main logo icon

Published on

September 19, 2026

|

19 min read

Best Manufacturing Penetration Testing Companies (2026): CMMC, IEC 62443, TISAX and the IT/OT Boundary

Ranked guide to the best manufacturing penetration testing companies in 2026, with what CMMC, NIST SP 800-171, IEC 62443, TISAX and NIST CSF 2.0 actually ask of a test, what is safe to scope inside a plant, and US and Canadian price bands.

Arafat Afzalzada

Arafat Afzalzada

Founder

Network SecurityWeb App Security

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

Manufacturing was the most attacked industry for the fifth consecutive year in IBM's 2026 X-Force Threat Intelligence Index, accounting for 27.7% of incidents. Dragos tracked 119 ransomware groups hitting industrial organizations in 2025, 3,300 victims in total, with manufacturing more than two thirds of them and an average OT dwell time of 42 days. No manufacturing regime imposes a blanket annual penetration testing mandate. CMMC Levels 1 and 2 do not require a contractor penetration test at all, and Level 3 does through CA.L3-3.12.1e. IEC 62443-4-1 names penetration testing outright at SVV-4 for product suppliers. TISAX pushes testing through its assessment levels rather than a published calendar. NIST CSF 2.0 and its draft Manufacturing Profile are voluntary. SOC 2 applies when the manufacturer also sells software or a connected service. The scope question matters more than the cadence question. Corporate IT, ERP and MES, remote access into the plant and IT/OT segmentation are actively testable. Live production controllers are reviewed and tested passively, or on a lab and replica environment, because a crashed PLC is a safety event. The best manufacturing penetration testing companies in 2026 are Stingrai, Dragos, GuidePoint Security, NetSPI, 1898 & Co., DNV Cyber, IOActive, Red Trident, Bishop Fox, Packetlabs and Rockwell Automation. Every vendor entry links to the vendor's own published page, verified on 19 September 2026.

Manufacturing was the most attacked industry for the fifth consecutive year in IBM's 2026 X-Force Threat Intelligence Index, accounting for 27.7% of incidents observed by X-Force, with data theft the most common outcome. The operational picture is worse. Dragos tracked 119 ransomware groups targeting industrial organizations in 2025, up from 80 in 2024, 3,300 organizations impacted, manufacturing more than two thirds of all victims, and an industry-wide average dwell time of 42 days in OT environments, per the Dragos 2026 OT/ICS Cybersecurity Report and Year in Review published 17 February 2026.

Where Stingrai fits: Stingrai is a CREST-accredited penetration testing service provider headquartered in Toronto with a London office, founded in 2021. Its penetration testers work the IT side of the boundary, which is where almost every manufacturing incident starts: the external perimeter and remote access paths into the plant, internal lateral movement and Active Directory privilege escalation, segmentation testing between corporate IT and the plant networks, the ERP and MES web layer, the cloud tenancy behind a connected product, plant Wi-Fi, and phishing and physical entry against site staff. Snipe, Stingrai's autonomous AI agent, covers web applications and their APIs, and works concurrently with penetration testers on Hybrid web engagements. Testing is delivered one-time or continuously, with published pricing from US$3,000 for one web application and its APIs on the pricing page and every other scope quoted.

The regulatory picture for manufacturers is scattered across at least five regimes, and only two of them name penetration testing at all. The ranking below is built on what each regime actually says, on what can safely be tested in a live plant, and on vendor pages verified on 19 September 2026.

Quick answer: who are the best manufacturing penetration testing companies in 2026?

The best manufacturing penetration testing companies in 2026 are Stingrai, Dragos, GuidePoint Security, NetSPI, 1898 & Co., DNV Cyber, IOActive, Red Trident, Bishop Fox, Packetlabs and Rockwell Automation. Stingrai is a CREST-accredited penetration testing service provider whose two-tester teams (OSCE³, OSWE, OSEP, CREST CRT, CISSP, 18 published CVEs, Hall of Fame credit at Apple, Google, the US Department of Defense and the US Federal Reserve) test the IT side of the plant boundary: the external perimeter and remote access paths, internal lateral movement and Active Directory, IT/OT segmentation, the ERP, MES and connected-product web layer, plant Wi-Fi, and phishing and physical entry, one-time or as a continuous program through its PTaaS platform with named testers and retesting included. Dragos, GuidePoint Security and NetSPI follow for OT-native threat expertise, a published OT penetration testing service line, and device and hardware depth under a PTaaS model respectively.

Comparison chart of what CMMC, IEC 62443, TISAX, NIST CSF 2.0 and SOC 2 each ask of a manufacturing penetration test in 2026

What manufacturers are actually required to test

Five regimes drive manufacturing security procurement in North America. They say very different things, and buying against the wrong one is how plants end up with an expensive report nobody in the audit file can use.

Does CMMC require penetration testing for defense suppliers?

