Pentest booked this week, report in your hands in two
A customer, an auditor or an investor asked you for a pentest. Get a fixed fee in writing today, a named certified tester on your scope, and a report your auditor will accept. No discovery call, and no hourly surprises.
Authorised testing only. We test with your explicit written authorisation, inside a scope and rules of engagement agreed before any testing begins. Unauthorised testing is illegal under the Computer Fraud and Abuse Act (18 U.S.C. § 1030). We do not perform or condone it.
Four questions, about a minute. A written price back, usually within four working hours.
What a pentest costs with us
Fixed fees, agreed in writing before any work starts. So the number you approve is the number you pay.
Every price includes real manual testing hours, a named certified tester, an audit-ready report, an attestation letter and one retest. Because those are the parts that cost money, anyone quoting under $4,000 is selling you an automated scan.
Price my exact scopeThe teams who buy a pentest from us
Security and engineering teams book with us to clear audits and customer reviews, and they do it without stalling the roadmap.
Logos are the property of their respective owners.
Pentest packages, priced before you commit
Pick the shape that matches your scope. However, if none of them fits, send the form and we will build one that does, at a fixed fee.
Essential pentest
One application or one external network. The usual first purchase.
FromFixed fee, one asset in scope
- 15+ manual hours, stated in your contract
- Named tester, OSCP or CREST held
- Audit-ready report and attestation letter
- One retest inside 30 days
- Report delivered in 10 working days
Standard pentest
Up to three assets. What most SOC 2 and PCI DSS buyers need.
FromFixed fee, up to 3 assets in scope
- 45+ manual hours, stated in your contract
- Web app, API and external network together
- Live remediation call with your engineers
- Critical findings reported the same day
- One retest inside 30 days
Advanced pentest
Full scope, including internal, cloud or mobile. For a real attack picture.
FromFixed fee, scope agreed in writing
- 90+ manual hours, stated in your contract
- Internal network, cloud and mobile in scope
- Attack-chain scenarios, not just a finding list
- Board-ready summary for your investors
- Two retests inside 60 days
Four reasons buyers pick our pentest
None of these are unusual to ask for. However, very few firms will put all four in writing before you sign.
Manual hours in the contract
Your contract states the number of hands-on hours you are buying. Because that single line is where most of the price difference between two quotes actually lives, we put it in writing rather than leaving it vague.
You meet your pentest tester first
We name the practitioner and the credential they hold before day one, whether that is OSCP, CREST CRT or GXPN. So you know exactly who is on your systems, not just which logo is on the invoice.
A retest is included
Fixing something you cannot prove you fixed is not much use in an audit. Therefore one retest is inside every package, and the retest letter is what your auditor actually wants to see.
Fixed fee, or we re-quote first
The fee is agreed before work starts, with inclusions and exclusions both written down. If the scope genuinely changes, we re-quote in writing and wait for your approval, so nothing lands on an invoice unannounced.
Pentest or vulnerability scan: what you are paying for
This is where buyers lose the most money. Scans get sold at pentest prices, and the difference only surfaces later, when an auditor reads the report properly.
| Vulnerability scan | Our pentest | |
|---|---|---|
| Who does it | A tool, running on a schedule. | A named certified person, on your specific system. |
| What it finds | Known problems that match a database. | Business logic flaws, broken access control, chains of small issues. |
| Proof | A warning, often a false alarm. | A demonstrated way in, with the exact steps. |
| Typical price | $2,000 to $10,000 | $5,900 to $50,000, fixed before you start |
| Retest | Rarely included. | Always included. |
| Passes an audit | Sometimes, until someone reads it closely. | Yes. That is what it is built for. |
How your pentest runs, week by week
Five stages, following OWASP WSTG and NIST SP 800-115. So you always know which one you are in, and who is doing the work.
Scope and authorise
We agree what is in, what is off limits, and when. Because authorisation is not optional, you sign it in writing before anything is touched.
Meet your tester
You are told who runs your pentest and what they hold, whether that is OSCP, CREST or GXPN, and you are told before day one.
Manual testing
Three to ten days of hands-on work against your scope. Critical findings reach you the same day rather than waiting for the report.
Report and call
An executive summary a director reads in ten minutes, plus findings with real proof and also specific fixes for the engineers.
Retest
Included in every package, so you can prove the fix worked instead of just claiming it. That letter is what your auditor asks for.
What you get when your pentest ends
The report is the product. In short, it is what your auditor reads, what your customer asks for, and what your investor checks.
Executive summary
Ten minutes, no jargon. What was tested, what the real business risk is, and also the three to five things worth fixing first.
Findings with proof
Each issue in plain language, with severity, the exact request or screenshot that proves it, and the specific fix. In short, not a scanner export.
Pentest attestation letter
A one-page signed letter confirming the work happened and what it covered, so you can share proof but without handing over the findings.
Retest letter
After your fixes, written confirmation of what was closed. That is the document auditors and enterprise buyers actually want to see.
