main logo icon

Published on

September 19, 2026

|

18 min read

Best Identity Verification and KYC Penetration Testing Companies (2026)

Ranked guide to the best penetration testing companies for identity verification, KYC, biometric liveness and age verification platforms in 2026, with the regimes that govern the test and every vendor sourced from its own published page.

Arafat Afzalzada

Arafat Afzalzada

Founder

Web App SecurityNetwork Security

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

Identity verification platforms are tested against a stack no other software category carries at once: SOC 2 Type II as the universal customer ask, NIST SP 800-63-4 for identity and authentication assurance, ISO/IEC 30107-3:2023 for presentation attack detection, FinCEN CIP and FINTRAC obligations that flow down from regulated customers, and biometric privacy statutes in Illinois and Quebec that attach real money to a storage or transmission failure. NIST finalised SP 800-63-4 on 26 August 2025, and SP 800-63A-4 now tells credential service providers to detect virtual cameras, device emulators and jailbroken devices during remote proofing, which moves digital injection from a research topic to a control an assessor can ask about. Sumsub put deepfakes at 11 percent of all identity fraud globally in its Identity Fraud Report 2025-2026. The best identity verification and KYC penetration testing companies in 2026 are Stingrai, NetSPI, NCC Group, Coalfire, Praetorian, Include Security, Trail of Bits, Schellman, Bishop Fox, Synack, Software Secured and Cobalt. Every vendor entry links to the vendor's own published page, verified on 19 September 2026.

Deepfakes accounted for 11 percent of all identity fraud globally in 2025, AI-assisted document forgery went from 0 percent to 2 percent of cases in a single year, and multi-step attacks chaining several techniques together grew from 10 percent to 28 percent of identity fraud, according to Sumsub's Identity Fraud Report 2025-2026, published 25 November 2025, which puts the global identity fraud rate at 2.2 percent of all verification attempts. For the downstream damage, the US Federal Trade Commission's Consumer Sentinel Network Data Book 2024 logged US$12.5 billion in reported fraud losses and more than 1.1 million identity theft reports.

Identity verification vendors sit exactly where that pressure lands. They are the control their customers point at when a regulator asks how a person was identified, which makes an IDV platform a software product, a fraud control and a piece of somebody else's compliance evidence at the same time.

Where Stingrai fits: Stingrai is a CREST-accredited penetration testing service provider at firm level, headquartered in Toronto with a London office and founded in 2021. Each engagement is staffed with two named penetration testers holding OSCE³, OSWE, OSEP, CREST CRT and CISSP, with 18 published CVEs across the team and Hall of Fame listings at Apple, Google, the US Department of Defense and the US Federal Reserve. For an identity platform they test the verification flow and decisioning APIs authenticated across every tenant and analyst role, the mobile capture SDK and its host application against OWASP MASVS and MASTG including Keychain and Keystore storage, certificate pinning and root and jailbreak detection bypass with Frida and objection, and the cloud environment holding documents and biometric templates, delivered as a one-time engagement or a continuous programme through its PTaaS platform with retesting and an attestation letter included. Published pricing is US$3,000 for an Autonomous Pentest and US$6,800 for a Hybrid Pentest covering one web application and its APIs on the pricing page; every other scope is quoted individually.

The ranking below is built around the regimes that actually govern an identity platform's test, and every vendor entry links to the page on that vendor's own site that supports the claim, last verified on 19 September 2026.

Quick answer: who are the best identity verification and KYC penetration testing companies in 2026?

The best identity verification and KYC penetration testing companies in 2026 are Stingrai, NetSPI, NCC Group, Coalfire, Praetorian, Include Security, Trail of Bits, Schellman, Bishop Fox, Synack, Software Secured and Cobalt. Stingrai is a CREST-accredited penetration testing service provider at firm level, whose two named penetration testers per engagement cover the verification flow and decisioning APIs across every tenant and analyst role, the mobile capture SDK against OWASP MASVS and MASTG, and the cloud and internal estate an identity platform runs on, with one-time and continuous delivery through PTaaS and retesting and an attestation letter included. NetSPI, NCC Group and Coalfire follow for enterprise PTaaS scale, mobile and hardware assessment depth, and payment-regime assessment adjacency respectively.

