Pentest Cost by SaaS Size in Brazil: 2026 Benchmarks by MRR
What B2B SaaS companies in Brazil pay for a pentest in 2026, by MRR (R$ 10k to R$ 1M): real price ranges, scope, ROI and when to hire.
Security researcher and founder of No Vuln

The most common question a SaaS CTO asks when they start thinking about a pentest is: “How much will I pay?” The honest answer depends on the size of the product, and most generic comparisons hide that. Here are the real ranges for Brazilian B2B SaaS in 2026, broken down by MRR (Monthly Recurring Revenue), with the scope, coverage and expected ROI for each size. All figures are Brazilian market prices, in reais (R$) — useful if you run a SaaS in Brazil or are benchmarking Brazilian providers.
Executive summary
| Size (MRR) | One-off pentest range | Typical scope | Ideal frequency |
|---|---|---|---|
| Pre-revenue / MVP | R$ 3,000 to R$ 6,000 | Web + basic API, black box | Once, before launch |
| R$ 10k–R$ 50k MRR | R$ 6,000 to R$ 12,000 | + Multi-tenant + full auth | Annual |
| R$ 50k–R$ 200k MRR | R$ 12,000 to R$ 18,000 | + SSO + OAuth + webhooks | Annual + one focused test per quarter |
| R$ 200k–R$ 500k MRR (pre-SOC 2) | R$ 18,000 to R$ 30,000 | + SOC 2 + integrations + billing | Every six months + ongoing |
| R$ 500k–R$ 1M+ MRR (Series A+) | R$ 30,000 to R$ 60,000 | Full white box + mobile + cloud | Sprint-aligned ongoing testing |
These ranges are what the Brazilian market charges Brazilian SaaS companies. If your SaaS is based outside Brazil and you're talking to No Vuln, pricing is in USD, by hour package: Sprint (25h), US$ 3,750 to US$ 6,250, for smaller scopes; Deep Dive (50h), US$ 7,500 to US$ 12,500, for mid-sized ones; and Full Scope (100h+), from US$ 15,000, for large ones. The hourly rate ranges from US$ 150 to US$ 250 depending on stack, testing mode and timeline — larger packages have a lower hourly rate. Invoiced in USD via Wise or international wire transfer: 50% at kickoff, 50% on delivery.
Why MRR is the right metric for pricing a pentest
It's not revenue. It's not headcount. It's not customer count. It's MRR — because MRR is a direct proxy for attack surface, technical debt and breach impact.
- Attack surface grows with MRR — more customers = more features sold = more endpoints, more integrations, more webhooks
- Breach impact grows with MRR — a breach that would cost 5 contracts at a R$ 50k MRR SaaS can cost 80 contracts at a R$ 500k MRR SaaS
- Ability to pay grows with MRR — a pentest is a function of what's at stake, and of what fits the budget
Pre-revenue / MVP — R$ 3,000 to R$ 6,000
Stage: product still being validated, first 5–20 customers, possibly no formal recurring subscription yet. You don't have the budget for an enterprise pentest, and you don't need one.
What to cover at this stage:
- Web + API black box, up to 50 endpoints
- Auth (login, recovery, session)
- OWASP Top 10 (web)
- Basic multi-tenant isolation (if it's a multi-customer SaaS)
What you DON'T need to cover: SSO, OAuth as a provider, threat modeling, white box, mobile.
Expected ROI: avoiding an embarrassing breach at the stage when every customer is critical and you have no legal team to contain the damage. A BOLA found here is worth more than the cost of the pentest, period.
R$ 10k–R$ 50k MRR — R$ 6,000 to R$ 12,000
Stage: SaaS in production, an active customer base, possibly already facing your first security questionnaire from an enterprise prospect (and stuck on a question or two).
What to cover at this stage:
- Everything from the MVP tier, plus:
- Full multi-tenant coverage — cross-tenant BOLA on every endpoint
- Auth matrix — roles × endpoints × verbs
- Webhooks (inbound and outbound)
- Storage (S3/GCS bucket isolation)
- Payment flow analysis (if applicable)
A clear sign it's time: your first enterprise prospect asked for a pentest report and you don't have one.
Expected ROI: unblocking sales. A stalled deal worth R$ 5k in MRR pays for the pentest in 2 months.
R$ 50k–R$ 200k MRR — R$ 12,000 to R$ 18,000
Stage: mature product, an engineering team of 5–15, active third-party integrations (Stripe, Slack, Salesforce). You're probably already thinking about SOC 2.
