Research for buyers
Penetration testing companies, independently compared.
Compare offers by scope, price, testing approach and retest terms. See which options deserve a closer look, what could rule them out and the questions to resolve before booking.
Choose what needs testing and prepare a scope checklist for the providers you contact.
Penetration testing companies compared
Selected offers from eight companies, with a focus on web applications and APIs. Compare the specific offer: the same company may sell human testing, AI testing and scanning separately.
Companies appear A to Z within each group. This is not a ranking. Prices are in US dollars for the stated package; “not stated” means the detail was not found in the sources reviewed. Sources and check dates
Tests led by people
These offers include human testing. The scope, use of automation and amount of testing still need to match your project.
| Company and offer | Who tests; what is covered | Published price and commitment | Retesting | Stated timing | Next step |
|---|---|---|---|---|---|
| AstraPentest Expert | Human testers plus autonomous agents. One web or SaaS app and its consumed APIs count as one target. | $5,999/year per target. Includes a manual pentest and ongoing scanning; confirm the target count. | Two manual re-scans; request within 30 days of findings being reported. Policy (Astra source: Rescan rules) | Manual exercise: 10–20 working days in its help documentation; scope and workload affect timing. Details (Astra source: Testing duration) | |
Sources and check details: Astra · Pentest Expert
| |||||
| Bishop FoxApplication penetration testing | Assessors use manual and automated testing; selected for application type and programming language. | Quote required. Confirm scope, effort and total commitment. | Count and window not stated. | Booking and report dates not stated. | |
Sources and check details: Bishop Fox · Application penetration testing
| |||||
| BreachLockStandard / Extended / Extensive | In-house testers. Application and network scope agreed for the project; platform access is optional. | Quote required. Package and scope determine the offer. | One / two / custom manual retests, respectively; window not stated. | Booking and report dates not stated. | |
Sources and check details: BreachLock · Standard / Extended / Extensive
| |||||
| CobaltStandard / Premium / Enterprise | Vetted testers with AI-supported delivery; scoped engagements. | Quote required. Annual credit packages; confirm credits needed and the applicable unused-credit terms. | Six / twelve / twelve months, subject to the active-contract cutoff below. | Advertised starts: three / two / one business days by tier after submitting the pentest for review; submissions after the stated 11 a.m. PST cutoff add one business day. Engagement-dependent. Scheduling rules (Cobalt source: Scheduling and submission cutoff) | |
Sources and check details: Cobalt · Standard / Premium / Enterprise
| |||||
| NetSPIPTaaS | In-house testers. Application, API, network, cloud and other specialist services. | Quote required. Confirm the exact service and commitment. | Remediation testing listed; count and window not stated. | Booking and report dates not stated. | |
Sources and check details: NetSPI · PTaaS
| |||||
| Pentest-Tools.comManaged web app testing | Manual testing of a web app. Black box covers an anonymous attacker; gray box includes authenticated roles. | $3,400 for the black-box offer. Gray box starts at $3,400 + $900 per user role. | Count and window not stated. | Black box: three working days, best effort; report on day four. Gray box: four or more working days; report when ready. | |
Sources and check details: Pentest-Tools.com · Managed web app testing
| |||||
| SynackSynackST | One human tester. Up to 25 unauthenticated web apps, one low-complexity authenticated app, or 100 host IPs. | From $10,283/test. Required platform line item is separate. | Patch verification listed; count and window not stated. | Five-day assessment window. | |
Sources and check details: Synack · SynackST
| |||||
| SynackSynack14 | Researcher team. Up to 50 unauthenticated web apps, one authenticated app, or 250 host IPs. | From $27,120/test. Required platform line item is separate. | Patch verification listed; count and window not stated. | Fourteen-day assessment window. | |
Sources and check details: Synack · Synack14
| |||||
Cobalt’s retest limit matters: its documented six- and twelve-month periods apply to Agile and Comprehensive pentests while the contract remains active. Requests close at the earlier of the retest period’s end or ten days before the contract ends. Read the retest policy (Cobalt source: Retesting policy)
Cobalt’s credit rollover terms need written clarification: its Enterprise comparison table lists rollover of up to 10%, while the FAQ on the same pricing page says credits do not roll into the next contract. Ask which term will apply to your agreement. Compare both statements (Cobalt source: Pricing and offer terms, including conflicting rollover statements)
Tests led by AI
Read the human role in each offer. Having experts build a system, direct a test or check a fix are different services. Confirm that the testing approach meets your customer’s, auditor’s or security team’s requirements.