Comparison chart of what SOC 2, NIST SP 800-63-4, ISO IEC 30107-3, PCI DSS, FinCEN and FINTRAC, and biometric privacy law each ask of an identity verification platform in 2026

What identity verification providers are actually required to test

Six regimes show up in IDV procurement, and they ask for six different things. The common failure is buying a generic web application assessment for a stack that needed a presentation attack detection evaluation, or the reverse.

Does SOC 2 require penetration testing for an identity verification platform?

No, not by name. The AICPA's 2017 Trust Services Criteria never uses the phrase. The hooks are CC4.1, where the entity performs ongoing or separate evaluations to ascertain whether the components of internal control are present and functioning, and CC7.1, covering vulnerability identification. Auditors read penetration testing into those criteria, which is why a SOC 2 Type II report is the universal ask in IDV sales cycles and why the test gets scheduled around the observation window rather than the release calendar. More on shaping that evidence is in the guide to SOC 2 penetration testing companies.

What does NIST SP 800-63-4 require of identity proofing and liveness?

NIST finalised SP 800-63-4 on 26 August 2025, with the identity proofing volume SP 800-63A-4 published in July 2025. IAL is the Identity Assurance Level, the rigour of proofing; AAL is the Authentication Assurance Level, the strength of the authenticator. Two clauses in SP 800-63A-4 land directly in a test scope. Section 3.11 sets the biometric bar:

When collecting and comparing biometric characteristics remotely, the CSP SHALL implement presentation attack detection (PAD) capabilities that meet the impostor attack presentation accept rate (IAPAR) performance metric of <0.07 ... All biometric presentation attack detection tests SHALL be conformant to ISO/IEC 30107-3:2023.

Section 3.14, "Digital Injection Prevention and Forged Media Detection", turns an old research problem into a testable control:

CSPs SHALL implement technical controls to increase confidence that digital media is being produced by a genuine sensor during the proofing process (e.g., detect the presence of a virtual camera, device emulator, or a jailbroken device).

That is the reason virtual camera injection, emulator detection bypass and mobile tamper resistance now belong in the statement of work rather than in a research backlog.

What is ISO/IEC 30107-3 and how do iBeta PAD levels work?

ISO/IEC 30107-3:2023, "Information technology, Biometric presentation attack detection, Part 3: Testing and reporting", second edition published September 2023, defines how presentation attack detection is measured and reported, including the APCER, BPCER and IAPAR metrics NIST now points at. The commercial route to that evidence is a conformance test at an accredited laboratory. iBeta publishes the structure: Level 1 artefact materials cannot exceed US$30 across six attack instrument species, Level 2 raises that to US$300 and takes two to four days per subject and species, Level 1 must pass first, and the gate caps BPCER and false non-match rate at 15 percent for Levels 1 and 2. iBeta states that conformance testing is not a certification of the vendor's product.

This is the split buyers get wrong most often. A PAD conformance test measures the matcher against artefacts in a laboratory. A penetration test attacks the platform around it: the capture SDK, the transport, the decisioning API, the review console and the webhook that carries the answer.

What do FinCEN, the BSA and FINTRAC require of an identity vendor?

Nothing directly, which is exactly why the pressure arrives anyway. The US Customer Identification Program rule at 31 CFR 1020.220 obliges the bank, and its reliance provision at 1020.220(a)(6) is limited to reliance on another institution subject to an anti-money-laundering programme rule and regulated by a federal functional regulator. A technology vendor does not absorb the obligation, so the bank keeps it and pushes assurance down by contract, formalised by the Interagency Guidance on Third-Party Relationships: Risk Management issued 6 June 2023 at 88 FR 37920, which directs banking organisations to monitor third-party information security controls including reviews of audit and testing results. In practice, that is a request for your report.

In Canada, FINTRAC's methods to verify the identity of persons and entities requires government-issued photo identification to be authentic, valid and current, bearing a name, photograph and unique identifying number that match the person presenting it. If your platform is the mechanism a reporting entity uses to meet that test, the integrity of your document pipeline is the integrity of their compliance record.

What do BIPA and Quebec law add for biometric data?

