main logo icon

Published on

October 1, 2026

|

31 min read

Best Enterprise Penetration Testing Companies (2026): Ranked for Global Programs, Procurement and Continuous Coverage

Ranked guide to the best enterprise penetration testing companies in 2026 for US and Canadian security and procurement teams, with what PCI DSS, NYDFS, the SEC, OSFI, DORA, TIBER-EU and CBEST ask of a provider, verified 1 October 2026.

Arafat Afzalzada

Arafat Afzalzada

Founder

Network SecurityWeb App SecuritySocial Engineering

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

Most rules an enterprise answers to require testing without saying who may do it. PCI DSS v4.0.1 requires internal and external penetration tests at least once every 12 months and after significant change, NYDFS 23 NYCRR 500.5 requires annual testing by a qualified internal or external party, SEC Item 106 asks registrants to disclose whether they engage third-party assessors or consultants, and OSFI Guideline B-13 expects defined triggers and minimum frequencies for intelligence-led threat assessments, and regular tests and exercises such as penetration testing and red teaming. The threat-led schemes are where the provider itself is qualified: DORA Article 27 requires TLPT testers to provide, among other conditions, an independent assurance or audit report and professional indemnity insurance, the Bank of England's CBEST guide requires accredited providers that are CREST members, and OSFI's I-CRT leaves vendor due diligence to the institution. The best enterprise penetration testing companies in 2026 are Stingrai, NCC Group, NetSPI, IBM X-Force Red, GuidePoint Security, Optiv, Praetorian, TrustedSec, Kroll, Coalfire and Bishop Fox. Every vendor entry links to a page on the vendor's own site and was verified on 1 October 2026.

The average data breach in the United States cost a record US$11.5 million in IBM's Cost of a Data Breach Report 2026, more than twice the US$4.99 million global average, and Canadian organizations paid a record CA$7.11 million on average according to IBM's Canadian release of the same study (Ponemon Institute, 602 organizations breached between March 2025 and February 2026, published July 2026). In the same report, offensive security testing (IBM's label covers red teaming, pen or vulnerability testing) lowered the average breach cost by US$211,339 when measured in isolation against the global average. The Verizon 2026 Data Breach Investigations Report, published in May 2026 and covering incidents from 1 November 2024 to 31 October 2025, found third-party involvement in 48 percent of the breaches in its dataset, "up from 30% last year." That second number matters twice to an enterprise buying a penetration test, because the firm you hire is itself a third party with privileged access to your weaknesses.

Where Stingrai fits: Stingrai is a CREST-accredited penetration testing service provider at firm level, headquartered in Toronto with a London office and founded in 2021. Two named penetration testers from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP certifications run each human-led engagement, reviewed by the team lead and an engagement partner, backed by 18 published CVEs. For an enterprise that means one contract covering web applications and APIs, mobile, AI and LLM systems, AWS, Azure with Entra ID and Google Cloud, internal and external networks with segmentation testing, Active Directory, Wi-Fi, phishing, vishing and physical entry, and red and purple teaming against your SOC, delivered as one-time annual engagements or continuous programs through a PTaaS portal that pushes findings into Jira, ServiceNow, Slack or Teams. Retesting is included, and human-led and hybrid engagements include an attestation letter. Published prices cover one web application and its APIs at US$3,000 for an Autonomous Pentest and US$6,800 for a Hybrid Pentest per assessment (pricing); enterprise scopes are quoted.

Quick answer: who are the best enterprise penetration testing companies in 2026?

The best enterprise penetration testing companies in 2026 are Stingrai, NCC Group, NetSPI, IBM X-Force Red, GuidePoint Security, Optiv, Praetorian, TrustedSec, Kroll, Coalfire and Bishop Fox. Stingrai ranks first for named, certified penetration testers on an enterprise's highest-risk applications, identity and cloud estates, red and purple teaming in the same contract, published package prices and a portal that feeds Jira and ServiceNow, one-time or continuous. NCC Group, NetSPI and IBM X-Force Red follow for the broadest threat-led accreditations with North American offices, more than 350 in-house testers on one platform, and testing built for DORA TLPT, TIBER-EU and OSFI's I-CRT.

This page compares providers. To score their proposals, use the pentest and red team RFP question bank and its 75 weighted questions with red-flag answers; for a twelve-criteria evaluation framework that applies to any buyer, see penetration testing vendors in 2026.

Two-column chart of what US, Canadian and global financial-sector rules ask of an enterprise penetration testing provider in 2026

What enterprise rules actually ask of a penetration testing provider

Most of the rules an enterprise answers to require testing and say little about who does it. The threat-led schemes used for financial groups are the exception: they qualify the provider, down to insurance, references and the years of experience of the red team.

PCI DSS v4.0.1, Requirement 11.4

PCI DSS v4.0.1, published in June 2024, requires internal (11.4.2) and external (11.4.3) penetration testing at least once every 12 months and after any significant infrastructure or application upgrade or change, by a qualified internal resource or qualified external third party, with organizational independence of the tester, who does not have to be a QSA or ASV. Requirement 11.4.4 requires exploitable vulnerabilities to be corrected and the testing repeated to verify the corrections. Where segmentation isolates the cardholder data environment, 11.4.5 requires the segmentation controls to be tested at least once every 12 months, and 11.4.6 raises that to at least once every six months for service providers. An enterprise with several card environments and a payments business line is buying several tests a year.

NYDFS 23 NYCRR 500.5 and 500.4

New York's cybersecurity regulation, as amended in November 2023, requires written vulnerability management policies and procedures designed to ensure that covered entities conduct, at a minimum, "penetration testing of their information systems from both inside and outside the information systems' boundaries by a qualified internal or external party at least annually" (section 500.5(a)(1)), alongside automated scans and manual review of systems the scans do not cover. Section 500.4(b) requires the CISO to report in writing "at least annually to the senior governing body," including on material cybersecurity risks, the overall effectiveness of the program and plans for remediating material inadequacies. The NYDFS guide covers the evidence an examiner asks for.

