SEE MATPROOF ON YOUR STACK — BOOK A 30-MINUTE DEMO

Penetration testing · United States

US penetration testing companies: 19 providers compared.

Every value comes from the provider's own page, with a source link and a date. Where a provider publishes nothing, the cell says “not published”. We do not guess, and we do not rank.

Go to the table

Sources: the provider pages themselves · Matproof sits in the table on the same terms · Read on 8 and 15 September 2026

Short answer

10 of 19 publish a price. For the rest you book a call first.

Published prices: Matproof, Astra Security, Bright Defense, Cobalt, CYBRI, Packet33, Rhino Security Labs, Software Secured, Stingrai and Synack. No figure on the pages we read: Bishop Fox, BreachLock, Coalfire, Echelon Risk + Cyber, Kroll, NetSPI, Praetorian, Rapid7 and Red Sentry. The cheapest published fixed plan is Bright Defense at USD 2,750. The providers split into consultancies that scope each test, platforms that sell a test online, and hybrids where AI agents run first and people check the result. Pick the split your auditor or customer will accept, then compare within it.

The table

19 penetration testing companies for US buyers, every value sourced.

Included: every provider named when we asked ChatGPT and Perplexity six US buyer questions on 15 September 2026, or ranked on page one of Google US for “penetration testing companies” that day. Rows are alphabetical after our own. The order is not a ranking.

ProviderHow it is deliveredPublished priceRetest includedFrameworks namedStated timingStated location
MatproofusAI agent platform, self-serveEUR 149 per run. EUR 299 per month for 3 scans. EUR 1,490 per month for 20 scans. Enterprise on quote.YesSOC 2, ISO 27001, DORA, NIS2 mappingnot publishedPlatform hosted in Germany, at Hetzner
Astra SecurityAutomated scan plus manual pentestPentest Auto USD 199 per month or USD 2,999 per year. Pentest Expert USD 5,999 per year. Enterprise from USD 9,999 per year.YesSOC 2, ISO 27001, PCI DSS, HIPAAAutomated: “First report on the same day”. Manual pentest: “10-15 working days”.not published
Bishop FoxConsultant-led testing, plus AI-assisted application testing with findings validated by its testersnot publishednot publishednot publishedAI-Powered Application Penetration Testing only: “most tests are completed within two to five business days”1414 W Broadway Road, Suite 233, Tempe, AZ 85282 (Global Headquarters)
BreachLockPTaaS with in-house certified pentesters, AI-acceleratednot publishedYesSOC 2, PCI DSS, ISO 27001, HIPAA, HITRUST“Launch penetration tests in 24–48 hours”1350 Avenue of the Americas, New York, NY 10019 (BreachLock Inc.) and Amsterdam (BreachLock NL B.V.)
Bright DefenseFixed-scope pentest plans from a compliance services firmIgnite USD 2,750. Elevate USD 5,250. Summit USD 9,250.YesSOC 2, ISO 27001, PCI DSS, CMMCnot published9415 Culver Blvd, #2, Culver City, CA 90232
CoalfireHuman-led offensive security team (DivisionHex)not publishednot publishedPCI, HIPAA, FedRAMPnot published330 N Wabash Ave, Suite 1430, Chicago, IL 60611 (mailing address)
CobaltPTaaS with a vetted tester poolAutonomous Pentest USD 3,500 per test, stated as a limited time offer. Standard, Premium and Enterprise are quote-only.Yesnot publishedFindings in 24 hours for the autonomous test. Test start in 1 to 3 business days by tier.not published
CYBRIPTaaS with senior testers (Red Team members) on a platformFrom USD 5,000 (Web Application package). Remediation testing is listed on the USD 9,500 and USD 20,000 packages.YesHIPAA, PCI-DSS, SOC 2, ISO 27001, SECFrom 5 business days, covering testing, reporting and final delivery433 Broadway, 5th Floor, New York, NY 10013
Echelon Risk + CyberConsultant-led testing following PTESnot publishednot publishedCMMC, HIPAA, HITRUST, ISO 27001, NIST CSF, FFIEC, NCUA, GLBA, FISMA, SOC 2, PCI DSSnot publishedUS locations listed: Pittsburgh, Austin, Charlotte, Atlanta, Raleigh, Philadelphia
KrollIn-house team of certified pen testerscould not verifycould not verifynot publishedcould not verifyOne World Trade Center, 285 Fulton Street, 31st Floor, New York, NY 10007
NetSPIHuman-delivered PTaaS, in-house testersnot publishednot publishednot publishednot publishednot published
Packet33Senior practitioner-led testing at a fixed price per scopeWeb and API testing USD 8,000 to USD 30,000. External network testing USD 10,000 to USD 25,000.not publishedSOC 2, HIPAA, ISO 27001, CIS“Most engagements complete in 1-3 weeks from kickoff.”not published
PraetorianEngineer-led testing on a proprietary platformnot publishedYesFDA, GLBA, HIPAA, NERC, PCI-DSSnot published3801 N Capital of Texas Hwy, Ste E240 Unit #3421, Austin, TX 78746 (mailing address in its terms of service)
Rapid7Consultant-led point-in-time assessments, stated as 85% manual and 15% automatednot publishednot publishedNIST, CIS Top 20 (named in its service brief)not published120 Causeway Street, Suite 400, Boston, MA 02114 (Global Headquarters)
Red SentryHuman-led pentesting delivered through a PTaaS platformnot publishedYesSOC 2, ISO 27001, HIPAA, PCI DSSFindings “in weeks, not months”3490 Piedmont Rd. NE, Suite 1350, Atlanta, GA 30305
Rhino Security LabsMostly manual, engineer-led assessmentsStated as “generally start around the $10,000 range”, growing to six figures for large, in-depth projects.not publishedPCI, HIPAA, SOC 2Projects start at about one week and most run multiple weeks; the schedule can be booked 2 to 6 weeks out464 12th Ave, Suite 300, Seattle, WA 98122
Software SecuredHuman-led PTaaS subscription with full-time pentestersFrom USD 21,400 (PTaaS)YesSOC 2, ISO 27001Scheduling within 3 to 6 weeks; report within 48 to 72 hours of test completion301 Moodie Dr, Unit 108, Ottawa, ON K2H 9C4, Canada
StingraiAutonomous agent alone, or together with human pentesters, on a PTaaS platformUSD 3,000 one-time (Autonomous Pentest). USD 6,800 one-time (Hybrid Pentest). One web app plus its APIs.YesSOC 2, HIPAA, PCI DSS, ISO 27001Autonomous Pentest: “Same-day results”1 Adelaide Street East, #3001, Toronto, Ontario M5C 2V9, Canada (HQ)
SynackVetted researcher team, on demandAI Sara Pentest from USD 4,181. Standard Pentest from USD 10,283. Synack14 Pentest from USD 27,120.not publishedFedRAMP moderate designation“Launch tests in days, not weeks”not published