Not at the levels most suppliers hold. The word "penetration" appears exactly once in 32 CFR part 170, at § 170.14(c)(4)(xx), inside a Level 3 requirement, CA.L3-3.12.1e. It appears zero times in NIST SP 800-171 Revision 2, which is the complete Level 2 control set. Levels 1 and 2 place no penetration testing obligation on a contractor.

What makes testing the practical evidence at Level 2 is the scoring. Four requirements carry five points each under the DoD Assessment Methodology and are ineligible for a plan of action: RA.L2-3.11.2, CA.L2-3.12.1, CA.L2-3.12.3 and SI.L2-3.14.1. NIST SP 800-171A gives assessors EXAMINE, INTERVIEW and TEST as method families, and names "conducting penetration testing of key system components" among typical assessor actions under TEST. An independent test report is the artifact that most reliably answers an assessor asking whether a control is effective rather than merely documented.

For a tier-two supplier, the practical scope is the CUI enclave: the external perimeter, the internal enclave and Active Directory, the applications that touch controlled unclassified information, and the cloud tenancy holding it. Plant-floor assets are typically Specialized Assets or Out-of-Scope Assets, reviewed rather than assessed. The clause-by-clause treatment is in the CMMC penetration testing requirements guide, the vendor view is in the CMMC penetration testing companies ranking, and Canadian suppliers facing both regimes should read the CMMC and CPCSC guide for Canadian defence suppliers.

Does IEC 62443 require penetration testing?

Yes, for one specific audience, and it says so by name. IEC 62443-4-1, the secure product development lifecycle standard for industrial automation and control systems, places security verification and validation testing in Practice 5. Its requirements run SVV-1 security requirements testing, SVV-2 threat mitigation testing, SVV-3 vulnerability testing, SVV-4 penetration testing, and SVV-5 independence of testers, per the published table of contents of the ANSI/ISA version.

That binds one kind of manufacturer: the one that builds industrial products, controllers, gateways, drives, sensors or connected machines and sells them onward. If your customers ask for a 62443-4-1 aligned development process, SVV-4 turns a penetration test into a lifecycle artifact and SVV-5 governs who may run it. Asset owners and system integrators sit under different parts of the series, principally 62443-2-1 and 62443-3-2, which drive zone and conduit risk assessment rather than a named test.

What does TISAX require of automotive suppliers?

TISAX is run by the ENX Association and assessed against the VDA Information Security Assessment catalogue published by the German automotive industry association. There is no published annual penetration testing mandate. What exists is an assessment level structure: a higher assessment level brings on-site verification of systems rather than a remote document review, and technical review of critical IT systems and services is where penetration testing enters the catalogue.

For a North American automotive supplier the practical read is that the OEM's security addendum, not the catalogue, is usually what names the test. Treat TISAX as the reason the OEM is asking and the addendum as the specification you scope against, and confirm which assessment level your label requires before buying anything.

Does NIST CSF 2.0 require penetration testing for manufacturers?

No. NIST Cybersecurity Framework 2.0 is voluntary, and the sector guidance built on it is voluntary too. NIST published the initial public draft of NIST IR 8183 Revision 2, the CSF 2.0 Manufacturing Profile, on 29 September 2025, with comments closing 17 November 2025. As of 19 September 2026 it remains a draft. The revision realigns the profile to the six CSF 2.0 Functions, including the new GOVERN function, and adds guidance for supply chain risk management and platform security.

CSF 2.0 remains the most useful framing document to put in front of a board, because it organizes the program rather than prescribing a test. It is not, on its own, a reason to buy one.

When does a manufacturer need SOC 2?

When the manufacturer sells software, a connected product with a cloud service behind it, or a customer-facing portal processing customer data. A machine builder shipping steel does not need SOC 2. The same builder shipping steel plus a telemetry platform customers log into generally does, because the customer is now buying a service and will send a vendor security questionnaire that assumes one. Aftermarket marketplaces, remote monitoring subscriptions and fleet dashboards sit in the same place.

In that case the penetration test scope is the connected product, not the plant: the web application, the APIs, the mobile companion app, the tenancy model and the cloud environment. Penetration testing supports the SOC 2 program by producing the scope statement, technical report, remediation record and retest evidence the program consumes. The vendor view is in the SOC 2 penetration testing companies ranking.

What about cyber insurance and OEM security addenda?

These two drive more manufacturing penetration testing spend than every framework above combined, and neither publishes a standard. Insurance questionnaires ask whether an independent test was performed in the last twelve months, whether critical findings were remediated, and whether remote access to OT uses phishing-resistant multi-factor authentication. OEM addenda, especially in automotive and aerospace, name specific evidence: a current test report, a remediation plan with dates, and sometimes a retest letter. Answer both documents literally, and make the report say so on its cover page.

What a manufacturing penetration test can safely scope

The single biggest difference between a manufacturing engagement and an enterprise one is that the wrong packet can stop a line or trip a safety system. A competent provider partitions the estate before the first scan.

Scope chart showing what is actively tested against what is reviewed or tested passively in a manufacturing penetration test

Actively tested, the way any enterprise estate would be:

  • Corporate IT and Active Directory. The domain is where ransomware operators build the access they later use against the plant: perimeter, internal network, privilege escalation and lateral movement.