SEC Regulation S-K, Item 106

For SEC registrants, Item 106 of Regulation S-K requires a description of the processes, if any, for assessing, identifying and managing material cybersecurity risks, which should address, as applicable, "whether the registrant engages assessors, consultants, auditors, or other third parties in connection with any such processes," and a description of "the board of directors' oversight of risks from cybersecurity threats." It names no penetration test. A testing program, and the firm that runs it, are among the processes and third parties that disclosure can cover.

OSFI Guideline B-13, section 3.1.2

Guideline B-13, dated 31 July 2022 and effective 1 January 2024, sets OSFI's technology and cyber risk expectations for all federally regulated financial institutions. Section 3.1.2 says institutions "should set defined triggers, and minimum frequencies, for intelligence-led threat assessments to test cyber security processes and controls" and "should also regularly perform tests and exercises, to identify vulnerabilities or control gaps in its cyber security programs (e.g., penetration testing and red teaming) using an intelligence-led approach." The guideline is written as expectations rather than statute, and it names penetration testing and red teaming together. The B-13 guide maps the rest of the guideline.

OSFI's Intelligence-led Cyber Resilience Testing (I-CRT) framework

I-CRT, an OSFI advisory dated 1 April 2023, is a supervisory "how to" guide, and OSFI states it "is not a policy instrument used to set regulatory expectations." Its current scope "applies to all Systemically Important Banks (SIBs) and Internationally Active Insurance Groups (IAIGs)" on a three-year supervisory cycle, and other institutions may request an assessment. The institution selects, contracts and pays the threat intelligence provider and the red team provider. OSFI recommends separate vendors for the two roles and says due diligence is required to ensure the vendors have "the requisite skills set, experience, and capability." It names no accreditation.

OSFI Guideline B-10, Annex 2

Guideline B-10 on third-party risk management, dated 30 April 2023, lists in Annex 2 the provisions institutions should include in high-risk and critical third-party agreements: the nature and scope of the work, including the "physical location of the services being provided," parameters on subcontractors, ownership of and access to assets, the "confidentiality, integrity, security, and availability of records and data," notice of incidents and of "changes in ownership of the third party," return of data on termination, and appropriate insurance. It works as a checklist for any penetration testing MSA, whether or not your testing firm is classed as high-risk.

DORA Articles 24 to 27 and the TLPT standards

For groups with EU financial entities, DORA, which applies from 17 January 2025, requires tests to be "undertaken by independent parties, whether internal or external" (Article 24(4)), appropriate tests at least yearly on all ICT systems and applications supporting critical or important functions (Article 24(6)), and threat-led penetration testing "at least every 3 years" on live production systems for entities their competent authority identifies (Article 26). Article 27 limits TLPT to testers that, among other conditions, "are certified by an accreditation body in a Member State or adhere to formal codes of conduct or ethical frameworks," that "provide an independent assurance, or an audit report, in relation to the sound management of risks associated with the carrying out of TLPT" and that are "duly and fully covered by relevant professional indemnity insurances, including against risks of misconduct and negligence." The TLPT standards in Commission Delegated Regulation (EU) 2025/1190, published on 18 June 2025, add CVs and certifications, at least five references and a red team led by a manager with at least five years of penetration and red team testing (Article 7).

TIBER-EU

The European Central Bank's TIBER-EU framework for threat intelligence-based ethical red teaming was published in May 2018 and "updated in 2024 to ensure its full alignment with the Regulatory Technical Standards on threat-led penetration testing (TLPT) of the Digital Operational Resilience Act (DORA)." The ECB says it "can be used for entities in all critical sectors, not just the financial sector," and it publishes separate guidance on purple teaming in the testing and closure phases.

CBEST

In the UK, the CBEST Implementation Guide (2024 edition) states that service providers, accredited through a process the guide says is undertaken by the Bank of England, "must be accredited in order to conduct the threat intelligence, penetration testing and reporting elements of the CBEST" and "must also be members of the cyber security membership body CREST." As a pre-condition of accreditation, penetration testing providers employ certified individuals, including a CREST Certified Red Team Manager or a Cyber Scheme Red Team Manager. The comparison of TIBER-EU, CBEST and DORA TLPT in our related reading sets the three side by side.

Rule

Applies to

Names penetration testing or red teaming?

Cadence

What it asks of the provider

PCI DSS v4.0.1, Requirement 11.4

Entities that store, process or transmit card data

Penetration testing

At least every 12 months and after significant change; segmentation every six months for service providers

A qualified tester with organizational independence; repeat testing to verify corrections

NYDFS 23 NYCRR 500.5

NYDFS-licensed banks, insurers and other covered entities

Penetration testing

At least annually

A qualified internal or external party testing from inside and outside

SEC Regulation S-K, Item 106

SEC registrants

No

Annual disclosure

Disclosure of whether third parties are engaged, and of board oversight

OSFI Guideline B-13, 3.1.2

Federally regulated financial institutions

Both, as examples

Triggers and minimum frequencies for intelligence-led threat assessments; tests and exercises regularly

Intelligence-led testing with defined scope and risk controls

OSFI I-CRT

SIBs and IAIGs; others on request

Intelligence-led red teaming

Three-year supervisory cycle

Separate threat intelligence and red team vendors, chosen after due diligence

OSFI Guideline B-10, Annex 2

High-risk and critical third-party agreements

No

Not applicable

Contract terms on location, subcontractors, data security, ownership changes and insurance

DORA Articles 24 to 27

EU financial entities

Both; TLPT for identified entities

Yearly tests of critical systems; TLPT at least every 3 years

Independent testers; for TLPT, certification by an accreditation body in a Member State or adherence to formal codes of conduct or ethical frameworks, an assurance or audit report and professional indemnity insurance

TIBER-EU

Entities in any critical sector that adopt it

Threat intelligence-based red teaming

Set by the authority

Threat intelligence and red team provider roles; purple teaming guidance

CBEST

UK firms and financial market infrastructures

Intelligence-led penetration testing

Set by the regulators

CBEST-accredited CREST members with certified red team managers

The enterprise attack surface: what a program has to cover

An enterprise test that stops at one application or one network range proves very little. The scope that matters spans subsidiaries, identity, clouds, partners and the people who reset passwords.