The Matproof, Astra Security, Cobalt, NetSPI and Synack rows were read on 8 September 2026; all other rows, and Synack's price, on 15 September 2026, each from the provider's own website. “Not published” means the pages we read carry no such value; it is not a criticism and not a “no”. “Could not verify” means we could not read that part of the site. “Frameworks named” records which frameworks a provider names on the page we read. It is not a statement that the provider holds a certification or an accreditation, or that it is audited against the framework. “Stated location” is whatever the provider states, including mailing addresses, and is not normalised. Row order carries no judgement.

Fit

Who each provider is the right answer for.

One line per provider, written from what they publish about their own service.

ProviderThe right answer when
MatproofTeams that need a repeatable report for an ISO 27001 or SOC 2 audit and want the price published before they talk to anyone.
Astra SecurityBuyers who want one supplier for an automated scanner and a human pentest, with both prices on the page.
Bishop FoxEnterprises with large application portfolios that want AI-assisted testing with findings validated by a Bishop Fox tester.
BreachLockTeams that want in-house testers on a platform for one-time, periodic or continuous pentests.
Bright DefenseCompanies that need a fixed-price web and API pentest report for SOC 2, ISO 27001, PCI DSS or CMMC.
CoalfireOrganizations that need offensive testing aligned with PCI, HIPAA or FedRAMP from a firm that states 3PAO experience.
CobaltBuyers who want a named human tester pool and can accept a quote for everything above the entry test.
CYBRICompanies that want a fixed-price, manual-first pentest of a web app, API, cloud or network.
Echelon Risk + CyberOrganizations that need testing mapped to regulated-industry standards such as CMMC, HITRUST, FFIEC, NCUA or PCI DSS.
KrollLarge organizations that want complex or large-scale pentest programs next to an incident response practice.
NetSPILarge estates that want one supplier across network, cloud and application testing, on a quote.
Packet33SaaS and healthtech startups that need a fixed-price pentest report for a SOC 2, HIPAA or ISO 27001 audit.
PraetorianOrganizations that want a single assessment or a continuous testing program across applications, cloud, network, IoT and AI systems.
Rapid7Organizations that want point-in-time network, web app, IoT, wireless, social engineering or red team tests.
Red SentryTeams that test more than once a year and want live findings and a free remediation re-test.
Rhino Security LabsOrganizations that want mostly manual testing, with a focus on AWS, GCP and Azure cloud, network and web applications.
Software SecuredSoftware teams that ship often and want recurring manual pentests aligned to releases.
StingraiTeams that need a pentest of one web app and its APIs at a published fixed price, autonomous or with human testers.
SynackBuyers with a US public sector requirement, or who want a continuous engagement rather than one test.