| Company and offer | Who tests; what is covered | Published price and commitment | Retesting | Stated timing | Next step |
|---|---|---|---|---|---|
| AstraPentest Auto | Autonomous testing for web and SaaS apps. | $2,999/year per target. | One manual re-scan; request within 30 days of findings being reported. Policy (Astra source: Rescan rules) | First report advertised the same day. | |
Sources and check details: Astra · Pentest Auto
| |||||
| CobaltAutonomous Pentest | AI testing with Cobalt Core testers directing scope, execution and quality; web applications. | $3,500/test promotion. Must start and finish before December 31, 2026. | Offer-specific allowance not stated. | Findings within 24 hours; report at engagement close. | |
Sources and check details: Cobalt · Autonomous Pentest
| |||||
| IntruderAI web app pentest | AI-powered white-box web app testing; code repository integration required. | $3,500/test on its pricing page. New-customer pricing differs in another official source; see below. | Unlimited retesting listed; time limit not stated. | Same-day reports advertised. | |
Sources and check details: Intruder · AI web app pentest
| |||||
| SynackSara Pentest | AI-led test of one low-complexity web app or 100 host IPs. | From $4,181/test. Required platform line item is separate. | Patch verification listed; count and window not stated. | Four- to five-day assessment window. | |
Sources and check details: Synack · Sara Pentest
| |||||
Price and credit terms to confirm: Intruder’s pricing page (Intruder source: Pentest pricing) lists $3,500 per test, while its cost article (Intruder source: Cost article) lists $4,000 for new customers and $3,500 for existing customers. Ask which applies. Synack requires a separate platform line item and also describes a free Basic tier; ask which platform your purchase requires and its complete price. Synack credits expire one year from the purchase date. Pricing and credit FAQ (Synack source: Testing packages, platform terms and credit expiry FAQ)
Timing above is the provider’s stated start, testing or reporting period—not a reserved delivery date. Ask for your actual report deadline in writing.
Which offers deserve a closer look?
Start with the requirement that would rule an offer out. These starting points follow the documented differences above.
| Your priority | Where to look first | What to confirm |
|---|---|---|
| A published price for human testing | Astra Pentest Expert and Pentest-Tools.com’s managed web app service. | Compare the annual package with the project offer; make sure authenticated roles and APIs are covered. |
| Several tests across the year | Cobalt’s annual credit packages. | Credits needed per engagement and written confirmation of the conflicting Enterprise rollover terms above. One credit represents eight equivalent testing hours across automation and human work. |
| A provider-employed testing team | BreachLock and NetSPI, which describe in-house delivery. | Who will test your systems, relevant experience, scope and report requirements. |
| Assessors familiar with your application technology | Bishop Fox describes selecting assessors for application type and language. | The proposed team’s relevant work and the testing effort in your quote. |
| An AI-led web app test | Astra Auto, Cobalt Autonomous, Intruder and Synack Sara. | Required access, human involvement, report acceptance and a confirmed delivery date. |
Already have a provider or a quote? Put it through the same six questions below. The useful outcome may be confirming the option you already have.
How we turn offer terms into a buying decision
The PenTest Index Purchase Check applies a buyer’s requirements to the terms of an exact offer—not to a company-wide score. Each finding shows the relevant evidence, what follows from it and the question still worth asking. Missing information remains unresolved.
Six things to settle before you book
Ask each company the same questions about the same project:
What will be tested?
Name the applications, APIs, user roles and environments. Ask what is excluded and whether testing covers the business workflows that matter to you.
Who will do the work?
Establish the human testing, AI testing and review included in this specific offer. Ask for experience relevant to your systems.
What report do you need?
Confirm your customer’s, auditor’s or security team’s requirements. Review a sample for scope, evidence, findings and remediation guidance.
What is the complete commitment?
Include required subscriptions, platform access, scope charges and renewal terms. Confirm whether you are paying for one test or a continuing package.
Who checks the fixes, and until when?
Confirm the retest count, window, when the window starts and what happens if remediation takes longer.
When will the report arrive?
Agree on scoping, access, the test start and report delivery. Include time for fixes and retesting if your recipient needs them completed.
Send each company the same brief so you can compare its answer to the same job.
Four worked Purchase Checks
Example brief: one SaaS web app and its API, two authenticated user roles, no source code access, and a manual check of fixes requested 45 days after findings are reported.
