# Penetration testing cost and pricing (2026, EUR)

A web application or API penetration test in the Netherlands typically costs EUR 5,000 to 15,000 excluding VAT; published Dutch day rates run from about EUR 1,000 to 2,000. At Scotoma that is 4 to 10 tester days at EUR 1,250 to 1,500 per day.

Updated 2026-10-09. All prices in EUR, excluding VAT. Company: Scotoma.

## Three lines

| Product | Price (EUR, excl. VAT) | Testing days |
|---|---|---|
| AI Pentest | From 4,000 | 3 to 10 |
| Launch Clearance | 10,000 to 20,000 | 8 to 14 |
| Stack Pentest | From 5,000 | 4 to 10 |

## Packages

| Product | Package | Price (EUR, excl. VAT) | Testing days |
|---|---|---|---|
| AI Pentest | Chatbot & RAG | EUR 4,000 to 10,000 | 3 to 7 |
| AI Pentest | Agent & MCP | EUR 6,000 to 15,000 | 4 to 10 |
| Launch Clearance | SaaS + AI feature | EUR 10,000 to 20,000 | 8 to 14 |
| Stack Pentest | Web & API | EUR 5,000 to 15,000 | 4 to 10 |
| Stack Pentest | Cloud & Infrastructure | Quoted per scope | Per scope |

### AI Pentest: Chatbot & RAG

A customer-facing assistant, an AI search or a RAG application. Details: https://scotoma-epj.pages.dev/pricing/#ai-chatbot-rag

What we test: Prompt injection, direct and through retrieved content; System prompt and data leakage; Retrieval and tenant isolation in the vector store; Output handling before it reaches code or browsers; Consumption limits (denial of wallet).

What moves the price: How many assistants and data sources; Black box, or grey box with the system prompt; Conversation flows with real effects.

### AI Pentest: Agent & MCP

An agent that calls tools, holds credentials or runs on MCP servers. Details: https://scotoma-epj.pages.dev/pricing/#ai-agent-mcp

What we test: Everything in Chatbot & RAG; Tool and function calls kept within the task; Agent identity and delegated credentials; MCP servers and tool definitions, yours and third-party; Memory and shared context integrity.

What moves the price: How many tools, and what they can change; MCP servers in scope; Hand-offs between agents.

### Launch Clearance: SaaS + AI feature

Your SaaS platform and the AI feature on it, as one scope. Details: https://scotoma-epj.pages.dev/pricing/#launch-clearance

What we test: The AI feature, as in Agent & MCP or Chatbot & RAG; The web application and APIs under it, as in Web & API; Cross-layer findings: where a model issue reaches a stack issue; One kickoff, one report, one attestation letter.

What moves the price: Chat only, or tools that act; The size of the platform’s API surface; Roles and tenants.

### Stack Pentest: Web & API

A web application, its REST or GraphQL APIs, or both. Details: https://scotoma-epj.pages.dev/pricing/#stack-web-api

What we test: Authentication and sessions; Authorization and tenant isolation; Business logic and multi-step workflows; API risks mapped to the OWASP API Security Top 10 (2023); Severity in CVSS v4.0.

What moves the price: Roles, tenants and workflows; Endpoints and integrations; Black box or grey box.

### Stack Pentest: Cloud & Infrastructure

AWS, Azure or GCP accounts, and the hosts you expose. Details: https://scotoma-epj.pages.dev/pricing/#stack-cloud-infra

What we test: Identity, roles and privilege paths; Storage exposure and access policies; Secrets in code, images and pipelines; Workload identity and metadata access; External hosts and remote access.

What moves the price: Accounts, subscriptions and regions; Services in use; A configuration review, an outside view, or both.

## Why a human-led test costs more than an automated one

Automated tests now sell for EUR 1,250 to 3,500 a test. They are worth running. Ours costs more because the price buys a person’s hours, spent where tooling tends to stop: business logic that only breaks in the third step, chained abuse that turns three small issues into one real risk, an agent calling a tool on a stranger’s say-so, a record that crosses from one tenant to another.

## After the report

A finding is not closed when the report lands. It is closed when the fix holds.

## Fixed quotes, payment and VAT

- The quote: Book a 30-minute scoping call. A quote follows the call.
- Payment: Payment terms are in the quote.
- VAT: Every price on this page excludes VAT. Prices are in euros.

## Questions about the price

### What drives the price of a penetration test?

Mostly the number of things a person has to understand: roles, tenants, workflows, API endpoints, and for AI, the tools an agent can call and the data it retrieves. Black box testing takes longer than grey box for the same coverage. Production-only testing adds a little time for safer pacing.

### How many testing days does a pentest need?

A single web application or API usually needs 4 to 10 testing days. A chatbot or RAG application needs 3 to 7, an agent with tools and MCP servers 4 to 10, and a SaaS platform with its AI feature 8 to 14. The scoping call turns that range into one number.

### Why do you publish prices at all?

Because you need a number before you can ask for budget, and a range you can check is more useful than a sales call. Our ranges are the bands our quotes land in. If your scope sits outside them, we say so on the call, before any work starts.

### Do your prices include VAT?

No. Every price on this page excludes VAT and is in euros. Your quote states the VAT that applies to your organisation and the country it is registered in. The date at the top of this page says when these ranges last changed.

## Sources

- Zolder B.V. (CCV-certified Dutch pentest firm, own published price): https://zolder.io/dienst/pentesting/ (checked 2026-10-09)
- Securiguide (aggregates published Dutch rates; IBgids August 2026 survey): https://www.securiguide.nl/risico-en-compliance/pentest-kosten/ (checked 2026-10-09)
- Hadrian Security (own published price): https://hadrian.io/nova-demo (checked 2026-10-09)
- Aikido Security (own published price): https://www.aikido.dev/comparison/aikido-vs-novee-security (checked 2026-10-09)

Book a 30-minute scoping call: https://scotoma-epj.pages.dev/contact/

Full page: https://scotoma-epj.pages.dev/pricing/
