Ask five Malaysian security vendors what a penetration test costs and you get five ranges, none of them comparable. Published figures run from RM5,000 to over RM150,000. The ranges are not wrong, just useless on their own, because "pentest" now covers two different products sold under one name.
Since 2024, penetration testing has been a licensed activity in Malaysia. Almost no vendor leads with that, and it filters more of them than any price comparison.
How much does penetration testing cost in Malaysia?
Rough bands, from what Malaysian providers publish and what we charge for our own cybersecurity work:
| Scope | Typical range | What you get |
|---|---|---|
| Single web application | RM5,000 to RM20,000 | Manual testing of auth, roles, payment flows, APIs |
| Larger web app or API suite | RM15,000 to RM45,000 | Multiple roles, integrations, deeper exploitation |
| Full infrastructure | RM20,000 to RM80,000 | Servers, network config, cloud, mobile, compliance docs |
| Automated scan only | Under RM3,000 | A tool ran. Nobody read the output. |
Watch that last row. A scanner licence costs a vendor a few hundred ringgit a month. At RM1,500, the maths only works if a tool did everything and a template wrote the report.
What moves a penetration testing quote
Scope comes first, and it is not page count. What matters is how many user roles and permission boundaries exist, because the interesting bugs live at the boundaries.
After that, whether a human exploits or only reports. Confirming a flagged SQL injection is real, and showing what it pulls out, takes hours. Listing it takes seconds.
Retest. Many quotes exclude it. You fix everything, then pay again to prove you fixed it. Ask up front, because it changes the real cost by a third.
Box colour. Black box (no credentials) is cheaper and shallower. Grey box (a normal user login) finds far more for a modest increase, and suits almost every Malaysian SME.
Check the licence before you check the price
The Cyber Security Act 2024 came into operation on 26 August 2024. Its licensing regulations single out exactly two services as requiring a licence: managed security operations centre monitoring, and penetration testing. NACSA's own FAQ defines the second:
A penetration testing service under the Cyber Security (Licensing of Cyber Security Service Provider) Regulations 2024 [P.U. (A) 221/2024] is a service for assessing, testing or evaluating the level of cyber security of a computer or computer system, by searching for vulnerabilities on, and compromising, the cyber security defences of the computer or computer system.
Source: FAQ, Licensing of Cyber Security Service Provider, NACSA
Applications opened on 1 October 2024. The fee is what makes this a useful buyer's filter:
The application guide on NACSA's licensing portal, captured 19 August 2026.
The licence is valid for a period of one (1) year and the payment of the non-refundable fee needs to be completed during the application.
Penetration Testing Service: Individual RM400.00, Companies RM1,000.00 (per year)
Source: Licensing Portal for Cyber Security Service Providers, NACSA
RM1,000 a year is the entire barrier. A vendor charging RM20,000 for an engagement who has not paid it is not saving you money. Under section 27(5) of the Act, providing the service unlicensed carries a fine of up to RM500,000, up to ten years in prison, or both.
Two details before you sign. A subcontractor testing on behalf of your main contractor needs their own licence, so ask who is holding the keyboard. And applicants must show NACSA proof of certifications for the assigned staff, so the licence does some of your due diligence.
NACSA publishes every holder in a searchable register on the same portal. It takes a minute to check.
Our take: the licensing regime is the most useful thing to happen to Malaysian security buyers in years, and it is badly under-used. Buyers still open three quotes and pick the middle one. The register turns a judgement call into a lookup.
When a cheap scan is the right call
We run VAPT for a living and we will still say this: plenty of Malaysian businesses do not need a full penetration test yet.
Running a WordPress site with a contact form and no customer accounts? A RM2,000 scan plus fixing what it finds is honest value. The test earns its price when something behind the login is worth stealing, or when a client, an auditor or PDPA exposure means you need evidence someone competent looked.
What you should not do is buy the scan and file it as a penetration test. The report says "no critical vulnerabilities found" either way. Our post on cloud security mistakes covers what scanners miss.
Five questions to ask before you sign
- What is your NACSA licence number?
- Is one retest included after we remediate?
- Grey box or black box, and why that one for our app?
- How many hours are manual testing, as opposed to tool time?
- Can we see a redacted sample report?
If a vendor gets defensive about question one or four, you have your answer.
Want a straight quote with scope and retest written down? WhatsApp us and tell us what you are running.
General information only, not legal or professional cybersecurity advice. Licensing requirements and fees may change, so verify with NACSA. Prices are estimates and vary by scope.
References
- Cyber Security Act 2024 (Act 854), NACSA
- FAQ, Cyber Security (Licensing of Cyber Security Service Provider) Regulations 2024, NACSA
- Licensing Portal for Cyber Security Service Providers, NACSA
- Unveiling Malaysia's Cyber Security Act 2024, Tay & Partners
- Malaysia's New Cyber Security Act 2024, Mayer Brown
- Pentest Companies in Malaysia 2026, DeepStrike
- Pentest Cost in Malaysia, Flawtrack