Ask us for a redacted sample before you buy. We will send one. A firm that will not show you a sample report is telling you something, and a report your engineers cannot follow is a report nobody acts on.
What changes the price of a pentest
Two quotes that look identical are usually separated by one of the four things below. However, most firms will not volunteer any of them.
| Driver | Effect on your quote |
|---|---|
| Scope size | The biggest factor by far. Every extra application, API or user role adds testing days. |
| Manual hours | A $6,000 pentest is roughly 15 hours of human work. A $20,000 one is roughly 60. Most of the gap lives here. |
| Tester seniority | Day rates run $1,500 to $3,500 in the mid-market, and $4,000 to $7,000 at the top. A Big Four badge costs 2 to 3 times a boutique. |
| Retest included | Often the single line that explains why one quote looks higher. Ours is always included, so compare like with like. |
Who runs your pentest, and what they hold
Security buyers have no patience for vagueness. So here is the whole structure, with nothing left out.
Us
Thornbury Labs is the firm you contract with, and also the firm accountable to you. We scope the work, manage the engagement, run quality assurance on every report, and remain your single point of contact throughout.
Your pentest practitioner
Testing is performed by vetted independent practitioners under contract to us, holding credentials such as OSCP, OSWE, CREST CRT and CCT, or GXPN. Although they are not our employees, we name yours before the engagement starts.
What we will not claim
We are not a CREST-accredited company, and we do not describe the test itself as certified, because certifications are held by people rather than by tests. We also cannot promise to find every vulnerability, and neither can anyone else.
The question worth asking any firm. Not "are you certified", but "who specifically will test my systems, and what do they hold". We answer that in writing before you sign, and you can decline the assigned practitioner and ask for another.
Which rules require a pentest
Most engagements are bought because something demands one. Therefore it pays to scope to the actual requirement instead of guessing at it.
| Framework | Required? | How often |
|---|---|---|
| PCI DSS | Yes, explicitly (Requirement 11.4) | Annually, and every six months for service providers |
| FedRAMP | Yes, explicitly (CA-8(2)) | Annually or after a significant change |
| CMMC | Yes, at Level 3 (CA.L3-3.12.1E) | At least annually |
| DORA | Yes (Articles 24 to 27) | Threat-led testing every three years, basic testing annually |
| SOC 2 | Not named as mandatory, but expected in practice | Annually. Around 85 percent of Type II reports include one |
| ISO 27001 | Not mandated. Driven by your risk assessment | Annex A 8.8 and 8.29 |
One more thing worth knowing. Since independence rules forbid it, the firm auditing you cannot also run your pentest. So buying the two separately is normal and expected, and it is not a sign that anyone is upselling you.
Where your pentest is run from
You contract with Thornbury Labs wherever your engagement runs. Because work is coordinated across US and UK hours, findings get discussed the same working day rather than the next one.
Boston
Massachusetts, United States
1 Beacon StreetBoston, Massachusetts
United States
Eastern Time · US engagements
London
United Kingdom
169 PiccadillyLondon W1J 9EH
United Kingdom
Greenwich Mean Time · UK and EU engagements
Pentest questions buyers ask before booking
How much will my pentest actually cost?
Packages start at $5,900 for one asset and $14,500 for up to three. Most buyers land between $10,000 and $30,000. Send the four-question form and you get a fixed number for your own scope, usually within four working hours.
How quickly can you start?
Usually within one to two weeks, and the report follows about ten working days after testing ends. However, Q4 books out four to six weeks ahead, since compliance deadlines cluster at year end.
Is a pentest the same as a vulnerability scan?
No, and the gap is where most money gets wasted. A scan is automated and matches your systems against a database of known problems. Our pentest puts a named certified person on your system, finding the business logic flaws and chains of issues no tool can see.
Who will actually run my pentest?
A vetted independent practitioner under contract to us, holding credentials like OSCP or CREST. Although they are not our employees, we say so up front and name yours before the engagement starts. You can also decline and ask for a different practitioner.
Will the report pass a SOC 2 or PCI DSS audit?
That is what it is built for. Because scope, methodology and findings are documented the way auditors expect, you also get an attestation letter you can share with customers without exposing the findings themselves.
Can you guarantee you will find everything?
No, and walk away from anyone who says otherwise. A pentest proves what an attacker could do inside the agreed scope and time. But what we do commit to is real manual hours in your contract, a named tester, and a report that survives an auditor reading it closely.
Is there such a thing as a certified pentest?
Certifications are held by people, and accreditations by companies, so a test itself is never certified by anyone. What you should ask for instead is a tester who holds OSCP or CREST, named in writing before you sign. That is exactly what we provide.
Why is there no phone number on this site?
Because four written questions tell us more about your scope than a discovery call would, and it also respects your time. Answer them and you get a fixed price and a scope back rather than a calendar link.
Book your pentest in four questions
These four answers are genuinely what anyone needs to price the work. So we can send a fixed fee and a scope without putting you through a call first.











