Penetration testing · United States
US penetration testing companies: 19 providers compared.
Every value comes from the provider's own page, with a source link and a date. Where a provider publishes nothing, the cell says “not published”. We do not guess, and we do not rank.
Go to the tableSources: the provider pages themselves · Matproof sits in the table on the same terms · Read on 8 and 15 September 2026
Short answer
10 of 19 publish a price. For the rest you book a call first.
Published prices: Matproof, Astra Security, Bright Defense, Cobalt, CYBRI, Packet33, Rhino Security Labs, Software Secured, Stingrai and Synack. No figure on the pages we read: Bishop Fox, BreachLock, Coalfire, Echelon Risk + Cyber, Kroll, NetSPI, Praetorian, Rapid7 and Red Sentry. The cheapest published fixed plan is Bright Defense at USD 2,750. The providers split into consultancies that scope each test, platforms that sell a test online, and hybrids where AI agents run first and people check the result. Pick the split your auditor or customer will accept, then compare within it.
The table
19 penetration testing companies for US buyers, every value sourced.
Included: every provider named when we asked ChatGPT and Perplexity six US buyer questions on 15 September 2026, or ranked on page one of Google US for “penetration testing companies” that day. Rows are alphabetical after our own. The order is not a ranking.
| Provider | How it is delivered | Published price | Retest included | Frameworks named | Stated timing | Stated location |
|---|---|---|---|---|---|---|
| Matproofus | AI agent platform, self-serve | EUR 149 per run. EUR 299 per month for 3 scans. EUR 1,490 per month for 20 scans. Enterprise on quote. | Yes | SOC 2, ISO 27001, DORA, NIS2 mapping | not published | Platform hosted in Germany, at Hetzner |
| Astra Security | Automated scan plus manual pentest | Pentest Auto USD 199 per month or USD 2,999 per year. Pentest Expert USD 5,999 per year. Enterprise from USD 9,999 per year. | Yes | SOC 2, ISO 27001, PCI DSS, HIPAA | Automated: “First report on the same day”. Manual pentest: “10-15 working days”. | not published |
| Bishop Fox | Consultant-led testing, plus AI-assisted application testing with findings validated by its testers | not published | not published | not published | AI-Powered Application Penetration Testing only: “most tests are completed within two to five business days” | 1414 W Broadway Road, Suite 233, Tempe, AZ 85282 (Global Headquarters) |
| BreachLock | PTaaS with in-house certified pentesters, AI-accelerated | not published | Yes | SOC 2, PCI DSS, ISO 27001, HIPAA, HITRUST | “Launch penetration tests in 24–48 hours” | 1350 Avenue of the Americas, New York, NY 10019 (BreachLock Inc.) and Amsterdam (BreachLock NL B.V.) |
| Bright Defense | Fixed-scope pentest plans from a compliance services firm | Ignite USD 2,750. Elevate USD 5,250. Summit USD 9,250. | Yes | SOC 2, ISO 27001, PCI DSS, CMMC | not published | 9415 Culver Blvd, #2, Culver City, CA 90232 |
| Coalfire | Human-led offensive security team (DivisionHex) | not published | not published | PCI, HIPAA, FedRAMP | not published | 330 N Wabash Ave, Suite 1430, Chicago, IL 60611 (mailing address) |
| Cobalt | PTaaS with a vetted tester pool | Autonomous Pentest USD 3,500 per test, stated as a limited time offer. Standard, Premium and Enterprise are quote-only. | Yes | not published | Findings in 24 hours for the autonomous test. Test start in 1 to 3 business days by tier. | not published |
| CYBRI | PTaaS with senior testers (Red Team members) on a platform | From USD 5,000 (Web Application package). Remediation testing is listed on the USD 9,500 and USD 20,000 packages. | Yes | HIPAA, PCI-DSS, SOC 2, ISO 27001, SEC | From 5 business days, covering testing, reporting and final delivery | 433 Broadway, 5th Floor, New York, NY 10013 |
