main logo icon

Published on

August 21, 2026

|

19 min read

Best Cloud Penetration Testing Companies (2026 Ranked)

The best cloud penetration testing companies in 2026 are Stingrai, NetSPI, Bishop Fox, Rhino Security Labs, Praetorian, NCC Group, TrustedSec, Cobalt and Software Secured. Compare AWS, Azure and GCP depth, delivery model and published pricing.

Arafat Afzalzada

Arafat Afzalzada

Founder

Network SecurityWeb App Security

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

The best cloud penetration testing companies in 2026 are Stingrai, NetSPI, Bishop Fox, Rhino Security Labs, Praetorian, NCC Group, TrustedSec, Cobalt and Software Secured. Stingrai leads for buyers who want firm-level CREST accreditation, senior in-house cloud testers and both one-time annual engagements and continuous programmes, with published list pricing from US$3,000. NetSPI is the enterprise PTaaS pick, Bishop Fox the consulting heavyweight with a published cloud methodology, and Rhino Security Labs the boutique with the deepest public AWS tooling record through Pacu and CloudGoat. Praetorian splits cloud work into configuration review, penetration test and attack-path mapping. NCC Group brings global scale and CIS-benchmark configuration assessments across five cloud platforms including Oracle and Alibaba. TrustedSec builds cloud engagements on an assumed-access model, Cobalt sells cloud testing through a PTaaS credit model aligned to the OWASP Cloud-Native Top 10, and Software Secured runs a deliberately read-only cloud review with published pricing from US$6,200. Cloud penetration testing is the fastest-growing service line in the market, forecast at a 16.63 percent CAGR through 2031 by Mordor Intelligence. A scoped cloud penetration test generally runs US$10,000 to US$50,000 or more. AWS, Microsoft and Google all permit customers to test resources they own without prior approval, subject to each provider's published rules.

The best cloud penetration testing companies in 2026 are Stingrai, NetSPI, Bishop Fox, Rhino Security Labs, Praetorian, NCC Group, TrustedSec, Cobalt and Software Secured. Stingrai ranks first for buyers who want firm-level accreditation, senior in-house cloud testers and a choice between a one-time annual engagement and a continuous programme, with list pricing published rather than quoted on request. NetSPI is the pick for enterprise-scale PTaaS across AWS, Azure and Google Cloud. Bishop Fox is the consulting heavyweight with a published cloud testing methodology. Rhino Security Labs is the boutique with the strongest public AWS tooling record. Praetorian, NCC Group, TrustedSec, Cobalt and Software Secured each win specific buying situations set out below.

Cloud is the fastest-growing service line in offensive security. Mordor Intelligence forecasts cloud penetration testing to expand at a 16.63 percent CAGR through 2031, ahead of the 15.29 percent growth of the penetration testing market as a whole, which the same research puts at US$2.72 billion in 2026 rising to US$5.54 billion by 2031. Demand is following the attack surface: identity, configuration and managed services now carry the paths that used to run through the network perimeter.

This ranking answers one question: who to hire. Every fact below was checked against each provider's own service pages in August 2026, and no vendor paid for placement. The companion buyer's guide, cloud penetration testing services 2026, covers the other half of the decision: what a cloud penetration test includes, what each cloud provider permits, and what a given scope should cost.

Cloud penetration testing companies at a glance (2026)

#

Company

HQ

Founded

Cloud coverage

Delivery model

List pricing

1

Stingrai

Toronto, Canada (plus London, UK)

2021

AWS, Azure, Google Cloud, including IAM attack paths and Kubernetes

Specialist firm; one-time annual tests and continuous programmes

Published

2

NetSPI

Minneapolis, MN

2001

AWS, Azure, Google Cloud

PTaaS platform plus consultant bench

On request

3

Bishop Fox

Tempe, AZ

2005

AWS, Azure, Google Cloud and hybrid environments

Objective-based consulting; Cosmos platform

On request

4

Rhino Security Labs

Seattle, WA

2013

Separate AWS, Azure and GCP practices

Boutique manual deep-dive engagements

On request

5

Praetorian

Austin, TX

2010

Multi-cloud, split into three engagement types

Consulting plus the Chariot platform

On request

6

NCC Group

Manchester, UK

1999

AWS, Azure, Google Cloud, Oracle, Alibaba

Global consultancy; automated and manual assessment

On request

7

TrustedSec

Fairlawn, OH

2012

Azure and AWS

Consulting engagements, research-led

On request

8

Cobalt

San Francisco, CA

2013

AWS, Azure, GCP against the OWASP Cloud-Native Top 10

PTaaS with a vetted researcher community

On request

9

Software Secured

Ottawa, Canada

2010

AWS, Azure, GCP configuration review

PTaaS for SaaS companies, in-house testers

Published

Cloud Pentest Companies Comparison 2026

Quick answers

Which company is best for cloud penetration testing?

