How it works
A pentest starts with a scope and rules of engagement: which systems are in, which test accounts to use, the dates, and what is off limits, all signed off by someone with authority over those systems. Testers then work through the target by hand and with tools such as Burp Suite, following methods like the OWASP Web Security Testing Guide. Black-box tests start with no inside knowledge, grey-box tests get user accounts, and white-box tests also see the source code.
The deliverable is a report that ranks each finding by severity (often with a CVSS score), explains the impact in plain terms, gives developers enough detail to reproduce it and suggests fixes. A retest after the fixes confirms they worked. The report is often what customers, investors and auditors ask for: PCI DSS requires penetration testing at least once a year and after significant changes, and SOC 2 and ISO 27001 audits commonly expect one.
A vulnerability scan is automated and finds known issues quickly; a pentest adds human judgement and catches broken business logic, such as paying for one item and receiving ten. A red team exercise goes further and tests whether defenders notice a realistic, stealthy attack.
Penetration testing pros and cons
Pros
- A scoped, methodical look at the systems that matter most
- Finds business logic flaws that automated scanners miss
- Produces a formal report for customers, auditors and PCI DSS
- Testers explain the fixes and retest them
Cons
- A snapshot in time: code shipped after the test is not covered
- Quality varies widely between firms and testers
- You pay for the time whether or not serious issues turn up
- A fixed number of days limits how deep testers can go
When to use Penetration testing
Pick it when
- Before launching a product that handles money, health or personal data
- A client, investor or auditor asks for a recent report
- After major changes to login, payments or infrastructure
Skip it when
- The product is still a prototype that changes every week
- Automated scans and dependency updates have not been run yet
Penetration testing pricing
Paid
Quoted per engagement, based on the scope and the number of testing days. Pentest-as-a-service firms such as Cobalt sell yearly packages of testing credits, also priced on request.
Penetration testing pricing page (opens in a new tab)Approximate, checked September 2026.What the other tools cost
Penetration testing vs the alternatives
Related terms
More in Security
Testing and research