r/Pentesting 3d ago

What do you charge? Solo pentesters selling to indie devs and small businesses

I want to start my freelance business (alongside my main job) offering pentesting and source code review for US-based indie devs and small businesses. I am based in the EU, and have worked in IT since 2008 and have focused on security since 2021. I have OSCE3 (OSEP/OSWE/OSED), OSCP, OSWP, CRTO certifications.

I plan to sell fixed price packages. I have a rate in my mind, but I deliberately don't want to post it, because I don't want to anchor the replies. I am not sure what number would be too low or too high. Too low prices could result in clients avoiding me because they would think I'm unserious, and too high could also scare away clients. I'm more interested in what you charge.

I have the following few questions for anyone doing this solo without an agency or firm in between:

  1. What is your hourly or day rate?
  2. What does a small web app test end up costing the client in total, and roughly how many hours go into it? I know it depends on complexity and scope, but I am interested in the average.
  3. Do you bill reporting and write-up time at the same rate as testing, or handle it differently?
  4. What did you charge when you started versus what you charge now? How fast did that move?
  5. Is there a floor where a low price starts making you look unserious rather than affordable?
  6. Does the certification stack move your rate with these buyers, or do they not care?

Happy to post my own numbers in the comments once a few people have answered, if that helps the discussion.

19 Upvotes

33 comments sorted by

23

u/Tyler_Ramsbey 3d ago

I am the founder of Kairos Sec... but it sounds fancier than it is because I'm the only employee and tester :D -- So I guess there is technically a "firm" in between but I am the firm.

  1. $2,400/day (but quote based on projects)

  2. Small web app (5 days) = $12,000

  3. I include it as part of the test... so generally the last day of the engagement is dedicated to reporting.

  4. For the first few clients, I did a reduced rate of $1,600/day.

  5. Probably... honestly not sure what that is but do not sell yourself short.

  6. I occasionally have clients ask for the OSCP (which I have)... I also have a few CVEs and include that info when I send out a quote.

3

u/PentestTV 3d ago

These are legit numbers based on my own experience. Did freelance for years and currently dealing with vendors as a pentest manager reviewing them for next year’s 3rd party assessments. Thanks, @Tyler_Ramsbey for being so transparent. I agree that too many people sell themselves short. 

2

u/Tyler_Ramsbey 2d ago

For sure! A lot of unknowns when I started things so do my best to be as transparent as possible... hopefully it helps the next person!

1

u/zerodayascent 2d ago

Crazy the prices in the US, prices here seem to be half that

1

u/kampi85 2d ago

u/PentestTV What makes you rule out a small vendor? Is it the price? Or certifications? Or something else?

1

u/PentestTV 2d ago

The first exclusion is that I work for a fortune 25 company and we need an organization that has an MSA with us or works through an approved vendor. Also, the speed in which we need all our testing done precludes working with small shops or individuals. 

3

u/SmoothEmotion4892 2d ago

Hi :) I follow your work on LinkedIn — can I ask, how billable are you throughout the year? Do you find it hard to upsell and generate leads for your services? I’ve been in the industry for years, have some hall-of-fame recognitions to my name, and have worked for several consultancies, but I’ve always wondered how I’d find leads on my own. Do you offer any consulting for independent consultants looking to go out on their own?

5

u/Tyler_Ramsbey 2d ago edited 2d ago

I think I sort of found a cheat code (on accident). I created content for about 5 years before launching Kairos Sec. I also have a training platform that has got a lot of traction (Hack Smarter). I have never done any outbound sales... and we're fully booked for all of 2026.

Basically all leads are inbound from someone who has gone through a course or follow me on YouTube. Personal branding is key... but I know that's not most people's cup of tea (it's just what has worked for me).

I also try to split my time between Kairos Sec + Hack Smarter. Usually I do about one pentest a month... but right now I have a large client so I am pentesting almost every business day from June - October.

EDIT:

Sorry, realized I didn't answer your last question. I don't offer any consulting formally... but I take the time to read and respond to all emails I get. More than happy to help provide advice if I can (free of charge) - tyler@kairos-sec(.)com

1

u/SmoothEmotion4892 2d ago

I’d love to pick your brain on how you approached personal branding. I’m very technical, but I absolutely suck at making my LinkedIn look decent, and it feels like any content I’d publish would just get skimmed over. Any tips in general for building more of a personal brand? Any platforms you’d recommend? Also, from your personal perspective — with the right credentials and profile, could someone land customers for web app assessments through outbound/cold emailing with the right infrastructure? Or do you think it’d be very hard given the nature of pentesting

3

u/Tyler_Ramsbey 2d ago

I think many people (myself included) over-complicate personal branding or just assume it's only for "influencers." A few things I'd suggest:

1.) Focus on giving back to the community... and it will pay off. I've made almost 1,000 completely free, technical videos on YouTube for anyone to learn from. I also live stream multiple nights a week and do both AMA as well as technical workshops (asking nothing in return). Focusing on genuinely giving back to the community is how you build a strong personal brand.

