A penetration test for a small or mid-size business usually costs from around 50,000 CZK for a focused, single-target scope to several hundred thousand CZK for a full annual program across infrastructure, applications, and phishing. In global terms, most SMB engagements land between $5,000 and $15,000, and the broad market average sits near $18,000. The spread is wide because a pen test is priced by effort, not by a fixed package.
That is also why so many vendor pages avoid giving you a number. This guide is the honest version: what actually drives the price, real ranges by test type, what you get for the money, how often you need one, and how to scope a test so you do not overpay or, worse, buy something that only looks like a real test.
Penetration testing is priced by man-day (MD), so cost follows scope, not a price list. A focused SMB test starts around 50,000 CZK; a web application or API test runs roughly 100,000 to 150,000 CZK; a full infrastructure test 150,000 CZK and up; a complete annual program for a 50 to 250-person company can reach several hundred thousand CZK. A real test always includes scoping, manual testing, a report ranked by severity, remediation guidance, and a retest to confirm the fixes. Anything advertised for a few hundred crowns is a scan, not a pen test.
What actually drives the cost of a penetration test?
Czech security firms quote by the man-day, the effort a senior tester spends on your systems. The number of man-days is set by these factors:
- Scope size. How many IP addresses, applications, APIs, endpoints, and user roles are in scope. This is the single biggest driver.
- Test type. A web app test, an external network test, an internal network test, and a mobile app test are different amounts of work.
- Black-box vs white-box. Black-box starts blind and spends time on reconnaissance. White-box gives the tester source or credentials, so each asset takes less time and gets deeper coverage. Our white-box vs black-box guide covers the trade-off.
- Manual depth. A real pen test is manual exploitation by a human, not just an automated scan. Depth costs time, and depth is the point.
- Retest included. A proper engagement retests after you fix the findings. Confirm it is in the quote.
- Compliance rigor. ISO 27001, PCI DSS, or SOC 2 reporting requirements can raise the effort and the report format.
How much does a penetration test cost by type?
Here is a realistic view. Treat these as orientational ranges: the Czech figures are directional and current market rates trend higher, so lean on the man-day logic rather than a single number.
Test type | Czech market (CZK) | Global (USD) |
|---|---|---|
Focused / small SMB scope | from ~50 000 | $5,000 to $15,000 |
Web application or API | ~100 000 to 150 000 | $8,000 to $30,000 |
External / internal network | ~150 000 and up | $7,000 to $35,000 |
Mobile application | ~90 000 | $5,000 to $40,000 |
Full annual program (50 to 250 staff) | several hundred thousand | $30,000 and up |
Sources: Czech per-type figures from Integra and the state CSIRT.cz; global ranges and the ~$18,000 average from Astra. Bitvea prices SMB penetration testing from 50,000 CZK, deliberately at the entry end of this scale.
What do you actually get for the money?
A real penetration test is a process with a deliverable you can act on, not a tool report. A proper engagement includes:
- Scoping. Agreeing what is tested and how, so the effort and the price are clear up front.
- Reconnaissance and discovery. Mapping the attack surface and finding weaknesses.
- Manual exploitation. A human trying to break in, chain findings, and escalate, which is what separates a pen test from a scan.
- A report ranked by severity. An executive summary plus each finding with evidence and a specific fix, in priority order.
- A retest. Re-checking after you remediate, to confirm the holes are actually closed.
A focused external test often takes three to five days of active testing; a broader engagement runs one to three weeks. Scoping the attacker perspective first, which is where OSINT helps, makes the test itself tighter and cheaper because you are aiming at what is actually exposed.
How often should you run a penetration test?
The baseline is at least once a year, and again after any major change to your infrastructure or applications. Higher-risk systems are tested more often. Beyond good practice, regulation is now a driver for many Czech firms: the EU NIS2 directive, transposed into Czech cybersecurity law, expands the set of companies that must test regularly and pushes security testing into sectors that were not covered before. The Czech authority NÚKIB publishes guidance on what a proper test should look like (NÚKIB penetration testing guide). Standards like ISO 27001 and PCI DSS also require regular testing.
If NIS2 applies to you, check your exact obligations against NÚKIB rather than a blog, this one included. The point for budgeting is simple: for a growing number of companies, a pen test is no longer optional.
Why is a real pen test not a few hundred crowns?
Search for pen test prices in Czech and you will see aggregator listings quoting a few hundred crowns. That is not a penetration test. For a few hundred crowns you get an automated vulnerability scan: a tool that lists known issues. Useful, but it does not try to exploit anything, chain weaknesses, or think like an attacker. A real test is senior human effort, which is why it is priced in man-days. Anything under roughly 4,000 dollars globally is very unlikely to be a genuine manual test. Cheap here is expensive later.
How to scope a test so you do not overpay
The way to keep the cost sensible is to test what matters, not everything at once. Start with your most exposed and most valuable systems: the public-facing app, the login, the customer data. A good partner will give you a transparent man-day estimate, tell you honestly where a smaller scope is enough, and not sell you an enterprise package your risk does not justify. That is how we approach it at Bitvea: SMB-scoped, white-box where it gets you deeper coverage for less, and paired with OSINT so the test aims at your real exposure.
Frequently Asked Questions
How much does a penetration test cost for a small business?
A focused SMB test typically starts around 50,000 CZK (roughly $5,000 to $15,000 globally), depending on scope. The price scales with the number of systems in scope and the depth of testing, because pen testing is priced by man-day.
What is included in a penetration test?
Scoping, reconnaissance, manual exploitation by a tester, a report ranked by severity with an executive summary and specific fixes, and a retest to confirm the fixes work. If a quote is missing the report detail or the retest, ask about them.
How long does a penetration test take?
A focused external test is often three to five days of active testing. A broader engagement across infrastructure and applications runs one to three weeks, plus scoping before and the report after.
How often should you do a penetration test?
At least annually, and again after any major change to your systems. Higher-risk environments test more often. Regulations such as NIS2, ISO 27001, and PCI DSS require regular testing for the companies they cover.
What is the difference between a pen test and a vulnerability scan?
A vulnerability scan is an automated tool that lists known issues. A penetration test is a human actively trying to exploit those issues, chain them together, and reach real impact. The scan is cheap and fast; the test tells you what an attacker could actually do.
Does NIS2 require penetration testing?
NIS2, as transposed into Czech cybersecurity law, expands which companies must test their security regularly and adds sectors that were not previously covered. Whether it applies to you, and exactly what it requires, should be confirmed against NÚKIB and the current statute rather than a blog.
The bottom line
A penetration test costs what its scope costs, because it is priced by human effort. For an SMB that means from around 50,000 CZK for a focused test, more for a full program. What you should look for is not the lowest number but a real deliverable: manual testing, a report you can act on, and a retest. Scope tightly, test what matters most first, and treat anything advertised for a few hundred crowns as a scan, not a test.
Want a straight quote for your scope?
Tell us what you run and we will give you an honest man-day estimate, right-sized for your risk, not an enterprise package. Book a free consultation.