Pentest quote 2026: How much does Penetration Testing cost?
- 4 hours ago
- 7 min read
The cost of Pentesting for a small website or system with a limited scope can be estimated at approximately VND 30–50 million. For enterprise applications with many features, APIs, or user roles, the budget typically needs to be in the range of VND 50–180 million.
Cloud, financial, complex system, or Red Team projects may require a budget ranging from VND 100 million to several hundred million.
This is a reference budget range, not a fixed price list. The official cost needs to be determined after agreeing on the scope, testing methodology, implementation timeline, deliverable reports, and number of Retests.
For comparison, a reference source in the U.S. market lists Web Application Pentesting in 2026 at USD 4,000–25,000, External Network Pentesting at USD 3,000–15,000, and Internal Network Pentesting at USD 5,000–20,000. This source also notes that prices that are too low may include only automated scanning instead of in-depth manual testing.

Reference Pentest Price list for 2026
Item | Reference budget range | Suitable scope |
Small website | VND 30–50 million | Few features, 1–2 roles |
Enterprise website | VND 40–80 million | Login, administration, and access control |
E-commerce website | VND 60–150 million | Payments, orders, customer accounts |
Web application or SaaS | VND 60–180 million | Many features, roles, and business workflows |
Small-scope API | VND 40–70 million | Few endpoints, complete documentation |
Enterprise API | VND 70–180 million | Many endpoints, roles, and transaction workflows |
Single-platform Mobile App | VND 60–120 million | Android or iOS, limited scope |
Android, iOS, and API | VND 100–250 million | Application and backend system testing |
External Network Pentest | VND 40–100 million | Public IPs, VPN, Firewall, Internet services |
Internal Network Pentest | VND 70–180 million | Servers, Active Directory, network segmentation |
Cloud Pentest | VND 100–300 million | AWS, Azure, Google Cloud, or Hybrid Cloud |
Red Team Assessment | From VND 250 million | Multi-stage attack simulation |
AI system Pentest | Separate assessment | AI Agents, data, models, and integrated systems |
Important note: The figures above are editorial budget estimates intended to help businesses envision their budgets. They are not IPSIP's official listed prices or pricing data representative of the entire Vietnamese market.
To receive an accurate figure, businesses need to provide information about assets, features, accounts, APIs, environments, and reporting requirements.
Quick comparison of Pentest packages
Criterion | Basic package | Enterprise package | Advanced package |
Reference budget | VND 30–50 million | VND 50–180 million | From VND 150 million |
Scope | Small website or system | Web, API, Mobile, or Network | Cloud, finance, large systems |
User roles | 1–2 roles | Multiple roles | Complex access control and architecture |
Business logic testing | Limited | Included | In-depth |
Technical report | Included | Included | Included |
Executive report | Depending on scope | Recommended | Included |
Retest | One Retest should be included | One Retest should be included | As agreed |
Estimated timeline | A few business days | Approximately 1–3 weeks | Separate assessment |
Website Pentest pricing
The cost of website Pentesting typically ranges from VND 30–150 million, depending on the type of website and its complexity.
Small website: approximately VND 30–50 million
This budget range may be suitable when the system:
Has only one website.
Has few features.
Has one or two user roles.
Does not have payments.
Does not have many APIs.
Does not have a complex approval process.
Does not require a separate compliance report.
Example: a corporate profile website with login functionality, a contact form, and a basic administration area.
This price level needs to come with a clearly defined scope. “From VND 30 million” should not be used for a system that has not yet been assessed.
Enterprise website: approximately VND 40–80 million
Suitable for systems with:
Login functionality.
An administration area.
Multiple user groups.
File upload functionality.
Customer data management.
APIs or third-party integrations.
Access control rules.
E-commerce website: approximately VND 60–150 million
E-commerce websites typically require additional testing of:
Registration and login.
Shopping cart.
Payments.
Discount codes.
Order management.
Refunds.