What to cover at this stage:
- Everything from the previous tier, plus:
- SSO (SAML XSW, OIDC) — practically mandatory to close enterprise deals
- OAuth as a provider (if you have a public API for integrators)
- Billing — Stripe webhook signatures, race conditions on upgrade/downgrade
- Outbound integrations — confused deputy when you're the OAuth client
- Mobile (if applicable) — cert pinning, deep link hijacking
Ideal frequency: 1 full annual pentest + 1 focused pentest per quarter (reduced scope, on new features). Total: ~R$ 20k/year.
Expected ROI: the ability to close enterprise deals and prepare for SOC 2 without constant firefighting. One R$ 30k MRR deal pays for it.
R$ 200k–R$ 500k MRR (pre-SOC 2 / ISO 27001) — R$ 18,000 to R$ 30,000
Stage: SaaS at scale, a team of 15–40, possibly preparing for SOC 2 Type I or Type II or ISO 27001:2022. The auditor is asking for formal pentest evidence.
What to cover at this stage:
- Partial white box — code access for sensitive areas
- Collaborative threat modeling
- Full OAuth/OIDC/SAML/SCIM coverage
- Cloud (AWS/GCP/Azure) — IAM misconfigurations, S3, metadata SSRF
- CI/CD pipeline — secret leaks, build poisoning
- A report formatted for the SOC 2 / ISO 27001 auditor
Ideal frequency: 1 in-depth pentest every six months + sprint-aligned ongoing testing (PTaaS, on request).
Expected ROI: passing the SOC 2 or ISO audit. Without formal evidence, certification doesn't go through — and every month of delay is a month of lost enterprise opportunity.
R$ 500k–R$ 1M+ MRR (Series A+) — R$ 30,000 to R$ 60,000
Stage: established SaaS, possibly with a Series A raised, a team of 40+, Fortune 500 or large Brazilian enterprise customers. At this point, pentesting isn't an event — it's a process.
What to cover at this stage:
- Full white box — code + infra + pipeline
- Mobile — iOS + Android, including any custom SDK
- In-depth cloud — Kubernetes, service mesh, IRSA, Workload Identity
- Enterprise integrations — SAP, Workday, custom Salesforce
- Reports tailored to each auditor (SOC 2 Type II, ISO 27001, the LGPD — Brazil's data protection law — and industry rules)
- A presentation to the C-suite and/or board
Ideal frequency: sprint-aligned ongoing testing (PTaaS, on request), with an annual in-depth pentest of ~R$ 40k.
Expected ROI: lower cost for each audit cycle, continuous approval from enterprise customers (who audit you every year) and support with security questionnaire responses.
3 signs you're paying the wrong price for a pentest
- You paid less than R$ 3k for a production SaaS — it was probably an automated scanner sold as a pentest. It will produce “findings” with no real severity and no PoC.
- You paid more than R$ 60k for a R$ 100k MRR SaaS — probably an inflated scope or a consultancy charging a premium without proportional coverage.
- You didn't get a retest at no extra cost — retesting is table stakes in 2026. If you're paying for it separately, you're being charged twice for the same work.
What MRR-based pricing doesn't capture
MRR works as a starting heuristic, but four factors can double the price:
- Regulated sector — fintech (BACEN Resolution 4,893 (CMN 4,893), the Central Bank of Brazil's cybersecurity rule), healthcare (LGPD Art. 11, sensitive data) and payments (PCI DSS) cost more because they require specific coverage and a report formatted for the regulatory auditor
- Financial transaction volume — a SaaS that processes payments directly needs extra coverage (race conditions on refunds, BOPLA on orders)
- Depth — black box costs half as much as a full white box
- Execution window — an emergency (10 days) carries a premium over the standard schedule (4–6 weeks)
Conclusion
Paying for a pentest that fits your size is the difference between treating security as an expense line and treating it as a unit-economics investment. A R$ 50k MRR SaaS doesn't need a R$ 30k pentest — it needs a R$ 8k one. A R$ 500k MRR SaaS can't get by on R$ 8k — it needs coverage proportional to its breach impact.
If you're looking for a range for your specific company, our SaaS penetration testing page breaks it down by scope, and our 2026 pentest pricing overview has the big-picture comparison across sectors.
Next step
Want to apply this to your system?
No Vuln runs in-depth penetration tests with the same methodology described in this article. Request a proposal: mutual NDA within 24h, scope defined on a technical call.