  • ERP, MES and the business applications above the line. Order data, formulations, bills of material and supplier records are the theft targets in the IBM data, and object-level authorization is the class that leaks them.

  • Remote access into the plant. Jump hosts, VPN concentrators, vendor support tunnels and remote desktop gateways, the path built for maintenance and reused for entry.

  • The IT to OT boundary itself. Segmentation is a control with a testable claim: can a compromised corporate workstation reach the process network, and by what route. Testing it is how you find the forgotten dual-homed engineering laptop.

  • Cloud environments and connected product backends. Telemetry ingestion, device identity, tenancy isolation and the APIs the product calls home on.

  • People. Phishing against plant supervisors and maintenance staff, who often sit outside the awareness program the office runs.

Reviewed, tested passively, or tested on a replica:

  • Live PLCs, RTUs and DCS controllers. Fragile protocol stacks mean an ordinary scan can fault a controller. Examine through configuration and architecture review, passive traffic analysis, or active testing on a lab bench or replica during a planned outage.

  • Safety instrumented systems. Never active-tested in production.

  • Historians and engineering workstations in production. Usually reviewed, with any active testing agreed in writing against a maintenance window.

  • Plant wireless and field devices. Scoped case by case, often during shutdown.

A provider proposing an unrestricted active scan of the process network on a running line has told you it does not test manufacturing. A provider proposing zero OT scope has told you it will sell an office network test with a plant-shaped cover page. The right answer is a written scope naming which assets are active, which are passive, which window each runs in, and who can stop the test. The penetration testing statement of work template carries that language.

How we ranked them

Eleven providers were scored against six manufacturing-specific criteria. Every claim below traces to a page the provider publishes itself, checked on 19 September 2026.

  1. Published manufacturing, industrial or OT testing page on the provider's own domain. Logo walls did not count.

  2. Safety-aware methodology: evidence the provider distinguishes active from passive testing and works around production constraints.

  3. IT/OT boundary competence: whether it tests segmentation and remote access, not just one side.

  4. Regulatory evidence quality: whether the report satisfies a CMMC assessor, a 62443 certification body, an OEM addendum or an insurer.

  5. Corporate estate depth: Active Directory, cloud, web applications and social engineering, because that is where initial access occurs in the incident data.

  6. Delivery model fit: support for both a one-time annual engagement and a continuous program, with findings reaching engineers in their tracker.

Providers whose product is monitoring, asset inventory or compliance documentation without offensive testing were not ranked here, and several candidates were dropped because no page on their own domain described manufacturing or OT testing work.

Quick comparison: best manufacturing penetration testing companies

Company

HQ

Delivery model

Best for

Source page, verified 19 September 2026

1. Stingrai

Toronto, Canada

Human-led, named penetration testers, PTaaS portal, one-time and continuous

Manufacturers testing the IT side of the boundary: perimeter and remote access, Active Directory, IT/OT segmentation, ERP, MES and connected-product web, plant Wi-Fi, phishing and physical entry

stingrai.io

2. Dragos

Washington, DC, USA

OT-native consulting plus platform

Plants that want OT threat intelligence behind the assessment

dragos.com/services

3. GuidePoint Security

Reston, Virginia, USA

Consulting, blended IT and OT teams

Buyers wanting a named OT penetration testing service line

guidepointsecurity.com/ot-penetration-testing

4. NetSPI

Minneapolis, Minnesota, USA

PTaaS platform plus hardware practice

Connected product makers needing device and OT hardware depth

netspi.com operational technology

5. 1898 & Co.

Kansas City, Missouri, USA

Engineering-led consulting, part of Burns & McDonnell

Heavy industrial and process estates where engineering context matters

1898andco.burnsmcd.com assessments

6. DNV Cyber

Norway, global delivery

Consulting inside an assurance group

Manufacturers who also need industrial certification work

dnv ICS penetration testing

7. IOActive

Seattle, Washington, USA

Research-led consulting

Deep hardware and embedded research on industrial products

ioactive.com ICS/OT

8. Red Trident

Houston, Texas, USA

Boutique OT consulting

Process and energy-adjacent plants wanting a specialist bench

redtrident.com OT assessments

9. Bishop Fox

Tempe, Arizona, USA

Consulting plus continuous offensive platform

Large manufacturers buying a manufacturing-specific offensive program

bishopfox.com manufacturing

10. Packetlabs

Toronto, Ontario, Canada

Manual-first consulting

Canadian plants wanting a published manufacturing testing page

packetlabs.net manufacturing

11. Rockwell Automation

Milwaukee, Wisconsin, USA

Vendor-led OT services

Estates standardized on one automation vendor's stack

rockwellautomation.com penetration testing


1. Stingrai (top rated for manufacturing)

Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.

Each human-led engagement is run by two named penetration testers and reviewed by a team lead with 16 years in penetration testing and exploit development. The team has 18 published CVEs and Hall of Fame credit at Apple, Google, the US Department of Defense and the US Federal Reserve. Engagements run one-time or as a continuous program through the PTaaS platform. Explore the PTaaS platform.

