How much does a penetration test cost in 2026? A straight answer for Montana SMBs and healthcare
Most Montana clinics, law firms, and small businesses should expect $3,750 to $18,000 for a real penetration test. What drives the price, and how to compare quotes.
By Big Sky Support

Attackers don't care that you ran a scan. They care about the paths you didn't see.
When you finally decide you should probably get a penetration test, the first question is almost always what it's going to cost. Then the quotes come in, ranging from a few thousand dollars to well over thirty thousand, and it's no wonder most Montana leaders feel stuck.
For most Montana clinics, health systems, law firms, and small businesses, a serious penetration test typically runs between $3,750 and $18,000, with complex, multi-site, or heavily regulated environments reaching $30,000 or more. The spread isn't random. It reflects how much of your real attack surface actually gets tested, and whether you're getting expert work or a relabeled scan.
Where real pentest pricing lands
Generic online price ranges are hard to apply to a Montana clinic or law firm. For organizations like yours, the useful ranges look like this:
- Basic external test: $3,750 to $8,000. A fit for a single-location practice or business with a small set of internet-facing systems, like firewalls, VPN gateways, patient or client portals, and email access.
- Typical clinic, law firm, or small business test: $7,500 to $15,000. Usually external testing plus a light internal network review or one high-value web application, like a patient portal, client portal, or financial system.
- Comprehensive multi-segment or multi-application engagement: $15,000 to $30,000 or more. Multiple sites, separate network segments, several critical applications or EHR modules, and deeper adversarial testing.
- Enterprise-scale or heavily regulated environments: $30,000 to $50,000 or more. Larger health systems, hospitals, payers, and multi-office legal groups testing multiple networks and applications together.
These are per-engagement prices, not monthly retainers. Many of our clients pair an annual penetration test with ongoing security monitoring and vulnerability management, so the pentest is the crash test, not the only control.
Our own standard engagement is $3,750: three days of hands-on manual testing covering either your external footprint or your internal network, with findings prioritized by business impact, a report in one to two weeks, and a 90-day retest included. If you need both external and internal testing, we scope it on a call. What changes the price is scope, number of locations, and depth, with no emergency rates or per-finding charges.
What actually drives the price
Two quotes can both say "penetration test" and not be testing the same thing at all.
Scope and type of test
First, what are you asking testers to attack?
- External network: public IP addresses, firewalls, VPNs, portals, and other internet-facing services. Smaller attack surfaces cost less to test.
- Internal network: what happens if a phishing email works or a device is compromised. This is where testers find lateral movement into EHRs, file shares, and domain controllers, and it usually takes more hours.
- Web, mobile, and APIs: custom or critical applications, priced by how many roles, workflows, and integrations need testing. In healthcare, portals and EHR integrations usually live here.
A one-provider clinic with one portal is a very different job from a health system with multiple locations, vendors, and custom integrations.
Number of assets and complexity
Ten simple IP addresses with a static website aren't the same as sixty addresses fronting reverse proxies, VPNs, and several applications. Flat, undocumented networks take longer, because testers have to discover what you actually have before they can test it. You're ultimately buying expert hours, and more moving parts take more of them.
Testing depth
This is the biggest factor. Shallow work leans on automated scanners and hands you a tool-generated PDF with minimal human analysis. Deep work tries to chain weaknesses, abuse misconfigurations, and show the exact path an attacker could take to PHI, legal records, financial systems, or domain administrator access. Attackers don't care that you ran a scan. They care about the paths you didn't see.
Manual effort vs. automation
Automation is great for quick breadth and catching known issues. Manual testing is where logic flaws, workflow abuse, and "nobody realized these two issues together mean full network compromise" get uncovered. Manual work is billed in days, which is why deeper engagements cost more, and why they're the ones that matter when a ransomware crew shows up.
Black box, grey box, or white box
How much information you share changes the effort. Black box testing assumes testers know nothing, which sounds appealing but spends more time on reconnaissance. Grey box gives testers enough to represent a realistic attacker with a foothold, and it's often the sweet spot. White box shares everything, which can increase coverage but still takes time to work through. For small and mid-sized healthcare and professional firms, we usually recommend grey box.
Regulatory and reporting requirements
Healthcare and legal clients often need findings mapped to HIPAA, payer requirements, contracts, or cyber insurance language, plus reporting executives can use. That alignment adds hours. It's also where a crisis response mindset pays off: reports should help you in a real incident or audit, not sit in a folder.
Why per-IP pricing can mislead you
Per-IP pricing sounds clean, but it hides important details. One IP address might host a brochure website while another is a reverse proxy with several sensitive applications behind it: same count, very different risk. To hit a low per-IP price, some vendors quietly reduce how deeply they test each system, so you're covered on paper but not in reality. And it focuses the conversation on counts instead of attack paths into the systems that matter.
