Contact us: info@tenendo.com

Pricing

Flexible pricing for tailored work.

Pricing depends on the size and complexity of your infrastructure or application, the roles and components in scope, and the testing approaches we apply. Every engagement is individually scoped — no hidden costs, no templates.

Figures are indicative starting points. Final quote returned within 1–2 business days of scoping.
Vulnerability Assessment
2,800
from · per assessment
Manual validation combined with tailored fuzzing and application security scans across a single application.
Output · prioritized findings report
  • Single web app or API in scope
  • Manual scan result triage to cut false positives
  • Severity-ranked, fix-oriented findings
  • Re-test of fixed issues
Get a quote
Scales with application complexity
Most popular
Application Pentest
4,000
from · per assessment
Manual penetration test of a single application suite (e.g. a complex application with both web and mobile clients), scoped to roles and complexity.
Output · audit-grade PDF · SOC 2 / ISO 27001
  • Web + mobile + API or desktop thick clients
  • Business-logic & OWASP ASVS coverage
  • Role-based / authenticated manual objective-oriented testing
  • Fewer, more relevant findings — not noise
  • Free re-test after remediation
Scope my pentest
Scales with app complexity & scenarios tested
Continuous AppSec
Custom
retainer · tailored to releases
Ongoing testing and security code review across your release cycle, plus secure-SDLC consulting.
Output · continuous findings & reports
  • Everything in Application Pentest
  • Security code review (whitebox)
  • Re-testing on every major release
  • Secure-SDLC & DevSecOps guidance
Request a quote
Complex scoping required for pricing
External Infrastructure
2,800
from · per assessment
A penetration test of your internet-facing perimeter, covering the attack surface the attackers reach first.
Output · audit-grade PDF report
  • External attack surface mapping and enumeration
  • Data leak audit during the OSINT step
  • Exploitation of exposed services
  • Perimeter hardening recommendations
  • Re-test of fixed issues
Get a quote
Priced by the scale of the infrastructure
Most popular
Internal Infrastructure
4,500
from · per assessment
An assumed breach test of your internal infrastructure, simulating the later stages of an attack.
Output · audit-grade PDF · attack path map
  • Attack scenarios tailored to the environment
  • IAM exploitation & privilege escalation
  • Simulated post-exploitation, based on a defined objective
  • Monitoring & detection gap analysis
  • Free re-test after remediation
Scope my pentest
Scales with infrastructure scale and complexity of simulated scenarios
Cloud Security Assessment
3,000
from · or custom
Architecture review and segmentation testing across AWS, Azure, or GCP, both standalone and for PCI DSS purposes.
Output · architecture findings & roadmap
  • Security assessment of the architecture
  • Cloud segmentation & PCI DSS testing
  • Multi-cloud & hybrid coverage
Request a quote
Scales with the scenarios tested and the scale of the cloud infrastructure
Red Teaming
Custom
objective-based engagement
Full-scope attack simulation with no prior knowledge and little restrictions.
Output · executive & technical debrief
  • An advanced, realistic external attack
  • In-house tools & payloads
  • Complex social engineering and other tailored initial access vectors
  • SOC / SIEM / EDR effectiveness evaluation
  • Simulated post-exploitation and objective completion
Request a quote
Pricing scales with the size of the infrastructure and scenario complexity
DORA-aligned
TLPT & DORA
Custom
regulatory engagement
Threat-Led Penetration Testing aligned to DORA and TIBER-EU, delivered with threat intelligence and compliance reporting.
Output · regulator-ready deliverables
  • Threat intelligence-led red teaming scenarios
  • DORA & TIBER-EU methodology
  • Integrated compliance reporting
  • Partner ecosystem (e.g. TI vendors) for full-cycle delivery
  • Up to 40% saving vs. fragmented vendors
Talk to us about DORA
Pricing scales with the size of the infrastructure and scenario complexity
Purple Teaming & Readiness
Custom
collaborative engagement
Tabletop exercises, ransomware readiness, and SIEM/EDR tuning.
Output · tuned detections & playbooks
  • Tabletop exercises & role drills
  • Ransomware & incident readiness
  • SIEM / EDR effectiveness evaluation
  • Detection engineering specifically for your infrastructure
Request a quote
Pricing for TTX and consulting depend on consultants’ involvement; detection engineering pricing scales with attack scenarios covered

Also under Enterprise — audits, compliance & advisory

CISO as a ServiceStrategic security leadership on demand
ISO 27001 · NIS2 · NIST CSF 2.0Audits & technical consulting
Due DiligenceCybersecurity & ICT technical DD
TrainingSecure coding, IT ops & code review

How scoping works

From questionnaire to scheduled work in days.

01

Complete the questionnaire

Tell us about your application, infrastructure, and goals. It helps us make an offer that’s realistic, accurate, and tailored — not a template.

02

Receive a commercial offer

Once we have your questionnaire, we typically return a fixed, individually-scoped commercial offer within 1–2 business days.

03

We schedule & start

As soon as the offer is accepted, we begin planning and scheduling the work without delay — and keep you in the loop throughout.

Every engagement includes

The same standard, whatever the scope.

Audit-grade reporting

Reports accepted for SOC 2, ISO 27001, PCI DSS, and other certification needs.

Re-testing of fixes

We validate your remediation so you can prove issues are genuinely closed.

Signal, not noise

Fewer, more relevant findings — prioritized so you focus on what matters.

Defensive recommendations

Detection, monitoring, logging, and hardening guidance drawn from blue-team experience.

See the deliverable

Download an example report.

Get a full, audit-grade sample dossier — with evidence, reproduction steps, and remediation guidance — so you know exactly what lands at the end of an engagement.

Penetration Test Report
Tenendo Limited · 2026
Findings summary
Remediation roadmap

Fixed-price projects welcome

Have a specific budget and a clear security challenge? Tell us your priorities and constraints — we’ll craft the most effective solution within your budget on a fixed-price basis.

Why don’t you list one flat price?

A pentest’s cost depends on scope — number of apps, roles, hosts, cloud accounts, and testing depth. Flat pricing either overcharges small scopes or under-delivers on large ones. We scope each engagement so the quote is fair and accurate.

How fast can we start?

Once your questionnaire is in, expect a commercial offer within 1–2 business days. Scheduling begins as soon as it’s accepted.

Do you re-test after we fix issues?

Yes — re-testing of remediated findings is included, so you can demonstrate closure to auditors and stakeholders.

Are reports accepted for compliance?

Our reports are audit-grade and used for SOC 2, ISO 27001, PCI DSS, DORA, and similar frameworks.

Take control

Find out what a real attacker would find first.

Tell us your priorities and constraints. We typically return a tailored commercial offer within 1–2 business days — fixed-price projects welcome.