Method

How we chose and compared.

We asked ChatGPT (gpt-4.1 with web search) and Perplexity (sonar) six questions a US buyer asks, about SOC 2, HIPAA, cost, PTaaS, AI testing and the best providers for a mid-sized company. We listed every provider they named, added page one of Google US for “penetration testing companies”, and read each provider's own website.

For every row we read the penetration testing page, the pricing page where one exists, and the contact, company or legal page for the location. A script compared each quoted value against the saved page text. We used no review sites, no analyst reports and nothing from memory.

Matproof publishes this page and sells one of the products in it. Our row carries sources like every other row, and it says what does not flatter us: we sell an automated platform with no human tester, billed in EUR, and we publish no turnaround time.

All sources

What we could not source, and how to read some cells

  • Named in the US answers but not yet in this table, because we have not read their sites: UnderDefense, Mandiant, Secureworks, ScienceSoft, PurpleSec, Qualysec, Pentest Express, Pentest Testing Corp, Invadel and Clearwater. We add a row when we have read the provider's own pages, not before.
  • Blaze Information Security: its site served a bot check to every reader we tried on 15 September 2026, so there is no row.
  • Kroll: price, retest and timing could not be read. See the FAQ.
  • Bishop Fox: the two to five business days apply to its AI-Powered Application Penetration Testing only, not to all services.
  • Rapid7: its penetration testing page names no framework. NIST and CIS Top 20 come from the service brief PDF linked from that page.
  • Rhino Security Labs: the price is a stated starting range from its FAQ, not a list price. It describes a revisit after patching as an additional service without saying whether it costs extra, so the retest cell says “not published”.
  • Packet33: the pentest page gives “1-3 weeks from kickoff” and, in a headline, delivery in two weeks. We print the range. We found no address on its site.
  • Praetorian lists a re-test as a step in its process but does not say whether it costs extra. Its address is the mailing address in its terms of service. Red Sentry's address comes from its terms page, and it states that it publishes no price packages.
  • Echelon Risk + Cyber lists six US cities and no street address.

FAQ

Common questions about US penetration testing companies

Which penetration testing company is best in the US?

It depends on what the report is for. If you need a fixed price for a SOC 2 or ISO 27001 audit, Bright Defense publishes three plans from USD 2,750 and Packet33 publishes ranges from USD 8,000. If PCI, HIPAA or FedRAMP drives the test, Coalfire names all three and states 3PAO experience. If you want mostly manual work, Rhino Security Labs states around 95 per cent hands-on and Rapid7 states 85 per cent manual. If you want AI-assisted testing checked by people, Bishop Fox and Stingrai say their testers validate findings. If you want repeatable automated evidence at a published monthly price, Matproof publishes EUR 299 per month, with no human tester. All values from the providers' own pages.

How much does a penetration test cost in the US?

10 of the 19 providers here publish a figure on their own site: Matproof, Astra Security, Bright Defense, Cobalt, CYBRI, Packet33, Rhino Security Labs, Software Secured, Stingrai and Synack. Examples: Bright Defense USD 2,750 to USD 9,250 per plan, Stingrai USD 3,000 for an autonomous test and USD 6,800 for a hybrid test, Packet33 USD 8,000 to USD 30,000 for web and API testing, and Rhino Security Labs stating that tests generally start around USD 10,000. For dated market ranges by scope and the rules that force a test, read our US cost guide at matproof.com/blog/penetration-testing-cost-usa-2026.

Does a US penetration testing company need a certification?

No US rule we read names one. PCI DSS v4.0 requirement 11.4 asks for a qualified internal resource or qualified external third party with organizational independence. NYDFS 23 NYCRR 500.5 asks for a qualified internal or external party. Neither names CREST, OSCP or any other credential. Individual tester certifications are a market signal. Your QSA, auditor or customer contract may still ask for one, so read it before you shop.

Why are Canadian and European providers on a US list?

Because US buyers are pointed to them. Stingrai and Software Secured state addresses in Canada, and both were named in the US answers we collected. BreachLock states offices in New York and Amsterdam. The location column prints what each provider states, so you can filter on it if your contract requires US-based testing. Matproof's platform is hosted in Germany.

Why does the table say “could not verify” for Kroll?

Kroll's penetration testing page blocked our automated reader, and in a normal browser the answers to its cost, duration and retest questions did not load. We print “could not verify” for those cells instead of guessing. It is a statement about our reading, not about Kroll's service.

Next step

See your own attack surface first.

The free scan checks your public surface without an account and returns a report you can take to any provider above, including the ones that are not us.

Run the free scan

Read next