External Penetration Testing
Your internet-facing perimeter, tested the way a real attacker sees it — no prior access, no inside knowledge. Exposed services, VPNs, mail systems, and cloud edges probed and exploited by hand. Manual testing by OSCP-certified professionals, $985 per tester-day (US) · €849/day (EU), delivered in 7 days.
What an external pentest covers
- Attack-surface discovery — every host, service, and subdomain exposed to the internet
- Exposed service exploitation — web servers, VPNs, RDP, mail, and misconfigured cloud edges
- Authentication attacks — credential stuffing, default credentials, weak MFA on public logins
- Known-vulnerability exploitation — verified, not just flagged from a version banner
- Information leakage — data exposed through misconfigured storage, headers, or error pages
- Perimeter breach demonstration — a proven path in, with evidence, not a theoretical list
Pair external testing with an internal penetration test for full coverage, or run both continuously with penetration testing as a service. New to pentesting? Start with our complete guide.
External Penetration Testing FAQ
What is external penetration testing?
External penetration testing assesses your internet-facing attack surface — the servers, services, applications, VPNs, mail systems, and cloud edges an outside attacker can reach without any prior access. The tester takes the position of an anonymous attacker on the internet and attempts to find and exploit a way in.
How much does an external penetration test cost?
External penetration tests are priced per tester-day: $985 per tester-day for US clients, €849 per day in the EU. A typical external test runs 2–4 tester-days depending on the number of live hosts and exposed services, so most engagements land between $2,000 and $4,000 — including the report and one free retest. Third-party guides commonly quote $4,000–$20,000; our published rate is on our Pentest Price Index.
What is the difference between external and internal penetration testing?
External testing looks at your perimeter from the outside, as an anonymous internet attacker. Internal testing assumes that perimeter is already breached and tests what an attacker can do from inside. External answers 'can they get in?'; internal answers 'once in, how far can they get?'. Most programs run both.
How often should I run an external penetration test?
At least annually for most compliance regimes (SOC 2, ISO 27001, PCI DSS), and after any significant change to your internet-facing infrastructure — new services, major releases, migrations, or acquisitions. Because your external surface changes constantly, many teams move to a per-release or quarterly cadence via penetration testing as a service.
Does external penetration testing satisfy compliance requirements?
Yes — external testing is a baseline expectation for SOC 2, ISO 27001, PCI DSS, and NIS2. Every engagement is manual, performed by OSCP-certified testers, and reported with exploitation evidence, tester identity, and methodology mapping — the format auditors accept.