Illinois' Biometric Information Privacy Act at 740 ILCS 14/15(e) requires a private entity holding biometric identifiers to store, transmit and protect them using the reasonable standard of care within the private entity's industry, and at least as protectively as its other confidential information. Statutory damages are US$1,000 for negligent and US$5,000 for intentional or reckless violations. Public Act 103-769, effective 8 August 2024, limited repeated collection of the same identifier from the same person by the same method to a single recovery, removing the per-scan accrual theory. The 15(e) standard of care is untouched, and an industry standard of care is exactly the claim a penetration test report either supports or undermines.

In Quebec, the Act to establish a legal framework for information technology, CQLR c C-1.1, section 45 requires the creation of a biometric database to be disclosed to the Commission d'accès à l'information promptly and not later than 60 days before it is brought into service, with section 44, as amended by Law 25, requiring express consent. PIPEDA treats biometric data as sensitive, raising the expected safeguard level under its security principle.

Does PCI DSS apply to an identity verification platform?

Only where card data is captured, which is more common than IDV teams expect once a product bundles payment-instrument verification, micro-deposit checks or a paid consumer age check. Where it applies, PCI DSS 4.0.1 requirement 11.4 is the operative clause set: a documented methodology at 11.4.1, internal penetration testing at least every 12 months and after significant change at 11.4.2, external testing on the same cadence at 11.4.3, correction and repeat testing of exploitable findings at 11.4.4, and segmentation testing at least every 12 months at 11.4.5, tightening to every six months for service providers at 11.4.6. The standard is published in the PCI SSC document library.

What about US state age verification laws?

Age assurance became a distinct product line after the Supreme Court decided Free Speech Coalition, Inc. v. Paxton on 27 June 2025, upholding Texas House Bill 1181 on the reasoning that the law triggers and survives intermediate scrutiny because it only incidentally burdens the protected speech of adults. The consequence for vendors is consumer-scale traffic across a growing number of states, running on code newer than the KYC stack beside it, with strong incentives to minimise retention. High volume plus new code plus deliberately short-lived data is a testing scope in its own right.

Regime

Does it name penetration testing?

Cadence

What the evidence has to show

SOC 2 (2017 TSC)

No. CC4.1 evaluations and CC7.1 vulnerability identification are the hooks

Set by the observation window

An evaluation that was performed, scoped to the system described

NIST SP 800-63-4, final 26 August 2025

No, but it sets testable controls

Not stated

PAD meeting IAPAR below 0.07, plus virtual camera, emulator and jailbreak detection

ISO/IEC 30107-3:2023

No. It is the PAD test method

Per evaluation

A laboratory conformance report, not a product certification

PCI DSS 4.0.1 requirement 11.4

Yes, where card data is in scope

At least every 12 months and after significant change

Internal and external tests, findings corrected and retested

FinCEN CIP and FINTRAC

No. Obligations sit on the regulated customer

Contractual

Assurance passed down under third-party risk management

BIPA 15(e) and Quebec section 45

No

Continuous obligation

A reasonable industry standard of care, and a CAI notice at least 60 days before launch

How we ranked them

Twelve vendors were scored against six criteria specific to identity platforms. Every claim traces to a page the vendor publishes itself.

  1. Published coverage of the surfaces an IDV platform actually exposes. Mobile SDK, API, web console and cloud, on the vendor's own service pages rather than inferred from a logo wall.

  2. Mobile and client-side depth. Tamper resistance, certificate pinning, emulator and jailbreak detection, and local storage of captured images and extracted data.

  3. Authorization and business logic depth. Object-level authorization on verification records, tenant isolation for platform vendors, and abuse of the decisioning flow itself.

  4. Evidence quality. Whether the report is shaped for a SOC 2 auditor, a bank's third-party risk team and a regulator reading an incident file, including reproduction steps and tester credentials.

  5. Manual depth relative to automation. Manual verification of findings rather than scanner output rewritten as narrative.

  6. Delivery model fit. Whether the vendor supports both a one-time annual test and a continuous programme, and whether findings reach engineers in their tracker.

Vendors whose product is attack surface discovery, vulnerability management or compliance attestation without offensive testing were not ranked here, regardless of their strength in their own category.

