping gear, and having people physically present costs money. For most application and network testing, remote delivery is completely credible. The attacker you're worried about is remote too. But some things genuinely need boots on site: physical social engineering, OT and ICS environments with air gaps, anything where the hardware itself is the target. If a vendor insists everything must be on-site, ask why. If you insist everything must be remote, be honest about what that rules out.

5. Reporting expectations. This one gets underestimated. A raw findings dump is fast to produce and nearly useless to everyone except your engineers. A report with evidence, severity in business terms, remediation guidance, and an executive narrative your board can actually read takes real time to write. Prospects ask us for report samples before signing for exactly this reason: the report is the product you're buying. Price it like one.

6. Remediation validation. The test finds the problems. Then what? Retesting the fixes (confirming the remediation actually worked) is either included in the engagement or it's a second purchase. Decide up front. A finding without a validated fix is just a liability you now know about.


What a good SOW looks like

If you take nothing else from this post, take this: a credible statement of work answers these questions before anyone signs.

  • Scope boundaries. Exactly what's in and out, in writing. IP ranges, applications, APIs, user roles, physical locations.
  • Methodology. What kind of test is this, and what rules govern it? What's explicitly excluded (denial of service, social engineering, production data)?
  • Deliverables. Report format, evidence standards, debrief or readout, and who gets what.
  • Timeline. Start and end dates, testing windows, and when the report lands.
  • Roles. Who's the point of contact on each side, and who has authority to expand scope mid-test if something interesting turns up.
  • Retest terms. Is validation included? For how long after delivery?

If a vendor's SOW doesn't answer most of these, the price attached to it doesn't mean much either.


How to run an RFP that gets you real answers

Now an important piece: how to actually buy one of these things without getting burned.

Describe the outcome, not the label. "We need a pen test" tells vendors nothing. "We need to answer whether an attacker can reach customer data from the internet, and we need evidence our board will accept" tells them everything. Lead with the risk question and your constraints (budget, timeline, compliance drivers), and let vendors propose the scope that fits.

Ask every vendor the same scoping questions. How many applications and hosts? What authentication is provided? What's in scope for social engineering? Is retesting included? Identical questions force comparable answers. Without them, you're comparing a quote for a scan against a quote for a campaign.

Require evidence, not adjectives. Ask for a redacted sample report. Ask who will actually do the work: not the firm's credentials, the operator's. Ask what the methodology looks like in practice, not just its name. "We do OWASP-aligned testing" is a sentence, not a methodology.

Compare approaches, then prices. The cheapest test that doesn't answer your question is the most expensive purchase you'll make this year. You paid for the illusion of assurance. Price matters, but it's the last filter, not the first.

Watch for red flags. Flat pricing with no scoping call means they haven't thought about your environment. No questions about your stack means they're selling hours, not outcomes. "We'll test everything" means they haven't read your RFP.


Bring us one risk question

You don't need to arrive with a perfect scope. That's our job. Bring one risk question and your constraints (budget, timeline, what the board or your auditor actually needs), and we'll translate it into an assessment scope that's credible, defensible, and priced for what it is.


Further reading

Related Article

Minnesota Water Attacks and the Predictable Reality

August 12, 2026 by Andrew Heller How possible Iran-linked actors exploited exposed PLCs in the 2026 Minnesota water attacks. MITRE ATT&CK mapping, risk matrix, and OT security lessons from Lares. Read More Blog, Penetration Testing, Purple Teaming, Red Teaming

Part 3: The Collapse of the Testing Boundary: Why Purple Teaming is Mission-Critical

August 7, 2026 by Andrew Heller Point-in-time pen tests can't catch AI agents that fail in minutes. See why continuous purple teaming is the only defense — and how to build the budget case. Read More Artificial Intelligence, Blog, Purple Teaming

Part 2: The Collapse of the Testing Boundary: Anthropic and the Behavioral Threat

August 7, 2026 by Andrew Heller Claude models attacked real infrastructure while believing they were in a simulation. Anthropic's retrospective reveals a new AI risk class beyond alignment. Read More Artificial Intelligence, Blog, Purple Teaming

Part 1: The Collapse of the Testing Boundary: Deconstructing the OpenAI Agent Breakout

August 7, 2026 by Andrew Heller OpenAI's frontier model escaped its sandbox and breached Hugging Face's cluster in under 13 hours. See the full kill chain mapped to MITRE ATT&CK and ATLAS. Read More Artificial Intelligence, Blog, Purple Teaming

Social Profiling – OSINT for Red/Blue

July 27, 2026 by Lares Labs Read More Blog, Penetration Testing, Red Teaming

The Phantom Menace: Exposing hidden risks through ACLs in Active Directory

June 18, 2026 by Raúl Redondo Discover how attackers exploit hidden risks in Active Directory ACLs. Explore techniques like GenericAll, GenericWrite, and WriteDACL abuse in our latest post. Read More Blog, Insider Threat, Penetration Testing, Red Teaming

Kerberos IV - Delegations

June 17, 2026 by Raúl Redondo Discover how to abuse Kerberos for lateral movement. Learn User Impersonation techniques like Pass the Ticket, Shadow Credentials, and forging tickets. Read More Blog, Blue Team, Penetration Testing, Red Teaming

Kerberos III - User Impersonation

June 17, 2026 by Raúl Redondo Discover how to abuse Kerberos for lateral movement. Learn User Impersonation techniques like Pass the Ticket, Shadow Credentials, and forging tickets. Read More Blog, Blue Team, Penetration Testing, Red Teaming

Kerberos II - Credential Access

June 16, 2026 by Raúl Redondo Dive into the fundamentals of the Kerberos authentication protocol. Explore its history, core concepts, authentication flow, and PKINIT in part one of our series. Read More Blog, Blue Team, Penetration Testing, Red Teaming

Kerberos I - Overview

June 16, 2026 by Raúl Redondo Dive into the fundamentals of the Kerberos authentication protocol. Explore its history, core concepts, authentication flow, and PKINIT in part one of our series. Read More Blog, Blue Team, Penetration Testing, Red Teaming

Empowering Organizations to Maximize Their Security Potential.

Lares is a security consulting firm that helps companies secure electronic, physical, intellectual, and financial assets through a unique blend of assessment, testing, and coaching since 2008.

18+ Years

In business

600+

Customers worldwide

4,500+

Engagements

Where There is Unity, There is Victory

[Ubi concordia, ibi victoria]

– Publius Syrus

Contact Lares Consulting logo (image)

Continuous defensive improvement through adversarial simulation and collaboration.

Email Us

©2025 Lares, a Damovo Company | All rights reserved.