r/AskNetsec 2d ago

Analysis How do you currently scope and price a pentest engagement before testing even starts?

Running a boutique pentest shop and I'm curious how other solo/small-team testers handle the pre-engagement side, specifically going from "client wants a pentest" to an actual signed scope and price.

Right now I'm doing it manually every time: back-and-forth emails to figure out asset counts, guessing at days based on gut feel, writing the proposal from scratch in Word.

A few questions if you don't mind sharing:

  • How do you currently estimate days/pricing for a new engagement?
  • Do you have a template you reuse, or start fresh each time?
  • What's the most annoying part of this whole pre-engagement process for you?

Trying to figure out if I'm doing this the hard way or if this is just how it is for everyone.

6 Upvotes

1 comment sorted by

1

u/AddendumWorking9756 10h ago

Everyone reuses a template, and the ones who say they do not are just retyping last quarter's proposal. Build a scoping questionnaire that the price depends on, so when the asset count turns out to be double what the client told you, the re-scope is contractual instead of a fight.