Quick comparison: best identity verification and KYC penetration testing companies

Company

HQ

Delivery model

Named penetration testers

Retest

Client portal

Published pricing

Best for

1. Stingrai

Toronto, ON and London, UK

Human-led by two named testers, one-time or continuous through PTaaS

Yes, two per engagement

Included, with attestation letter

Yes, findings posted as confirmed

Yes, from US$3,000

Firm-level CREST accreditation across the verification flow, decisioning APIs, mobile capture SDK, cloud and internal estate

2. NetSPI

Minneapolis, MN

Enterprise PTaaS platform

Not published

Platform workflow

Yes

No

Large IDV platforms consolidating many assets into one managed programme

3. NCC Group

Manchester, UK

Consultant-led assessments

Not published

Scoped per engagement

Partial

No

Mobile, embedded and cryptographic depth on capture and matching stacks

4. Coalfire

Westminster, CO

Assessment-led plus technical testing

Not published

Scoped per engagement

Partial

No

Platforms whose procurement is driven by a payment or assessment relationship

5. Praetorian

Austin, TX

Continuous offensive security platform

Not published

Platform workflow

Yes

No

Cloud-native IDV estates where asset discovery is the first problem

6. Include Security

Brooklyn, NY

Boutique consultant-led

Not published

Scoped per engagement

No

No

Deep mobile and reverse engineering work on a capture SDK

7. Trail of Bits

New York, NY

Research-led high assurance

Not published

Scoped per engagement

No

No

Cryptographic design review and AI and ML components in a matching pipeline

8. Schellman

Tampa, FL

Assessment firm with a testing practice

Not published

Scoped per engagement

Partial

No

Teams buying testing alongside an existing attestation relationship

9. Bishop Fox

Tempe, AZ

Consultant-led plus platform

Not published

Platform workflow

Yes

No

Application and mobile assessment depth at enterprise scale

10. Synack

Redwood City, CA

Vetted researcher community on a platform

No, community model

Platform workflow

Yes

No

Continuous coverage across a broad asset inventory

11. Software Secured

Ottawa, ON

Subscription PTaaS

Not published

Within 12 months of report

Yes

No

Canadian fintech and IDV teams wanting developer-centric reporting

12. Cobalt

San Francisco, CA

PTaaS with a pentester network

Not published

Platform workflow

Yes

Credit model, not a price

Fast kickoff on a single web or API asset


1. Stingrai (top rated for identity verification and KYC)

Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.

Every engagement is staffed with two named penetration testers, reviewed by the team lead and an engagement partner. The team has 18 published CVEs and includes a founding member of Uber's offensive security team covering web, mobile and LLM work and a researcher with more than 400 Hall of Fame reports at Apple, Facebook, Google, Yahoo and the US Department of Defense, delivering one-time or continuously through its PTaaS platform. That breadth matters for an identity platform because the exploitable path almost always crosses a boundary: a capture SDK weakness becomes a decisioning API weakness becomes an enumerable verification result. Explore the PTaaS platform.

Services and scope

For an IDV, KYC or age assurance provider, scope typically covers the consumer-facing verification flow, the mobile capture SDK and its host application tested against OWASP MASVS and MASTG with static and dynamic analysis of the IPA and APK, Keychain and Keystore storage, certificate pinning and root and jailbreak detection bypass, the decisioning and results APIs tested authenticated across every tenant, the customer-facing dashboard, the internal review console where analysts adjudicate borderline cases and where broken function level authorization does the most damage, and the cloud environment holding captured documents and biometric templates, down to bucket policies, key management and cross-account role assumption.

Delivery and evidence

Engagements include documented findings with reproduction steps, remediation guidance and retesting. Clients get named penetration testers, live findings and direct communication with those testers through the PTaaS platform, plus a remediation tracking workflow. CREST accreditation applies to Stingrai as a penetration testing service provider and is separate from the individual certifications held by team members, which include OSCE3, OSCP, OSWE, OSEP, CREST CRT and CISSP. The team has 18 published CVEs, presents research at BSides and community conferences, and holds a 5.0 out of 5.0 rating across 19 Clutch reviews and 4.9 out of 5 on G2. Every report comes with an attestation letter and a verified badge naming scope, dates and methodology. Stingrai's penetration testing supports SOC 2, ISO 27001, PCI DSS 4.0 and NIST SP 800-53 and 800-171 programmes, which is the evidence pack an IDV vendor hands to a bank's third-party risk team.

