Guide
Manual penetration testing, measured in hours you can see
Manual penetration testing means a named person spends real hours trying to break your system. So the number that matters in any quote is how many of those hours you are buying.
- Fixed fee before we start
- Named tester in writing
- Retest and attestation letter
What manual penetration testing finds
Tools match known patterns. However, the serious findings in modern apps are usually logic flaws, so they need a person who understands what the app is meant to do.
- One customer reading another customer's data
- A user giving themselves admin rights
- A payment or discount step that can be skipped
- Several small issues chained into one serious one
Manual penetration testing hours by package
We put the hours in the contract, because that line explains most of the gap between two quotes.
| Package | Manual hours | From |
|---|---|---|
| Essential | 15 or more, so one asset is covered properly. | $5,900. |
| Standard | 45 or more, across up to three assets. | $14,500. |
| Advanced | 90 or more, because full scope needs depth. | $29,000. |
Is your quote really manual penetration testing?
Tick each item the proposal states clearly. Fewer ticks usually means more automation.
Your result appears here as you tick, so you can see what is still open.
How to check a quote for manual penetration testing
Ask how many hours are hands-on. Also ask who will test and what they hold. If a firm cannot answer both in one line, you are probably buying a scan at test prices. As a rough guide, a $6,000 test is about 15 hours, while a $20,000 one is about 60.
Where tools still help in manual penetration testing
Testers do use tools, because they speed up discovery. But the tool output is a starting point, not the finding. Each finding in our report is reproduced by hand, so false alarms are removed before you see them.
What the method looks like
Work follows the OWASP Web Security Testing Guide and NIST SP 800-115. So your auditor can see which areas were covered, and in what order.
Manual penetration testing questions
Is manual penetration testing slower than automated testing?
Yes, but that is the point. Hands-on work usually runs three to ten days, because a person checks what a tool cannot.
Do testers use any tools?
Yes, for discovery. However, every reported finding is confirmed by hand.
How many hours do we need?
It depends on scope. One asset usually needs at least 15, so three assets need more.
Can we see the hours in the contract?
Yes. Every package states the manual hours in writing.
Related guides
Get manual penetration testing with hours in writing
Send your scope and we reply with a fixed fee that states the manual hours, so you can compare quotes like for like.
Get my fixed-fee quote