For a manufacturer, that work sits on the IT side of the boundary, which is where compromise actually begins. The testers take the external perimeter and the remote access route a vendor or maintenance engineer uses, then move inside: Active Directory ACL abuse, Kerberos and delegation paths to domain admin, and segmentation testing to establish whether a foothold on a corporate laptop can reach the plant network at all. On the application side they test the ERP and MES front ends and the connected-product portal authenticated as each user role, looking for broken authorization in order, entitlement and telemetry workflows. Phishing and vishing against plant and office staff, a physical entry attempt at the site perimeter, and a plant Wi-Fi assessment can be scoped into the same engagement.

Services and scope

Delivery and evidence

Findings reach the PTaaS portal as they are confirmed, each with a working proof of concept and prioritized remediation guidance, so a plant engineering team can start fixing before the report exists. Clients chat live with their named penetration testers during the test, push findings into Jira or Slack, get a redactable PDF report they can share with an OEM customer or an auditor, and get retesting of remediated findings plus an attestation letter and verified badge with every report. CREST accreditation applies to Stingrai as a penetration testing service provider, separate from individual tester certifications. Stingrai's penetration testing supports CMMC and NIST SP 800-171 readiness, SOC 2, ISO 27001 and PCI DSS programs by producing the scope statement, technical report, remediation record and retest evidence those programs consume.

Where Snipe fits

Snipe is Stingrai's autonomous AI agent for web application penetration testing, including the application's APIs. It hunts the complex classes that matter to a manufacturer's portal and MES front end: broken object-level authorization, IDOR and business logic flaws in order, quoting and entitlement workflows. Snipe also performs white-box code review and can gate pull requests. On a Hybrid engagement, penetration testers and Snipe test at the same time, with the testers directing Snipe's focus and extending the paths it surfaces. Network, cloud, Active Directory, social engineering and red team scopes are delivered by Stingrai's penetration testers.

Pricing and fit: Published Autonomous and Hybrid packages cover one web application and its APIs, from US$3,000 one-time. Multi-site plants, ERP estates, connected product programs and network scopes are quoted individually. Request a scoped quote. Stingrai suits manufacturers that want CREST-accredited offensive security with named penetration testers, retesting included, and a choice of annual or continuous delivery.

2. Dragos

Dragos publishes a professional services page covering OT Cyber Assessment, Red Team Services, OT Tabletop Exercises and incident response, with penetration testing named alongside network vulnerability assessment and purple team operations for ICS and OT environments. It is headquartered in Washington, DC, with global delivery, and it publishes the annual OT/ICS Year in Review that most of this article's threat data comes from.

Pros

  • OT-native from the ground up, with threat group intelligence that informs the assessment rather than decorating it.

  • Red team and purple team services designed for industrial environments, not repackaged enterprise engagements.

Cons

  • Platform-led commercial gravity: many buyers arrive through the monitoring product, which shapes the services relationship.

  • Corporate IT, web application and cloud testing is not the centre of the practice, so most manufacturers still need a second provider for that layer.

Best for: plants that want OT threat intelligence standing behind the assessment and can pair it with a separate corporate estate test.


3. GuidePoint Security

GuidePoint Security, headquartered in Reston, Virginia, publishes a dedicated OT penetration testing service alongside a broader OT security practice. Its published positioning combines IT and OT testing methodologies into one engagement rather than treating them as separate purchases, and its OT program review work maps to frameworks including the NIST Cybersecurity Framework, NIST SP 800-82, CIS Controls and IEC 62443.

Pros

  • One of the few large consultancies with OT penetration testing as a named, standalone service line rather than a footnote under industrial advisory.

  • Blended IT and OT methodology matches how attacks actually traverse a manufacturing estate.

Cons

  • Large reseller-and-services model means the delivery team varies by region, so pin down named testers in the statement of work.

  • Published methodology detail is thin at the service page level, so ask for a redacted sample report.

Best for: manufacturers who want a single provider running both sides of the IT/OT boundary in one engagement.


4. NetSPI

NetSPI, headquartered in Minneapolis, publishes an operational technology penetration testing page under its hardware systems practice, covering network configurations and processes, passive assets, active assets, active networks, device code review, system hardening, thick client applications and threat vectors, with non-production breach and attack simulation available. The same hardware practice covers automotive, medical device, IoT and ATM testing.

Pros

  • The passive versus active asset distinction is published on the page itself, which is the single clearest signal that a provider understands plant safety constraints.

  • Device code review and thick client testing cover the engineering software layer most providers skip.

Cons

  • Enterprise platform pricing and process suit programs more than a single scoped plant test.

  • No published manufacturing industry page, so the industry framing comes from your side of the table.

Best for: connected product manufacturers and larger estates that want device-level depth inside a platform relationship.


5. 1898 & Co.