| Echelon Risk + Cyber | Consultant-led testing following PTES | not published | not published | CMMC, HIPAA, HITRUST, ISO 27001, NIST CSF, FFIEC, NCUA, GLBA, FISMA, SOC 2, PCI DSS | not published | US locations listed: Pittsburgh, Austin, Charlotte, Atlanta, Raleigh, Philadelphia |
| Kroll | In-house team of certified pen testers | could not verify | could not verify | not published | could not verify | One World Trade Center, 285 Fulton Street, 31st Floor, New York, NY 10007 |
| NetSPI | Human-delivered PTaaS, in-house testers | not published | not published | not published | not published | not published |
| Packet33 | Senior practitioner-led testing at a fixed price per scope | Web and API testing USD 8,000 to USD 30,000. External network testing USD 10,000 to USD 25,000. | not published | SOC 2, HIPAA, ISO 27001, CIS | “Most engagements complete in 1-3 weeks from kickoff.” | not published |
| Praetorian | Engineer-led testing on a proprietary platform | not published | Yes | FDA, GLBA, HIPAA, NERC, PCI-DSS | not published | 3801 N Capital of Texas Hwy, Ste E240 Unit #3421, Austin, TX 78746 (mailing address in its terms of service) |
| Rapid7 | Consultant-led point-in-time assessments, stated as 85% manual and 15% automated | not published | not published | NIST, CIS Top 20 (named in its service brief) | not published | 120 Causeway Street, Suite 400, Boston, MA 02114 (Global Headquarters) |
| Red Sentry | Human-led pentesting delivered through a PTaaS platform | not published | Yes | SOC 2, ISO 27001, HIPAA, PCI DSS | Findings “in weeks, not months” | 3490 Piedmont Rd. NE, Suite 1350, Atlanta, GA 30305 |
| Rhino Security Labs | Mostly manual, engineer-led assessments | Stated as “generally start around the $10,000 range”, growing to six figures for large, in-depth projects. | not published | PCI, HIPAA, SOC 2 | Projects start at about one week and most run multiple weeks; the schedule can be booked 2 to 6 weeks out | 464 12th Ave, Suite 300, Seattle, WA 98122 |
| Software Secured | Human-led PTaaS subscription with full-time pentesters | From USD 21,400 (PTaaS) | Yes | SOC 2, ISO 27001 | Scheduling within 3 to 6 weeks; report within 48 to 72 hours of test completion | 301 Moodie Dr, Unit 108, Ottawa, ON K2H 9C4, Canada |
| Stingrai | Autonomous agent alone, or together with human pentesters, on a PTaaS platform | USD 3,000 one-time (Autonomous Pentest). USD 6,800 one-time (Hybrid Pentest). One web app plus its APIs. | Yes | SOC 2, HIPAA, PCI DSS, ISO 27001 | Autonomous Pentest: “Same-day results” | 1 Adelaide Street East, #3001, Toronto, Ontario M5C 2V9, Canada (HQ) |
| Synack | Vetted researcher team, on demand | AI Sara Pentest from USD 4,181. Standard Pentest from USD 10,283. Synack14 Pentest from USD 27,120. | not published | FedRAMP moderate designation | “Launch tests in days, not weeks” | not published |
The Matproof, Astra Security, Cobalt, NetSPI and Synack rows were read on 8 September 2026; all other rows, and Synack's price, on 15 September 2026, each from the provider's own website. “Not published” means the pages we read carry no such value; it is not a criticism and not a “no”. “Could not verify” means we could not read that part of the site. “Frameworks named” records which frameworks a provider names on the page we read. It is not a statement that the provider holds a certification or an accreditation, or that it is audited against the framework. “Stated location” is whatever the provider states, including mailing addresses, and is not normalised. Row order carries no judgement.
