SEE MATPROOF ON YOUR STACK — BOOK A 30-MINUTE DEMO

Penetration testing

Penetration testing: 12 providers compared.

Every value in this table comes from the provider's own page, with a source link and a date. Where a provider publishes nothing, the cell says “not published”. We do not guess, and we do not rank.

Go to the table

As of 8 September 2026 · Sources: the provider pages themselves · Matproof sits in the table on the same terms 8 September 2026

Short answer

Five of twelve providers publish a price. The rest want a call first.

That is the finding that decides most shortlists. Astra Security, Cobalt, Detectify, Matproof and Precursor Security print figures on their own pages. Astra Security, Cobalt, DeepStrike, HackerOne and Matproof state that a retest after remediation is included. Precursor Security publishes CREST accreditation for its own testing alongside a starting price. Edgescan and Intigriti publish an address inside the European Union. Pick the column your audit actually asks about, then read down it.

The table

12 penetration testing providers, every value sourced.

Rows are alphabetical after our own. The order is not a ranking. Each cell reflects one or more pages on that provider's own website, read on the date given, and every source URL is listed further down.

ProviderHow it is deliveredPublished priceRetest includedFrameworks namedStated timingStated location
MatproofusAI agent platform, self-serveEUR 149 per run. EUR 299 per month for 3 scans. EUR 1,490 per month for 20 scans. Enterprise on quote.YesSOC 2, ISO 27001, DORA, NIS2 mappingnot publishedPlatform hosted in Germany, at Hetzner
Astra SecurityAutomated scan plus manual pentestPentest Auto USD 199 per month or USD 2,999 per year. Pentest Expert USD 5,999 per year. Enterprise from USD 9,999 per year.YesSOC 2, ISO 27001, PCI DSS, HIPAAAutomated: “First report on the same day”. Manual pentest: “10-15 working days”.not published
CobaltPTaaS with a vetted tester poolAutonomous Pentest USD 3,500 per test, stated as a limited time offer. Standard, Premium and Enterprise are quote-only.Yesnot publishedFindings in 24 hours for the autonomous test. Test start in 1 to 3 business days by tier.not published
DeepStrikeManaged pentest, one-off or continuousnot publishedYesnot published“Start Pentest within 48 hours”131 Continental Dr Suite 305, Newark, DE 19713
DetectifyAttack surface and application scanning, not a pentest serviceStarter EUR 0. Standard EUR 2,500. Professional EUR 5,000. Enterprise EUR 15,000. All stated as an annual platform fee.not publishedPCI ASV scanning, priced separately at EUR 500 per yearnot publishednot published
EdgescanPTaaS, automation plus human assessmentnot publishednot publishedPCInot publishedUnit 701 Northwest Business Park, Ballycoolin, Dublin 15, Ireland
HackerOnePTaaS on a researcher communitynot publishedYesSOC 2, ISO 27001, GDPR, NIST CSF 2.0, NIST 800-53, FISMA, DORA“Our team typically responds within 1 business day”not published
IntigritiBug bounty platform with PTaaSnot publishednot publishednot publishednot publishedKlokstraat 16, 2600 Antwerpen, Belgium
NetSPIHuman-delivered PTaaS, in-house testersnot publishednot publishednot publishednot publishednot published
PenteraSoftware the customer runs itselfnot publishednot publishedSOC 2, ISO/IEC 27001, ISO/IEC 42001, PCI DSS v4.0, NIST, CMMC, DORA, NIS2, GDPR, HIPAA, FedRAMPnot published200 Summit Drive, 3rd floor, Burlington, Massachusetts, 01803
Precursor SecurityCREST-accredited consultancyPenetration testing from GBP 2,500. Cyber Essentials certification from GBP 1,500. Red team from GBP 15,000. SOC from GBP 900 per month.not publishedISO 27001, Cyber Essentials, PCI DSS, GDPR“Starts Within 2 Weeks Of scope sign-off”Headquarters in Leeds, United Kingdom
SynackVetted researcher team, on demandnot publishednot publishedFedRAMP moderate designation“Launch tests in days, not weeks”not published

Read on 8 September 2026 from each provider's own website. “Not published” means the pages we read carry no such value; it is not a criticism and not a “no”. “Frameworks named” records which frameworks a provider names on the page we read. It is not a statement that the provider holds a certification or an accreditation in that framework, and it is not a statement that the provider is audited against it. “Stated location” is whatever the provider states: a head office, an office address, or a hosting location. The wording differs by provider and we did not normalise it. The order of rows is alphabetical after our own row and carries no judgement.

Fit

Who each provider is the right answer for.

One line per provider, written from what they publish about their own service. If your situation is not on this list, the table above is the better guide.

ProviderThe right answer when
MatproofTeams that need a repeatable report for an ISO 27001 or SOC 2 audit and want the price published before they talk to anyone.
Astra SecurityBuyers who want one supplier for an automated scanner and a human pentest, with both prices on the page.
CobaltBuyers who want a named human tester pool and can accept a quote for everything above the entry test.
DeepStrikeBuyers who care most about how fast a test can start and are willing to ask for the price.
DetectifyContinuous coverage of a large external estate. It is a scanner, so it does not replace a report signed by a tester.
EdgescanEU buyers who want the supplier itself inside the EU and are buying a programme rather than a single test.
HackerOneBuyers who already run or plan a bug bounty and want the pentest in the same platform.
IntigritiEuropean buyers who want a European platform company and are buying bug bounty first, pentest second.
NetSPILarge estates that want one supplier across network, cloud and application testing, on a quote.
PenteraSecurity teams that want to run validation themselves on their own schedule, not buy a report.
Precursor SecurityUK buyers who need CREST on the paperwork, or who need Cyber Essentials Plus and the pentest from one firm.
SynackBuyers with a US public sector requirement, or who want a continuous engagement rather than one test.