Scope map of ten areas an enterprise penetration testing program should cover, from the internet perimeter and acquired estates to red and purple teaming against the SOC
  • Internet perimeter and acquired estates. IBM's 2026 report found that a lack of visibility into the number and location of applications (shadow IT) added US$201,165 to the average breach cost, measured in isolation. Test every subsidiary's internet-facing estate, including VPNs, remote access and management interfaces, and test acquisition targets before the deal closes.

  • Web applications and APIs. Authorization across every role and tenant, business logic and IDOR, tested per application with retests after each major release, as web application penetration testing is scoped.

  • Active Directory, Entra ID and SSO. Kerberos and delegation paths, ACL abuse, consent grants, Conditional Access exceptions and federation trust between domains, the paths an Active Directory assessment follows to domain admin.

  • Multi-account cloud. Cross-account role assumption, resource and bucket policies, metadata access and service principals across AWS, Azure and Google Cloud, covered by cloud penetration testing.

  • Internal networks and segmentation. Lateral movement from an assumed-breach foothold, and evidence that card, OT and restricted segments are isolated, which PCI DSS 11.4.5 and 11.4.6 require wherever segmentation isolates a card environment. Internal and external network testing covers both.

  • Third-party connections and SaaS. Supply chain breaches, in which business partners were compromised, were "the most expensive factor in increasing breach costs" in IBM's 2026 report, adding US$227,250 on average. Test vendor remote access, partner APIs, SaaS integrations and the tokens that connect them.

  • AI and LLM applications and agents. Prompt injection, system prompt leakage, excessive agency and tool misuse in assistants connected to enterprise data, through AI and LLM penetration testing.

  • Mobile applications. iOS and Android apps with their backend APIs, local storage, certificate pinning and exported components, through mobile application penetration testing.

  • People: the help desk, phishing and physical entry. Vishing aimed at password resets, phishing of finance and IT staff, and entry to offices and data rooms, run as social engineering engagements.

  • Detection and response. Red teaming measures whether the SOC sees a realistic attack, and purple teaming replays what it missed until the detections work.

What enterprises evaluate that smaller buyers can skip

Capacity for concurrent engagements. An enterprise rarely buys one test. It buys a calendar: application releases, a PCI cycle, a cloud migration, an acquisition and a red team in the same quarter. Ask how many testers can be on your engagements at the same time and who they are. NCC Group says its global team of over 500 security specialists let it work with one multinational client across that client's international offices at the same time, NetSPI describes more than 350 in-house security experts and IBM X-Force Red more than 200 hackers. A smaller firm can carry a program if the schedule is agreed up front.

Named, screened testers. Require names, certifications and CVs before signing, and substitution only with your written approval. The DORA TLPT standards already demand "a detailed curriculum vitae and copies of certifications" from external testers, and the same request works for any enterprise test. Ask how testers are screened and whether any are subcontractors; OSFI's B-10 expects institutions to understand a third party's "number and criticality of subcontractors."

Data handling. A test produces one of the most sensitive files an enterprise owns: a list of its exploitable weaknesses, plus any credentials captured along the way. Ask where findings and evidence are stored, who can reach them, how long they are kept and how they are destroyed. DORA writes this into law for threat-led tests: the independent assurance or audit report must cover "the due protection of the financial entity's confidential information," and the TLPT standards require "secure deletion of information related to passwords, credentials, and other secret keys compromised during the TLPT." Ask for professional indemnity and cyber insurance certificates in the same request.

MSA and SOW terms. Use B-10's Annex 2 as the skeleton: scope and location of services, subcontractors, ownership of assets, security of records and data, notice of incidents and ownership changes, data return on termination and insurance. Add what is specific to testing: written authorization to test, rules of engagement, a stop-work contact, change control for scope found mid-test, and retest windows. The statement of work template turns these into clauses.

Global delivery and regulator-recognized schemes. A global financial group needs to know which scheme each entity falls under and which providers qualify. The CREST Marketplace shows threat-led accreditations firm by firm; CBEST requires accredited providers that are CREST members; DORA sets tester requirements in law; TIBER-EU defines the provider roles; and I-CRT leaves provider due diligence to the institution. Confirm which legal entity holds each accreditation and which entity will sign, because several firms in this ranking hold theirs through UK or European entities.

Integrations. Findings that live only in a PDF do not get fixed at enterprise scale. Ask whether findings sync with Jira or ServiceNow, whether the portal supports single sign-on, and whether test activity can be correlated in your SIEM so the SOC can tell a tester from an attacker during red and purple team work. Among the ranked firms, Stingrai, NetSPI and Bishop Fox state on their own sites that test findings can flow into ServiceNow.

Executive and board reporting. NYDFS requires the CISO to report "at least annually to the senior governing body," and SEC registrants describe "the board of directors' oversight of risks from cybersecurity threats." Ask for a board-level summary of each engagement and trend reporting across engagements, not just a findings list.

Red and purple teaming alongside penetration testing. B-13 names penetration testing and red teaming together, and the DORA TLPT standards require the control team to "conduct a purple teaming exercise" in the closure phase (Article 12(5) of Commission Delegated Regulation (EU) 2025/1190). Buying all three from one firm keeps findings, detections and fixes in one record; splitting them across two firms adds independence. Either works if the contract says which, and our adversary simulation and red teaming services ranking compares providers for threat-led testing and purple teaming. The RFP question bank turns each of these into scored questions.

