How much does penetration testing cost in Rwanda?

On this page

Cost is one of the first questions every organisation asks about penetration testing, and one of the hardest to get a straight answer to. Most security firms in Rwanda and across East Africa do not publish prices, and for good reason: every engagement is different.

This guide explains what drives penetration testing costs, what you should expect from a professional assessment and how to evaluate proposals on substance rather than price alone. For a complete overview of penetration testing in Rwanda, including scope, methodology and the requirements of the National Bank of Rwanda (BNR), see our full penetration testing guide.

What determines the cost?

A penetration test is skilled people simulating real attacks on your systems, so its price follows the effort involved. Several factors shape that effort:

FactorImpact on costWhy it matters
ScopeHighA single web app is far less effort than a full assessment covering web, mobile, APIs, USSD and internal infrastructure. More assets in scope means more testing time.
Application complexityHighA core banking platform with hundreds of endpoints, multiple user roles and transaction processing takes significantly longer to test than a brochure website.
Testing methodologyMediumBlack box (no credentials) requires more reconnaissance than grey box (credentials provided). Most engagements use grey box for the best balance of realism and coverage.
Tester expertiseHighExperienced offensive-security testers who have worked across financial institutions deliver substantially deeper findings than junior analysts running automated tools.
Compliance mappingMediumMapping findings to BNR regulations, PCI DSS or ISO 27001 requires additional analysis and structured reporting beyond a standard technical report.
DeliverablesMediumExecutive summaries, remediation workshops, board-ready presentations and re-testing all add to the engagement's scope and value.

What should a professional pentest include?

Regardless of scope, a legitimate penetration test from a qualified provider should always include:

  • Manual testing led by a credentialled practitioner: tools such as Nessus and Burp Suite are where testing starts, and the value lies in what a skilled tester does beyond their output.
  • Recognised methodology: OWASP Web Security Testing Guide, PTES, OSSTMM or NIST SP 800-115. If the provider cannot name their methodology, that is a red flag.
  • Executive summary: a non-technical overview suitable for management and board reporting, with risk ratings and business impact analysis.
  • Detailed technical report: every finding documented with CVSS scoring, proof-of-concept evidence, affected assets and step-by-step remediation guidance.
  • Debrief session: a walkthrough of findings with your technical team to answer questions and prioritise remediation.
  • Re-test: after you remediate the findings, the provider should verify the fixes are effective. Ask for at least one re-test round to be included in the engagement.

Compare what each quote buys. For a BNR-regulated financial institution, the penetration test is the evidence that shows the regulator, and your customers, that security is being managed. An automated scan repackaged as a "pentest report" will not satisfy an examiner or protect you from a real attack.

International firms vs local providers

Many Rwandan organisations turn by default to international providers from Europe, the US or South Africa for their security assessments. These firms do good work; the trade-off is overhead, in the form of flights and accommodation, higher day rates and the logistics of any on-site phase.

A Kigali-based provider with equivalent certifications and experience can deliver methodology and reporting that hold up against international firms at a substantially lower cost. The savings come from having no travel to bill, lower operating overheads and existing familiarity with the technologies common in East African financial services: USSD, mobile money platforms and local banking infrastructure.

What matters is verifying credentials. OSCP is a widely used benchmark of hands-on penetration testing skill, and BNR Regulation N° 50/2022 lists it among the qualifying certifications for testers serving regulated institutions. If a provider's testing is led by an OSCP-credentialled practitioner with demonstrated experience inside financial institutions, the work can hold up against larger firms regardless of where they are headquartered.

How to budget for security testing

If you are an IT manager or CISO building a security budget for your organisation in Rwanda, think about penetration testing in tiers:

Foundational programme

Annual web application and external network testing. For BNR-supervised institutions, this covers the annual penetration test that Regulation N° 50/2022 requires (the regulation also mandates vulnerability assessments at least twice a year) and gives you visibility into your most exposed attack surface. Suitable for smaller institutions and fintechs with a limited number of customer-facing applications.

Quarterly application testing combined with an annual full-scope assessment that includes internal network, mobile app and API testing. This gives regular visibility and catches new vulnerabilities introduced by development cycles. Suitable for mid-size banks, microfinance institutions and telecoms.

