Home/Services/Pricing
security service

Pricing

Transparent pricing for penetration testing, protection and incident response in Europe. Fixed price from €1,800, free scoping call and free retest.

Manual, expert-ledEvidence-based findingsFree remediation retest

Straight pricing for penetration testing, protection and incident response across Europe. Every engagement is fixed-price and quoted after a free 20-minute scoping call, so the number you approve is the number you pay. A retest to confirm your fixes is always included.

Penetration testing

Project work is fixed-price, scoped by what is actually in play: how many applications or live hosts, whether testing is authenticated, and how fast you need it.

Service What’s included Timeline From
Web application pentest Authenticated + unauthenticated testing, OWASP Top 10, business logic, full report 3–8 working days from €2,500
External network pentest Every internet-facing host and service, priced by live-host count 3–6 working days from €1,800
Internal network pentest Post-breach lateral movement, Active Directory, privilege escalation 4–8 working days from €3,000
Mobile app pentest (iOS/Android) Client, back-end API, data storage, MASVS-aligned 5–8 working days from €3,000
API pentest (REST / GraphQL) Authorization, BOLA, business flows, tokens 3–6 working days from €2,500
Cloud config review + pentest AWS, Azure or GCP: IAM, storage, metadata, CIS benchmarks 4–10 working days from €3,500
Red team assessment Goal-based, multi-vector, stealthy, detection & response tested 3–6 weeks from €12,000
Social engineering / phishing Targeted simulation with awareness follow-up 1–3 weeks from €1,500

Get a fixed quote

Compliance-driven testing

When the test exists to satisfy an auditor, the scope is set by the framework and the deliverables include a formal attestation letter your assessor will accept.

Framework What it satisfies Deliverable From
PCI DSS Requirement 11.4 external + internal testing, segmentation checks Report + attestation letter from €3,000
ISO 27001 Annex A vulnerability-management control testing Report + attestation from €3,000
SOC 2 Security-criteria evidence for your Type I/II audit Auditor-ready report from €3,000
GDPR / HIPAA Article 32 / Security Rule technical measures Assessment + remediation plan from €3,000
DORA / TIBER-EU Threat-led penetration testing (TLPT) Intelligence-led red team from €15,000
NIS2 Resilience testing for essential & important entities Report + hardening roadmap scoped

Protection & monitoring

Ongoing protection is billed monthly and tiered by the number of assets. Cancel anytime; setup is one-off where it applies.

Plan What’s covered Response Price
Website firewall (WAF) Managed rules, virtual patching, OWASP CRS tuning Business hours from €120/mo (+€600 setup)
Managed protection WAF + uptime & malware monitoring + monthly review Same business day from €250/mo
Vulnerability management Recurring authenticated scans, triage, verified retest Weekly cycle from €120/mo
Email security & DMARC SPF/DKIM/DMARC to p=reject, spoofing monitoring Business hours from €120/mo
Managed SOC / MDR 24/7 detection, triage and response across your estate 24/7 scoped to assets

Talk to us about protection

Incident response & recovery

If you are compromised right now, an engineer can be on within hours. Recovery is fixed-package where the scope is clear, hourly where it is still unfolding.

Package What’s included Response time Price
Emergency incident response Containment, eradication, evidence preservation Within hours, 24/7 from €180/hr
Rapid-response package Single compromised site: contain, clean, restore, harden Same day from €900
Hacked website repair Malware & backdoor removal, blacklist cleanup, hardening Same-day start from €450
Ransomware / data-breach response Full IR, forensics, GDPR 72-hour support, recovery Engineer within hours scoped on the call
Incident response retainer Pre-agreed SLA, named team, discounted hourly 24/7 from €800/mo
Disaster recovery planning RTO/RPO, backup strategy, immutable copies, tabletop Project from €1,200

Start emergency response

Custom development

Custom web and e-commerce development is a separate practice from our security work and is always project-scoped. There is no honest day-rate to quote blind: tell us what you want built and you get a fixed project quote after a free call.

Scope my project

What every engagement includes

An executive summary for leadership and a full technical report
Every finding with a CVSS score, proof and reproduction steps
Prioritized, actionable fixes your team can implement
A free retest after you fix, with an updated report
An attestation letter for auditors, clients and regulators
Fixed price agreed up front, no hourly surprises
Work under NDA, findings handled securely
Reports mapped to PCI DSS, ISO 27001, SOC 2, GDPR, DORA and NIS2

How our pricing works

These are starting prices for typical European engagements. The final figure depends on scope: the number of applications, hosts or users, whether testing is authenticated, and your timeline. We scope in writing, quote one fixed price, and never bill hourly surprises on project work. If you commission more than one service, or move from a one-off test to ongoing protection, we discount the bundle. A short, free scoping call is all it takes to turn these ranges into an exact number.

Get a fixed quote

Pricing FAQ

Why do you show “from” prices instead of one fixed number?
Because scope drives cost. A five-page brochure site and a multi-tenant SaaS are both “web app pentests” but not the same job. The “from” price is a real starting point; you get an exact fixed quote after a short free call.
Is the retest really included?
Yes. Once you fix the findings we re-verify every one and issue an updated report and attestation letter at no extra charge.
Do you bill by the hour?
Not for project work. Pentests, audits and recovery packages are fixed-price. Only open-ended incident response and retainers use an hourly rate, agreed in advance.
Can you work to our compliance deadline?
Usually yes. Tell us the framework (PCI DSS, ISO 27001, SOC 2, DORA, NIS2) and the date, and we align scope, deliverables and the attestation to it.
Do you discount multiple services?
Yes. Bundling a pentest with ongoing protection, or testing several applications together, brings the per-item price down. We set it out clearly in the quote.
How fast can I get a quote?
A scoping call takes about 20 minutes, and you usually have a written fixed quote within one business day.
How do you price a pentest, per app or per scope?
By scope. We count the applications, roles, APIs, and live hosts in play and whether testing is authenticated, then quote one fixed price for the whole engagement.
What do I actually get for the price?
An executive summary, a technical report with CVSS and reproduction steps for every finding, prioritized fixes, a free retest, and an attestation letter. Everything you need to fix the issues and prove it to a third party.
Not sure which you need?

Tell us what you are protecting and we will point you to the right engagement and a fixed price on a free call.

why safetybis

Security you can prove

The same standard on every engagement, big or small.

Evidence, not opinions

Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".

Humans over scanners

Certified engineers find the logic flaws and chained attacks automated tools walk straight past.

Fixed price, free retest

You know the cost up front, and verifying the fix is part of the deal — not a second invoice.

500+
assessments delivered
<30min
incident first response
12k+
infections removed
98%
fixed within one retest
$ safetybis quote --service "Pricing"

Ready to lock this down?

Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.

get in touch

Tell us what you're running

Scoping is free. We reply within one business day, and under 30 minutes for active incidents.