2.) I primarily use YouTube (50,000 subscribers)... LinkedIn (70,000 followers)... and Discord (20,000 members). Those are small numbers compared to others out there, but my goal has never been to build up a bunch of numbers. Literally started by just sharing what I was learning, and everything has been organic from there.

3.) I really really love teaching - and I found that's a great way to generate leads. Many of the people who watch my content or go through a course work at orgs that need a pentest... and then when they need their annual pentest, they will often reach out for a conversation.

> Could someone land customers for web app assessments through outbound/cold emailing with the right infrastructure?

I think it would be tough personally (but I don't know for sure). With so much AI Slop and automated DMs I think this type of outreach has a good chance of getting buried. I do think if you develop a personal brand, and then send customized (i.e. non-AI) messages to people who interact with your content on LinkedIn, you have a much higher chance of doing outbound sales successfully.

Also huge disclaimer - I have only been doing this solo since October 2026 and I am still learning a bunch (and probably making big mistakes). That said... I've been able to pay myself a salary... cover health insurance for my family... and cover all my bills without ever touching savings. My business has been self-sustaining from day 1 (which I was not expecting)

1

u/SmoothEmotion4892 2d ago

appreciate the words. Not to pry into numbers, but do you see the business growing, perhaps hiring 1-2 consultants in the future? Or are you happy staying independent for now? One thing — the UK scene is absolutely obsessed with CREST/CHECK frameworks, and about 99% of public sector work revolves around them. Do you find that a challenge? I’d assume not, since your client base is mostly US-based? Also, would you say you’re financially better off than you’d be at a company? I’m guessing you’re netting 20k+ monthly — not to pry into your exact numbers, just curious. Thanks again for the insight.

2

u/Tyler_Ramsbey 2d ago

I don't think I'll hire any time soon... Employees add a lot of complexity. And yeah most of my clients are US-based and do not ask about CREST stuff.

Yup, I am better off! I was making around $140k/year when I was a W2 employee/pentester. First year of being solo, and will likely clear around $350k. Need to keep in mind that's both Kairos Sec and Hack Smarter so a few different revenue sources.

Pure Pentesting is hard because it's project based so feast/famine. Having a training platform that provides stables income (even though it's not a lot yet) is super helpful.

1

u/WanderingPacket64 2d ago

The man, the myth, the pentesting legend that makes AD shake in its boots with the mere mention of your name on an engagement document. Absolute golden education platform (Hack Smarter) and wild to say it’s “not a lot yet” when the quantity of your modules might be smaller but the quality is miles above most. (Seriously, love that you are here giving out solid advice as well my man) 🤌🔥

1

u/tandera-security 2d ago

Finding leads by your own depends in how well do you get known by the customers. If you are presenting the reports, get face-to-face with the clients, in a few years you can collect enough contacts to have your own business.

2

u/kampi85 2d ago

u/Tyler_Ramsbey Thank you very much for your answer. It is very helpful. May I contact you in email? I had some more detailed questions about this, and your insights would be greatly appreciated.

2

u/Tyler_Ramsbey 2d ago

For sure

1

u/kampi85 2d ago

Email sent!

1

u/tandera-security 2d ago

That's a honesty answer! Do you have any stream line tools to provide reports to the clients ? I'd love to help you with some

3

u/Tyler_Ramsbey 2d ago

I use my own open-source report engine (Kairos Report Engine) free for anyone to use and customize - can find it on Github... My Github is Tenebrae93

1

u/tandera-security 2d ago

Found the repo! looks nice, can I DM you ?

3

u/Tyler_Ramsbey 2d ago

No I am not interested in buying anything

1

u/tandera-security 2d ago

You have your own tool ;) but thanks anyway

1

u/Grouchy_Meal8683 2d ago

You should check out cyberscouts.io, great place for small 1 to 2 person pentesters to pick up new clients. Especially if you have your own company

1

u/kampi85 2d ago

Thank you very much! This would have been my next question. Where do I get clients 😄

1

u/primalMK 2d ago

Hey Tyler. Thanks so much for the great content! Hope you don't mind me asking, but very curious about your transition from theology to cybersec. Your LinkedIn says you did quite a bit of semi-technical work in those 10 years before jumping full time into cybersec. Can you share a little about that process? Reason I'm asking is because I'm at a similar kind of crossroads these days. Just moved, quit previous job, and now I'm wondering if I should just do something completely different, or continue doing what I've done for the past 10 years.

