Hosts and network segments in scope
More hosts and more segments mean more manual enumeration time and more lateral movement paths to test. This is usually the single biggest cost driver, and the one clients underestimate least often.
Internal penetration testing is priced by scope, not by a flat day rate, which is why two companies of similar size can receive very different quotes for what looks like the same test on paper.
The ranges below are drawn from general industry pricing patterns for internal network engagements. They are not confirmed quotes from any vendor in our UAE ranking, and no vendor listed there publishes fixed prices. Use these figures to sanity-check a proposal, not to replace one — request a scoped quote for an exact number.
Six variables account for most of the spread between quotes. Ask every vendor to state where your environment sits on each one before comparing totals.
Hosts and network segments in scope
More hosts and more segments mean more manual enumeration time and more lateral movement paths to test. This is usually the single biggest cost driver, and the one clients underestimate least often.
Active Directory complexity
A flat single-domain environment with a handful of Group Policy Objects takes far less time to enumerate and attack than a multi-domain forest with complex trusts, extensive delegation and Active Directory Certificate Services in play. AD complexity is the most common source of quote surprises.
Assumed starting position
A test starting from an assumed compromised workstation with standard domain user credentials costs less than one that also includes a physical or on-site access component, or a separate rogue-employee insider track. Each of those is a distinct testing phase.
Depth of attack-chain validation
Documenting a full narrative chain toward Domain Admin with evidence at each stage takes more manual time than delivering a findings list scored by CVSS. A cheaper quote sometimes reflects a shallower methodology rather than better value.
Detection validation requirements
If you want the vendor to record whether your EDR, SIEM or identity monitoring detected the simulated attack at each stage, that coordination work adds time, and usually cost, to the engagement.
Retesting and reporting depth
A vendor including a defined retest cycle plus detailed executive and technical reporting in the base price costs more upfront than one treating retesting as a separate line item — but often less overall once remediation validation is paid for.
The table below maps organization profiles to the scope they usually imply and an estimated range. Figures are stated in US dollars because most UAE providers quote internal network engagements that way; expect an AED equivalent on the invoice.
| Organization profile | Typical scope | Estimated range |
|---|---|---|
| Small business, single office | Single AD domain, under roughly 50 hosts, one or two network segments | $3,500 – $10,000 |
| Mid-market company | Multi-segment network, moderate AD complexity, 50–300 hosts | $10,000 – $30,000 |
| Enterprise or regulated entity | Multi-domain AD forest, extensive segmentation, compliance-driven reporting requirements | $30,000 – $80,000+ |
| Complex enterprise with insider-threat and detection-validation tracks | Adds rogue-employee scenario testing and explicit EDR/SIEM detection validation | Add 15–40% on top of the base engagement estimate |
Estimated ranges reflect general industry pricing patterns for internal network engagements, not quoted UAE vendor prices. Every provider in the ranking quotes on a scoped basis.
A $6,000 quote and a $22,000 quote for “internal penetration testing” against a similarly sized network are usually not pricing the same deliverable. The gap is normally methodology depth, not margin.
Explicit Active Directory attack-path testing rather than host-level scanning only. A documented lateral movement and privilege escalation methodology. A defined retest cycle with its cost stated. A report built around an attack-chain narrative rather than a CVSS-sorted list.
Four items sit outside the base price often enough to be worth confirming in writing before you sign. Remediation consulting — the vendor helping your team fix what was found — is normally a separate engagement, because it puts the tester on the other side of the table. Retesting after remediation is sometimes included for a fixed window, sometimes billed per round; ask which, and how long the window runs. On-site attendance in the UAE carries travel and, for some providers, a per-day premium over remote testing through a deployed appliance or jump host. And out-of-hours testing, where the scope touches production systems that cannot be disturbed during business hours, is usually charged at a higher rate.
None of those exclusions makes a quote dishonest. They become a problem only when two proposals are compared as if they covered the same ground, and the cheaper one turns out to price the test alone while the other prices the test, the retest and the fix cycle together.
If two quotes still differ sharply once all four are confirmed present, the remaining variables are usually tester seniority and the number of testing days. Ask for both in writing: how many days of manual testing, and who performs them. A quote that will not state either is quoting a scan.
Our internal pentest RFP checklist on the main ranking page sets out the six requirements to put in front of every vendor before you compare numbers, including the sample-report request that most reliably separates methodologies.