How we ranked them

Eleven firms were scored against nine criteria. Every accreditation was checked on the CREST Marketplace, and every vendor entry links to pages on the vendor's own site, read live on 1 October 2026, except Kroll's red team services page, which blocks automated requests: its quotes were read from a Wayback Machine capture dated 18 February 2026 and confirmed on the live page in a browser on 2 October 2026.

  1. Enterprise evidence on the firm's own site: an enterprise testing page, named enterprise clients, case studies at enterprise scale or a global delivery footprint.

  2. Firm-level accreditation on the CREST Marketplace, including CREST's threat-led accreditations where held.

  3. Capacity, from what the firm says about its testing team and footprint.

  4. Named testers, identified with their certifications before signing.

  5. Integrations named on the firm's site: Jira, ServiceNow, SIEM.

  6. Executive and board reporting described on the firm's site.

  7. Red and purple teaming alongside penetration testing.

  8. Delivery: one-time and continuous options, a findings portal and a stated retest policy.

  9. North American delivery and pricing transparency: offices or legal entities in the United States and Canada, and published prices.

The 11 companies at a glance

#

Company

HQ and North American presence

CREST accreditations (Marketplace)

Integrations named

Red and purple teaming

Best for

1

Stingrai

Toronto, ON (London, UK office)

Penetration Testing, firm level

Jira, ServiceNow, Slack, Teams; SSO and API on Enterprise

Both

Named, certified testers on the highest-risk scopes, one-time or continuous

2

NCC Group

Manchester, UK; Chicago regional HQ; Waterloo, ON

Penetration Testing, Threat Led Penetration Testing, TLPT-FS, threat intelligence, incident response and more

Cyber Services Portal into vulnerability management

Both, plus black and gold teams

CBEST, TIBER-EU or DORA TLPT capability with North American delivery

3

NetSPI

Minneapolis, MN; Canada office per CREST listing

Penetration Testing, Threat Led Penetration Testing

Jira, ServiceNow, Microsoft Sentinel, Teams

Red team operations

High-volume programs on one platform

4

IBM X-Force Red

Armonk, NY

Penetration Testing, Incident Response, Vulnerability Assessment (UK entity)

Not stated

Both

DORA TLPT, TIBER-EU and I-CRT work inside an IBM relationship

5

GuidePoint Security

Reston, VA

Penetration Testing

Not stated

Both

Manual-first testing with red and purple teams for US enterprises

6

Optiv

Leawood, KS; Optiv Canada Inc., Mississauga, ON

Penetration Testing

Not stated

Both

Testing under an existing integrator agreement in the US and Canada

7

Praetorian

Austin, TX

Penetration Testing

Not stated

Both

Continuous testing across many brands and subsidiaries

8

TrustedSec

Fairlawn, OH

Penetration Testing

Not stated

Both

Board, CISO and engineering readouts; acquisition testing

9

Kroll

New York, NY; Toronto, ON office

Penetration Testing, Incident Response, Security Operations Centre

Not stated

Both

Testing beside incident response

10

Coalfire

Chicago, IL (mailing address)

Penetration Testing (UK entity)

Not stated

Red teaming

FedRAMP penetration testing for cloud providers

11

Bishop Fox

Tempe, AZ

Penetration Testing

Jira, ServiceNow

Red teaming

Continuous external testing that syncs with ServiceNow

"Not stated" means the firm's own pages reviewed for this ranking do not say. Ask for it in writing.


1. Stingrai

Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.

What a vendor-risk team can check. The firm-level accreditation is on the CREST Marketplace supplier page for Stingrai Inc, separate from the CREST CRT certifications individual testers hold. Stingrai is rated 5.0 out of 5 across 20 reviews on Clutch. The team has published 18 CVEs, including CVE-2025-50674, a privilege escalation to root in OpenMediaVault, and CVE-2024-32136, an SQL injection in a WordPress plugin, and team members are listed in the bug bounty Halls of Fame of Apple, Google, the US Department of Defense and the US Federal Reserve. Two named penetration testers from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP certifications run each human-led engagement, reviewed by the team lead, who has 16 years in penetration testing, red teaming and exploit development, and an engagement partner, under founder Arafat Afzalzada, who has 11 years in offensive security.

How an enterprise program is tested. Web applications and APIs are tested black, grey or white box, authenticated across every user role, for broken authorization, IDOR and business logic under OWASP Top 10 and ASVS. Cloud testing runs from control plane to workload across AWS, Azure with Entra ID and Google Cloud: cross-account role assumption, app registrations, service principals, consent grants, Conditional Access gaps and hybrid-join trust. The Active Directory assessment follows ACL abuse and Kerberos and delegation paths to domain admin, and network testing covers the external perimeter, lateral movement and segmentation. Mobile apps are tested against OWASP MASVS and MASTG, and AI and LLM systems against the OWASP Top 10 for LLM Applications, the OWASP Top 10 for Agentic Applications and MITRE ATLAS. Red teaming runs assumed breach, black-box full chain and threat intelligence-led scenarios built in the style DORA and TIBER-EU describe, on-premise and in cloud, and purple teaming works through real-world TTPs with your SOC. Phishing, vishing, Wi-Fi and physical entry complete the scope.

Delivery, integrations and reporting. Findings post to the PTaaS portal as they are confirmed, each with a working proof of concept and remediation guidance, with live chat to the assigned testers. Findings push into Jira, ServiceNow, Slack or Teams, and Enterprise plans add single sign-on and API access, a high-level management report, an executive post-remediation report, dark web credential leakage monitoring and a dedicated security concierge. Reports are redactable, the dashboard gives executives analytics across engagements, and red team reports include an executive and board summary, a chronological attack narrative and a detection and response timeline. Retesting is included, and human-led and hybrid engagements include an attestation letter. Stingrai runs both one-time annual engagements timed to an audit cycle and continuous programs that test after every release.