- Matproof: “3 full Sentinel pentests per month … Remediation-diff metric across re-tests” https://matproof.com/pricing
- Astra Security: “Pentest report for SOC2, ISO27001, HIPAA etc. compliances” https://www.getastra.com/pricing
- Bishop Fox: “Findings are delivered in the portal as they are validated, and most tests are completed within two to five business days.” https://bishopfox.com/services/penetration-testing-services
- BreachLock: “Every BreachLock pentest is conducted by in-house certified pentesters across the U.S., Europe, and Asia carrying certifications including CREST, OSCP, OSCE.” https://www.breachlock.com/pricing/penetration-testing-pricing/
- Bright Defense: “Three fixed-scope plans (Ignite, Elevate, and Summit) so you know the cost before you start.” https://www.brightdefense.com/penetration-testing/
- Coalfire: “DivisionHex unites Coalfire’s 20+ years of 3PAO expertise with hacker-level testing to meet PCI, HIPAA, and FedRAMP standards — fast, accurate, and audit-ready.” https://coalfire.com/services/security/offensive-security-services-coalfire-divisionhex
- Cobalt: “unlimited on-demand retesting throughout your contract term” https://www.cobalt.io/pricing
- CYBRI: “CYBRI Pen Tests are on-demand hacker-powered penetration tests performed by one or two Red Team members.” https://cybri.com/pricing/
- Echelon Risk + Cyber: “Our penetration testing service follows the Penetration Testing Execution Standard (PTES), widely accepted and adopted as a best practice in the industry.” https://echeloncyber.com/services/offensive-security-and-testing/penetration-testing
- Kroll: “Kroll has built the foundation and experience needed to handle large-scale, complex penetration testing engagements, including for the world’s top companies in industries from media and entertainment to critical infrastructure.” https://www.kroll.com/en/services/cyber/threat-exposure-management/penetration-testing
- NetSPI: “human-delivered, contextualized pentesting services” with “350+ in-house pentesters” https://www.netspi.com/security-testing/penetration-testing-as-a-service/
- Packet33: “Most engagements complete in 1-3 weeks from kickoff.” https://packet33.com/services/pentesting/
- Praetorian: “We guide fixes, re-test, and verify vulnerabilities are closed, completing the feedback loop.” https://www.praetorian.com/penetration-testing/
- Rapid7: “Testing methodology (85% manual, 15% automated) goes beyond validating technology driven scan results.” https://www.rapid7.com/services/penetration-testing/
- Red Sentry: “Human-led testing, a dedicated project manager, findings delivered live, audit-ready reports mapped to SOC 2, HIPAA, and PCI DSS with a letter of attestation, a free remediation re-test, and ongoing platform access.” https://redsentry.com/pentest-cost
- Rhino Security Labs: “The amount of manual work varies project-to-project, but around 95% of the pentest is hands-on.” https://rhinosecuritylabs.com/assessment-services/penetration-testing-faq/
- Software Secured: “Frequent, human led pentesting aligned to releases; we prove exploitability, verify fixes through unlimited retesting, and deliver stakeholder-ready evidence that accelerates audits and approvals.” https://www.softwaresecured.com/service/penetration-testing-as-a-service
- Stingrai: “Every reported vulnerability is verified by our penetration testers, who work alongside Snipe throughout the engagement.” https://www.stingrai.io/pricing
- Synack: “Synack14 provides a two-week process for pentesting while Synack90 and Synack365 provide 90-day and year-round options respectively” https://www.synack.com/platform/pricing/
Fit
Who each provider is the right answer for.
One line per provider, written from what they publish about their own service.