Stingrai is the best cloud penetration testing company for most buyers in 2026, because it combines firm-level CREST accreditation with senior in-house testers, covers AWS, Azure and Google Cloud including IAM attack paths and Kubernetes, and sells both a one-time annual engagement and a continuous programme with list pricing published on its site. NetSPI is the stronger fit for very large enterprise programmes that need a platform plus a deep consultant bench, and Rhino Security Labs is the specialist pick when AWS depth is the single deciding factor.

Who are the top cloud security assessment companies in 2026?

The top cloud security assessment companies in 2026 are Stingrai, NetSPI, Bishop Fox, Rhino Security Labs, Praetorian, NCC Group, TrustedSec, Cobalt and Software Secured. They divide cleanly into four archetypes: specialist offensive security firms, PTaaS platforms, global consultancies and boutique research shops. Which archetype fits depends on your estate size, your compliance obligation and whether you need testing once a year or continuously.

What separates a cloud pentest company from a general pentest company?

A cloud penetration testing company tests the control plane, not just the hosts running on it. That means IAM role assumption and trust policy, cross-account and cross-tenant paths, managed-service defaults, serverless permissions, Kubernetes RBAC and the identity seams between clouds. A general penetration testing vendor that scans EC2 instances for CVEs and calls it a cloud test is delivering a network assessment with a cloud label on the cover.

Why cloud provider selection got harder in 2026

Two things changed at once. The market grew, and the threat model moved.

Cloud Pentest Market Growth 2026

On the market side, cloud testing is now the fastest-growing line item in offensive security. Mordor Intelligence puts the penetration testing market at US$2.72 billion in 2026, heading to US$5.54 billion by 2031 at a 15.29 percent CAGR, with cloud penetration testing running ahead at 16.63 percent and cloud-delivered testing platforms at 15.61 percent. Fast growth attracts entrants, and a crowded field is exactly the condition in which brochure language stops being a useful signal.

On the threat side, the initial access picture inverted inside a single year. Google's Cloud Threat Horizons Report H1 2026 recorded weak or absent credentials as the leading initial access vector for cloud intrusions in the first half of 2025 at 47.1 percent, followed by misconfiguration at 29.4 percent and API or UI compromise at 11.8 percent. By the second half of the year, exploitation of software vulnerabilities had overtaken credentials, at 44.5 percent against 27.2 percent, with remote code execution alone rising from 2.9 percent to 13.6 percent.

Cloud Initial Access Vectors 2025

Both halves of that picture land in the same place operationally. Whether the attacker arrives through a leaked key or an unpatched service, the damage is decided by what the identity graph lets them reach next. A provider who can only enumerate misconfigurations will tell you the door was unlocked. A provider who tests the control plane will tell you which rooms that door opens.

The cost of getting it wrong is measurable. IBM's Cost of a Data Breach Report 2026 puts the global average breach at US$4.99 million, rising to US$6 million where the breach was AI-enabled, and found cloud misconfigurations among the factors in 27 percent of breaches that targeted AI models or applications.

How we ranked these companies

Seven criteria, applied in this order. Each is checkable from public sources rather than from a sales conversation.

  1. A productised cloud offering, not an adjacent one. The provider must sell cloud penetration testing as a named service with its own scope, not fold it into a generic infrastructure test. Vendors whose cloud story is a line item on a network testing page were not considered.

  2. Control-plane depth over configuration breadth. Does the published methodology reach IAM privilege escalation, role assumption, trust policy and cross-account paths, or does it stop at benchmark comparison? Both have value, and the ranking distinguishes them rather than treating them as equivalent.

  3. Per-cloud specificity. AWS accounts and roles, Azure subscriptions and Entra ID, and Google Cloud projects and service-account impersonation are three different identity models. Providers who address them separately outrank providers who publish one undifferentiated cloud page.

  4. Verifiable public research or tooling. Open-source cloud tooling, published methodologies, disclosed vulnerabilities and conference research are checkable proof of depth. Customer logos are not.

  5. Delivery-model fit. One-time annual engagement, continuous programme, platform subscription and brokered marketplace suit different buyers. The ranking rewards providers who are explicit about which they sell.

  6. Independence and accreditation. Firm-level accreditation, in-house employed testers and independence from the cloud provider being assessed all matter to an auditor or an enterprise security reviewer.

  7. Pricing transparency. Publishing list prices is a real buyer service and a real commercial risk. Providers who publish were credited for it.

Two disclosures. First, Stingrai publishes this ranking and appears in it at number one, so weigh our self-assessment against the checkable signals listed in that entry rather than against the ranking position. Second, this is a snapshot: every claim was verified against provider service pages in August 2026, and provider offerings change. Where a provider's own page did not state a fact, that fact was left out rather than estimated.

