pricing guide
How Much Does a Penetration Test Cost in NZ?
A plain-English guide to what penetration testing costs in New Zealand, what changes the price, and where our own fixed-price packages sit.
In New Zealand, a focused penetration test on a single application or network usually costs between $3,000 and $15,000 plus GST, depending on the scope and how complex the environment is. Larger or multi-part engagements cost more. Our own fixed-price penetration tests start at $3,100 plus GST, with the price agreed before any work begins.
What drives the price
- Scope and number of targets. How many applications, IPs, endpoints or user roles are in scope.
- Type of test. A web application test, a network test and a cloud review each take different effort.
- Size and complexity of the environment. More hosts, more integrations and unusual technology all add time.
- Retesting is included. Every engagement comes with 90 days of free retesting, so confirming your fixes is not an extra cost.
- On-site or remote. Internal and wireless work may need someone on site, where external and web testing is done remotely.
Cost by test type
Fixed prices for our standard, well-scoped engagements. All prices are in NZD and exclude GST.
| Test | Scope | Fixed price |
|---|---|---|
| Web Application Penetration Test Single app, up to 5 functional pages, 2 user roles | Single app, up to 5 functional pages, 2 user roles | $4,800 |
| API Penetration Test Up to 25 endpoints, 1 auth method, 2 user roles | Up to 25 endpoints, 1 auth method, 2 user roles | $4,600 |
| Mobile Application Security Assessment Single app (Android/iOS), 2 user roles, 20 backend functions | Single app (Android/iOS), 2 user roles, 20 backend functions | $6,200 |
| External Network Penetration Test Up to 5 public-facing IPs / services | Up to 5 public-facing IPs / services | $3,100 |
| Microsoft 365 Secure Configuration Review One tenant, maximum 30 users, 1 Exchange domain | One tenant, maximum 30 users, 1 Exchange domain | $4,600 |
| Internal Network Penetration Test Up to 50 hosts, 1 Windows domain | Up to 50 hosts, 1 Windows domain | $6,500 |
| Cloud Secure Configuration Review One account, up to 5 primary services | One account, up to 5 primary services | $4,600 |
| Device Secure Configuration Review Single device (switch, router, firewall, computer, or laptop) | Single device (switch, router, firewall, computer, or laptop) | $3,100 |
| Internal Network Vulnerability Scan Up to 50 active hosts via VPN | Up to 50 active hosts via VPN | $3,500 |
| External Network Vulnerability Scan Up to 5 IP addresses | Up to 5 IP addresses | $1,400 |
| Cloud Attack Surface Assessment Single cloud environment, up to 10 internet-facing assets | Single cloud environment, up to 10 internet-facing assets | $4,600 |
| Hardware Security Assessment One device with Tier 1 testing only | One device with Tier 1 testing only | $6,800 |
These are the same packages listed on our pricing page. Anything larger or more complex is quoted on scope.
Fixed price or a custom quote
Standard, well-scoped tests have a fixed price, so you know the cost before any work starts. When an environment is larger or does not fit a standard scope, we quote on scope instead: we look at what needs testing and give you a single fixed price for that work. Either way, the number is agreed up front.
Why a cheap pentest can cost more later
Some of the lowest quotes are an automated scan with a report attached, sold as a penetration test. A scan has its place, but it does not validate findings or test business logic, so real issues get missed and false positives waste your developers' time. A consultant-led test costs more because a person is doing the work: finding the flaws that matter, confirming they are real, and showing you how to fix them. That is usually the difference between a report you can act on and one that sits in a drawer.
Getting an accurate quote
The only way to price a test properly is to look at what needs testing. Tell us about your systems and what you want to protect, and we will come back with a fixed-price quote.
Request a quoteCommon questions
- Is a vulnerability scan cheaper than a penetration test?
- Yes. A vulnerability scan is largely automated and costs less, but it only lists known issues. A penetration test adds a consultant who validates findings, chains weaknesses together and finds the logic and access-control flaws a scanner cannot. They answer different questions.
- How often should we get a penetration test?
- Most businesses test once a year, and again after a significant change such as a new application, a major release or a move to new infrastructure. Some compliance frameworks and customers ask for annual testing as a baseline.
- Is the retest included?
- Yes. Every engagement includes 90 days of free retesting, so once you have fixed the findings we confirm the issues are resolved at no extra cost, giving you evidence for customers, auditors and insurers.
- Do prices include GST?
- Prices are quoted in New Zealand dollars and exclude GST. GST is added at 15 percent on your invoice.