| Tier | What you get | Real 2026 price |
|---|---|---|
| 0 · Free | Open-source scanners, dependency alerts, header and TLS graders | $0 |
| 1 · Self-serve scanner | Automated authenticated scanning, subscription | $699–$5,000/yr |
| 2 · Automated "pentest" | Autonomous or AI-assisted test, one re-scan | $2,999–$3,500 |
| 3 · Small human pentest | 3–8 tester-days, single app, under ~20 pages | $1,500–$6,000 |
| 4 · Standard SaaS pentest | 5–12 tester-days, grey box, API and roles, retest | $6,000–$24,000 |
| 5 · Enterprise / multi-app | Multiple roles and APIs, source code review | $15,000–$60,000+ |
| 6 · Red team / continuous | Adversary simulation, ongoing programme | $20,000–$150,000+ |
| 7 · Bug bounty programme | Platform + triage + bounty pool, first year | $40,000–$120,000 |
| 8 · SOC 2 Type II audit | Attestation only — pentest is a separate line item | $15,000–$200,000 |
More than most people assume, and this is where a solo builder should start.
| Tool | Covers | Doesn't cover |
|---|---|---|
| OWASP ZAP | SQL injection, XSS, SSRF, path traversal, command injection, header misconfiguration. Authenticated scanning and AJAX-heavy pages. Broadest free coverage available. | Full scans take 1–8 hours; misses some single-page-app routes; false positives. |
| Nuclei | Known CVEs, misconfigurations, exposed panels, default credentials — 11,000+ community templates, new CVEs covered within days. Good in CI. | Doesn't crawl or discover endpoints. Won't fuzz for unknown bugs. |
| Nikto | Outdated server software, dangerous default files, server misconfiguration — 7,000+ checks. | No application logic, no crawling, high false-positive rate. |
| GitHub code + secret scanning | Free on public repos: CodeQL static analysis, leaked credential detection, push protection. | Private repos are paid, billed per active committer. |
| Dependabot / npm audit | Known-vulnerable dependencies. Free on GitHub's free plan. | Nothing about your own code or logic. |
| Snyk Free | Dependencies, static analysis, infrastructure-as-code, containers, IDE and CLI. | Five-project limit. |
| Mozilla HTTP Observatory | HTTP headers, CSP, HSTS, key security config. Has run 47 million scans. | Configuration only. |
| SSL Labs · securityheaders.com | TLS configuration and certificate chain; response header grading. | One narrow layer each. |
| Free tiers: Intruder, Probely, Beagle | Intruder: 5 web apps, weekly external scans. Probely: 5 scan hours/month. Beagle: 1 test/month. | Not continuous. |
The honest framing: stack ZAP + Nuclei + Dependabot + Snyk Free + Observatory + SSL Labs and you have covered configuration, known CVEs, vulnerable dependencies and the classic injection and XSS classes — for nothing.
What $0 cannot buy is business logic flaws, broken access control between tenants or roles, and authentication bypass. That is precisely what human testers are paid to find, and precisely what breaks small SaaS apps. It's also, not coincidentally, what the research keeps finding in AI-generated code — one study of five agentic coding tools found them "very prone to business logic vulnerabilities" while encountering not a single exploitable SQL injection or XSS.
| Vendor | Published price |
|---|---|
| Astra | Scanner Lite $69/mo · $699/yr (1 target) · Scanner $199/mo · $1,999/yr (unlimited scans) · Scanner Agency $499/mo · $4,999/yr (5 targets, compliance views). Pentest Auto $2,999/yr, Pentest Expert $5,999/yr. $7 one-week trial. The most price-transparent vendor in the market. |
| Beagle Security | Free (1 test/mo) · Essential $99/mo · Advanced $299/mo (15 tests/mo, API and GraphQL). Usage-based, no per-target fee. |
| Intruder | Free tier · Cloud $299/mo · Pro $499/mo. AI-powered web app pentests from $3,500/test. 20% off annual. |
| Pentest-Tools | From $95/mo (NetSec) to $190/mo (Pentest Suite) at 5 assets. Annual = pay for 10 months. |
| Detectify | Starter €0 · Standard from €2,500/yr · Professional from €5,000/yr · Enterprise from €15,000/yr. Watch out: per-domain and per-target charges sit on top, so the headline is a floor. |
| Snyk | Free · Team from $25/developer/mo · Ignite from $1,260/developer/yr. |
| Tenable | Web App Scanning $7,434/yr for 5 domains · Vulnerability Management $6,112/yr for 100 assets. |
| Acunetix · Invicti · Qualys | Not published. Acunetix is around $7,000/yr entry per a cloud marketplace listing; Qualys web app scanning is quoted by resellers near $1,995/yr for 25 apps. Treat both as third-party estimates, not vendor prices. |
Start at the free end. Before you price anything above, see what your live app currently exposes — A–F grade, free, no signup.
