Pentest retest: the free 14-day pass, then a new quote
A pentest retest is one free check of the same URL within 14 days of a $2,400 one-time review. A new feature or a second app is a new quote.
A pentest retest is the second look at findings you already paid me to write down.
You fixed them. You want to know if they still open. That is the whole job.
Short answer: A pentest retest is one free pass on the same URL, inside 14 days of the first report, included in the $2,400 one-time web application security review. $1,200 starts the original review. I recheck the findings you say are fixed. A new feature, a new URL, or a second app is a new quote. There is no subscription.
HackerOne’s pentest retest docs (updated June 13, 2025) give Essential customers 30 calendar days and Premium customers 90, with unlimited retests during that window. I do not sell that program. I sell one retest, one URL, 14 days. The review price sits on pricing.
What does a pentest retest actually include?
A pentest retest checks the findings from the original report on the same application and the same target URL. I mark each one fixed, still open, or not retested. I do not hunt a feature you shipped after the report.
The table is the quote. Read it before you treat “retest” as a second full review.
| Free pentest retest | New review | |
|---|---|---|
| Price | Included in the $2,400 one-time fee | $2,400 again, $1,200 to start |
| Window | Once, within 14 days of the first report | Whenever you book |
| Target | Same application, same URL | New URL, new app, or a material new surface |
| What I open | Findings already in the report | Frontend, auth, and the APIs the UI calls |
| What you get | A short note on those findings | A new severity-ranked report |
| Not included | New routes, a second app, source review, a compliance stamp | Leftover work on the previous app |
The first PDF — severity, evidence without payloads, a remediation an engineer can ticket — matches the sample report. The retest note is shorter. It points at the original findings. It does not reprint a cookbook.
How long is the pentest retest window?
The free pentest retest ends 14 days after I send the first report, not 14 days after your last pull request merges. If the report lands on a Monday, day 14 is two Mondays later. Ask inside that window. After it closes, the same check is a new $2,400 quote.
The original 48-hour clock starts when login works. That rule is in how the 48-hour review clock starts. The retest clock starts when you have the report.
Inside those 14 days:
- You name which findings you believe are fixed.
- The URL is the one in the written scope.
- A test user can still sign in, or you send a fresh invite if you rotated access.
- You say so if a finding was accepted and will not be fixed.
A dead login on day 13 does not extend the window. Send a working user before it closes.
A 2026 pentest RFP template from Stingrai lists one retest within 60 days as a common fixed-price clause. That is a larger-firm window. It is not this offer.
Which changes make the pentest retest a new job?
Same URL, same findings, one pass: free. A new hostname, a second application, a feature the first report never saw, or a second retest after the free one: a new quote at $2,400.
The path is short:
Trigger. You write that specific findings are fixed, and the date is still inside 14 days.
Action. I sign in with the same roles and reopen only those findings.
System of record. A short retest note on the original report: fixed, still open, or skipped because you accepted the risk.
Human escalation. If the route is new, the host changed, or you want the whole app walked again, I stop and send a new quote. I do not widen the free pass in silence.
Lines I actually use:
- You patched the findings and deployed them to the same production URL. That is the retest.
- You patched them on staging, and the scoped URL was production. That is a different host. I retest the URL in the scope, not both.
- You shipped a billing page the first report never opened. That page is a new engagement, even on the same domain.
- You have a second product, or you want the repository read. Two apps, and source review, are separate quotes. The retest stays on the running app.
Invoice chase and Friday numbers are a different job: One Lane is $3,500 once for one named ops lane. Booking from ChatGPT is Business MCP, not a security review. A retest does not do either.
What should you send before the pentest retest?
Send the finding list, a working login, and the same URL that was in the written scope. I do not need a meeting, a slide deck, or a scanner export. If the password changed, send the new one before day 14 or I cannot run the pass.
Use this list:
- Written confirmation you still authorize the same target.
- Finding titles from the report, marked fixed or accepted.
- The URL, unchanged.
- A test user that can reach those screens. A second role only if the original finding needed it.
- Anything you rotated: password, guest invite, IP allowlist.
- The deploy time, so I am not checking Friday’s build against Thursday’s note.
I put test state back the way I found it. Credentials and payloads stay out of the note.
When this isn’t the right move yet
Skip the pentest retest if nothing is fixed yet, if day 14 has already passed, or if you want a new page or a second app tested. Those are a new review at $2,400, not a free extra on the first PDF.
Do not start the original review yet if you cannot name the URL, cannot create a test user, or cannot authorize the work in writing. The $1,200 start does not replace access. It is on the review page. The first report’s clock still waits until login works.
Do not buy this if you need a SOC 2 letter, a CREST badge, or a PCI QSA stamp. I do not sell those. I do not hold offensive-security certifications, and a 14-day retest is not an audit letter.
Do not treat the pass as a retainer. One retest is included. A later look is a new $2,400. A monthly scanner is a subscription from someone else.
If the app is still a prototype with no real accounts, wait. A retest of an empty login is a note that says the login is empty.
What does the retest note tell your engineer?
The note tells your engineer which original findings are closed and which still reproduce on the same URL. It is not a new discovery report, and it is not a certificate you can hand an auditor.
Hand engineering the original PDF plus those lines. If something is still open, the first remediation still stands.
If you want the format before you pay, ask for the redacted sample on the sample request form. Start when the URL and a user exist.
Pay $1,200 to start on the security review page, or ask for the sample first. I reply with scope and what access I need. The free pentest retest exists only after that report is already in your hands.
FAQ
What is included in a pentest retest? +
One pass on the same application and target URL, within 14 days of the first report. I mark findings you say you fixed as fixed, still open, or skipped. It is included in the $2,400 one-time review. A second app, a new URL, or a feature the first report never saw is a new $2,400 quote.
How much does it cost if I only want the retest? +
The retest is not sold alone. The review is $2,400 per application, $1,200 to start and $1,200 when the report is delivered. The one free retest is part of that price. If the 14 days have passed, or you want another pass, that is a new $2,400, not a discount add-on.
Does the retest cover a new page we shipped? +
No. The free pass reopens findings already in the report, on the same URL. A page, role, or hostname that was not in the original scope is a new engagement. Tell me before I log in so I do not treat a new surface as a free extra.
Will the retest note include exploit steps? +
No. The note names the original finding, whether it still reproduces, and the same remediation language as the first PDF. No payloads, no credentials, and no client names. Ask for the redacted sample before you send access if you want that format first.