1898 & Co. is the consulting practice of Burns & McDonnell, the employee-owned engineering and construction firm headquartered in Kansas City, Missouri. Its industrial cybersecurity assessment services cover testing and validation across networks and software applications end to end, alongside managed OT detection and response, and it names manufacturing and industrial among the sectors it serves.

Pros

  • Engineering-first heritage. The people scoping your test have built the kind of plant they are testing, which changes the conversation about what can go active.

  • Testing sits alongside managed OT monitoring, so findings can hand off to a team that will watch the environment afterwards.

Cons

  • Penetration testing is described inside a broad testing and validation line rather than as a distinct published service, so specify the engagement type precisely.

  • Consulting-scale procurement is heavier than a mid-market manufacturer may want for an annual test.

Best for: process and heavy industrial manufacturers who value engineering context over offensive-security brand.


6. DNV Cyber

DNV Cyber is the cybersecurity arm of DNV, the Norwegian assurance and classification group, and it publishes an ICS penetration testing service covering ICS penetration testing and testing of network segregation, stress and robustness testing, phishing campaigns, screening of running services, patches and firmware, authentication weaknesses, portable media security, traffic anomalies and software quality. Its published OT work emphasises assessing production environments without disrupting operations.

Pros

  • Network segregation testing is called out explicitly, which is the highest-value single test in most manufacturing estates.

  • Portable media and firmware screening reflect the actual infection paths in industrial environments.

Cons

  • Global delivery means North American manufacturers should confirm the regional bench and time zone coverage.

  • Service pages are organised by region, so the contracting entity and scope language vary by market.

Best for: manufacturers who need industrial assurance and offensive testing from the same group.


7. IOActive

IOActive, headquartered in Seattle, publishes an ICS and OT security practice spanning full stack security assessments, red and purple team services and advisory work, with critical infrastructure, energy and manufacturing named among its focus areas. Its public research record on SCADA and industrial control system vulnerabilities is among the longest in the field.

Pros

  • Research depth on embedded and industrial hardware is genuinely rare and shows up in findings other firms miss.

  • Full stack framing covers the product, the network and the backend together.

Cons

  • Research-led consultancies scope bespoke engagements, so timelines and pricing are less predictable than platform providers.

  • Less suited to a routine annual corporate network and application test.

Best for: industrial product manufacturers who need deep hardware and firmware research, including work that supports an IEC 62443-4-1 SVV-4 file.


8. Red Trident

Red Trident, headquartered in Houston, Texas, is an OT-focused boutique publishing OT cybersecurity assessments covering asset and network discovery, vulnerability assessment and penetration tests, risk assessments, red team exercises, compliance assessments and incident response assessments, with manufacturing named among the industries served.

Pros

  • Small specialist bench with process-industry operating experience, which usually means fewer arguments about what can be touched on a running line.

  • Penetration testing named directly in the assessment service rather than implied.

Cons

  • Boutique capacity constrains multi-site programs and parallel engagements.

  • Limited published web application, cloud and identity testing, so the corporate layer usually needs a second provider.

Best for: single-site and process manufacturers who want a specialist OT bench rather than a general consultancy.


9. Bishop Fox

Bishop Fox, headquartered in Tempe, Arizona, publishes a manufacturing industry page describing OT and ICS hardware penetration testing across PLCs, HMIs, SCADA systems and DCS, IT/OT segmentation validation, remote access pathways, historian and MES/ERP integrations, and cloud-to-plant connectivity, alongside continuous threat exposure management and supply chain testing.

Pros

  • The published scope list is the closest match in this ranking to the scope model set out earlier in this guide.

  • Continuous offensive testing alongside point-in-time engagements.

Cons

  • Enterprise programs are the commercial centre of gravity, so mid-market single-plant buyers may find the engagement model heavy.

  • Public pricing is not available, so budget planning requires a scoping call first.

Best for: large manufacturers buying a manufacturing-specific offensive program rather than a single annual test.


10. Packetlabs

Packetlabs, headquartered in Toronto, Ontario, publishes a manufacturing penetration testing page describing security testing for industrial and plant-floor environments across OT and ICS systems, IT/OT segmentation, remote access, and web applications and portals, framed around the reality that a cyber incident can halt production and disrupt supply chains.

Pros

  • A published manufacturing page with a plant-floor scope breakdown, which most Canadian providers do not have.

  • Manual-first testing approach with a consistent methodology across engagements.

Cons

  • Consulting delivery without a client platform, so findings integration into an engineering tracker is a statement-of-work item.

  • Depth on the OT side is lighter than the OT-native specialists higher in this list.

Best for: Canadian manufacturers who want a domestic, manual-first provider with published plant-floor scope.


11. Rockwell Automation

Rockwell Automation, headquartered in Milwaukee, Wisconsin, publishes penetration testing within its industrial cybersecurity services, alongside OT risk assessments, following its acquisition of the Verve industrial security business.

Pros

  • Nobody knows a Rockwell control stack better than Rockwell, which shortens the safety conversation on Allen-Bradley estates.

  • Services sit next to asset inventory and lifecycle management, so findings can feed a remediation program the same vendor supports.