Scan my app free →This short list is the useful part of this page, because it's what the rest of the internet doesn't give you.
| Vendor | Published prices |
|---|---|
| Sherlock Forensics | Quick Audit $1,500 CAD, 3–5 days — auth and session, access control, injection, secrets across code and git history, API enumeration, OWASP mapping, retest included. Standard $5,000 CAD (10–15 days). Comprehensive $12,000 CAD. The only genuinely solo-founder-priced published card we found. |
| Software Secured | Web & API pentest from $10,800 with 3 retest rounds over 12 months · mobile from $5,400 · secure code review from $9,300 · external network from $5,400 · PTaaS subscription from $21,400/yr with unlimited retesting. |
| Astra | Pentest Expert $5,999/yr — manual testing by certified experts, 2 re-scans, one target. |
| Budget Security | €849/day (~$985), OSCP-certified manual testing, full report plus one free retest. |
| Secure Ideas | Publishes its hourly rate: $340/hr, and states the industry band is $200–$500/hr. |
For two of the biggest names, aggregated real signed-contract data exists — stronger evidence than any published guide:
| Vendor | Median contract | Range | Sample |
|---|---|---|---|
| Cobalt.io | $30,000/yr | $8,937 – $87,840 | 194 purchases |
| HackerOne | $40,000/yr | $18,609 – $125,834 | 305 purchases |
Note Cobalt's floor: $8,937 is a real price a small buyer has actually achieved, well below the five-figure minimums usually implied. Buyers routinely negotiate 15–30% off list.
The disagreement is almost entirely about the floor. For a small, simple web app under about 20 pages with no API, published guides range from $2,500–$6,000 at the low end to $5,000–$30,000 at the high end. For a medium SaaS with a REST API and multiple roles, the consensus is roughly $6,000–$15,000; complex enterprise work runs $15,000–$40,000+, and full-stack with source code review reaches $20,000–$60,000+.
The 2026 average across the market is put at around $18,300, with most organisations spending $10,000–$30,000 per test.
Tester-days is the real unit; everything else is a proxy for it. A grey-box test of a medium SaaS application takes a minimum of 5–10 business days of active testing. At mid-market day rates of $1,500–$3,500 that arithmetic alone produces $7,500–$35,000.
Day rates themselves span roughly seven times across the market — from about $985/day published at the budget end to $4,000–$7,000/day at boutique and Big Four firms, with the Big Four typically charging 2–3× a boutique for identical scope.
| Framework | Pentest required? | Cost |
|---|---|---|
| PCI DSS | Yes — requirements 11.4.1 and 11.4.4, at least annually plus after significant change. But only for SAQ C and SAQ D. Not required for SAQ A, B, B-IP, C-VT or P2PE. | $12,000–$25,000, or a 15–30% premium on a base test |
| SOC 2 | No. SOC 2 does not explicitly require penetration testing. CC4.1 lists it as one example of a separate evaluation; CC7.1 references vulnerability scanning. Auditors recommend it and it's strong Type II evidence — but it is not mandatory. | Audit fee: Type I $5,000–$25,000 · Type II $15,000–$200,000 depending on firm tier. Pentest is a separate $8,000–$30,000 line item. Total programme typically $30,000–$150,000; startups $20,000–$60,000; maintenance ~40% of initial spend annually. |
| ISO 27001 | Not named as a mandatory control. No accredited certification body publishes a rate card. | Audit fees quote-only. Compliance tooling for a 25-person org runs $7,500–$32,500/yr depending on vendor. |
| HIPAA · FedRAMP | Effectively yes in practice | HIPAA $10,000–$50,000 · FedRAMP $15,000–$75,000+ |
A common assumption, and it's backwards. Real contract data puts HackerOne's median at $40,000/year. A vulnerability disclosure programme with no bounties still runs $20,000–$50,000/year in platform fees. First-year totals for a small or mid-market company land at $40,000–$120,000 — the platform floor alone exceeds a full mid-tier human pentest before a single bounty is paid.