Where Snipe fits

Snipe is Stingrai's AI agent for web application penetration testing, including the application's APIs. It is trained on more than 6,000 HackerOne Hacktivity disclosure reports and on skills distilled from Stingrai's own penetration testing methodology, and it hunts the classes that break identity platforms hardest: broken object level authorization on verification records, broken authorization between tenants, and business logic abuse in the decisioning flow. It performs black-box testing and white-box source review, generates AutoFix pull requests, and can run as a pull-request gate. Stingrai's penetration testers work concurrently with Snipe throughout the engagement, directing its focus and extending the attack paths it opens. Mobile SDKs, cloud, internal networks and social engineering are scoped with Stingrai's penetration testers.

Pricing and fit: Published Autonomous and Hybrid packages cover one web application and its APIs, with a one-time Autonomous Pentest from US$3,000, a one-time Hybrid Pentest with certified penetration testers at US$6,800, and the same tiers as subscriptions from US$650 and US$1,275 per month on a 12-month engagement. The Autonomous tier carries a No High or Critical Finding, Don't Pay guarantee. Mobile SDK, cloud, internal and multi-application scopes are quoted individually. Request a scoped quote.

Best for: identity verification, KYC and age assurance platforms that need CREST-accredited testing across the whole estate, with named penetration testers, retesting included and either an annual engagement or a continuous programme.


2. NetSPI

NetSPI, headquartered in Minneapolis, publishes a mobile application penetration testing service describing human-led testing of iOS and Android applications in which its testers manually assess application data storage, platform use and server-side APIs. Client and backend as one assessment is the correct shape for an SDK that ships inside somebody else's banking application, and platform delivery suits a large asset inventory.

Watch for: there is no published identity or biometric service page, so the domain context comes from your scoping brief, and enterprise programme pricing is heavy for a single application test.

Best for: larger identity platforms consolidating web, API, mobile and cloud testing into one managed programme.


3. NCC Group

NCC Group, headquartered in Manchester, UK, publishes application penetration testing and security assessments covering iOS, Android and other applications, their remote communications and their interactions with other applications, with consultant-led work aimed at business logic errors as well as technical vulnerabilities. The mobile, embedded and cryptography benches are the three disciplines a capture and matching stack leans on hardest.

Watch for: in a consultancy this large, tester seniority and continuity vary across engagements, so pin both down in the statement of work, and expect report-centric delivery rather than tracker integration.

Best for: IDV vendors needing deep mobile, embedded or cryptographic review of the capture and matching stack.


4. Coalfire

Coalfire, headquartered in Westminster, Colorado, publishes a financial services practice pairing offensive security with PCI DSS advisory and assessment work, including scope definition and PCI DSS 4.0 preparation. For an identity platform that touches card data anywhere in the funnel, buying the scope conversation and the test from a firm that assesses against the standard daily has obvious appeal.

Watch for: assessment-led procurement can scope the technical test to the framework rather than to the product's real attack surface, and the published material is service-level rather than methodology-level.

Best for: identity platforms whose testing budget already sits inside a payment or assessment relationship.


5. Praetorian

Praetorian, headquartered in Austin, Texas, publishes application penetration testing for web and mobile built on a methodology derived from the OWASP Application Security Verification Standard, with tiered levels of testing rigour, and states that its mobile coverage spans the on-device application through to the backend web services and REST APIs behind it. An ASVS-anchored methodology gives a defensible answer when an auditor asks what the test covered.

Watch for: attack surface management is the lead product, so confirm manual depth on a single authorization-heavy application, and the platform commercial model suits programme budgets more than a one-off test.

Best for: cloud-native identity platforms where finding the unknown assets is the first problem and testing them is the second.


6. Include Security

Include Security, based in Brooklyn, New York, publishes mobile application assessments, web application assessments and server applications, alongside software reverse engineering and exploit development. That last pair is the interesting one for an IDV vendor, because the realistic attack on a capture SDK starts with pulling it apart rather than with a proxy.

Watch for: no published findings portal, so delivery is report-centric, and no published identity, fintech or biometric vertical page.

Best for: teams who need a capture SDK or native client taken apart properly rather than scanned.


7. Trail of Bits

Trail of Bits, headquartered in New York, publishes multi-disciplinary security reviews spanning application security, cryptography, blockchain, and AI and machine learning, and states it has published 946 reports and completed more than 620 audits since 2012. Engagements ship custom Semgrep or CodeQL rules, fuzzing harnesses and proof-of-concept exploits alongside the findings, which matters when template protection, key management or a matching model is homegrown.