Where Snipe fits. Snipe, Stingrai's autonomous AI penetration testing agent for web applications and their APIs, covers the application portfolio. It hunts broken authorization, IDOR and business logic flaws, reviews code white-box, opens AutoFix pull requests and can gate pull requests. The Autonomous tier is Snipe alone, with no penetration testers; in a Hybrid engagement Snipe and the penetration testers test together throughout, with the testers directing its focus. Identity, cloud, network, mobile, AI and LLM, social engineering and red team work is human-led.

Pricing: US$3,000 for an Autonomous Pentest and US$6,800 for a Hybrid Pentest per assessment of exactly one web application and its APIs, or US$650 and US$1,275 per month on 12-month continuous plans, on the pricing page. Every other scope is quoted through get a quote.

Strength: named, certified testers with public research records on the scopes enterprises are breached through, with red and purple teaming, ServiceNow delivery and published package prices in one firm. Limitation: a small team, so a program with many simultaneous engagements needs its calendar agreed up front, and Stingrai holds CREST's Penetration Testing accreditation rather than its threat-led accreditations, so a regulator-designated CBEST or STAR-FS test needs a provider that holds them. Best for: US and Canadian enterprises that want named, certified penetration testers on their highest-risk applications, identity and cloud estates, with red and purple teaming in the same contract, one-time or continuous.

2. NCC Group

NCC Group lists its global headquarters in Manchester, England, its North American regional headquarters at 11 E Adams Street in Chicago and an office in Waterloo, Ontario on its office locations page, and its about page describes "our team of over 1,800 experts" across the UK, Europe, North America and Asia Pacific. Its clearest enterprise evidence is a global network testing case study: a multinational industrial organization needed regular network penetration testing across hundreds of network segments, and NCC Group combined Horizon3's NodeZero autonomous testing with expert-led penetration testing so the client could map risk "across over 100,000 assets globally." The case study adds that NCC Group's "global team of over 500 security specialists allowed simultaneous collaboration with the client across their international offices." CREST lists the broadest accreditation set in this ranking, with 19 years of membership: Penetration Testing, Threat Led Penetration Testing, Threat Intelligence for Simulated Attack, TLPT-FS threat-led testing and threat intelligence, Cyber Threat Intelligence, Incident Response, Incident Exercising, Security Operations Centre and Vulnerability Assessment, plus the CREST AI Charter, ISO 27001 and ISO 9001. Its attack simulation service runs red, black, purple and gold team exercises and prepares clients for "CBEST, TIBER-EU, iCAST, AASE, CORIE, and FEER regulations." Its penetration testing page describes "an expert team of in-house security specialists" and integration into vulnerability management systems through its Cyber Services Portal, and a continuous penetration testing service is offered. Named testers, retest terms and pricing are not stated.

Strength: the widest set of CREST threat-led accreditations here, backed by a testing team that has worked across one client's global estate at once. Limitation: the CREST listing belongs to the UK parent, so confirm which entity contracts and delivers North American work, and no commercial terms are published. Best for: global financial groups that need CBEST, TIBER-EU or DORA TLPT capability and North American delivery from one firm.

3. NetSPI

NetSPI is headquartered in Minneapolis, according to its merger announcement, and its CREST listing describes "offices across the U.S., Canada, the UK, and India." Its PTaaS page describes more than 350 in-house security experts, and its integrations page shows connectors for Jira, ServiceNow, Microsoft Sentinel, Microsoft Teams and GitHub, with "all integrations included." Its red team operations page offers assumed breach, black box and threat intelligence-led scenarios, says its DORA work is "fully aligned with TIBER-EU standards," and claims "accreditations from CBEST and CREST." In its Chubb customer story, the insurer's vice president of cybersecurity services says "NetSPI is performing on-demand penetration tests for some of our insureds as part of the underwriting process for their renewals," and a UK insurer's case study covers a threat-led red team. CREST lists Penetration Testing and Threat Led Penetration Testing with 10 years of membership and no company certifications. On 2 September 2026 NetSPI and Synack announced a definitive agreement to merge; the transaction "is expected to close in October 2026, subject to customary closing conditions and regulatory approvals." Named testers and pricing are not stated.

Strength: a large in-house testing bench on one platform with ServiceNow, Jira and SIEM connectors, plus a threat-led accreditation. Limitation: the pending merger means a change of ownership early in any new multi-year term, so write continuity of named staff, data handling and pricing into the MSA. Best for: enterprises running dozens of tests a year that want findings flowing into ServiceNow or Jira from one platform.

4. IBM X-Force Red

X-Force Red is IBM's offensive security team, and IBM datelines its newsroom releases from Armonk, New York. Its service page describes "IBM's team of 200+ hackers worldwide," offering penetration testing, vulnerability management and adversary simulation, red teaming, purple teaming and ongoing managed testing, plus "specialized threat intelligence-based testing for compliance frameworks such as DORA TLPT, TIBER-EU, I-CRT and others," the last being OSFI's Canadian framework. Engagements can be bought as projects, from an a-la-carte menu, or on a monthly budget for continuous testing. Its enterprise evidence is a stated outcome: "X-Force Red helped a large enterprise reduce a backlog of critical vulnerabilities by 60% in four months." CREST lists IBM, through a UK entity, for Penetration Testing, Incident Response and Vulnerability Assessment with 12 years of membership, plus ISO 27001 and ISO 9001. Named testers and pricing are not stated.

Strength: threat intelligence-based testing that names OSFI's I-CRT alongside DORA TLPT and TIBER-EU, from a team that spans the globe. Limitation: the CREST listing belongs to a UK entity, so confirm the delivery team and contracting entity for US and Canadian work. Best for: enterprises already buying from IBM, and Canadian or EU financial groups planning I-CRT or TLPT work.

