Since this is what i do for a living, I have a little insight into how we price out pentests. WE charge around 20K for a full blown external pen test. This includes a cd with all of your known exposures as well as the links to do a hot patch. In my opinion this is a better method than handing someone a phonebook with all of their discovered holes in their network. However, risk assess and pen tests from other large known companies can differ in pricing on many different factors including:

How many ingress points into your network
size of your network in nodes
how in depth you would like the scope to be (executive report, or the 4000 page phone book)

Be prepared to spend anywhere from 40-80k with these large firms.