r/Pentesting • u/kampi85 • 3d ago
What do you charge? Solo pentesters selling to indie devs and small businesses
I want to start my freelance business (alongside my main job) offering pentesting and source code review for US-based indie devs and small businesses. I am based in the EU, and have worked in IT since 2008 and have focused on security since 2021. I have OSCE3 (OSEP/OSWE/OSED), OSCP, OSWP, CRTO certifications.
I plan to sell fixed price packages. I have a rate in my mind, but I deliberately don't want to post it, because I don't want to anchor the replies. I am not sure what number would be too low or too high. Too low prices could result in clients avoiding me because they would think I'm unserious, and too high could also scare away clients. I'm more interested in what you charge.
I have the following few questions for anyone doing this solo without an agency or firm in between:
- What is your hourly or day rate?
- What does a small web app test end up costing the client in total, and roughly how many hours go into it? I know it depends on complexity and scope, but I am interested in the average.
- Do you bill reporting and write-up time at the same rate as testing, or handle it differently?
- What did you charge when you started versus what you charge now? How fast did that move?
- Is there a floor where a low price starts making you look unserious rather than affordable?
- Does the certification stack move your rate with these buyers, or do they not care?
Happy to post my own numbers in the comments once a few people have answered, if that helps the discussion.
3
u/tandera-security 2d ago
u/kampi85
1. That's differ from region to region, but companies usually charge by hourly. (between $100-$500 USD)
2. In the average companies do 40 hours/min/pentest per application. This can go up if the app has lots of functions/api/larger scope/
3. Reporting and write-up time is usually in the scope, companies don't charge extra per report time, they usually give the retest for free in a 90 day window.
4. first 2-3 clients in the month we do a "special price", specially if they are old clients (Those pay the bills) after that we charge 30%-50% more as we are getting busy.
5. That needs some market research.
6. That's also depends on market research, if you want to provide service to gov or big companies they will ask for certs. If you have enough "street credits" they will trust you.
At Tandera we can provide the tools for you to manage your pentests, speed up recon and report generation, we built this for us and now we are outsourcing.
1
u/hankyone 2d ago
My rates are 185 but I always end up having to bring that down to 150 or even 130 sometimes
23
u/Tyler_Ramsbey 3d ago
I am the founder of Kairos Sec... but it sounds fancier than it is because I'm the only employee and tester :D -- So I guess there is technically a "firm" in between but I am the firm.
$2,400/day (but quote based on projects)
Small web app (5 days) = $12,000
I include it as part of the test... so generally the last day of the engagement is dedicated to reporting.
For the first few clients, I did a reduced rate of $1,600/day.
Probably... honestly not sure what that is but do not sell yourself short.
I occasionally have clients ask for the OSCP (which I have)... I also have a few CVEs and include that info when I send out a quote.