Cons

  • Vendor-led testing of a vendor's own products raises an independence question that an auditor or certification body may ask about.

  • Corporate IT, application and identity testing is not the practice, so this is one layer of a program rather than the whole of it.

Best for: estates standardized on one automation vendor's stack that want the vendor's own team on the control layer.


How much does manufacturing penetration testing cost in 2026?

Manufacturing engagements price above a generic web application test because scope usually spans a corporate domain, a remote access path, an ERP or MES layer and a segmentation claim, with a written safety envelope around the plant. The bands below reflect commercial ranges observed across the North American market in 2026. Every real number depends on asset counts, site count and how much of the estate goes active.

Scope

United States

Canada

What that buys

Connected product web app and APIs

US$4,000 to US$12,000

C$5,000 to C$16,000

One authenticated application, roles and APIs, retest included

External plus internal network, single site

US$12,000 to US$30,000

C$16,000 to C$40,000

Perimeter, domain, privilege escalation, lateral movement

IT/OT segmentation and remote access review

US$15,000 to US$35,000

C$20,000 to C$45,000

Boundary testing, jump hosts, vendor tunnels, passive OT review

Multi-site manufacturer, phased program

US$45,000 to US$120,000

C$60,000 to C$160,000

Several plants, staged windows, consolidated reporting

Continuous testing program, annual

US$30,000 to US$100,000

C$40,000 to C$135,000

Ongoing testing, retests, portal access, change-driven retesting

Stingrai publishes package pricing openly. A one-time Autonomous Pentest with Snipe starts at US$3,000 and a one-time Hybrid Pentest with certified penetration testers is US$6,800, both covering exactly one web application and its APIs, and the same tiers run as subscriptions from US$650 per month and US$1,275 per month on a 12-month engagement. Retesting is included. Network, cloud, multi-site and connected product scopes are quoted individually. Current figures are on the pricing page, and the penetration testing cost calculator gives a scope-based estimate.

A buyer checklist for manufacturers

Take this into the scoping call and make the provider answer in writing.

  1. Name the driver. CMMC level, IEC 62443 clause, TISAX label, OEM addendum, insurer questionnaire or board mandate. The driver determines the report format, not just the scope.

  2. Split the estate on paper. Which assets are actively tested, which are passively reviewed, which are excluded, and which require a replica or a maintenance window.

  3. Get the safety envelope in the statement of work. Named stop authority on your side, an agreed window, a live communication channel, and an explicit no-active-testing list covering safety instrumented systems.

  4. Ask who tests. Named penetration testers, their certifications, and whether the people on the proposal are the people on the engagement.

  5. Ask what happens on the boundary. A provider who cannot describe how it would test whether a corporate workstation can reach the process network is not testing your actual risk.

  6. Confirm retesting is included. Every addendum and questionnaire that asks about findings also asks whether they were fixed. A retest letter answers that in one page.

  7. Confirm evidence format. Tester independence, scope, duration, methods, findings and reproduction steps satisfies an assessor, a certification body and an insurer alike.

  8. Check delivery model fit. An annual engagement suits a stable estate. A plant shipping MES and portal changes monthly is better served by a continuous program. Ask for both prices.

The vendor-facing version of these questions is in the penetration testing RFP template.


Frequently Asked Questions

Who are the best manufacturing penetration testing companies in 2026?

The best manufacturing penetration testing companies in 2026 are Stingrai, Dragos, GuidePoint Security, NetSPI, 1898 & Co., DNV Cyber, IOActive, Red Trident, Bishop Fox, Packetlabs and Rockwell Automation. Stingrai is a CREST-accredited penetration testing service provider whose two-tester teams (OSCE³, OSWE, OSEP, CREST CRT, CISSP, 18 published CVEs, Hall of Fame credit at Apple, Google, the US Department of Defense and the US Federal Reserve) test the IT side of the plant boundary: the external perimeter and remote access paths, internal lateral movement and Active Directory, IT/OT segmentation, the ERP, MES and connected-product web layer, plant Wi-Fi, and phishing and physical entry, one-time or as a continuous program through its PTaaS platform with named testers and retesting included. Dragos, GuidePoint Security and NetSPI follow for OT-native threat expertise, a published OT penetration testing service line, and device and hardware depth respectively. Every entry links to the provider's own published page and was verified on 19 September 2026.

Does CMMC require penetration testing for defense suppliers?

Not at Levels 1 and 2. The word "penetration" appears once in 32 CFR part 170, at § 170.14(c)(4)(xx), inside the Level 3 requirement CA.L3-3.12.1e, and zero times in NIST SP 800-171 Revision 2, which is the complete Level 2 control set. What makes a test the practical evidence at Level 2 is that four requirements carry five points each and cannot be deferred to a plan of action, and NIST SP 800-171A names "conducting penetration testing of key system components" among typical assessor actions under the TEST method.

Does IEC 62443 require penetration testing?

