forumNew topic

I got three quotes for a penetration test, there's a 4x difference between them — what determines these prices?

NNuri K***Member
Job title
Product Manager
Sector
Real estate
Organization type
sole proprietorship
Joined
Apr 2023
Message
3
#1

We need a penetration test for our company's cybersecurity audit. I went to a digital agency and got three quotes. The first is 15k lira, the second 45k, the third 65k. They all say 'penetration test' but there's a 4x difference. How can it vary so much?

Our web servers, databases, and internal network — all need auditing. I asked if we could enter a government tender, they said 'report required' but i don't know which standard it needs to comply with.

I'm really confused. If you have a consultant, let me know, otherwise are you gonna go with the cheap agency?

HHatice Ş***Member
Job title
Human Resources Specialist
Sector
IT services
Organization type
early-stage startup
Joined
Sep 2025
Message
123
Most Helpful#2

Penetration test pricing depends on four factors: scope size, test type, report requirements (OWASP, NIST, ISO 27001), and urgency.

15k — web app, 1-2 days, simple report. 45k — network + app, 5-10 days, detailed report. 65k — entire system, incl. social engineering, 2-3 weeks.

My advice: ask the bidders for a 'scope of work' document. Which systems are included, what's the report template, how long will it take, etc.

BBurcu E***MemberCommunity member
Joined
Feb 2023
Message
94
#3

experienced the same thing and all pirce inflation. like i think pick the middle one make sure there's a warranty and i asked for a written report. got good service but the agency went silent afterwards

FFiliz P***ExpertCommunity member
Joined
Nov 2024
Message
14
#4

Main reasons for price differences: Number of people (1-2 vs 5-6), Duration (weekly vs monthly), Tools and software licenses, Experience (uncertified vs certified)

SSerkan G***Expert
Job title
Penetration testing specialist
Organization type
a company within a holding
Joined
Nov 2023
Message
154
#5

90% of what's called 'penetration test' in Turkey is marketing. Mid-sized firms run the same scripts and present different reports. More expensive doesn't guarantee better.

EEbru Y***Expert
Job title
Content strategist
Joined
Nov 2023
Message
186
#6

'Scope' is very important in penetration testing. 1) attack from external network, 2) attack from internal network 3) incl. social engineering. Each has a different price.

UUfuk B***Member
Job title
Field sales representative
Sector
Paper
Organization type
chain store
Joined
Nov 2024
Message
2
#7

If you're entering a government tender, choose a firm approved by BILGEM, there's no other way.

OOsman K***Expert
Job title
Software developer
Sector
Education
Organization type
two-branch business
Joined
Dec 2023
Message
23
#8

I felt relieved reading this answer, so it's not just me. When we decide without measuring, we always end up in the same place.

I'm also curious if anyone does it differently.

CCeren E***MemberCommunity member
Joined
May 2024
Message
1
#9

We experienced almost the exact same thing last year. When making decisions, write down the worst-case scenario too, not just the best.

Hope this helps.

SSelçukMember
Job title
Sports club
Organization type
boutique agency
Joined
Jun 2024
Message
76
#10

great work. btw taking notes for two weeks yields better results than a six-month estimate.

correcct me if I'm wrong.

BBeren T***MemberCommunity member
Joined
Nov 2023
Message
6
#11

Thanks for posting.

İİlknur C***MemberCommunity member
Joined
Feb 2025
Message
18
#12

let me summarize what's been said so far. payment information changes are never verified through the channel they came from.

when making decisions write down the worst-case scenario too not just the best but this is my opinion Im not claiming its absolute truth.

AAlper K***MemberCommunity member
Joined
Jun 2024
Message
366
#13

I was thinking the same thing... btw if it's your first time start small; scaling comes later.

Just leaving this note it might be useful.

RRabia K***MemberCommunity member
Joined
May 2022
Message
16
#14

You're right, I've been down that road too. Mistakes made on the penetration test prices side are usually reversible but expensive.

Taking measures without an inventory leaves doors you haven't seen open. Proven by experience.

HHüsniye A***Veteran
Job title
Graphic Designer
Sector
Packaging
Organization type
40-person manufacturing company
Joined
Feb 2025
Message
137
#15

We need to take it step by step. Hasty decisions become decisions you have to fix six months later.

An automated scan report is not the same as a penetration test.

ÖÖzge Ç***Member
Job title
Administrative manager
Sector
Accounting & advisory
Organization type
120-person company
Joined
Nov 2024
Message
2
#16

You're right.

EErdemMember
Job title
Architecture firm
Joined
Dec 2023
Message
72
#17

Following. Most time waste accumulates in tasks waiting for approval.

That's all, sorry if I went on too long.

AAli T***Member
Job title
Call center representative
Sector
Paper
Organization type
workshop
Joined
Jul 2024
Message
269
#18

I partly agree, partly disagree. Mistakes made on the penetration test prices side are usually reversible but expensive.

Hope this helps.

BBeren N***Member
Job title
Project manager
Sector
Insurance
Organization type
300-person organization
Joined
Mar 2024
Message
6

Doki · Interface design · 2025

#19

Don't miss this: If you scold false alarms, nobody will report again.

If I were you, I'd go this route.

AAycan Ö***MemberCommunity member
Joined
Jul 2023
Message
321
#20

Sorry, but this doesn't apply in every case. If you scold false alarms, nobody will report again.

Proven by experience.

Reply