1. Stingrai

Best for enterprise-grade PTaaS powered by Snipe, its proprietary AI pentesting agent, working alongside certified human pentesters throughout every engagement (CREST-accredited firm), for one-time or continuous testing in highly regulated industries with SOC 2, ISO 27001, PCI DSS and CMMC compliance programs.

Stingrai is an offensive security firm headquartered in Toronto with a London office, founded in 2021. Cloud engagements are run by its senior human penetration testers, who work the control plane directly: IAM privilege escalation and role assumption on AWS, application registrations and Conditional Access gaps on Azure and Entra ID, service-account impersonation and IAM Conditions on Google Cloud, plus Kubernetes RBAC, serverless permissions and the identity seams that appear in multi-cloud estates. Where the scope includes the web and API layers sitting on top of that infrastructure, Snipe, Stingrai's autonomous AI penetration testing agent for web applications, tests concurrently with the human team rather than after it. The testers direct where Snipe focuses, then take the application-layer findings it surfaces and pursue them onward through the cloud control plane themselves. Both contribute findings across every severity.

Snipe is built to hunt complex classes rather than known-class bugs: IDOR, broken authorisation and business logic flaws. It performs black-box dynamic testing and white-box source review, generates AutoFix pull requests, and can run as a pull-request gating check. It was custom-trained on more than 6,000 HackerOne Hacktivity disclosure reports and on skills distilled from years of Stingrai's own pentesters' methodology.

At a glance

Signal

Detail

Founded

2021

Headquarters

Toronto, Ontario, Canada, with a London, UK office

Accreditation

CREST-accredited penetration testing service provider at firm level

Team certifications

OSCE3, OSCP, OSWE, OSED, OSEP, CREST CRT, CISSP, CRTO, GCPN, CRTE, eWPTX

Published research

18 CVEs; research presented at DEFCON and BSides

Reputation

5.0 out of 5.0 across 19 Clutch reviews

Delivery

Annual one-time cloud penetration tests and continuous testing programmes

Cloud scope

AWS, Azure and Google Cloud, including IAM attack paths, Kubernetes, serverless and multi-cloud identity seams

Pricing

Published list pricing from US$3,000 one-time, with cloud scope quoted against estate complexity

Why Stingrai ranks first

Firm-level CREST accreditation is the accreditation an enterprise reviewer actually asks about, and it is distinct from an individual tester holding CREST CRT. Stingrai holds the firm-level credential, and the distinction is unpacked in our guide to CREST-accredited penetration testing companies. The 18 published CVEs and the DEFCON and BSides research record are checkable rather than asserted. Delivery is explicit in both directions: a one-time annual cloud penetration test for a specific audit or enterprise security review, and a continuous programme for estates that change weekly. And list pricing is published on the Stingrai pricing page, starting at US$3,000 one-time or US$450 per month for the Autonomous tier and US$6,800 one-time or US$1,275 per month for the Hybrid tier, with cloud scope beyond those tiers quoted against account count, IAM complexity and managed-service surface.

Pros

  • Firm-level CREST accreditation, not just individual tester certifications.

  • Senior in-house testers on cloud engagements, with continuity between the test and the retest.

  • Explicit support for both one-time annual engagements and continuous programmes.

  • Published list pricing rather than quote-on-request for the productised tiers.

  • Testing evidence mapped to SOC 2, ISO 27001, PCI DSS 4.0, HIPAA, NIST SP 800-53 and 800-171, DORA and NIS2 programmes.

Cons

  • Smaller bench than a global consultancy, so peak audit season needs earlier booking.

  • No brokered researcher crowd, which some buyers specifically want for breadth.

  • Not the fit for buyers who need a named partner in every jurisdiction as part of a wider advisory contract.

Related pages: PTaaS, red teaming and get a quote.

2. NetSPI

Best for enterprise-scale cloud testing programmes that need a platform and a deep consultant bench.

NetSPI was founded in 2001 and is headquartered in Minneapolis, with further offices in Portland, Kansas City, Toronto, London and Pune. Its cloud offering is sold as Cloud Pentesting, described on its own site as securing "AWS, Azure, and Google Cloud (GCP) infrastructures", with dedicated sections for each of the three providers and delivery through the NetSPI Platform. That platform bundles penetration testing as a service with attack surface management and breach and attack simulation, and NetSPI also sells continuous Cloud Security Scans for AWS and Azure as a separate posture capability.

The buying case is scale. NetSPI is built for organisations running many cloud accounts across several business units, where the operational problem is not finding one vendor for one test but running a testing programme with consistent reporting and real-time collaboration across a large internal security team. The platform is the product as much as the testing is.

Watch for: the platform-plus-bench model means the proportion of manual testing in any given engagement is a scoping decision. Get the manual-to-automated split written into the statement of work, and confirm whether continuous cloud scanning is included or priced separately from the penetration test.