Watch for: research-led high assurance is priced and scheduled accordingly, and there is no PTaaS platform or published retest workflow.

Best for: identity platforms with proprietary cryptography or in-house models in the matching and liveness pipeline.


8. Schellman

Schellman, headquartered in Tampa, Florida, publishes a broad penetration testing portfolio spanning application testing of web apps, APIs and client-side applications, network, mobile for iOS and Android, social engineering, cloud, physical, hardware and IoT, red and purple teaming, and AI red teaming. It runs separate attestation practices, which is why it appears here: for many IDV vendors the attestation relationship predates the testing one.

Watch for: the testing material is not identity-specific, and where testing and attestation run together, confirm in writing which team performs which work and how independence is documented.

Best for: identity vendors already using the firm for attestation work who want testing under one contract.


9. Bishop Fox

Bishop Fox, headquartered in Tempe, Arizona, publishes application penetration testing across web applications, APIs and thick clients, a mobile assessment line performing manual and dynamic analysis of Android and iOS applications following OWASP methodologies, secure code review, and an AI-assisted application testing line pairing automation with expert review. The firm states it has conducted more than 10,000 application security assessments.

Watch for: no published identity verification or biometric vertical page, and enterprise scoping with no published rates.

Best for: larger identity platforms wanting application and mobile assessment depth from a well-known offensive security firm.


10. Synack

Synack, headquartered in Redwood City, California, publishes a financial services practice built on continuous testing through its platform using a vetted researcher community it describes as 1,500 researchers, with coverage analytics and role-based access control, framed explicitly against PCI, SOC 2, ISO 27001, the OWASP Top 10 and NIST 800-53. Coverage analytics give a defensible answer to what was tested and when.

Watch for: a community model means no named, consistent testing team, which some bank third-party risk reviews ask about directly, and breadth-first coverage suits inventory assurance more than a deep authorization review.

Best for: identity platforms needing continuous, analytics-backed coverage across a large and changing asset inventory.


11. Software Secured

Software Secured, a Canadian firm based in Ottawa, publishes a fintech penetration testing page describing testing of payment workflows and transaction processing, fraud scenarios, rate limiting and business logic abuse, tenant isolation, APIs and cloud infrastructure. It publishes concrete delivery commitments: onboarding in 24 to 48 hours, reports within 48 to 72 hours of test completion, and retesting available within 12 months of report delivery, with findings mapped to PCI DSS, SOC 2, ISO 27001, HIPAA and GDPR.

Watch for: subscription positioning fits an ongoing programme better than a single deep assessment, and the bench is smaller than the enterprise firms, so confirm native mobile capability if the SDK is the main target.

Best for: Canadian fintech and identity teams that want developer-centric reporting on a predictable cadence.


12. Cobalt

Cobalt, headquartered in San Francisco, publishes pentest services across web application, API, and AI and LLM testing, plus external and internal network and cloud infrastructure assessments, red teaming and secure code review, delivered on a platform promising launch in hours with real-time findings and direct access to testers. Commercially it runs a credit model rather than published per-test prices.

Watch for: time-boxed platform engagements can be shallow against a complex multi-role authorization model, and testers are drawn from a network, so continuity across a multi-year programme is not guaranteed.

Best for: early and growth-stage identity vendors who need a credible report on one web or API asset quickly.


What an identity verification penetration test should actually cover

The scope that matters is not the marketing site. It is the path from a camera on a stranger's phone to a trusted "approved" written into somebody else's compliance record.

  • Document injection and virtual camera attacks. Can a captured image be replaced by hooking the camera, running a virtual camera driver, using an emulator, or calling the upload endpoint directly? NIST SP 800-63A-4 section 3.14 asks for controls here, so a test that skips it leaves the newest named control unexamined.

  • Liveness bypass at the platform layer. Replay of a previously successful capture, reuse of a session token across verifications, and manipulation of a client-reported liveness verdict the server trusts.

  • Mobile SDK tamper resistance. Certificate pinning bypass, root and jailbreak detection bypass, hooking of the capture and scoring functions, keys in the shipped binary, and captured documents or biometric templates left in local storage, caches or logs.