Method

How we compared.

For every provider we read its own website: the pricing page where one exists, the service or platform page, and the contact page. All on 8 September 2026.

We used no review sites, no analyst reports, no directories and nothing from memory. Where a provider does not show a value, the cell says “not published” instead of an estimate.

Matproof publishes this page and sells one of the products in it. The Matproof row carries sources like every other row, and it carries what does not flatter us: we sell an automated platform, not a human tester, and we publish no turnaround time. Both facts are in the table.

What we could not source

  • Pentest People: www.pentestpeople.com now redirects to worknest.com. We could not read a stable page on the company's own domain, so we left the row out rather than guess.
  • JUMPSEC: www.jumpsec.com returned HTTP 522 on every attempt on 8 September 2026. Nothing was readable, so there is no row.
  • Probely: probely.com/pricing/ returned HTTP 403 to our reader. Their published plan prices exist; we simply could not read them ourselves, and we do not copy prices from third parties.
  • Bugcrowd: the pricing URL served no pricing content we could read.
  • Cobalt, Astra Security, HackerOne, NetSPI and Synack: we found no address on the pages we read, so the location cell is empty for them. That is a gap in our reading, not evidence that they publish nothing anywhere.
  • Retest policy is unpublished for Detectify, Edgescan, Intigriti, NetSPI, Pentera, Precursor Security and Synack on the pages we read. Ask for it in writing before you sign; it is the term that most often costs money later.

FAQ

Common questions about penetration testing providers

Which penetration testing company is the best?

There is no single best, because the buying situations differ. If you need CREST on the paperwork for a UK contract, Precursor Security publishes CREST accreditation and a starting price of GBP 2,500. If you want the price of a human test on the page, Astra Security publishes USD 5,999 per year for Pentest Expert. If you want a single fixed-price test with a fast result, Cobalt publishes USD 3,500 for its autonomous pentest as a limited time offer. If you want a repeatable report for an audit at a published monthly price, Matproof publishes EUR 299 per month for three scans. All values as of 8 September 2026, read from the providers' own pages.

How much does a penetration test cost in 2026?

Most providers publish no price at all. Of the twelve compared here, five show a real figure on their own site as of 8 September 2026: Astra Security from USD 199 per month, Cobalt at USD 3,500 for its autonomous test, Detectify from EUR 0 to EUR 15,000 as an annual platform fee, Matproof at EUR 149 per run or EUR 299 per month, and Precursor Security from GBP 2,500 for a penetration test. The other seven route you to a sales call. That is the single biggest reason pentest budgets are hard to plan: the market does not publish.

What is the difference between PTaaS and a traditional penetration test?

A traditional test is a project. You scope it, a tester runs it over a fixed window, and you receive a report. Penetration testing as a service puts the same work behind a platform: you start tests on demand, findings appear as they are confirmed rather than at the end, and retests are usually part of the contract. The label alone tells you little. Ask two questions instead: is a human involved in the testing, and is the retest after remediation included. Both answers are in the table above where the provider publishes them.

Do I need a penetration test for ISO 27001 or SOC 2?

Neither standard names a penetration test as a mandatory control. ISO/IEC 27001:2022 requires you to manage technical vulnerabilities under Annex A 8.8, and auditors commonly accept a penetration test as the evidence for it. SOC 2 works the same way: the Trust Services Criteria describe monitoring and change management, and the test is one way to show it. In practice most auditors expect a dated report from an independent tester, plus proof that the findings were fixed. That is why the retest column matters more than most buyers expect.

What does Cyber Essentials Plus require?

Cyber Essentials Plus is a UK scheme with a hands-on technical audit carried out by a certification body, not a penetration test. The two are different products and one does not replace the other. Some providers sell both: Precursor Security publishes Cyber Essentials certification from GBP 1,500 alongside its penetration testing. If you need both this year, buying them from one supplier saves a second scoping round. Confirm the assessor is appointed by an accreditation body before you sign.

Why does the table say “not published” so often?

Because we only print what a provider shows on its own site. If a pricing page carries no figure, there is no figure here. If a page names no retest policy, this table says so rather than guessing. We take nothing from review sites, analyst reports or search summaries. A wrong claim about a named competitor is a legal risk, not a copy problem. “Not published” is a statement about the page we read, not a criticism of the provider.

Is an AI-run penetration test a real penetration test?

It depends on what you need the report for. An automated or AI-driven test covers a defined surface repeatedly and cheaply, which is what continuous coverage and audit evidence usually need. A human tester finds business logic flaws that no scanner reaches, which is what a high-risk application needs before launch. Several providers now sell both: Cobalt pairs an autonomous test with its tester pool, and Astra Security sells an automated plan and a manual plan separately. Matproof sells the automated side only, and this page says so.

Next step

See your own attack surface first.

Before you scope a test, find out what is already exposed. The free scan checks your public surface and returns a report you can take into any of the providers above, including the ones that are not us.

Run the free scan

Read next