Skip to content

How Much Does a Pentest Cost in Switzerland?

June 2026


A penetration test in Switzerland typically costs between CHF 3,500 and CHF 50,000. A focused external pentest for an SME starts at around CHF 3,500, while comprehensive tests of web applications or internal networks usually range between CHF 8,000 and CHF 25,000. The price depends primarily on scope: the number of systems, the complexity of the applications, and the desired testing depth.

Many Swiss SMEs hesitate to ask because they don't know what to expect. This guide creates transparency: you'll see concrete price ranges, the main cost factors, and what's included at each price point.

Pentest Prices by Scope at a Glance

The following table shows typical price ranges for the Swiss market. The exact figures always depend on the individual scope — fixed prices are only set after a short scoping clarification.

Scope Typical Price Duration
Focused external pentest (SME Basis package) from CHF 3,500 2–3 days
External pentest + web application (SME Compact package) from CHF 6,900 4–6 days
Comprehensive web & API pentest CHF 8,000 – 18,000 1–2 weeks
Internal pentest / network CHF 10,000 – 25,000 1–2 weeks
Red teaming / threat simulation CHF 25,000 – 50,000+ 3–6 weeks

Which Factors Influence the Price?

A pentest is calculated based on effort. These factors determine how many days a test takes — and thus the price:

  • Number of systems and IP addresses: The more servers, services, and publicly accessible endpoints, the larger the attack surface that must be examined.
  • Number and complexity of web applications: A simple brochure website is tested in hours; a customer portal with login, payment functionality, and role logic takes days.
  • API endpoints: Interfaces with many functions significantly increase the testing effort.
  • Testing depth (black-, grey-, or white-box): The more information and access you provide, the more thorough — and efficient — the testing can be.
  • Re-test after remediation: A re-check of the fixed vulnerabilities is often worthwhile and is planned separately.
  • Compliance requirements: If a formal revDSG statement or a specific report format is needed, some additional effort is involved.

What's Included at Each Price Point?

From CHF 3,500 (Basis): A manual external penetration test of your publicly accessible systems, including an email security check and darknet exposure check. You receive an easy-to-understand traffic-light report with prioritized recommendations.

From CHF 6,900 (Compact): Everything from the Basis package plus a pentest of your most important web application and a revDSG compliance statement you can use directly with customers, partners, or authorities.

From CHF 15,000: Comprehensive engagements — internal network pentests, multiple web applications and APIs, social engineering, or red teaming scenarios that simulate a real attacker's approach over several weeks.

When Is CHF 3,500 Enough — and When Do You Need CHF 15,000+?

A test from CHF 3,500 is the right choice if you:

  • are an SME with few externally accessible services,
  • want an initial assessment of your security posture,
  • need initial evidence of your security efforts for customers or insurers.

A budget from CHF 15,000 becomes relevant if you:

  • operate complex web applications or multiple systems,
  • want your internal network tested for lateral movement,
  • process particularly sensitive data or are under regulatory pressure,
  • need a deep analysis after a security incident.

Why Transparency Pays Off

Since 1 September 2023, the revised Data Protection Act (revDSG) has required companies to demonstrate technical protective measures for personal data. Since April 2025, operators of critical infrastructure are also subject to a reporting obligation for cyber incidents to the Federal Office for Cybersecurity (BACS). A penetration test is one of the most effective ways to demonstrate this duty of care.

We work with fixed prices and no hourly-rate risk: after a short initial call, you know exactly what your test costs and what you get for it.

Finding the Right Scope Together

Unsure which scope fits your company? In a free, 30-minute initial consultation, we clarify together which test makes sense — no technical expertise required on your side. View our SME packages with fixed prices or request a non-binding quote.

Request a Quote