Enterprise programme

Continuous testing integrated into your development pipeline, managed vulnerability tracking, quarterly assessments across all assets and periodic red team exercises. This is the standard for large banks and organisations with complex, constantly evolving environments.

The right programme depends on your organisation's size, regulatory obligations and risk appetite. A qualified provider will help you settle the right scope on a scoping call, before you commit to anything.

Consider the alternative. IBM's Cost of a Data Breach Report 2026 puts the global average at USD 4.99 million per breach, and the financial-services average higher still, at USD 6.29 million. Regular security testing costs a fraction of what a single breach would cost your organisation in financial losses, regulatory penalties and reputational damage.

Red flags when evaluating proposals

Watch out for these warning signs when comparing penetration testing providers:

  • Extremely low pricing: if a quote looks implausibly low, ask how many days of manual testing it covers. Real penetration testing takes skilled consultants and time.
  • Pricing per vulnerability: this creates perverse incentives to inflate findings or miss them entirely. Professional engagements are scoped by time and assets, not by the number of findings.
  • No methodology referenced: ask which methodology the test follows (OWASP, PTES, OSSTMM or similar) and how it maps to your scope.
  • No sample report available: ask to see a redacted or lab-based sample so you know what the deliverable looks like before you sign.
  • No recognised certifications: OSCP, PNPT, CREST or equivalent hands-on certifications show that the tester can find and exploit vulnerabilities by hand, beyond running tools.
  • No re-test included: a fix nobody has verified is an assumption, so ask for at least one re-test round in the base price.

Getting a quote

To get an accurate quote from any provider, prepare the following information:

  • What systems need testing (web apps, APIs, mobile apps, network, USSD, cloud)
  • Number of applications and approximate number of pages or endpoints
  • Number of user roles per application
  • Whether credentials will be provided (grey box vs black box)
  • Any compliance requirements (BNR, PCI DSS, ISO 27001)
  • Preferred testing window and any blackout periods
  • Whether re-testing is required after remediation

A qualified provider will review this information, hold a scoping call and send a detailed proposal covering scope, methodology, timeline and a fixed price, typically within 48 hours of that call.

For more on what VAPT involves and how to choose a provider, read our complete penetration testing guide for Rwanda. If your main driver is BNR compliance, our BNR cybersecurity requirements guide explains what the regulator expects.

How we can help

IMIZI Cyber is a Kigali-based firm providing manual penetration testing for banks, fintechs, telecoms, government and healthcare institutions across Africa. Each engagement is priced at a fixed fee after a scoping call and paid per milestone on acceptance. Every proposal sets out scope, methodology, timeline, deliverables and one re-test round (every Critical and High finding, plus any Medium fixed by the re-test date), followed by a closure letter. Our reporting is built for BNR-aligned engagements and written to be acted on, not filed.

For details on what our engagements include, see our penetration testing service page. For broader security assessment needs, see our security assessments service page. Book a Free Call, share your scope details, and we will send a fixed-price proposal within 48 hours of the scoping call.

Frequently asked questions

How much does penetration testing cost in Rwanda?
Each engagement is priced individually, according to the number of systems, application complexity, testing methodology and compliance requirements. A Kigali-based provider with equivalent certifications has no international travel to bill, so it can deliver methodology and reporting that hold up against international firms at substantially lower cost.
What should a professional penetration test include?
A legitimate penetration test should include manual testing led by an OSCP-credentialled practitioner, a recognised methodology such as OWASP or PTES, an executive summary for management, detailed technical findings with proof-of-concept evidence, a debrief session and a re-test of Critical and High findings included in the engagement.
How do I evaluate penetration testing proposals in Rwanda?
Look for OSCP certification, a named methodology, a sample report showing evidence of manual testing, an included re-test round and a fixed-price proposal scoped to your environment. Treat extremely low pricing, per-vulnerability pricing or unrealistically short timelines as warning signs.

This article is general information, not legal advice. Check the current text of any regulation with your counsel or regulator.

Talk to us about your next test

IMIZI Cyber is a Kigali-based penetration testing firm working with banks, fintechs and regulated institutions across Africa. Our testing is led by an OSCP-credentialled practitioner. After a free scoping call, you get a fixed-price proposal within 48 hours.