Yes, for product suppliers. IEC 62443-4-1, the secure product development lifecycle standard for industrial automation and control systems, places security verification and validation testing in Practice 5, and its requirements run SVV-1 security requirements testing, SVV-2 threat mitigation testing, SVV-3 vulnerability testing, SVV-4 penetration testing, and SVV-5 independence of testers. Asset owners and system integrators sit under different parts of the series, principally 62443-2-1 and 62443-3-2, which drive zone and conduit risk assessment rather than a named test.

What does TISAX require of automotive suppliers?

TISAX is run by the ENX Association and assessed against the VDA Information Security Assessment catalogue. It publishes no annual penetration testing mandate. Testing enters through the assessment level structure, where a higher level brings on-site verification of systems rather than a remote document review, and through the catalogue's technical review of critical IT systems and services. For most North American automotive suppliers, the document that actually names the test is the OEM's security addendum rather than the catalogue itself.

What can a penetration test safely cover inside a manufacturing plant?

Corporate IT and Active Directory, ERP and MES applications, remote access paths including VPN concentrators and vendor support tunnels, the IT to OT boundary and its segmentation claims, cloud environments and connected product backends, and social engineering against plant staff are all actively testable. Live PLCs, RTUs, DCS controllers, safety instrumented systems, production historians and plant wireless are reviewed, tested passively, or tested on a lab or replica environment during a planned window. Safety instrumented systems are never active-tested in production.

How much does manufacturing penetration testing cost in 2026?

Cost tracks scope, asset counts and site count. Observed 2026 bands run US$4,000 to US$12,000 for a connected product web application and its APIs, US$12,000 to US$30,000 for an external plus internal network test at a single site, US$15,000 to US$35,000 for an IT/OT segmentation and remote access review, and US$45,000 to US$120,000 for a phased multi-site program, with Canadian figures roughly C$5,000 to C$160,000 across the same tiers. Stingrai publishes package pricing openly, with a one-time Autonomous Pentest from US$3,000 and a one-time Hybrid Pentest at US$6,800 covering one web application and its APIs, and the same tiers as subscriptions from US$650 and US$1,275 per month on a 12-month engagement.

How often should a manufacturer run a penetration test?

No manufacturing regime sets a binding universal cadence. In practice the driver sets it: an annual test before the CMMC assessment and the annual affirmation, a test tied to the product release for an IEC 62443-4-1 file, a test before the TISAX assessment or the OEM addendum deadline, and an annual test for the insurance questionnaire. Manufacturers shipping MES, portal or connected product changes monthly increasingly run continuous testing so the gap between a change and its first test is measured in days.

Should a manufacturer buy an OT specialist or a general penetration testing firm?

Usually both, sequenced. The incident data points at the corporate estate: the domain, remote access and business applications are where intrusions start and where ransomware operators build the access they later use against the plant. Test that first with a provider strong in networks, identity, cloud and applications. Then bring an OT specialist to the control layer for a passive review, a segmentation test and, where justified, a lab-based active test. Buying only the OT specialist leaves the entry path untested, and buying only the enterprise firm leaves the boundary claim unproven.



References

  1. IBM. _IBM 2026 X-Force Threat Index: AI-Driven Attacks are Escalating as Basic Security Gaps Leave Enterprises Exposed._ 25 February 2026. https://newsroom.ibm.com/2026-02-25-ibm-2026-x-force-threat-index-ai-driven-attacks-are-escalating-as-basic-security-gaps-leave-enterprises-exposed. Source of manufacturing as the most attacked industry for a fifth year at 27.7% of observed incidents.

  2. Dragos. _Dragos 2026 OT/ICS Cybersecurity Report and Year in Review._ Press release, 17 February 2026. https://www.dragos.com/resources/press-release/dragos-2026-year-in-review-new-ot-threats-ransomware. Source of 119 ransomware groups, 3,300 industrial organizations impacted, manufacturing as more than two thirds of victims, and 42 days average OT dwell time.

  3. Office of the Federal Register. _32 CFR part 170, Cybersecurity Maturity Model Certification Program._ https://www.ecfr.gov/current/title-32/subtitle-A/chapter-I/subchapter-G/part-170. Source of CA.L3-3.12.1e at § 170.14(c)(4)(xx) as the only penetration testing requirement in the CMMC rule.

  4. National Institute of Standards and Technology. _SP 800-171 Revision 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations._ https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171r2.pdf. The complete CMMC Level 2 control set.

  5. National Institute of Standards and Technology. _SP 800-171A, Assessing Security Requirements for Controlled Unclassified Information._ https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-171A.pdf. Names penetration testing of key system components among typical assessor actions under the TEST method.

  6. International Electrotechnical Commission. _IEC 62443-4-1:2018, Security for industrial automation and control systems: Secure product development lifecycle requirements._ https://webstore.iec.ch/en/publication/33615. Defines the secure development lifecycle practices including security verification and validation testing.

  7. International Society of Automation. _ANSI/ISA-62443-4-1-2018 table of contents._ https://www.isa.org/getmedia/99afef02-46b1-4d75-9b46-4c4531fd1c34/isa-62443-4-1-toc.pdf. Confirms Practice 5 requirements SVV-1 through SVV-5, with SVV-4 titled Penetration testing and SVV-5 Independence of testers.

