How much does a pentest cost in Spain? 2026 pricing guide
By the QuantumSec team
One of the first questions we get at QuantumSec is: how much does a pentest cost? The honest answer is that it depends —on the scope, the type of system and the depth you need. This guide breaks down the real price ranges in Spain for each type of pentest, what a quote should always include and how to spot proposals that, at best, won't add any value.
Why does the price of a pentest vary so much?
A pentest isn't an off-the-shelf product. It's a highly technical, tailored service that depends on multiple factors: the number of assets to analyze (applications, endpoints, servers, IP ranges), the type of environment (web, internal network, cloud, mobile), the depth of the analysis (black, grey or white box), the estimated execution time and the experience level of the team running it.
A web pentest for an application with 10 endpoints costs very differently from a full network infrastructure audit of a 500-employee company. Asking for a price without a defined scope is like asking the price of a building project without blueprints.
Price ranges by pentest type in Spain (2026)
These are indicative ranges in the Spanish market for medium-sized projects:
- Web pentest (application or e-commerce): €2,500 – €8,000
- API pentest (REST/GraphQL): €2,000 – €6,000
- Mobile app pentest (iOS or Android): €3,000 – €7,000
- Internal / perimeter network pentest: €4,000 – €12,000
- Active Directory pentest: €4,000 – €10,000
- Cloud pentest (AWS, Azure, GCP): €5,000 – €15,000
- IoT pentest: €3,500 – €10,000
- Phishing simulation (campaigns + report): €1,500 – €4,000
These ranges assume a standard scope for a mid-sized company. Projects with a larger attack surface or high confidentiality requirements can exceed these figures. Cost also varies depending on whether a re-test after fixes is requested (usually included or at a reduced rate).
What should a pentest quote always include?
Regardless of the provider, a serious quote should include:
- Detailed scope: exactly which systems are tested, with clear boundaries.
- Methodology: reference to standards like OWASP, PTES, OSSTMM or MITRE ATT&CK.
- Box type: black (no prior info), grey (with user credentials) or white (full access to code and architecture).
- Technical report: description of vulnerabilities found, evidence, CVSS, reproduction steps.
- Executive report: a non-technical summary for management.
- Closing meeting: presentation of findings and remediation roadmap.
- Post-delivery support: a period in which you can ask questions about remediation.
A quote that only mentions a security test without specifying scope or methodology is a red flag.
Red flags in a pentest offer
The market is noisy. These are the signs that should make you wary of a proposal:
⚠ Price below €500: a pentest at that price is really an automated scan. Automated tools don't find broken business logic, complex access control issues or vulnerabilities in authentication flows.
⚠ No defined scope: a serious provider will never quote without understanding what needs to be tested.
⚠ No team certifications: OSCP, CRTO, BSCP, eWPTX and other offensive certifications signal that the pentesters have real experience. If they don't mention them, ask directly.
⚠ No sample report: asking to see an anonymized report from a previous project is reasonable. If the answer is a flat no, be wary.
⚠ No re-test or support: a pentest with no follow-up to verify the fixes has very limited value.
Pentest vs vulnerability assessment: the price difference
A vulnerability assessment (VA) is cheaper because it's mostly automated: scanners are run, the results processed and a report of known vulnerabilities delivered. The cost usually ranges between €800 and €3,000.
A pentest goes further: the analyst actively exploits the vulnerabilities, chains findings to escalate privileges, simulates a real attacker's techniques and documents the real —not just potential— impact. That's why it's more expensive and why it adds far more value as evidence of real security.
The rule of thumb: if you need to prove to your client, an auditor or your board that a system is secure, you need a pentest. If you want a quick view of exposure to prioritize patches, a VA can be the first step.
FAQ
Is the cheapest pentest always a bad choice?
Not necessarily, but you should understand what you're buying. A cheaper project can be perfectly valid if the scope is limited and well defined. The problem is when a low price hides superficial work sold as a complete pentest. Always compare scope, methodology and team credentials, not just the number.
How much does a web pentest cost in Spain?
For a standard-sized web application (10-30 endpoints, user authentication and an admin panel), the usual range in Spain is between €2,500 and €6,000. If the application is complex (extensive business logic, multiple roles, third-party integrations), the cost can exceed €8,000.
How often should I run a pentest?
At a minimum, once a year. You should also run a pentest whenever you make significant changes to your application, when you need to comply with NIS2, DORA or ISO 27001, or before launching a new product.
Can I pay for the pentest in stages?
Yes. Many providers offer payment in two parts: a percentage on signing the contract and the rest on delivery of the report. On large projects, it's also possible to agree separate phases (e.g., web phase first, network phase later), which spreads the cost across the fiscal year.