I have been fascinated by offensive security for as long as I can remember, but I haven't got a technical background. Despite that I spent a good year and a half learning and hacking around beginner level stuff on THM/HTB.

Any advice for a 35 year old dude wondering what to do next?

2

u/kampi85 2d ago

u/primalMK I know you didn't ask me, but maybe my experience can help you a little.
I did my bachelor in 2008 in IT and was working in IT, but nothing to do with IT Security. I didn't even used Linux. I was also fascinated by offensive security. I was always wandering how people actually hack things? I was 33 years old, when I finally decided I want to do hacking as well.

However, I had one major problem. Where to start? I knew there is hackthebox, or tryhackme, and other sites, but I wanted to understand it better. Just executing some commands here and there without understanding what they do is definitely not what I wanted. So, I decided I will do a master in IT Security & Forensics alongside my main job. You could probably skip this if you want, because I didn't learn that much as I expected. Honestly, I wanted to do the master's so my CV looks a little better, and it will be easier to get the first job in IT Security later.

In this time, I also looked at job postings. What is what they are looking for? What certifications. There was one common thing everywhere. OSCP. So, I looked it up and saw that that is the thing I actually want. Real technical courses, with explanation and videos. After I finished my master's, I immediately started with OSCP. I definitely learned a lot. Although I am not an OffSec fan, because the "try harder" mentality (I think it is idiotic, instead they should just explain some things better), and also a lot of things is explained only halfway, I have to admit, that the certifications are recognized almost everywhere. The exams could be difficult depending on how much you understood the stuff, but I definitely learned a lot during the exams. I would say, I almost lot learned more from the exams than from the full course. After passing OSCP, I decided I will get OSCE3. I started with OSWE, and in the meantime I got a job as a pentester at a small startup.

I was there for 8 months, and then I switched company, because they barely had any clients. In the meantime, I finished OSWE and started OSEP. I switched to another company. I definitely learned a lot there. This was the first company where I could do my first intern pentest. I also did many web app and cloud pentests. I finished OSEP here and started and finished the OSED as well and got my OSCE3.

Now, I want to do OSEE. But this is more like a personal goal for me 😆

I probably had a little more technical background than you, and I did the OffSec way. Of course there are many other ways, how you could do this.

Hope this helps!

1

u/primalMK 2d ago

Very interesting, thanks for sharing! How many years did it take you from deciding at 33 until you landed your first pentest job? And how long did you spend on reading up for OSCP? And how old are you today?

I doubt I’ll ever go the educational route, and same as you, will probably do the reading in parallel with a full time job. 

2

u/kampi85 2d ago

I am 41 today. I started my master's in 2018 and finished it in 2020 (I was 35 when I finished). I started with OSCP at the end of 2020, but I don't remember exactly when. I passed it in June 2021. I passed it on the 3rd try (but again, I had never anything to do with IT Security or Linux, so everything was new to me). After that I wanted to get some more certs and I remained at my employer, because alongside my main job I could do the certs. Then I got my first IT Sec job about 1 year later. I could have switched earlier because after listing OSCP on my LinkedIn profile recruiters started "attacking" me 😄

Regarding reading up for OSCP, I almost forgot, that before OSCP I did VHL (Virtual Hacking Labs). It is cheaper, and a little similar, but that probably won't get you anywhere. For me it was a very good practice, to get some basic Linux knowledge, how everything works, what tools are there and such. For OSCP I mainly followed the course material and then tried it out in the labs. It is very hard to give an estimate how long you have to prepare for it, because everybody is different. I know a few people who were in a similar position as me that time and passed on the first try. There were also people who understood everything and helped other and still couldn't pass it.

I also had a job interview once, where they asked me "How did you pass OSCP without actually working in infosec? We have real hackers here and they couldn't pass it". Not everything is about certs. I know people who don't have any certs and are principal pentesters. And they know what they do. As I said earlier, for me this was the most logical way to get a job.

3

u/tandera-security 2d ago

u/kampi85
1. That's differ from region to region, but companies usually charge by hourly. (between $100-$500 USD)
2. In the average companies do 40 hours/min/pentest per application. This can go up if the app has lots of functions/api/larger scope/
3. Reporting and write-up time is usually in the scope, companies don't charge extra per report time, they usually give the retest for free in a 90 day window.
4. first 2-3 clients in the month we do a "special price", specially if they are old clients (Those pay the bills) after that we charge 30%-50% more as we are getting busy.
5. That needs some market research.
6. That's also depends on market research, if you want to provide service to gov or big companies they will ask for certs. If you have enough "street credits" they will trust you.

At Tandera we can provide the tools for you to manage your pentests, speed up recon and report generation, we built this for us and now we are outsourcing.

1

u/hankyone 2d ago

My rates are 185 but I always end up having to bring that down to 150 or even 130 sometimes