3. Bishop Fox

Best for objective-based cloud engagements where you define the scenario and want a published methodology behind it.

Bishop Fox has been operating in offensive security since 2005, is headquartered in Tempe, Arizona, and was co-founded by Vincent Liu and Francis Brown. Its cloud penetration testing service covers AWS, Azure, Google Cloud and hybrid environments, and combines configuration review with penetration testing rather than treating the two as alternatives. The firm publishes a downloadable Cloud Penetration Testing Methodology, which is a genuine buyer service: you can read how the work is structured before you sign anything.

Bishop Fox describes its cloud engagements as objective-based, with the client defining the scenario, which suits organisations that already know their crown-jewel assets and want a test framed around reaching them rather than a broad sweep. Its Cosmos platform and Cosmos AI Engine sit alongside the consulting practice for continuous attack surface work. On its own about page, Bishop Fox states that 26 of the Fortune 100 have engaged its services.

Watch for: Bishop Fox is a consulting engagement, priced accordingly, and cloud work competes internally for the same senior bench as its red team practice. Confirm tester seniority and start dates in writing.

4. Rhino Security Labs

Best for AWS depth, and for buyers who weight public offensive tooling above firm size.

Rhino Security Labs is a Seattle boutique founded in 2013 by Benjamin Caudill. It publishes separate AWS, Azure and GCP penetration testing practices rather than one undifferentiated cloud page, which is the single clearest structural signal in this ranking that a provider understands the three identity models are not interchangeable.

Its strongest credential is public and checkable. Rhino built and maintains Pacu, the open-source AWS exploitation framework, released at BSidesLV in August 2018 and now a standard tool in cloud offensive testing, and CloudGoat, a vulnerable-by-design AWS environment used across the industry for training and research. Very few providers in this market have shipped tooling that their own competitors use. The firm describes its work as manual, deep-dive engagements, which is the right posture for IAM privilege-escalation chains.

Watch for: boutique capacity. A small firm with a strong reputation books out, and multi-cloud or Kubernetes-heavy estates may need a broader bench than a boutique can field in a single cycle.

5. Praetorian

Best for buyers who want cloud work split into distinct, separately scoped engagement types.

Praetorian was founded in 2010 in Austin, Texas by Nathan Sportsman. Its cloud practice is unusually explicit about scope boundaries, publishing three separate engagement types: a Cloud Security Configuration Review, a Cloud Penetration Test and Cloud Attack Path Mapping. That structure is useful during procurement, because it forces the conversation most vendors avoid, namely whether you are buying a benchmark comparison or a proof of exploitability. Praetorian documents a seven-step delivery process running from environment examination through attack-path enumeration, threat modelling, test-case execution, reporting and a technical briefing.

Alongside the services practice, Praetorian runs Chariot, its continuous threat exposure management platform, and publishes open-source security tooling including Aurelian for multi-cloud testing. Its own company page describes its services professionals as security engineers rather than consultants, and that engineering-led culture shows in the tooling output.

Watch for: the three-engagement structure is a strength during scoping and a cost consideration afterwards, because the configuration review and the penetration test are separate purchases. Decide which you need before you request pricing.

6. NCC Group

Best for global, multi-jurisdiction cloud programmes and estates beyond the big three providers.

NCC Group was founded in 1999, is headquartered in Manchester in the United Kingdom, and states on its own about page that it has more than 1,800 experts across the UK, Europe, North America and Asia Pacific. Its flagship cloud offering is the Cloud Configuration Assessment, which covers AWS, Azure, Google Cloud, Oracle and Alibaba, making it the broadest platform coverage in this ranking. The assessment blends automated and manual review, and NCC states that its proprietary configuration scanner incorporates cloud-provider CIS benchmarks and the AWS Well-Architected Framework. Container and orchestration review and infrastructure architecture review sit alongside it, and penetration testing and continuous penetration testing are sold as separate service lines.

The buying case is reach. If your estate spans jurisdictions, includes Oracle Cloud or Alibaba Cloud, or sits in a regulated sector that expects a named global assurance provider, NCC covers ground that boutiques cannot.

Watch for: the flagship cloud product is a configuration assessment, which is a different deliverable from an exploitation-based penetration test. If you need proof of chained attack paths rather than benchmark conformance, scope the penetration testing service explicitly alongside it.

7. TrustedSec

Best for assumed-breach cloud scenarios and buyers who value a strong public research culture.

TrustedSec was founded in 2012 by David Kennedy and is headquartered in Fairlawn, Ohio. Its cloud offering builds on a conventional uncredentialed penetration test with what the firm calls the Assumed Access Model, which it describes as revealing what an attacker would have access to if they compromised user credentials. That is the correct default posture for cloud, where the interesting question is almost never whether an attacker can get a foothold, but what a foothold reaches. TrustedSec names Azure and AWS on its cloud testing page, and recommends layering social engineering, an assumed-breach scenario or a compromised developer component onto a cloud assessment to surface realistic attack paths.