  • API abuse and enumeration of verification results. Object-level authorization on verification identifiers, tenant isolation on shared endpoints, rate limiting, and whether the verification API can be used as an oracle to confirm a given person or document exists.

  • Webhook spoofing and result tampering. Unsigned or weakly signed callbacks, replayable notifications, and whether a forged webhook can mark a subject approved in the customer's system.

  • OCR and document pipeline injection. Malformed and adversarial images, payloads reaching downstream parsers, server-side request forgery in image fetching, and file handling in the conversion chain.

  • Privilege escalation in the review console. Role separation between analyst, supervisor and administrator, access to full document images versus redacted views, audit log integrity, and bulk export controls.

  • Biometric material at rest and in transit. This is where the Illinois standard of care and the Quebec notice obligation meet a technical finding.

Scope and acceptance criteria belong in writing: the penetration testing statement of work template and the penetration testing RFP template cover both sides of that conversation.

Buyer checklist: what to ask before you sign

  1. Does the scope name the mobile SDK separately from the web application? If not, the SDK gets tested as a client of the API and nothing more.

  2. Is document injection explicitly in scope, including virtual camera and emulator paths? Ask for it by name, and ask how it will be attempted.

  3. Who tests, and can you have their names and certifications? Bank third-party risk reviews ask this, so the answer needs to exist before the engagement.

  4. Is retesting included, and for how long after the report? A fix you cannot evidence as verified stays open in your customer's file.

  5. Will the report carry reproduction steps, scope, duration, methods and tester independence? That set is what makes a report usable by an auditor, a customer and a regulator alike.

  6. Does the vendor understand the difference between a PAD conformance test and a penetration test? A firm offering to certify your liveness is the wrong firm.

  7. What happens to the captured test data? You are handing a third party a pipeline built for identity documents, so retention and destruction terms belong in the contract.

How much does identity verification penetration testing cost in 2026?

Identity platforms price above a generic web application test because the realistic scope is three surfaces, not one: the consumer flow, the customer-facing API and dashboard, and the mobile capture SDK, with an internal review console behind them.

Scope

Typical range (USD)

Typical range (CAD)

Notes

Single verification API or web flow

US$5,000 to 15,000

C$7,000 to 21,000

Under roughly 25 endpoints, unauthenticated plus one role

Full IDV platform, web plus API, multi-role

US$15,000 to 40,000

C$21,000 to 55,000

Tenant isolation, review console, decisioning logic

Mobile capture SDK, iOS and Android

US$12,000 to 30,000

C$17,000 to 41,000

Tamper resistance, injection paths, local storage

Cloud environment review

US$8,000 to 25,000

C$11,000 to 34,000

Document and template storage, key management, IAM

Canadian figures are indicative conversions for budgeting, not quoted prices. Stingrai publishes package pricing openly: a one-time Autonomous Pentest from US$3,000 and a one-time Hybrid Pentest with certified penetration testers at US$6,800, each covering one web application and its APIs, with the same tiers as subscriptions from US$650 and US$1,275 per month on a 12-month engagement, retesting included. Mobile, cloud, internal and multi-application scopes are quoted individually on the pricing page. For a broader view, see the penetration testing cost guide.


Frequently Asked Questions

Who are the best identity verification and KYC penetration testing companies in 2026?

The best identity verification and KYC penetration testing companies in 2026 are Stingrai, NetSPI, NCC Group, Coalfire, Praetorian, Include Security, Trail of Bits, Schellman, Bishop Fox, Synack, Software Secured and Cobalt. Stingrai is a CREST-accredited penetration testing service provider at firm level, headquartered in Toronto with a London office, staffing each engagement with two named penetration testers (OSCE³, OSWE, OSEP, CREST CRT, CISSP, 18 published CVEs across the team). It tests the verification flow and decisioning APIs authenticated across every tenant and analyst role, the mobile capture SDK against OWASP MASVS and MASTG, the cloud environment holding documents and biometric templates, and the internal estate, delivered as a one-time engagement or a continuous PTaaS programme with retesting, an attestation letter and pricing published from US$3,000. NetSPI, NCC Group and Coalfire follow for enterprise platform scale, mobile and embedded depth, and payment-regime adjacency. Every entry links to the vendor's own published page, verified on 19 September 2026.

