Penetration testing
Penetration testing: 12 providers compared.
Every value in this table comes from the provider's own page, with a source link and a date. Where a provider publishes nothing, the cell says “not published”. We do not guess, and we do not rank.
Go to the tableAs of 8 September 2026 · Sources: the provider pages themselves · Matproof sits in the table on the same terms 8 September 2026
Short answer
Five of twelve providers publish a price. The rest want a call first.
That is the finding that decides most shortlists. Astra Security, Cobalt, Detectify, Matproof and Precursor Security print figures on their own pages. Astra Security, Cobalt, DeepStrike, HackerOne and Matproof state that a retest after remediation is included. Precursor Security publishes CREST accreditation for its own testing alongside a starting price. Edgescan and Intigriti publish an address inside the European Union. Pick the column your audit actually asks about, then read down it.
The table
12 penetration testing providers, every value sourced.
Rows are alphabetical after our own. The order is not a ranking. Each cell reflects one or more pages on that provider's own website, read on the date given, and every source URL is listed further down.
| Provider | How it is delivered | Published price | Retest included | Frameworks named | Stated timing | Stated location |
|---|---|---|---|---|---|---|
| Matproofus | AI agent platform, self-serve | EUR 149 per run. EUR 299 per month for 3 scans. EUR 1,490 per month for 20 scans. Enterprise on quote. | Yes | SOC 2, ISO 27001, DORA, NIS2 mapping | not published | Platform hosted in Germany, at Hetzner |
| Astra Security | Automated scan plus manual pentest | Pentest Auto USD 199 per month or USD 2,999 per year. Pentest Expert USD 5,999 per year. Enterprise from USD 9,999 per year. | Yes | SOC 2, ISO 27001, PCI DSS, HIPAA | Automated: “First report on the same day”. Manual pentest: “10-15 working days”. | not published |
| Cobalt | PTaaS with a vetted tester pool | Autonomous Pentest USD 3,500 per test, stated as a limited time offer. Standard, Premium and Enterprise are quote-only. | Yes | not published | Findings in 24 hours for the autonomous test. Test start in 1 to 3 business days by tier. | not published |
| DeepStrike | Managed pentest, one-off or continuous | not published | Yes | not published | “Start Pentest within 48 hours” | 131 Continental Dr Suite 305, Newark, DE 19713 |
| Detectify | Attack surface and application scanning, not a pentest service | Starter EUR 0. Standard EUR 2,500. Professional EUR 5,000. Enterprise EUR 15,000. All stated as an annual platform fee. | not published | PCI ASV scanning, priced separately at EUR 500 per year | not published | not published |
| Edgescan | PTaaS, automation plus human assessment | not published | not published | PCI | not published | Unit 701 Northwest Business Park, Ballycoolin, Dublin 15, Ireland |
| HackerOne | PTaaS on a researcher community | not published | Yes | SOC 2, ISO 27001, GDPR, NIST CSF 2.0, NIST 800-53, FISMA, DORA | “Our team typically responds within 1 business day” | not published |
| Intigriti | Bug bounty platform with PTaaS | not published | not published | not published | not published | Klokstraat 16, 2600 Antwerpen, Belgium |
| NetSPI | Human-delivered PTaaS, in-house testers | not published | not published | not published | not published | not published |
| Pentera | Software the customer runs itself | not published | not published | SOC 2, ISO/IEC 27001, ISO/IEC 42001, PCI DSS v4.0, NIST, CMMC, DORA, NIS2, GDPR, HIPAA, FedRAMP | not published | 200 Summit Drive, 3rd floor, Burlington, Massachusetts, 01803 |
| Precursor Security | CREST-accredited consultancy | Penetration testing from GBP 2,500. Cyber Essentials certification from GBP 1,500. Red team from GBP 15,000. SOC from GBP 900 per month. | not published | ISO 27001, Cyber Essentials, PCI DSS, GDPR | “Starts Within 2 Weeks Of scope sign-off” | Headquarters in Leeds, United Kingdom |
| Synack | Vetted researcher team, on demand | not published | not published | FedRAMP moderate designation | “Launch tests in days, not weeks” | not published |
Read on 8 September 2026 from each provider's own website. “Not published” means the pages we read carry no such value; it is not a criticism and not a “no”. “Frameworks named” records which frameworks a provider names on the page we read. It is not a statement that the provider holds a certification or an accreditation in that framework, and it is not a statement that the provider is audited against it. “Stated location” is whatever the provider states: a head office, an office address, or a hosting location. The wording differs by provider and we did not normalise it. The order of rows is alphabetical after our own row and carries no judgement.