The firm's public footprint is substantial. Its own site reports 7,400 custom security engagements completed, seven zero-day exploits uncovered, more than 50 conference talks given yearly and a 92 percent net promoter score, and it maintains widely used open-source security tooling.

Watch for: Google Cloud is not named on the cloud testing page. If GCP is a material part of your estate, confirm coverage before scoping.

8. Cobalt

Best for fast starts and for teams that want cloud testing inside an existing PTaaS subscription.

Cobalt Labs was founded in 2013, is headquartered in San Francisco, and pioneered the pentest-as-a-service model. Its Cloud Pentest Service simulates attacks against AWS, Azure and GCP environments, with testing aligned to the OWASP Cloud-Native Top 10 and focused on identity and access management, storage, networking and compute. Cobalt is explicit that the service goes beyond configuration checks to exploitability, using manual techniques and chained exploits.

Speed is the differentiator Cobalt leads with, advertising that testing can start within 24 hours. Delivery runs through the Cobalt Core, a vetted researcher community the company sizes at more than 500 pentesters, against a credit model that lets you reallocate testing across assets during the year. Cobalt's own about page reports more than 5,000 pentests annually and 13 years of accumulated exploit data.

Watch for: tester continuity between cycles is the standing question with any brokered community model. Ask whether the same researchers return for the retest, and confirm assurance-letter and NDA posture if you are in a regulated sector. For a wider platform comparison see best PTaaS providers 2026 and Cobalt alternatives 2026.

9. Software Secured

Best for SaaS companies that want a low-disruption cloud review with published pricing.

Software Secured was founded in 2010 in Ottawa by Sherif Koussa, who also founded the OWASP Ottawa chapter. Its cloud offering is the Secure Cloud Review, covering AWS, Azure and GCP, and the company is unusually candid about what that is: a manual review conducted with read-only audit access, with, in its own words, "no exploit payloads involved". Scope covers identity and role enumeration, network segmentation and egress controls, storage policy, key management and secret rotation, backup and recovery readiness, and logging and detection coverage.

Read that positioning as a feature, not a limitation, provided it matches your need. Plenty of buyers want a rigorous configuration and identity review that cannot disturb production, and Software Secured publishes a starting price for it of US$6,200, alongside published prices for its other service lines. Its own site reports more than 2,000 penetration tests in the last five years across more than 350 customers.

Watch for: a read-only review does not produce proof of exploitability. If your auditor, your enterprise customer or your board wants a validated attack path rather than a prioritised list of findings, scope an exploitation-based penetration test instead or in addition.

What a cloud penetration test should cover, whoever you hire

Six layers, and a gap in any one of them is a gap an attacker or an enterprise security reviewer will find:

  • Identity and IAM. Privilege escalation chains, role assumption abuse, cross-account trust, confused-deputy paths, service-account impersonation. Detail in cloud IAM penetration testing.

  • Configuration and posture. Which flagged misconfigurations are genuinely reachable and chainable, and which are noise sitting behind a compensating control.

  • External network exposure. Internet-reachable services, exposed management interfaces, unintended public endpoints, segmentation failures.

  • Workloads and Kubernetes. Control-plane exposure, RBAC over-permissioning, container breakout, network policy gaps, secrets handling. Detail in cloud and Kubernetes scoping and cost.

  • Serverless and managed services. Function permissions, event-source injection, managed-service defaults, AI and inference infrastructure.

  • Data stores and secrets. Reachability of production data, object-store access policy, key and secret sprawl, encryption gaps.

Two things a cloud penetration test is not. It is not your cloud provider's audit package, which covers the provider's side of the shared responsibility line and explicitly lists the controls you own; the evidence auditors accept and reject is set out in why a cloud provider's compliance report is not your cloud pentest evidence. And it is not a CNAPP or CSPM, which enumerates misconfigurations continuously but structurally cannot prove which of them chain into a breach; the four blind spots are catalogued in CNAPP blind spots.

First-party automated testing sits in the same category. AWS Security Agent reached general availability in 2026 as on-demand automated testing priced per task-hour, and it is genuinely useful, but it is first-party, which is precisely the property that makes independent assurance independent. We worked through whether it satisfies an auditor in does AWS Security Agent replace a cloud penetration test.

How much does a cloud penetration test cost in 2026?

A scoped cloud penetration test generally runs US$10,000 to US$50,000 or more. Cloud is priced by environment complexity rather than by asset count, which is why quoting against a URL count tells a provider almost nothing.