Seller and buyer permissions.
Access to customer data.
Partner integration APIs.
The cost is higher because experts must not only test for technical vulnerabilities but also assess transaction logic and the potential for business process abuse.
API Pentest pricing
API Pentesting may require a budget of approximately VND 40–180 million.
API scope | Budget range |
Small API, few endpoints | VND 40–70 million |
API with multiple roles | VND 70–120 million |
API with complex transaction logic | VND 100–180 million |
Financial or sensitive data API | Separate assessment |
API Pentest pricing should not be based solely on the number of endpoints.
A system with 30 endpoints but five user roles may require more testing time than a system with 100 simple endpoints. Experts must test the access permissions of each account group and the relationships between business workflows.
Factors that increase the cost of API Pentesting include:
No Swagger or Postman documentation.
Multiple API versions.
Multiple user roles.
Financial transactions.
Partner-facing APIs.
File upload functionality.
Personal or sensitive data.
Multiple environments that need to be assessed.
See also API Security documentation.
Mobile App Pentest pricing
The cost of Mobile App Pentesting can typically range from VND 60–250 million.
Scope | Budget range |
Android or iOS, small scope | VND 60–120 million |
One application and backend API | VND 80–160 million |
Android, iOS, and API | VND 100–250 million |
Financial or sensitive data application | Separate assessment |
Mobile App Pentesting may include:
On-device data storage.
Encryption mechanisms.
Authentication and session management.
Deep Links.
WebView.
Digital certificates.
Reverse Engineering.
Root or Jailbreak.
Communication with the backend API.
Application permissions.
When comparing quotes, businesses need to check whether the API is included in the Mobile App Pentest scope or quoted separately.
Network Pentest pricing
External Network Pentest: approximately VND 40–100 million
External Network Pentesting assesses assets accessible from the Internet:
Public IPs.
VPN Gateway.
Firewall.
Mail Server.
Web Server.
Remote access services.
Publicly accessible administration ports.
Pricing typically depends on the number of IPs, the number of open services, and the level of exploitation permitted.
Internal Network Pentest: approximately VND 70–180 million
Internal Network Pentesting may include:
Internal servers.
Workstations.
Active Directory.
User accounts.
Network segmentation.
Privilege escalation.
Lateral movement.
Access to critical assets.
Internal Pentesting typically requires more time than External Pentesting because experts must test the potential to expand access privileges after gaining an initial foothold in the system.
Cloud Pentest Pricing
Cloud Pentesting may require a budget of approximately VND 100–300 million or more for complex architectures.
The scope may include:
AWS, Azure, or Google Cloud.
Identity and Access Management.
Virtual machines.
Storage Buckets.
Databases.
Containers.
Kubernetes.
API Gateway.
Secrets and Access Keys.
Logging and Monitoring.
Network Security Groups.
Hybrid Cloud connectivity.
Cloud scope | Budget range |
One Cloud account, few services | VND 100–150 million |
Multiple Subscriptions or Projects | VND 150–250 million |
Kubernetes, Container, or Hybrid Cloud | VND 200–300 million or more |
Multi-cloud or high compliance requirements | Separate assessment |
5 factors affecting Pentest Pricing
1. Number of assets
The larger the scope, the higher the cost. Assets may be counted by:
Website or domain.
API endpoint.
Application.
IP address.
Server.
Cloud account.
User role.
Testing environment.
2. Number of features and roles
A website with few pages but many user permissions may still require a large testing scope.
For example, with five user roles, experts may have to test many access combinations to determine whether users can view, edit, or delete data without authorization.
3. Business logic
The following features typically increase testing time:
Payments.
Refunds.
Discount codes.
E-wallets.
Multi-level approvals.
File uploads.
Data sharing.
Money transfers.
Access rights management.
Partner integrations.
4. Manual testing
Professional Pentesting requires a combination of tools and manual testing.
