What a penetration test actually is
A vulnerability scan finds weaknesses. A penetration test tries to use them, the way an attacker would, to show what could really happen: which findings can be chained together, how far an intruder could get, and what they could reach. That difference is why auditors ask for one. SOC 2, HIPAA, ISO 27001, and PCI DSS Requirement 11.4 all call for penetration testing, and a scan alone doesn't satisfy them.
Why it cost $10,000
Because a person did it. A consultant's week costs a consultant's week, plus scoping calls, a report written by hand, and a queue of other clients ahead of you. The result was thorough, but it was also a snapshot: the day after the test, every new deployment and every new vulnerability disclosure made it a little less true. And a test you can only afford once a year is a test that's out of date for eleven months of it.
What changed
The techniques a tester uses on the first day of an engagement, the reconnaissance, the exploit attempts, the chaining of findings, can now run as software. Automated penetration testing does that part on demand: you define the scope, it starts in minutes, it attempts real exploitation safely, and it reports what it could actually reach, not just what looked vulnerable. It doesn't replace a senior tester for the hardest problems, business logic flaws, and custom applications. It does put a real test within reach of every business, as often as they need it.
What it costs now
| Feature | Consultant pen test | Automated pen test (Clone Systems) | Managed pen test (Clone Systems) |
|---|---|---|---|
| Who does the work | A consulting team | Our platform, running attacker techniques | Our engineers |
| Time to start | 4 to 6 weeks, typically | Minutes | Scoped by email, scheduled within days |
| Duration | 1 to 3 weeks of testing | Results in days; 30-day window to retest | Depends on scope |
| How often you can run it | Once a year, usually | As often as you buy a window; annual programs available | Per engagement |
| Report | Written by hand | Executive summary and technical findings, with retesting | Written by our engineers, auditor-ready |
| Price | $5,000 to $20,000 per test | External from $1,995 (1 asset, 30 days); internal from $2,995 (25 hosts, 30 days) | Priced per engagement; scoping link on request |
| How to buy | Proposal and contract | Online, today | Request a quote |
Which one do you need?
- You need a pen test for an auditor or a customer questionnaire, on a deadline. Start with the automated external pen test. It produces the report most auditors accept for external testing, and you can have it this week. See the specific requirements for SOC 2, HIPAA, ISO 27001, and PCI DSS 11.4.
- You need to know what an attacker could reach from inside your network. The automated internal pen test, from $2,995 for 25 hosts.
- You have a custom web application, complex business logic, or an auditor who insists on a human. Managed penetration testing by Clone Systems engineers. Ask for the scoping link and you'll get a fixed price for your environment.
- You're not sure. Start with the automated external test. Its findings tell you whether a deeper test is worth the money.
Why Clone Systems
Clone Systems has been a PCI Approved Scanning Vendor since 2007 and runs more than 100 million vulnerability checks a day. Automated pen testing runs on the same platform as our scanning, so a scan finding can be tested for real exploitability without switching tools. Every package includes retesting after you fix things, and the optional AI Remediation Assistant explains each finding in plain language, privately, in our own data center.
See pen test packages and buy online · Request managed pen test scoping
Clone Systems is a PCI Security Standards Council Approved Scanning Vendor, listed since 2007. Consultant pricing ranges are typical market figures for a small to mid-size external engagement in 2026 and vary by scope.
