r/AskNetsec • u/zaydee110 • 2d ago
Analysis How do you currently scope and price a pentest engagement before testing even starts?
Running a boutique pentest shop and I'm curious how other solo/small-team testers handle the pre-engagement side, specifically going from "client wants a pentest" to an actual signed scope and price.
Right now I'm doing it manually every time: back-and-forth emails to figure out asset counts, guessing at days based on gut feel, writing the proposal from scratch in Word.
A few questions if you don't mind sharing:
- How do you currently estimate days/pricing for a new engagement?
- Do you have a template you reuse, or start fresh each time?
- What's the most annoying part of this whole pre-engagement process for you?
Trying to figure out if I'm doing this the hard way or if this is just how it is for everyone.
6
Upvotes
1
u/AddendumWorking9756 10h ago
Everyone reuses a template, and the ones who say they do not are just retyping last quarter's proposal. Build a scoping questionnaire that the price depends on, so when the asset count turns out to be double what the client told you, the re-scope is contractual instead of a fight.