Engagement scope

Typical range (USD)

What moves the number

Single-account configuration and IAM review

US$8,000 to US$15,000

Role count, federation, whether a grey-box foothold is provided

Standard cloud environment, one provider

US$10,000 to US$30,000

Account or subscription count, managed-service surface, region spread

Cloud plus Kubernetes scope

US$18,000 to US$45,000

Cluster count, RBAC complexity, workload and supply-chain depth

Multi-account or multi-cloud estate

US$30,000 to US$50,000+

Cross-cloud identity seams, CI/CD trust, number of organisation nodes

Objective-based cloud red team

US$40,000 to US$100,000+

Detection-evasion requirements, duration, whether the blue team is informed

Only two providers in this ranking publish list prices. Stingrai publishes productised tiers starting at US$3,000 one-time or US$450 per month, with the Hybrid tier at US$6,800 one-time or US$1,275 per month, and quotes cloud scope beyond those tiers against estate complexity; current figures are on the pricing page. Software Secured publishes a Secure Cloud Review starting at US$6,200. Everyone else quotes on request, which is normal for consulting-led delivery but makes comparison slower.

The full cost breakdown, including the five drivers that move a cloud quote more than anything else, is in cloud penetration testing services 2026 and the wider 2026 penetration testing cost guide.

Do AWS, Azure and GCP allow penetration testing?

Yes. As of August 2026, all three major cloud providers permit customers to test resources they own without prior approval, subject to each provider's published rules.

AWS states that customers "are welcome to carry out security assessments or penetration tests of their AWS infrastructure without prior approval" for the services on its permitted list, which covers EC2, RDS, CloudFront, Aurora, API Gateway, AppSync, Lambda, Lightsail, Elastic Beanstalk, ECS, Fargate, OpenSearch, FSx, Transit Gateway and Amazon Bedrock AgentCore. Denial of service testing, simulated DoS, port and protocol flooding, S3 bucket takeover, subdomain takeover and Route 53 DNS abuse are prohibited outright. Red, blue and purple team testing with command and control, simulated phishing, malware testing and iPerf testing require prior authorisation through the Simulated Events form.

Microsoft Azure removed the notification requirement on 15 June 2017, and its documentation states plainly that you do not need Microsoft's pre-approval. The Microsoft Cloud Unified Penetration Testing Rules of Engagement remain authoritative, and denial of service testing is prohibited under all circumstances; Microsoft lists approved simulation partners for DDoS resilience testing instead.

Google Cloud states that customers planning to evaluate the security of their own Cloud Platform infrastructure "are not required to contact us", subject to the Acceptable Use Policy and Terms of Service, and provided tests affect only your own projects.

Provider permission is separate from resource-owner authorisation, which still belongs in a signed scope agreement. The full rules of engagement, including the activities each provider treats as exceptions, are in cloud penetration testing rules of engagement for AWS, Azure and GCP.

How to choose between them

Eight checks, each answerable before you sign.

  1. Ask for a redacted sample report and look for an identity attack path drawn end to end. A report that lists CVEs on virtual machines is a network test wearing a cloud label.

  2. Establish whether you are buying a configuration review or an exploitation test. Both are legitimate deliverables and they cost different amounts. NCC Group's flagship cloud product is an assessment, Software Secured's is deliberately read-only, and Praetorian sells the two separately. Know which one your auditor is expecting.

  3. Check per-cloud specificity. Ask how the provider's Azure methodology differs from its AWS methodology. A vendor who cannot answer that in specifics is running one playbook across three identity models.

  4. Verify accreditation at the level you need. Firm-level CREST accreditation is a different credential from an individual tester holding CREST CRT. Both are worth having; conflating them is a common vendor tactic.

  5. Ask who actually tests, and whether they return for the retest. Employed testers, contracted associates and a brokered community are three different risk profiles for a regulated buyer.

  6. Get the manual-to-automated split in writing. Automated coverage belongs in any modern engagement. What you are paying a premium for is the manual attack-path work tooling cannot do.

  7. Confirm retest terms. Remediation without a retest closes nothing from an auditor's point of view. Ask whether retesting is bundled, time-boxed or billed separately.

  8. Match evidence output to your framework. Ask to see how findings map to SOC 2 Common Criteria, ISO 27001 Annex A or PCI DSS 4.0 requirements. The evidence auditors actually accept is catalogued in pentest evidence auditors accept.

Frequently Asked Questions

Which company is best for cloud penetration testing?

Stingrai is the best cloud penetration testing company for most buyers in 2026. It is a CREST-accredited penetration testing service provider at firm level, covers AWS, Azure and Google Cloud including IAM attack paths, Kubernetes and multi-cloud identity seams, and sells both a one-time annual engagement and a continuous programme with list pricing published from US$3,000. NetSPI is the stronger choice for very large enterprise programmes needing a platform plus a deep consultant bench, Bishop Fox for objective-based consulting engagements, and Rhino Security Labs when AWS depth is the deciding factor.

How much does a cloud penetration test cost?