A better model for Montana healthcare, legal, and small business clients is fixed-fee, clearly scoped work, like "external perimeter plus patient portal and one internal network segment, grey box, with full reporting and retest."
Pricing tiers, including continuous testing
- Small business: $3,750 to $12,000. A clinic, dental office, law firm, or CPA firm with 10 to 75 users. External testing, a light internal review or one key web application, and manual exploitation of critical issues.
- Mid-market: $12,000 to $30,000 or more. A health system or multi-site business with 75 to 500 users. External and internal testing, several applications or APIs, Active Directory testing, detailed reporting, and a retest.
- Enterprise or heavily regulated: $30,000 to $50,000 or more. Hospitals, payers, and large legal groups. Multiple networks, many applications, limited red team elements, and board-ready reporting.
- Pentesting as a service (PTaaS). Smaller, targeted tests on a subscription throughout the year. We offer it from $250 a month. At that entry rate it isn't meaningfully cheaper than an annual test; it's a different tool. It makes sense when your attack surface keeps moving: you ship software, build out infrastructure, or regularly add and retire systems. If your environment is stable, the annual test is the better purchase.
For many Montana organizations, the right move is to start in the small business tier with a meaningful scope, then expand coverage as you add locations, cloud services, or clinical systems.
Pentest cost vs. breach cost
On paper, $10,000 to $20,000 feels like a lot. Compared to a real incident, it isn't.
IBM's annual Cost of a Data Breach research has put the global average cost of a breach above $4 million for years, with healthcare consistently the most expensive industry. Even for smaller organizations, a serious incident can easily reach six figures once downtime, response, and recovery are counted.
For a Montana clinic, law firm, or business, that kind of hit isn't just a bad quarter. It can be existential. Against those numbers, a well-scoped penetration test is a small, controlled expense that lowers the odds you'll learn about your weaknesses from an attacker.
What a good engagement should include
- Clear scope and objectives. You should know exactly what's in scope, what's out, and what questions the test is meant to answer.
- A recognized methodology. The team should reference NIST, OWASP, or similar frameworks and walk through reconnaissance, exploitation, and post-exploitation.
- Manual exploitation and attack path analysis. Testers should behave like a real adversary, taking vulnerabilities, misconfigurations, and weak controls and seeing how far they actually go.
- Prioritized, business-friendly reporting. Findings should be ranked by what would actually hurt your business, explained, and mapped to your regulatory reality, with evidence but without noise.
- Remediation support and a retest. You should get time with the testing team to talk through fixes, plus a retest of high-risk issues.
How to compare quotes without getting burned
Good signs: scope and methodology are described in language your leadership can follow, manual testing and exploitation are explicitly included, a walkthrough is scheduled for both executives and technical staff, and retesting critical issues is part of the engagement or clearly available.
Red flags: pricing is purely per IP with no discussion of business impact or critical systems, someone claims to fully test a complex environment in a single day, the deliverable is described as scan results or looks like raw tool output, and there's no mention of how production risk will be handled or coordinated with your operations team.
If the cheapest quote looks too good to be true, it usually is. In our experience, that means a relabeled scan, which does little to prepare you for a determined attacker.
Common questions
Short answers to the questions we hear most about this topic.
Why do penetration test quotes vary so much?
Two quotes labeled "penetration test" often aren't testing the same thing. Price reflects how much of your real attack surface is covered, how complex your environment is, and how much manual, expert effort goes into exploiting and chaining weaknesses. The cheapest quote is often an automated scan labeled as a pentest.
Is once a year enough for penetration testing?
For smaller, relatively stable environments, yes, as long as it's paired with ongoing scanning and monitoring. For organizations that handle sensitive data, change quickly, or face heavier scrutiny, like healthcare, financial services, and SaaS, annual testing alone usually isn't enough.
Will penetration testing disrupt our operations?
It shouldn't, if it's planned properly. Higher-risk activities are discussed ahead of time and scheduled during agreed maintenance windows. The goal is realistic testing without unexpected downtime, especially for clinics and businesses that can't afford outages.
What's the minimum sensible penetration test scope for a small organization?
At minimum, test your internet-facing systems plus at least one critical internal network segment or application. Testing a single IP address with no context almost always creates a false sense of security.
Can we start with a smaller penetration test scope?
Yes. Many organizations start with a focused scope, like the external perimeter plus one key application, or a single location. They expand to more systems or sites in later rounds once they've seen the results.
Terms used in this article
Plain definitions, so nothing above needs a second search.
Get a straight quote for a real penetration test.
Same day onsite for contract clients. Everyone else pays $165 an hour, with no emergency surcharge, and gets forensic imaging before remediation.
See penetration testing pricingAll articles