5. GuidePoint Security

GuidePoint Security lists its headquarters at 1900 Reston Metro Plaza in Reston, Virginia, with offices in seven other US cities, on its contact page, which also claims 4,200+ enterprise-level customers and reliance by "40% of the Fortune 500." It publishes a dedicated enterprise penetration testing page that prioritizes manual testing and lists purple team and red team services beside network, application, cloud and facilities testing. Its July 2024 CREST announcement says its testing has been adapted for "large enterprises in the Fortune 100" and that the team includes CREST Certified Consultants. CREST lists Penetration Testing with three years of membership and a US SOC 2 Type 2 report. Its purple team deliverable includes an executive summary and a technical analysis, and its PTaaS offering pairs automated testing with an expert pentester who audits and validates results. Named testers and pricing are not stated, and remediation validation is described only for its cloud penetration test.

Strength: a SOC 2 Type 2 report on the CREST listing and a dedicated enterprise testing practice with red and purple teams. Limitation: no Canadian office appears on its contact page, and its PTaaS offering is built on automated testing that can be paired with expert validation. Best for: US enterprises that want manual-first penetration testing alongside red and purple teaming from a large security partner.

6. Optiv

Optiv lists its corporate headquarters at 5100 W 115th Place in Leawood, Kansas on its locations page, and its Canada operations page says Optiv Canada Inc. "is a Canadian legal entity with its own officers and board of directors," headquartered in Mississauga. Its attack and penetration service states that its penetration testing services "serve 64% of the Fortune 500," and its attack simulation service runs red and purple team exercises that, in Optiv's words, highlight "a breach's impact on an organization, the board and the executive team." Optiv announced CREST accreditation for penetration testing on 2 October 2025, presenting it as a credential for work with financial institutions, and CREST lists it with one year of membership and no company certifications. Named testers, retest terms and pricing are not stated.

Strength: a Canadian legal entity with its own board, and testing that already reaches most of the Fortune 500. Limitation: Optiv also sells and implements security technology, with "more than 450 technology partners" on its own count, so confirm in writing that testers are independent of products Optiv deployed for you. Best for: enterprises in the US and Canada that buy security technology through Optiv and want testing under the same master agreement.

7. Praetorian

Praetorian datelines its releases from Austin, Texas (example). Its customer stories name enterprise clients including Booking Holdings, Samsung, X, Zoom, Nielsen, Priceline and OpenTable, and the same page says the team "holds 170 active Offensive Security certifications." The Booking Holdings story is summarized as: "Chief Security Officer at Booking Holdings manages vendor and subsidiary risk by leveraging Praetorian's advanced offensive security offerings." Its continuous penetration testing service cycles through overt penetration testing, collaborative purple teaming and covert red teaming, which Praetorian calls "ideal for enterprises," and its penetration testing page ends each engagement by guiding fixes, re-testing and verifying that vulnerabilities are closed. CREST lists Penetration Testing with two years of membership. Named testers and pricing are not stated.

Strength: named enterprise clients and a continuous cycle that alternates penetration testing, purple and red teaming. Limitation: no Canadian office is stated. Best for: enterprises with many brands or subsidiaries that want one continuous offensive program across all of them.

8. TrustedSec

TrustedSec lists its address in Fairlawn, Ohio. Its enterprise penetration testing guide says it "has partnered with Fortune 500 organizations, financial institutions, and healthcare systems" and delivers findings through "a structured briefing model, including separate presentations tailored for the board, the CISO, and technical remediation teams." Its penetration testing service ends in validation testing: "After you've addressed identified vulnerabilities, we retest to confirm they've been successfully mitigated." It runs red team and purple team engagements, and a published case study describes external and internal penetration tests of a company a retailer was about to acquire, which found critical vulnerabilities an earlier assessment had missed. CREST lists Penetration Testing with two years of membership and 51 to 100 technical people. TrustedSec is also a PCI Qualified Security Assessor Company. Named testers and pricing are not stated.

Strength: separate readouts for the board, the CISO and engineers, with retesting stated and acquisition testing in its published work. Limitation: if TrustedSec also assesses your PCI program as a QSA company, agree in writing how its testers are separated from its assessors; no Canadian office is stated. Best for: enterprises that want board, CISO and engineering readouts from the same testing team, and testing of acquisition targets before close.

9. Kroll

Kroll lists One World Trade Center in New York as its headquarters address and a Toronto office at 333 Bay Street, and its about page counts "6,500 experts" across "more than 30 countries and territories worldwide." Its CREST listing, with Penetration Testing, Incident Response and Security Operations Centre accreditations, eight years of membership and ISO 27001, describes "over 700 cyber experts across 19 countries," "over 100,000 hours of offensive security assessments per year," and a presence "in over 60 cyber insurance carriers and brokers' preferred panels." Its red team services page, read from a Wayback Machine capture of 18 February 2026, describes red teaming that tests "detection and response capabilities against a simulated threat actor with defined objectives," follows MITRE ATT&CK, includes "a high-level overview for executive and management teams" in the report, and says a program "can include red team, social engineering, penetration testing and purple team." In a 2022 announcement, Kroll said that as a CREST-accredited penetration testing provider it "works on hundreds of cases a year." Named testers, retest terms, a findings portal and pricing are not stated.

Strength: testing from a firm that also runs incident response and sits on many cyber insurers' preferred panels, with a Toronto office. Limitation: offensive testing is one practice inside a large risk advisory firm, and no commercial terms are published. Best for: enterprises that want testing beside an incident response provider that sits on many cyber insurers' preferred panels.

10. Coalfire

Coalfire lists a mailing address at 330 N Wabash Avenue in Chicago on its contact page. Its enterprise niche is cloud providers selling to the US government: its FedRAMP assessment page describes Coalfire as a FedRAMP Third Party Assessment Organization (3PAO) whose assessments include "manual control testing, vulnerability scanning, and penetration testing," with assessment teams serving "hundreds of major cloud service providers," and its DivisionHex offensive security team runs red teaming, social engineering and threat-informed penetration testing for PCI, HIPAA and FedRAMP programs. CREST lists Coalfire Systems, a UK entity, for Penetration Testing with seven years of membership, plus ISO 27001, ISO 9001 and Cyber Essentials. Named testers, retest terms and pricing are not stated.