A scoped cloud penetration test typically costs US$10,000 to US$50,000 or more in 2026. A single-account configuration and IAM review sits nearer US$8,000 to US$15,000, a Kubernetes-inclusive scope runs US$18,000 to US$45,000, and multi-cloud estates or objective-based cloud red teams go higher. Five factors drive the number: account and project count, cluster count and size, IAM complexity, whether the test is black-box, grey-box or white-box, and how much compliance-mapped reporting is required. Stingrai publishes list pricing from US$3,000 one-time or US$450 per month on its pricing page, and Software Secured publishes a Secure Cloud Review from US$6,200. Most other providers quote on request.

Do AWS, Azure and GCP allow penetration testing?

Yes. None of the three major providers requires prior approval to test resources you own. AWS permits testing without prior approval for the services on its published permitted-services list, Microsoft removed the Azure notification requirement on 15 June 2017, and Google states that customers evaluating their own Cloud Platform infrastructure are not required to contact them. The exceptions are the loud activities: AWS requires written pre-authorisation via its Simulated Events form for red team testing with command and control, simulated phishing and malware testing, and denial of service testing is prohibited outright on both AWS and Azure. Provider permission is separate from resource-owner authorisation, which still belongs in a signed scope agreement.

What are the top cloud security assessment companies in 2026?

The top cloud security assessment companies in 2026 are Stingrai, NetSPI, Bishop Fox, Rhino Security Labs, Praetorian, NCC Group, TrustedSec, Cobalt and Software Secured. They fall into four archetypes: specialist offensive security firms, PTaaS platforms, global consultancies and boutique research shops. Match the archetype to your estate size, your compliance obligation and your testing cadence rather than picking on brand recognition.

Which cloud penetration testing company is best for AWS specifically?

Rhino Security Labs has the strongest public AWS credential in this ranking, because it built and maintains Pacu, the open-source AWS exploitation framework released at BSidesLV in August 2018, and CloudGoat, the vulnerable-by-design AWS environment. Both are used across the industry, including by competitors. Stingrai, NetSPI and Bishop Fox all run mature AWS practices at larger scale, and Praetorian publishes a separate AWS-inclusive attack-path mapping engagement. If AWS depth is your single deciding factor, shortlist Rhino Security Labs and Stingrai and ask both for a redacted AWS IAM privilege-escalation finding.

What is the difference between a cloud security assessment and a cloud penetration test?

A cloud security assessment reviews configuration and identity against best practice and benchmarks, typically using read-only access, and produces a prioritised list of findings. A cloud penetration test attempts to exploit and chain those findings, and produces validated attack paths: this object store leaked a credential, that credential assumed this role, that role read the production database. Assessments give you breadth safely. Penetration tests give you proof of exploitability, which is what an auditor, an enterprise security reviewer and a board are usually asking for. Several providers sell both, and Praetorian prices them separately.

Does a cloud penetration test satisfy SOC 2, ISO 27001 or PCI DSS?

A cloud penetration test produces the technical testing evidence those frameworks expect, and one well-scoped engagement can serve several at once. For SOC 2 it evidences the separate evaluations expected under CC4.1 and feeds the CC4.2 remediation loop, and for a Type II report the test, the remediation and the retest all have to fall inside the observation period. For ISO 27001 it supports technical vulnerability management and independent review, and for PCI DSS 4.0 it covers annual internal and external testing plus segmentation validation. Your cloud provider's own audit report does not substitute, because it covers only the provider's side of the shared responsibility line.

Is a CNAPP or CSPM the same as hiring a cloud penetration testing company?

No. A CNAPP or CSPM continuously enumerates misconfigurations across your accounts, which is valuable breadth, but it cannot prove which findings an attacker can chain into a breach, cannot validate real blast radius, and cannot reach application-layer broken authorisation or business logic flaws. A penetration test proves exploitability; posture tooling reports configuration state. Most mature cloud programmes run both. The detail is in CNAPP blind spots.

How often should we run a cloud penetration test?

At minimum annually, and more often if your estate changes materially between cycles. Most compliance programmes are written against an annual cadence, so a one-time annual engagement satisfies the letter of the requirement. The practical problem is drift: new accounts, clusters and managed services appear between audits, and a report dated eleven months ago describes an environment that no longer exists. Organisations shipping infrastructure changes weekly generally move to a continuous programme, which also gives an auditor many samples of the control operating rather than one.

How do I verify a cloud penetration testing company's claims?

Check four things that cannot be manufactured. Published CVEs with credited researchers, conference research at DEFCON, BSides or equivalent, open-source tooling with a public commit history, and firm-level accreditation listed on the accreditation body's own register rather than on the vendor's homepage. Customer logos, "trusted by" strips and unattributed statistics are not verification. Ask for a redacted sample report as well, since methodology quality shows up in reporting faster than in a sales call.