| Provider | The right answer when |
|---|---|
| Matproof | Teams that need a repeatable report for an ISO 27001 or SOC 2 audit and want the price published before they talk to anyone. |
| Astra Security | Buyers who want one supplier for an automated scanner and a human pentest, with both prices on the page. |
| Bishop Fox | Enterprises with large application portfolios that want AI-assisted testing with findings validated by a Bishop Fox tester. |
| BreachLock | Teams that want in-house testers on a platform for one-time, periodic or continuous pentests. |
| Bright Defense | Companies that need a fixed-price web and API pentest report for SOC 2, ISO 27001, PCI DSS or CMMC. |
| Coalfire | Organizations that need offensive testing aligned with PCI, HIPAA or FedRAMP from a firm that states 3PAO experience. |
| Cobalt | Buyers who want a named human tester pool and can accept a quote for everything above the entry test. |
| CYBRI | Companies that want a fixed-price, manual-first pentest of a web app, API, cloud or network. |
| Echelon Risk + Cyber | Organizations that need testing mapped to regulated-industry standards such as CMMC, HITRUST, FFIEC, NCUA or PCI DSS. |
| Kroll | Large organizations that want complex or large-scale pentest programs next to an incident response practice. |
| NetSPI | Large estates that want one supplier across network, cloud and application testing, on a quote. |
| Packet33 | SaaS and healthtech startups that need a fixed-price pentest report for a SOC 2, HIPAA or ISO 27001 audit. |
| Praetorian | Organizations that want a single assessment or a continuous testing program across applications, cloud, network, IoT and AI systems. |
| Rapid7 | Organizations that want point-in-time network, web app, IoT, wireless, social engineering or red team tests. |
| Red Sentry | Teams that test more than once a year and want live findings and a free remediation re-test. |
| Rhino Security Labs | Organizations that want mostly manual testing, with a focus on AWS, GCP and Azure cloud, network and web applications. |
| Software Secured | Software teams that ship often and want recurring manual pentests aligned to releases. |
| Stingrai | Teams that need a pentest of one web app and its APIs at a published fixed price, autonomous or with human testers. |
| Synack | Buyers with a US public sector requirement, or who want a continuous engagement rather than one test. |
Method
How we chose and compared.
We asked ChatGPT (gpt-4.1 with web search) and Perplexity (sonar) six questions a US buyer asks, about SOC 2, HIPAA, cost, PTaaS, AI testing and the best providers for a mid-sized company. We listed every provider they named, added page one of Google US for “penetration testing companies”, and read each provider's own website.
For every row we read the penetration testing page, the pricing page where one exists, and the contact, company or legal page for the location. A script compared each quoted value against the saved page text. We used no review sites, no analyst reports and nothing from memory.
Matproof publishes this page and sells one of the products in it. Our row carries sources like every other row, and it says what does not flatter us: we sell an automated platform with no human tester, billed in EUR, and we publish no turnaround time.
All sources
- Matproof
https://matproof.com/pricinghttps://matproof.com/trust - Astra Security
https://www.getastra.com/pricing - Bishop Fox
https://bishopfox.com/services/penetration-testing-serviceshttps://bishopfox.com/services/penetration-testing-services/ai-powered-application-penetration-testinghttps://bishopfox.com/contact - BreachLock
https://www.breachlock.com/pricing/penetration-testing-pricing/https://www.breachlock.com/products/ptaas/ - Bright Defense
https://www.brightdefense.com/penetration-testing/https://www.brightdefense.com/contact-us/ - Coalfire
https://coalfire.com/services/security/offensive-security-services-coalfire-divisionhexhttps://coalfire.com/about/contact-us - Cobalt
https://www.cobalt.io/pricing - CYBRI
https://cybri.com/pricing/https://cybri.com/contact-us/ - Echelon Risk + Cyber
https://echeloncyber.com/services/offensive-security-and-testing/penetration-testinghttps://echeloncyber.com/contact - Kroll
https://www.kroll.com/en/services/cyber/threat-exposure-management/penetration-testinghttps://www.kroll.com/en - NetSPI
https://www.netspi.com/security-testing/penetration-testing-as-a-service/ - Packet33
https://packet33.com/services/pentesting/https://packet33.com/contact/ - Praetorian
https://www.praetorian.com/penetration-testing/https://www.praetorian.com/terms-of-service/ - Rapid7
https://www.rapid7.com/services/penetration-testing/https://www.rapid7.com/cdn/assets/bltae59f6d57e921f52/67cf46eb5baf4854743a9de7/penetration-testing-services-brief.pdfhttps://www.rapid7.com/contact/ - Red Sentry
https://redsentry.com/pentest-costhttps://redsentry.com/ptaashttps://redsentry.com/https://redsentry.com/terms-and-conditions - Rhino Security Labs
https://rhinosecuritylabs.com/assessment-services/penetration-testing-faq/https://rhinosecuritylabs.com/assessment-services/network-penetration-testing/https://rhinosecuritylabs.com/contact/ - Software Secured
https://www.softwaresecured.com/service/penetration-testing-as-a-servicehttps://www.softwaresecured.com/contact-us - Stingrai
https://www.stingrai.io/pricinghttps://www.stingrai.io/contact-us - Synack
https://www.synack.com/platform/pricing/https://www.synack.com/platform/
What we could not source, and how to read some cells
- Named in the US answers but not yet in this table, because we have not read their sites: UnderDefense, Mandiant, Secureworks, ScienceSoft, PurpleSec, Qualysec, Pentest Express, Pentest Testing Corp, Invadel and Clearwater. We add a row when we have read the provider's own pages, not before.