According to TorchLight's pricing framework, manual testing by experts costs more than automated scanning because it can detect logic flaws, attack chains, and misconfigurations that tools may miss.
Businesses should clearly distinguish between Pentesting and vulnerability scanning.
5. Reports and Retesting
A low quote may not include:
An executive report.
Exploitation evidence.
Remediation guidance.
A results presentation session.
Support for the technical team.
Retesting after remediation.
A confirmation letter for the results.
Businesses should clearly ask about the number of Retests, the deadline for requesting a Retest, and the circumstances that incur additional fees.
What should a Pentest Quote include?
Item | Should be included |
Assessment and scope definition | Included |
Testing plan | Included |
Automated testing | Included |
Manual testing | Included |
Exploitability verification | Included |
Risk severity classification | Included |
Technical report | Included |
Remediation recommendations | Included |
Executive summary | Recommended |
Results presentation | Recommended |
Retesting after remediation | At least one Retest is recommended |
Completion confirmation letter | Upon request |
A good report needs to include the risk severity, evidence, impact, and specific remediation guidance. You can also refer to how to evaluate a high-quality Pentest report.
How to get an accurate Pentest quote
Businesses should provide:
The type of system to be tested.
The number of websites, APIs, applications, or IPs.
The number of user roles.
A list of key features.
Whether the environment is Staging or Production.
API documentation, if available.
The required completion time.
Reporting requirements.
Retest requirements.
Compliance requirements, if any.
Example of a request with insufficient information:
Provide a Pentest quote for a website.
Example of a clearer request:
Pentest a web application in a Staging environment, comprising approximately 20 features, 45 APIs, and three user roles. The system has login, file upload, and payment functionality. The project needs to be completed within three weeks and include one Retest.
The clearer the information, the closer the quote will be to the actual cost.
Get a Pentest Quote Based on the Actual Scope
Businesses can estimate:
VND 30–50 million for a small website with a limited scope.
VND 50–180 million for an enterprise application, API, or system with multiple roles.
VND 100–300 million for Cloud or a system with a complex architecture.
From VND 250 million for a Red Team or in-depth attack simulation project.
The figures above are only intended to help estimate the budget. The official quote needs to be based on the actual scope and number of working days.
Register to receive a Pentest quote
If your business is preparing to deploy a new system, needs to meet customer requirements, or wants to assess the security of its current infrastructure, please contact IPSIP Vietnam for consultation.
Frequently Asked Questions About Pentest Pricing
How much does website Pentesting cost?
A small website with a limited scope may require a budget of approximately VND 30–50 million. An enterprise or e-commerce website may fall within the range of VND 40–150 million.
How much does API Pentesting cost?
A small API may require approximately VND 40–70 million. An API with many endpoints, multiple roles, or complex transaction logic may require VND 70–180 million.
Why can't Pentest pricing be fixed?
Each system has a different number of assets, features, roles, and level of complexity. A fixed quote without an assessment may omit scope or lead to additional costs.
Does the quote include Retesting?
It depends on the provider. Businesses should prioritize quotes that include at least one Retest after remediation.
Is a low-cost Pentest reliable?
It cannot be assessed based on price alone. However, businesses need to be cautious about services completed in a very short time, that do not assess the scope, or that only provide reports from automated tools. TorchLight also considers excessively low fixed quotes that are not tailored to the scope a sign that warrants careful review.
-----------
Referral
Penetration Testing Cost: What to Expect in 2026: https://torchlight.io/blog/penetration-testing-cost-what-to-expect-in-2026/
Penetration Testing as a Service (PTaaS): https://www.netspi.com/resources/data-sheets/penetration-testing-as-a-service/
OWASP Web Security Testing Guide: https://owasp.org/www-project-web-security-testing-guide/
OWASP API Security Top 10: https://owasp.org/API-Security/
Technical Guide to Information Security Testing and Assessment: https://csrc.nist.gov/pubs/sp/800/115/final










Comments