A fixed-scope pentest is an engagement where the boundary of the work and its price are both set before anything starts. Instead of "we'll estimate the days and send a quote", it's "this tier covers up to N endpoints, these roles, this depth, one retest, delivered in D days, for $X".
What's actually fixed
- Surface: a stated number of endpoints / operations / hosts, and which
roles or tenants.
- Depth: whether it's a known-issue sweep, a full manual authenticated test,
a business-logic review, and so on.
- Deliverable: a report in a defined format, with a stated number of
retests.
- Price and delivery time.
What you give up
- Elasticity. If the test uncovers that the real surface is twice what you
described, you order a bigger tier or a second gig rather than expanding in place.
- A custom statement of work. The scope is a template. For most web apps,
APIs and networks that's fine; for unusual systems it may not fit.
- A named team you interviewed. You're choosing a vetted researcher by
profile, reputation and reviews, not a sales process.
When it's the right call
- You need a report for an audit or a customer and the surface is a normal
web app / API / network.
- You want to know the cost up front for budgeting.
- You don't have a security team to run a managed program.
- You need it soon — days, not a procurement cycle.
- You're doing a pre-launch check or verifying fixes from a previous test.
When to reach for something else
- Continuous coverage of changing surface → a managed bounty program.
- Novel or high-stakes systems — a payments core, a new protocol, hardware
→ a boutique firm that will scope custom depth.
- Very large surface where you want many researchers → a crowd.
How it works on a marketplace
You browse gigs, each showing its tiers and what they cover. You verify target ownership, pay into escrow, accept the Rules of Engagement, and the researcher starts. You get the report, review it, and release escrow — or dispute if it doesn't meet the stated scope. The whole flow is documented step by step.