The genuinely free version is a self-run disclosure programme: publish a security.txt, a clear disclosure policy and an email address. You pay nothing but triage time, and researchers do find things.
We looked for a survey of solo-founder or small-SaaS application security spend and couldn't find one. That absence is itself part of why this question is answered so badly online. The closest available data is general small-business security spend:
Put those together and the real answer emerges: a typical small business's entire annual security budget is one mid-tier penetration test. That's why the honest recommendation for most small apps is not "save up for a $15,000 pentest." It's: exhaust the free tier properly, add an automated scanner for the price of a lunch, and buy human testing when you have something specific that needs it — money, regulated data, or an enterprise customer asking.
| You are… | Buy this | Cost |
|---|---|---|
| Launching a side project or MVP | Free stack + your platform's built-in scan + an external scan of the live URL | $0 – ~$5 |
| Early SaaS with paying users, no regulated data | The above, plus an automated scanner subscription, run continuously | $699 – $2,000/yr |
| Taking payments via hosted checkout (Stripe etc.) | Same as above. Check your SAQ — you likely need no pentest for PCI | $699 – $2,000/yr |
| First enterprise customer asking security questions | A small human pentest with a letter of attestation — that's the document they want | $1,500 – $6,000 |
| Handling health, financial or regulated data | Full human pentest, scoped to compliance. Nothing automated substitutes | $6,000 – $25,000 |
| Pursuing SOC 2 Type II | Audit + readiness + tooling + a pentest as separate line items | $20,000 – $60,000 (startup range) |
For a genuinely small application, published rate cards start around $1,500–$5,000 for a human penetration test of 3–8 tester-days. Market guides put the band at $2,500–$6,000. Below roughly $4,000 you are usually buying an automated scan presented as a pentest. Automated scanning subscriptions with published prices start at $699/year, and a capable free stack costs nothing.
Because the unit is tester-days, and day rates span about seven times across the market — from roughly $985/day at the budget end to $4,000–$7,000/day at boutique and Big Four firms, who typically charge 2–3× a boutique for identical scope. On top of that, scope (endpoints, roles, APIs, multi-tenancy), methodology, whether retesting is included, and whether you need a letter of attestation all move the number substantially.
It's worth it if you understand you're buying an automated scan, and automated scans genuinely catch the most common failures in small apps — exposed databases, leaked keys, unprotected endpoints, missing headers. It is not worth it if it's sold as equivalent to a manual test. The tells: 24–48 hour turnaround, no stated tester-days, scanner output with little narrative, no authenticated testing, no retest.
No. SOC 2 does not explicitly require one — CC4.1 lists penetration testing as one example of the separate evaluations management may use, and CC7.1 references vulnerability scanning. Auditors commonly recommend it and it makes strong Type II evidence, but it is not mandatory. Budget it as a separate $8,000–$30,000 line item if you choose to do it, not as part of the audit fee.
Only for SAQ C and SAQ D. Requirements 11.4.1 and 11.4.4 mandate annual testing plus testing after significant change — but SAQ A, B, B-IP, C-VT and P2PE do not require it. If you take payments through a hosted checkout like Stripe, you're most likely SAQ A and need no penetration test for PCI purposes.
Free, in this order: run your platform's built-in scan if it has one; verify Row Level Security on every database table; check your JavaScript bundle for secret keys; confirm your API endpoints require authentication; then run a free external scan for headers, TLS and exposed files. That sequence catches the failures that actually take down small apps. The 10-minute pre-launch check walks through it step by step.
No — it's typically several times more expensive. Real contract data puts HackerOne's median at $40,000/year, and even a bounty-free disclosure programme runs $20,000–$50,000/year in platform fees. The free version is running your own: publish a security.txt, a disclosure policy and a contact address, and pay only in triage time.
An A–F security grade in seconds, no signup, including a live database-exposure test. A full report with fixes costs about a dollar.
Scan my app freeWe'll also tell you what a scan can't find — that's what the human tiers above are for.