- Blaze Information Security: its site served a bot check to every reader we tried on 15 September 2026, so there is no row.
- Kroll: price, retest and timing could not be read. See the FAQ.
- Bishop Fox: the two to five business days apply to its AI-Powered Application Penetration Testing only, not to all services.
- Rapid7: its penetration testing page names no framework. NIST and CIS Top 20 come from the service brief PDF linked from that page.
- Rhino Security Labs: the price is a stated starting range from its FAQ, not a list price. It describes a revisit after patching as an additional service without saying whether it costs extra, so the retest cell says “not published”.
- Packet33: the pentest page gives “1-3 weeks from kickoff” and, in a headline, delivery in two weeks. We print the range. We found no address on its site.
- Praetorian lists a re-test as a step in its process but does not say whether it costs extra. Its address is the mailing address in its terms of service. Red Sentry's address comes from its terms page, and it states that it publishes no price packages.
- Echelon Risk + Cyber lists six US cities and no street address.
FAQ
Common questions about US penetration testing companies
Which penetration testing company is best in the US?
It depends on what the report is for. If you need a fixed price for a SOC 2 or ISO 27001 audit, Bright Defense publishes three plans from USD 2,750 and Packet33 publishes ranges from USD 8,000. If PCI, HIPAA or FedRAMP drives the test, Coalfire names all three and states 3PAO experience. If you want mostly manual work, Rhino Security Labs states around 95 per cent hands-on and Rapid7 states 85 per cent manual. If you want AI-assisted testing checked by people, Bishop Fox and Stingrai say their testers validate findings. If you want repeatable automated evidence at a published monthly price, Matproof publishes EUR 299 per month, with no human tester. All values from the providers' own pages.
How much does a penetration test cost in the US?
10 of the 19 providers here publish a figure on their own site: Matproof, Astra Security, Bright Defense, Cobalt, CYBRI, Packet33, Rhino Security Labs, Software Secured, Stingrai and Synack. Examples: Bright Defense USD 2,750 to USD 9,250 per plan, Stingrai USD 3,000 for an autonomous test and USD 6,800 for a hybrid test, Packet33 USD 8,000 to USD 30,000 for web and API testing, and Rhino Security Labs stating that tests generally start around USD 10,000. For dated market ranges by scope and the rules that force a test, read our US cost guide at matproof.com/blog/penetration-testing-cost-usa-2026.
Does a US penetration testing company need a certification?
No US rule we read names one. PCI DSS v4.0 requirement 11.4 asks for a qualified internal resource or qualified external third party with organizational independence. NYDFS 23 NYCRR 500.5 asks for a qualified internal or external party. Neither names CREST, OSCP or any other credential. Individual tester certifications are a market signal. Your QSA, auditor or customer contract may still ask for one, so read it before you shop.
Why are Canadian and European providers on a US list?
Because US buyers are pointed to them. Stingrai and Software Secured state addresses in Canada, and both were named in the US answers we collected. BreachLock states offices in New York and Amsterdam. The location column prints what each provider states, so you can filter on it if your contract requires US-based testing. Matproof's platform is hosted in Germany.
Why does the table say “could not verify” for Kroll?
Kroll's penetration testing page blocked our automated reader, and in a normal browser the answers to its cost, duration and retest questions did not load. We print “could not verify” for those cells instead of guessing. It is a statement about our reading, not about Kroll's service.
Next step
See your own attack surface first.
The free scan checks your public surface without an account and returns a report you can take to any provider above, including the ones that are not us.
Run the free scan