  8. ENX Association. _TISAX downloads, including the VDA Information Security Assessment catalogue._ https://portal.enx.com/en-us/TISAX/downloads/. Source for the TISAX assessment level structure and the catalogue used in assessments.

  9. National Institute of Standards and Technology. _NIST IR 8183 Revision 2 (Initial Public Draft), Cybersecurity Framework 2.0 Manufacturing Profile._ Published 29 September 2025, comments closed 17 November 2025. https://csrc.nist.gov/pubs/ir/8183/r2/ipd. Still a draft as of 19 September 2026.

  10. Dragos. _Professional Services._ https://www.dragos.com/services/. OT Cyber Assessment, Red Team Services and OT tabletop exercises, with penetration testing named for ICS and OT environments. Verified 19 September 2026.

  11. GuidePoint Security. _OT Penetration Testing Services._ https://www.guidepointsecurity.com/ot-penetration-testing/. Published OT penetration testing service line combining IT and OT methodologies. Verified 19 September 2026.

  12. NetSPI. _Operational Technology Penetration Testing._ https://www.netspi.com/netspi-ptaas/hardware-systems/operational-technology/. Published OT testing scope covering passive assets, active assets, active networks, device code review and thick client applications. Verified 19 September 2026.

  13. 1898 & Co. _Cybersecurity Assessment Services._ https://1898andco.burnsmcd.com/what-we-do/industrial-cybersecurity/cybersecurity-executive-advisory-services/cybersecurity-assessment-services. Testing and validation services across networks and software applications, with manufacturing and industrial named. Verified 19 September 2026.

  14. DNV. _ICS Penetration Testing Services._ https://www.dnv.com.au/services/ics-penetration-testing-services-127257/. ICS penetration testing and network segregation testing, firmware and patch screening, portable media security. Verified 19 September 2026.

  15. IOActive. _ICS and OT Security._ https://ioactive.com/service/ics-ot-security/. Full stack security assessments, red and purple team services, with manufacturing and critical infrastructure named. Verified 19 September 2026.

  16. Red Trident. _OT Cybersecurity Assessments._ https://redtrident.com/ot-cybersecurity-assessments-ics/. Asset and network discovery, vulnerability assessment and penetration tests, red team exercises, with manufacturing named. Verified 19 September 2026.

  17. Bishop Fox. _Manufacturing._ https://bishopfox.com/industries/manufacturing-industry. OT and ICS hardware penetration testing across PLCs, HMIs, SCADA and DCS, plus IT/OT segmentation validation. Verified 19 September 2026.

  18. Packetlabs. _Manufacturing Penetration Testing._ https://www.packetlabs.net/industries/manufacturing/. Security testing for industrial and plant-floor environments covering OT and ICS systems, IT/OT segmentation and remote access. Verified 19 September 2026.

  19. Rockwell Automation. _Penetration Testing._ https://www.rockwellautomation.com/en-us/capabilities/industrial-cybersecurity/products-services/penetration-testing.html. Penetration testing within industrial cybersecurity products and services. Verified 19 September 2026.

  20. Stingrai. _Pricing._ https://www.stingrai.io/pricing. Published one-time and continuous package prices for one web application and its APIs.


Ready to scope a manufacturing penetration test?

The incident that stops a line almost never starts on the line. It starts with a phished maintenance account, a vendor support tunnel nobody retired, or a domain admin path that was three hops long. Stingrai is a CREST-accredited penetration testing service provider whose penetration testers cover the corporate estate, the remote access path, the ERP and portal layer and the cloud behind a connected product, with retesting included and a choice of one-time or continuous delivery. Book a free scoping call, get a quote for a multi-site estate, or read the published package prices on the pricing page.

0 views

0

X

Related reading

Best Banking and Credit Union Penetration Testing Companies (2026)
Network SecurityWeb App Security

Best Banking and Credit Union Penetration Testing Companies (2026)

Best penetration testing companies for banks and credit unions in 2026, ranked, with what FFIEC, GLBA, NYDFS 500.5 and OSFI B-13 really require.

19 min read

Best Cloud Penetration Testing Companies for AWS and SOC 2 (2026)
Network SecurityWeb App Security

Best Cloud Penetration Testing Companies for AWS and SOC 2 (2026)

Ten cloud penetration testing companies ranked for AWS and SOC 2 Type II buyers: cloud coverage, delivery model, retest, evidence and 2026 prices.

16 min read

Best Energy and Utilities Penetration Testing Companies (2026): NERC CIP, TSA Pipeline Directives and Canadian Regulators Compared
Network SecurityWeb App Security

Best Energy and Utilities Penetration Testing Companies (2026): NERC CIP, TSA Pipeline Directives and Canadian Regulators Compared

Best energy and utilities penetration testing companies in 2026, ranked, with what NERC CIP, TSA directives and Canadian regulators really require.

20 min read

Contents

X