These are selected checks against an illustrative brief. Each row examines one purchase condition; it does not establish that the whole offer fits. Sources for these examples checked October 8, 2026.
| Purchase condition | What the published terms establish | Question to send the provider |
|---|---|---|
| Two authenticated user rolesMandatory in the brief | Supported · starting amount only Pentest-Tools.com gray box: $5,200 starting amount, calculated as $3,400 + (2 × $900). The complete price for the API, retesting and any additional scope is unresolved. Published formula (Pentest-Tools.com source: Managed web app testing) | “For this app, its API and two roles, what is the complete price, including a manual retest requested 45 days after findings are reported?” |
Rule and provenance: Two authenticated user roles, Pentest-Tools.com · Managed web app testing
| ||
| Manual retest requested on day 45Mandatory in the brief | Mismatch · included request window Astra Expert: outside the included request window. Its two manual re-scans must be requested within 30 days of findings being reported. Extensions are considered case by case. Rescan terms (Astra source: Rescan rules) | “Can you include a manual re-scan requested 45 days after findings are reported? Please confirm the extension and any added cost in writing.” |
Rule and provenance: Manual retest requested on day 45, Astra · Pentest Expert
| ||
| No source code accessMandatory in the brief | Mismatch · source code access Intruder’s listed offer: access mismatch. Its white-box workflow requires connecting a code repository. A different arrangement would need confirmation. Offer and workflow (Intruder source: Pentest pricing) | “Do you offer a test without access to our source code? Please confirm its scope, testing approach and price.” |
Rule and provenance: No source code access, Intruder · AI web app pentest
| ||
| Complete purchase commitmentMandatory in the brief | Unresolved · complete total SynackST: total unresolved. The test starts at $10,283; a platform line item is required, and a free Basic tier is also described. Which tier applies still needs confirming. Platform and test terms (Synack source: Testing packages, platform terms and credit expiry FAQ) | “Can SynackST cover this app and API, and is the Basic platform tier eligible? Please itemize the test, any required platform charge, when purchased credits expire and the full contractual commitment.” |
Rule and provenance: Complete purchase commitment, Synack · SynackST
| ||
These are our calculations and interpretations of published terms. No provider has quoted for this illustrative brief.
Carry the unresolved questions into your scope checklist, so each provider answers the requirements that matter to your purchase.
Get the answer for your next decision
| What you need to decide | Start here |
|---|---|
| Choose the testing surface | What needs testing and what to compare |
| Understand published purchase terms | Published prices and commitments |
| Clarify the recipient’s needs | Questions for your report recipient |
| Prepare the work description | Prepare your scope checklist |
| Compare proposals consistently | Questions to compare offers |
Scanning and tools you operate
These are separate purchases from the managed testing offers above. A tool subscription gives you software to use; it does not by itself commission an independent assessment.
| Company and plan | Published price | What you are buying | Next step |
|---|---|---|---|
| AstraScanner | $199/month or $1,999/year for one target. | Unlimited vulnerability scanning. | |
Sources and check details: Astra · Scanner
| |||
| IntruderScanning platform | Plan and target-based pricing; use its calculator. | Ongoing vulnerability scanning; check included target types and plan features. | |
Sources and check details: Intruder · Scanning platform
| |||
| Pentest-Tools.comNetSec | Advertised from $95/month for five assets; price varies by asset count and billing cycle. | A self-service network assessment and discovery toolkit. Its managed testing service is listed separately above. | |
Sources and check details: Pentest-Tools.com · NetSec
| |||
Who stands behind the comparison
Published by The PenTest Index. We are responsible for the research, comparisons and corrections on this page. We do not sell penetration testing services.
Our current comparison uses provider-published sources. We have not purchased the listed services or independently assessed their testing quality. Written confirmations, inspected samples and documented buyer outcomes are identified separately when available; they support only what was actually checked.
How we make money
We may earn a referral fee if you choose a provider through this site. Paid relationships are disclosed beside the relevant links.
Payment does not determine editorial inclusion, comparison order or which offer fits your needs. A suitable provider can be listed and recommended without paying us.
A few questions before you choose
Do I have to use Find My PenTest Match?
No. Browse the comparisons or visit a provider directly. Find My PenTest Match helps you choose what needs testing and prepare the questions and scope details to discuss with a provider.
Will a report meet my customer’s or auditor’s requirements?
Confirm the required scope, testing approach and deliverables with the recipient before booking. A provider’s compliance claim is not approval from your recipient. Intruder advertises a refund if an auditor rejects its report; that is a refund promise, not confirmation that your report will be accepted. Intruder’s published offer (Intruder source: Pentest pricing)
Do I need a company near me?
Not necessarily. Ask whether any work needs to happen on site, where the assigned testers will work, and whether your contract restricts tester location or data handling. Include time-zone requirements in your brief.
Sources
Full offer comparison checked October 7, 2026. Cobalt’s start-time and rollover terms and Synack’s credit-expiry terms were rechecked October 8, 2026. All reported offer details are provider-published unless otherwise noted.
| Provider | Sources reviewed | Checked |
|---|---|---|
| Astra | ||
| Bishop Fox | ||
| BreachLock | ||
| Cobalt | ||
| Intruder | ||
| NetSPI | ||
| Pentest-Tools.com | ||
| Synack |