Strength: FedRAMP penetration testing and red teaming from a firm that also runs the FedRAMP assessment. Limitation: when Coalfire is also your 3PAO or PCI assessor, agree how its testing team is separated from its assessment team; the CREST listing covers a UK entity. Best for: SaaS and cloud enterprises pursuing or maintaining FedRAMP authorization.

11. Bishop Fox

Bishop Fox lists its global headquarters in Tempe, Arizona, and describes itself on its contact page as "remote first, with a presence in 19 countries and 38 states." Its Cosmos platform "integrates directly with customer workflows through Jira and ServiceNow, enabling bi-directional syncing of validated findings," and its customer stories include Equifax, which "runs year-round perimeter testing," and a Fortune 500 energy provider using attack surface management and red team assessments. CREST lists Penetration Testing with four years of membership and ISO 27001. Named testers and pricing are not stated.

Strength: validated findings that sync both ways with ServiceNow and Jira, and an ISO 27001 listing. Limitation: the platform centers on the external attack surface, and no Canadian office appears among the offices it lists. Best for: enterprises that want continuous external testing feeding ServiceNow.


Firms considered and not ranked

Synack appears inside the NetSPI entry rather than as its own rank, because the two companies announced their merger on 2 September 2026. Deloitte, EY, KPMG, PwC and Accenture all hold CREST accreditations, but the Marketplace lists them under UK or Dutch entities or KPMG's international network (Deloitte's, for example, is Deloitte Consultative Services B.V.), so a North American enterprise should confirm which member firm signs and which team delivers before comparing them with the firms above. Mandiant, part of Google Cloud, holds Penetration Testing and threat-led accreditations through an Irish entity whose CREST listing covers Europe and the Middle East.

How much does an enterprise penetration testing program cost in 2026?

Enterprise programs are quoted, not listed, but the components can be benchmarked. Stingrai publishes its package prices: US$3,000 for an Autonomous Pentest, which is Snipe alone with no penetration testers, and US$6,800 for a Hybrid Pentest, where penetration testers and Snipe test together, each per assessment of exactly one web application and its APIs. The same tiers run at US$650 and US$1,275 per month on 12-month continuous plans, and the No High or Critical Finding = Don't Pay guarantee applies to the Autonomous tier only. Every other scope, from more applications to networks, Active Directory, cloud, red and purple teaming and social engineering, is quoted through get a quote, with current figures on the pricing page.

The bands below are indicative, taken from our penetration testing cost guide for US dollars and the Canadian cost guide for standard Canadian scopes.

Enterprise scope

Indicative US band

Indicative Canadian band (standard scope)

Web application, each

US$5,000 to US$30,000

CA$12,000 to CA$25,000

API, each

US$6,000 to US$30,000

CA$15,000 to CA$25,000

Network, external or internal

US$5,000 to US$40,000

CA$15,000 to CA$35,000 external; CA$20,000 to CA$35,000 internal

Active Directory

No separate US band in the guide

CA$25,000 to CA$35,000

Cloud (IaaS or PaaS)

US$10,000 to US$50,000

CA$25,000 to CA$40,000

Red team or adversary simulation

Quoted on tester-days

CA$45,000 to CA$65,000

Annual enterprise program

US$50,000 to US$150,000 or more

CA$60,000 to CA$90,000 (PTaaS subscription)

Few of the ranked firms publish prices. TrustedSec's enterprise guide says a targeted web application test may range from US$15,000 to US$40,000 and a full-scope red team engagement for a large enterprise can range from US$75,000 to US$250,000 or more. Three things move an enterprise quote most: the number of applications and user roles, the number of domains, clouds and sites in scope, and the count and length of red team scenarios. The cost calculator gives a starting figure.

Buyer checklist: what to put in the MSA, SOW and security review

These nine questions cover what enterprise procurement and vendor-risk reviews add to a standard penetration testing RFP. The RFP question bank supplies the scored technical questions, and the statement of work template the clauses.

  1. How many testers can you commit to our program at the same time, and can we see their names, certifications and CVs before we sign, with substitution only on our written approval?

  2. Which legal entity holds your accreditation, which entity signs, and where do testers sit? Check the entity on the CREST Marketplace.

  3. Which threat-led schemes can you deliver? Ask for CREST threat-led accreditations or CBEST status, how you meet DORA Article 27, and your I-CRT experience if you are a Canadian bank or insurer.

  4. Where will our findings, captured credentials and evidence live, and how are they destroyed? Require encryption, a retention limit, secure deletion of credentials and return of data at exit.

  5. What insurance do you carry? Request certificates for professional indemnity, including misconduct and negligence, and cyber liability.

  6. Will you sign our MSA terms? Include location of services, subcontractor approval, notice of ownership changes, authorization to test, stop-work contacts, change control and termination.

  7. Do findings reach Jira or ServiceNow, and can our SIEM see your test activity? Ask for single sign-on to the portal and a deconfliction process for red and purple team work.

  8. What do our board and CISO receive? Ask for an executive summary per engagement and trend reporting across engagements that supports NYDFS and SEC disclosures.

  9. How do one-time, continuous and red team work fit in one contract? Ask for a rate card, retest windows and what happens to pricing and staff if your provider is acquired.

Frequently Asked Questions

Who are the best enterprise penetration testing companies in 2026?

The best enterprise penetration testing companies in 2026 are Stingrai, NCC Group, NetSPI, IBM X-Force Red, GuidePoint Security, Optiv, Praetorian, TrustedSec, Kroll, Coalfire and Bishop Fox. Stingrai ranks first: a CREST-accredited penetration testing service provider at firm level whose human-led engagements are run by two named penetration testers from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP certifications, covering applications, cloud, Active Directory, networks and people, with red and purple teaming, findings pushed into Jira or ServiceNow, and one-time or continuous delivery. NCC Group, NetSPI and IBM X-Force Red follow.