- Matproof: “3 full Sentinel pentests per month … Remediation-diff metric across re-tests” https://matproof.com/pricing
- Astra Security: “Pentest report for SOC2, ISO27001, HIPAA etc. compliances” https://www.getastra.com/pricing
- Cobalt: “unlimited on-demand retesting throughout your contract term” https://www.cobalt.io/pricing
- DeepStrike: “Free remediation retesting for 12 Months” https://deepstrike.io/pricing
- Detectify: “annual platform fee” https://detectify.com/pricing
- Edgescan: “Hybrid solution that combines the breadth of automation with the depth of human assessment” https://www.edgescan.com/pricing/
- HackerOne: “HackerOne provides retesting to confirm that the fixes have been correctly implemented” https://www.hackerone.com/product/pentest
- Intigriti: “Private & public bug bounty … Pentest as a Service (PTaaS)” https://www.intigriti.com/pricing
- NetSPI: “human-delivered, contextualized pentesting services” with “350+ in-house pentesters” https://www.netspi.com/security-testing/penetration-testing-as-a-service/
- Pentera: “run safely in production environments using customer-controlled guardrails” https://pentera.io/platform/
- Precursor Security: “CREST-accredited penetration testing” and “No offshoring of work” https://www.precursorsecurity.com/
- Synack: “Synack14 provides a two-week process for pentesting while Synack90 and Synack365 provide 90-day and year-round options respectively” https://www.synack.com/platform/
Fit
Who each provider is the right answer for.
One line per provider, written from what they publish about their own service. If your situation is not on this list, the table above is the better guide.
| Provider | The right answer when |
|---|---|
| Matproof | Teams that need a repeatable report for an ISO 27001 or SOC 2 audit and want the price published before they talk to anyone. |
| Astra Security | Buyers who want one supplier for an automated scanner and a human pentest, with both prices on the page. |
| Cobalt | Buyers who want a named human tester pool and can accept a quote for everything above the entry test. |
| DeepStrike | Buyers who care most about how fast a test can start and are willing to ask for the price. |
| Detectify | Continuous coverage of a large external estate. It is a scanner, so it does not replace a report signed by a tester. |
| Edgescan | EU buyers who want the supplier itself inside the EU and are buying a programme rather than a single test. |
| HackerOne | Buyers who already run or plan a bug bounty and want the pentest in the same platform. |
| Intigriti | European buyers who want a European platform company and are buying bug bounty first, pentest second. |
| NetSPI | Large estates that want one supplier across network, cloud and application testing, on a quote. |
| Pentera | Security teams that want to run validation themselves on their own schedule, not buy a report. |
| Precursor Security | UK buyers who need CREST on the paperwork, or who need Cyber Essentials Plus and the pentest from one firm. |
| Synack | Buyers with a US public sector requirement, or who want a continuous engagement rather than one test. |
Method
How we compared.
For every provider we read its own website: the pricing page where one exists, the service or platform page, and the contact page. All on 8 September 2026.
We used no review sites, no analyst reports, no directories and nothing from memory. Where a provider does not show a value, the cell says “not published” instead of an estimate.
Matproof publishes this page and sells one of the products in it. The Matproof row carries sources like every other row, and it carries what does not flatter us: we sell an automated platform, not a human tester, and we publish no turnaround time. Both facts are in the table.
All sources
- Matproof
https://matproof.com/pricinghttps://matproof.com/trust - Astra Security
https://www.getastra.com/pricing - Cobalt
https://www.cobalt.io/pricing - DeepStrike
https://deepstrike.io/pricing - Detectify
https://detectify.com/pricing - Edgescan
https://www.edgescan.com/pricing/ - HackerOne
https://www.hackerone.com/product/pentest - Intigriti
https://www.intigriti.com/pricinghttps://www.intigriti.com/contact - NetSPI
https://www.netspi.com/security-testing/penetration-testing-as-a-service/ - Pentera
https://pentera.io/platform/https://pentera.io/contact-us/ - Precursor Security
https://www.precursorsecurity.com/ - Synack
https://www.synack.com/platform/
What we could not source
- Pentest People: www.pentestpeople.com now redirects to worknest.com. We could not read a stable page on the company's own domain, so we left the row out rather than guess.