Ready to scope your cloud penetration test?

Cloud estates do not wait for the audit calendar. Whether you need a one-time annual cloud penetration test for a specific audit or enterprise security review, or a continuous programme that keeps pace with weekly infrastructure changes, Stingrai tests AWS, Azure and Google Cloud with certified senior pentesters, and brings Snipe onto the web and API layers alongside them. Stingrai is a CREST-accredited penetration testing service provider, has published 18 CVEs, and holds 5.0 out of 5.0 across 19 Clutch reviews. Get a quote or see current pricing.

References

  1. Mordor Intelligence. Penetration Testing Market Size, Share, Trends and Industry Report. Accessed August 2026. https://www.mordorintelligence.com/industry-reports/penetration-testing-market. Market sizing and per-service-line growth forecasts, including the cloud penetration testing CAGR.

  2. Google Cloud. Cloud Threat Horizons Report H1 2026. https://cloud.google.com/security/report/resources/cloud-threat-horizons-report-h1-2026. Initial access vector distribution for observed cloud intrusions across the first and second halves of 2025.

  3. IBM. Cost of a Data Breach Report 2026. https://newsroom.ibm.com/2026-07-29-ibm-study-one-in-four-malicious-breaches-are-ai-enabled,-costing-companies-6-million-on-average. Global average breach cost, AI-enabled breach cost and cloud misconfiguration prevalence.

  4. Amazon Web Services. Penetration Testing Customer Support Policy. https://aws.amazon.com/security/penetration-testing/. Permitted services list, prohibited activities and the Simulated Events authorisation process.

  5. Microsoft. Penetration testing on Azure. https://learn.microsoft.com/en-us/azure/security/fundamentals/pen-testing. Confirms pre-approval was removed on 15 June 2017 and summarises permitted and prohibited testing.

  6. Google Cloud. Penetration testing policy. https://support.google.com/cloud/answer/6262505. States that customers are not required to contact Google before testing their own projects.

  7. NetSPI. Cloud Penetration Testing. https://www.netspi.com/security-testing/cloud-penetration-testing/. Cloud service scope across AWS, Azure and Google Cloud, delivered through the NetSPI Platform.

  8. Bishop Fox. Cloud Penetration Testing. https://bishopfox.com/services/cloud-penetration-testing. Cloud service scope, objective-based delivery model and downloadable cloud testing methodology.

  9. Rhino Security Labs. Cloud Security Services. https://rhinosecuritylabs.com/cloud-security/. Separate AWS, Azure and GCP penetration testing practices, plus the Pacu and CloudGoat open-source projects.

  10. Praetorian. Cloud Penetration Testing. https://www.praetorian.com/services/cloud-penetration-testing/. Three cloud engagement types and the seven-step delivery process.

  11. NCC Group. Cloud Security Services. https://www.nccgroup.com/technical-assurance/cloud-security-services/. Cloud Configuration Assessment scope across AWS, Azure, Google Cloud, Oracle and Alibaba.

  12. TrustedSec. Cloud Testing. https://www.trustedsec.com/services/cloud-testing. Assumed Access Model and cloud engagement scope for Azure and AWS.

  13. Cobalt. Cloud Pentest Service. https://www.cobalt.io/services/cloud-pentest-service. Cloud testing scope aligned to the OWASP Cloud-Native Top 10 and the PTaaS delivery model.

  14. Software Secured. Secure Cloud Review. https://www.softwaresecured.com/service/secure-cloud-review. Read-only cloud review scope across AWS, Azure and GCP, with published starting price.

  15. Stingrai. Penetration Testing Pricing. https://www.stingrai.io/pricing. Current list pricing for the Autonomous, Hybrid and Enterprise tiers.

0 views

0

X

Related reading

API Security Statistics 2026: Attacks, Breaches and Exposure
Web App SecurityNetwork Security

API Security Statistics 2026: Attacks, Breaches and Exposure

API security statistics for 2026: 150B API attacks in two years, APIs now the top attack surface, 87% of orgs hit in 2025, up to $87B lost a year.

15 min read

Penetration Testing Statistics 2026: Adoption, Findings, Cost and Remediation
Web App SecurityNetwork Security

Penetration Testing Statistics 2026: Adoption, Findings, Cost and Remediation

Penetration testing market size, finding rates, remediation times and testing frequency for 2026, aggregated from Mordor, Cobalt, Verizon DBIR and OWASP.

20 min read

HackerOne Alternatives (2026): Pentest and Bug Bounty Platforms Compared
Web App SecurityNetwork Security

HackerOne Alternatives (2026): Pentest and Bug Bounty Platforms Compared

Compare the 9 best HackerOne alternatives for 2026 on delivery model, audit-grade evidence and published pricing, plus bug bounty vs pentest guidance.

18 min read

Contents

X