What should an enterprise look for in a penetration testing company?

Look for capacity to staff several engagements at once with named, certified testers; firm-level accreditation that covers the discipline you are buying, including CREST threat-led accreditations where a regulator requires them; documented handling of findings, evidence and captured credentials; professional indemnity insurance; MSA terms on location, subcontractors, ownership changes and data return; findings delivered into Jira or ServiceNow; board-level reporting; and red and purple teaming alongside penetration testing, one-time or continuous.

Does OSFI B-13 require penetration testing or red teaming?

Guideline B-13 sets OSFI's expectations rather than statutory rules, and it names both. Section 3.1.2 says federally regulated financial institutions should set defined triggers and minimum frequencies for intelligence-led threat assessments and should regularly perform tests and exercises, with penetration testing and red teaming as examples, using an intelligence-led approach. B-13 took effect on 1 January 2024. Separately, OSFI's I-CRT framework currently applies to systemically important banks and internationally active insurance groups on a three-year supervisory cycle.

Who has to run DORA threat-led penetration testing, and what does DORA require of the testers?

DORA Article 26 requires financial entities identified by their competent authority to carry out threat-led penetration testing at least every 3 years on live production systems supporting critical or important functions. Article 27 limits the work to testers of the highest suitability and reputability, with expertise in threat intelligence, penetration testing and red team testing, who are certified by an accreditation body in a Member State or adhere to formal codes of conduct or ethical frameworks, provide an independent assurance or audit report on the risks of the test and hold professional indemnity insurance covering misconduct and negligence. Commission Delegated Regulation (EU) 2025/1190 adds CVs, certifications, at least five references and minimum experience for the red team.

Does a CBEST assessment need an accredited provider?

Yes. The Bank of England's CBEST Implementation Guide states that service providers must be accredited to conduct the threat intelligence, penetration testing and reporting elements of a CBEST and must also be members of CREST, which the guide calls the CBEST accreditation body, and the register of approved companies is published on CREST's website. As a pre-condition of accreditation, providers employ certified individuals, including, for penetration testing, a CREST Certified Red Team Manager or a Cyber Scheme Red Team Manager.

Can one firm run both penetration testing and red teaming for an enterprise?

Yes, and every firm ranked here offers both. Guideline B-13 names penetration testing and red teaming together as tests and exercises institutions should perform using an intelligence-led approach, and the DORA TLPT standards require a purple teaming exercise in the closure phase of a threat-led test. Buying penetration testing, red teaming and purple teaming from one firm keeps findings, detections and fixes in one record; splitting them across two firms adds independence. Either works if the contract says which.

What does NYDFS Part 500 require for penetration testing?

Section 500.5, as amended in November 2023, requires written vulnerability management policies and procedures designed to ensure that covered entities conduct, at a minimum, penetration testing of their information systems from both inside and outside the information systems' boundaries by a qualified internal or external party at least annually, alongside automated scans and manual review of systems the scans do not cover. Section 500.4(b) requires the CISO to report in writing at least annually to the senior governing body, including on material cybersecurity risks, the program's overall effectiveness and plans for remediating material inadequacies.

Do US public companies have to disclose penetration testing?

Not by name. Item 106 of Regulation S-K requires registrants to describe their processes, if any, for assessing, identifying and managing material cybersecurity risks, addressing as applicable whether they engage assessors, consultants, auditors or other third parties in connection with those processes, and to describe the board's oversight of cybersecurity risk. A penetration testing program and the firm that runs it are among the processes and third parties that disclosure can cover.

How much does an enterprise penetration testing program cost in 2026?

Our cost guide puts an annual enterprise program at US$50,000 to US$150,000 or more, and our Canadian guide puts a standard annual PTaaS subscription at CA$60,000 to CA$90,000 and a standard red team at CA$45,000 to CA$65,000. Stingrai publishes US$3,000 for an Autonomous Pentest and US$6,800 for a Hybrid Pentest per assessment of one web application and its APIs, or US$650 and US$1,275 per month on 12-month continuous plans; every other scope is quoted.


Ready to scope an enterprise penetration testing program?

Enterprise breaches rarely start where the last test looked. They start in an acquired subsidiary's forgotten host, a consent grant nobody reviewed, a partner's API token or a help desk call. Stingrai is a CREST-accredited penetration testing service provider whose testing supports your PCI DSS, NYDFS, OSFI B-13, SOC 2 and ISO 27001 programs, delivered as one-time annual engagements or continuous coverage, with named penetration testers, red and purple teaming, findings in Jira or ServiceNow, retesting, and an attestation letter on human-led and hybrid engagements. Book a free scoping call, get a quote for a multi-entity program, or see the published package prices on the pricing page.

0 views

0

X

Related reading

Best Penetration Testing Companies for Construction and Engineering Firms (2026)
Network SecuritySocial Engineering

Best Penetration Testing Companies for Construction and Engineering Firms (2026)

The best penetration testing companies for construction and engineering firms in 2026, ranked, with what CMMC, CPCSC, owners and insurers actually require.

30 min read

Best Penetration Testing Companies for Hotels and Hospitality (2026): Ranked for PCI DSS, Guest Data and Franchise Networks
Network SecurityWeb App Security

Best Penetration Testing Companies for Hotels and Hospitality (2026): Ranked for PCI DSS, Guest Data and Franchise Networks

The best penetration testing companies for hotels and hospitality groups in 2026, ranked, with what PCI DSS 11.4, the FTC Marriott order and PIPEDA require.

31 min read

Best Penetration Testing Companies for Logistics and Transportation (2026): Ranked for Freight, Ports, Rail and Aviation
Network SecuritySocial Engineering

Best Penetration Testing Companies for Logistics and Transportation (2026): Ranked for Freight, Ports, Rail and Aviation

The best penetration testing companies for logistics, freight, ports, rail and aviation in 2026, ranked, with what the Coast Guard, TSA and Canada require.

30 min read

Contents

X