Does SOC 2 require penetration testing for an identity verification platform?

No, not by name. The AICPA's 2017 Trust Services Criteria never uses the phrase. CC4.1 requires ongoing or separate evaluations to determine whether internal control components are present and functioning, and CC7.1 covers vulnerability identification. Auditors read penetration testing into those criteria, which is why a SOC 2 Type II report is the universal customer ask for an identity vendor and why the test is normally scheduled inside the observation window.

What does NIST SP 800-63-4 require of identity proofing and liveness?

NIST finalised SP 800-63-4 on 26 August 2025, with the identity proofing volume SP 800-63A-4 published in July 2025. Section 3.11 states that when collecting and comparing biometric characteristics remotely, the credential service provider shall implement presentation attack detection meeting an impostor attack presentation accept rate below 0.07, with all such tests conformant to ISO/IEC 30107-3:2023. Section 3.14 requires technical controls to increase confidence that digital media is produced by a genuine sensor, giving detection of a virtual camera, device emulator or jailbroken device as examples, and requires analysis of submitted media for indicators of modification, manipulation, tampering or forgery.

What is ISO/IEC 30107-3 and how do iBeta PAD levels work?

ISO/IEC 30107-3:2023 is the biometric presentation attack detection testing and reporting standard, second edition published September 2023, which defines the metrics used to measure a liveness system. iBeta publishes the commercial structure: Level 1 uses attack instruments whose materials cannot exceed US$30, Level 2 raises that budget to US$300 and takes two to four days per subject and species, Level 1 must pass before Level 2 is attempted, and the gate caps the bona fide presentation classification error rate and false non-match rate at 15 percent for Levels 1 and 2. iBeta states that conformance testing does not translate to a certification of the vendor product, and it is not a substitute for a penetration test of the platform around the matcher.

How much does identity verification penetration testing cost in 2026?

Cost tracks scope. A single verification API or web flow typically runs US$5,000 to US$15,000, a full platform with multi-role web and API testing US$15,000 to US$40,000, a mobile capture SDK across iOS and Android US$12,000 to US$30,000, and a cloud environment review US$8,000 to US$25,000, with Canadian budgets roughly 1.35 times the US figure. Stingrai publishes package pricing openly, with a one-time Autonomous Pentest from US$3,000 and a one-time Hybrid Pentest with certified penetration testers at US$6,800, each covering one web application and its APIs, and the same tiers as subscriptions from US$650 and US$1,275 per month on a 12-month engagement. Other scopes are quoted individually on the pricing page.

What should an identity verification penetration test cover?

Document injection and virtual camera attacks against the capture path, liveness and presentation attack bypass at the platform layer including replay and client-trusted verdicts, mobile SDK tamper resistance covering pinning, root and jailbreak detection, hooking and local storage of captured material, API abuse and enumeration of verification results including object-level authorization and tenant isolation, webhook spoofing and result tampering, injection into the OCR and document processing pipeline, privilege escalation in the manual review console, and protection of biometric material at rest and in transit. The report should carry tester independence and expertise, scope, duration, methods and results with reproduction steps.


0 views

0

X

Related reading

Best Banking and Credit Union Penetration Testing Companies (2026)
Network SecurityWeb App Security

Best Banking and Credit Union Penetration Testing Companies (2026)

Best penetration testing companies for banks and credit unions in 2026, ranked, with what FFIEC, GLBA, NYDFS 500.5 and OSFI B-13 really require.

19 min read

Best Cloud Penetration Testing Companies for AWS and SOC 2 (2026)
Network SecurityWeb App Security

Best Cloud Penetration Testing Companies for AWS and SOC 2 (2026)

Ten cloud penetration testing companies ranked for AWS and SOC 2 Type II buyers: cloud coverage, delivery model, retest, evidence and 2026 prices.

16 min read

Best Energy and Utilities Penetration Testing Companies (2026): NERC CIP, TSA Pipeline Directives and Canadian Regulators Compared
Network SecurityWeb App Security

Best Energy and Utilities Penetration Testing Companies (2026): NERC CIP, TSA Pipeline Directives and Canadian Regulators Compared

Best energy and utilities penetration testing companies in 2026, ranked, with what NERC CIP, TSA directives and Canadian regulators really require.

20 min read

Contents

X