- JUMPSEC: www.jumpsec.com returned HTTP 522 on every attempt on 8 September 2026. Nothing was readable, so there is no row.
- Probely: probely.com/pricing/ returned HTTP 403 to our reader. Their published plan prices exist; we simply could not read them ourselves, and we do not copy prices from third parties.
- Bugcrowd: the pricing URL served no pricing content we could read.
- Cobalt, Astra Security, HackerOne, NetSPI and Synack: we found no address on the pages we read, so the location cell is empty for them. That is a gap in our reading, not evidence that they publish nothing anywhere.
- Retest policy is unpublished for Detectify, Edgescan, Intigriti, NetSPI, Pentera, Precursor Security and Synack on the pages we read. Ask for it in writing before you sign; it is the term that most often costs money later.
FAQ
Common questions about penetration testing providers
Which penetration testing company is the best?
There is no single best, because the buying situations differ. If you need CREST on the paperwork for a UK contract, Precursor Security publishes CREST accreditation and a starting price of GBP 2,500. If you want the price of a human test on the page, Astra Security publishes USD 5,999 per year for Pentest Expert. If you want a single fixed-price test with a fast result, Cobalt publishes USD 3,500 for its autonomous pentest as a limited time offer. If you want a repeatable report for an audit at a published monthly price, Matproof publishes EUR 299 per month for three scans. All values as of 8 September 2026, read from the providers' own pages.
How much does a penetration test cost in 2026?
Most providers publish no price at all. Of the twelve compared here, five show a real figure on their own site as of 8 September 2026: Astra Security from USD 199 per month, Cobalt at USD 3,500 for its autonomous test, Detectify from EUR 0 to EUR 15,000 as an annual platform fee, Matproof at EUR 149 per run or EUR 299 per month, and Precursor Security from GBP 2,500 for a penetration test. The other seven route you to a sales call. That is the single biggest reason pentest budgets are hard to plan: the market does not publish.
What is the difference between PTaaS and a traditional penetration test?
A traditional test is a project. You scope it, a tester runs it over a fixed window, and you receive a report. Penetration testing as a service puts the same work behind a platform: you start tests on demand, findings appear as they are confirmed rather than at the end, and retests are usually part of the contract. The label alone tells you little. Ask two questions instead: is a human involved in the testing, and is the retest after remediation included. Both answers are in the table above where the provider publishes them.
Do I need a penetration test for ISO 27001 or SOC 2?
Neither standard names a penetration test as a mandatory control. ISO/IEC 27001:2022 requires you to manage technical vulnerabilities under Annex A 8.8, and auditors commonly accept a penetration test as the evidence for it. SOC 2 works the same way: the Trust Services Criteria describe monitoring and change management, and the test is one way to show it. In practice most auditors expect a dated report from an independent tester, plus proof that the findings were fixed. That is why the retest column matters more than most buyers expect.
What does Cyber Essentials Plus require?
Cyber Essentials Plus is a UK scheme with a hands-on technical audit carried out by a certification body, not a penetration test. The two are different products and one does not replace the other. Some providers sell both: Precursor Security publishes Cyber Essentials certification from GBP 1,500 alongside its penetration testing. If you need both this year, buying them from one supplier saves a second scoping round. Confirm the assessor is appointed by an accreditation body before you sign.
Why does the table say “not published” so often?
Because we only print what a provider shows on its own site. If a pricing page carries no figure, there is no figure here. If a page names no retest policy, this table says so rather than guessing. We take nothing from review sites, analyst reports or search summaries. A wrong claim about a named competitor is a legal risk, not a copy problem. “Not published” is a statement about the page we read, not a criticism of the provider.
Is an AI-run penetration test a real penetration test?
It depends on what you need the report for. An automated or AI-driven test covers a defined surface repeatedly and cheaply, which is what continuous coverage and audit evidence usually need. A human tester finds business logic flaws that no scanner reaches, which is what a high-risk application needs before launch. Several providers now sell both: Cobalt pairs an autonomous test with its tester pool, and Astra Security sells an automated plan and a manual plan separately. Matproof sells the automated side only, and this page says so.
Next step
See your own attack surface first.
Before you scope a test, find out what is already exposed. The free scan checks your public surface and returns a report you can take into any of the providers above, including the ones that are not us.
Run the free scan