Nearly one in five US middle market executives say their company had a data breach in the past year. In the RSM US Middle Market Business Index Special Report: Cybersecurity 2026, published 13 May 2026, 18 percent of the 501 US middle market executives The Harris Poll surveyed for RSM between 6 and 30 January 2026 said their organization experienced a data breach in the previous 12 months, and a quarter of the 101 Canadian executives surveyed in February said the same. 24 percent of the US respondents reported at least one ransomware attack or demand over the same period. Many of the teams defending those companies are small: 46 percent of US respondents have 10 or fewer employees dedicated to data security and data privacy, and 20 percent have fewer than five, although 52 percent have more than 11. RSM defines the US middle market by revenue, from US$30 million to US$10 billion (CA$30 million to CA$1 billion for its Canadian sample).
That is the problem a mid-market testing program has to solve: several web applications and APIs, Active Directory joined to Microsoft 365 and Entra ID, one or two clouds, and audit, customer and insurer deadlines that land in the same quarter, often handled by a security team of a handful of people.
Where Stingrai fits: Stingrai is a CREST-accredited penetration testing service provider at firm level, founded in Toronto in 2021 with a London office, serving clients across the United States and Canada. Each human-led engagement is run by two named penetration testers from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP, reviewed by the team lead and an engagement partner, with 18 published CVEs across the team. For a mid-market company that means one scoping call and one statement of work covering the web applications and APIs customers log into, tested authenticated across every role; Microsoft 365 and Entra ID; Active Directory from an assumed-breach starting point; the external perimeter; and AWS, Azure or Google Cloud accounts. Findings post to the PTaaS portal as they are confirmed, with Jira and Slack integration and live chat with the testers, retesting is included, and human-led and hybrid engagements include an attestation letter for auditors and customers. Stingrai runs it as a one-time annual engagement timed to an audit window or as a continuous program. Published prices cover exactly one web application and its APIs: US$3,000 for an Autonomous Pentest and US$6,800 for a Hybrid Pentest (pricing); multi-app, network, Active Directory and cloud scopes are quoted.
Quick answer: who are the best penetration testing companies for mid-market companies in 2026?
The best penetration testing companies for mid-market companies in 2026 are Stingrai, RSM, BreachLock, Cherry Bekaert, Sprocket Security, CBIZ Pivot Point Security, Cobalt, Baker Tilly, Sikich and Rapid7. Stingrai ranks first for named, certified penetration testers across applications, Active Directory, Microsoft 365 and cloud in one engagement, with retesting, a findings portal and published per-application prices, one-time or continuous. RSM, BreachLock and Cherry Bekaert follow for hundreds of offensive security assessments a year from a firm built around the middle market, a CREST-accredited testing service with a medium enterprise offering and retest terms written per tier, and a testing and red team practice written for middle-market companies.

What auditors, regulators and customers actually require
Mid-market companies are not regulated as a class. The test reaches them through the frameworks they report against, and only some of those name it. The difference matters when you plan a program: where a rule names the test, it also sets a cadence and a standard of evidence; where it does not, the auditor or the customer decides what counts.
PCI DSS v4.0.1: the most specific rule
PCI DSS v4.0.1, published in June 2024, spells the test out. Requirement 11.4.2 requires internal penetration testing per the entity's defined methodology, at least once every 12 months and after any significant infrastructure or application upgrade or change, by a qualified internal resource or qualified external third party, on the condition that "Organizational independence of the tester exists (not required to be a QSA or ASV)." Requirement 11.4.3 applies the same terms to external testing. Requirement 11.4.4 requires exploitable vulnerabilities to be corrected and adds: "Penetration testing is repeated to verify the corrections." The retest is part of the requirement, not an extra. Where segmentation keeps the cardholder data environment small, 11.4.5 requires segmentation tests at least once every 12 months and after changes to segmentation controls, and 11.4.6 shortens that to every six months for service providers.
SOC 2: named, but only as an option
The AICPA's 2017 Trust Services Criteria, with revised points of focus from 2022, mention penetration testing under CC4.1, the monitoring criterion. A point of focus says an entity's risk and control evaluations "may include" items that end with "vulnerability scans, security assessment, penetration testing, and third-party assessments." The test is one form of evidence the criteria allow, not a mandate.
ISO 27001: evidence, not a requirement
ISO/IEC 27001:2022 does not require a penetration test, as the ISO 27001 guide sets out clause by clause. A test is the strongest evidence for two controls catalogued in ISO/IEC 27002:2022: 8.8, "Management of technical vulnerabilities," and 8.29, "Security testing in development and acceptance." A findings register that shows each issue fixed and retested is what turns the report into evidence for 8.8.
HIPAA: not named today, proposed every 12 months
The HIPAA Security Rule in force today does not use the word penetration. Its evaluation standard at 164.308(a)(8) requires "a periodic technical and nontechnical evaluation." HHS's proposed rule at 90 FR 898, published 6 January 2025, would add a proposed 164.312(h)(2)(iii) requiring penetration testing "at least once every 12 months or in accordance with" the entity's risk analysis, "whichever is more frequent." As of 1 October 2026 the Federal Register lists no final rule under that rulemaking, and the 2026 Unified Agenda lists it among long-term actions.
FTC Safeguards Rule and NYDFS Part 500
Two rules in particular name an annual test for mid-market financial companies. The FTC Safeguards Rule at 16 CFR 314.4(d)(2) requires non-bank financial institutions under FTC jurisdiction, absent effective continuous monitoring, to conduct "Annual penetration testing of your information systems determined each given year based on relevant identified risks in accordance with the risk assessment," plus vulnerability assessments "at least every six months." Under 314.6, institutions that hold customer information on fewer than 5,000 consumers are exempt from that testing clause. 23 NYCRR 500.5 requires New York-regulated covered entities to conduct "penetration testing of their information systems from both inside and outside the information systems' boundaries by a qualified internal or external party at least annually."
SEC Item 106 for listed companies
Listed mid-caps have one more reader. Item 106 of Regulation S-K, at 17 CFR 229.106, asks registrants to describe their processes for assessing, identifying and managing material cybersecurity risks, including whether the registrant "engages assessors, consultants, auditors, or other third parties in connection with any such processes." It does not name penetration testing, but an independent test is one of the third-party processes an annual report can describe.
Canada: PIPEDA, Quebec and OSFI B-13
Canadian privacy law asks for safeguards, not tests. PIPEDA Principle 4.7 says personal information "shall be protected by security safeguards appropriate to the sensitivity of the information," and section 10 of Quebec's private sector act requires security measures that "are reasonable given the sensitivity of the information, the purposes for which it is to be used, the quantity and distribution of the information and the medium on which it is stored." Neither names a test. Federally regulated financial institutions, including banks, trust and loan companies and insurers, also answer to OSFI Guideline B-13, effective 1 January 2024, which says they "should also regularly perform tests and exercises, to identify vulnerabilities or control gaps in its cyber security programs (e.g., penetration testing and red teaming) using an intelligence-led approach."
Customers and insurers
For many mid-market companies the most demanding reader of a penetration test is a customer. When an enterprise customer sends a vendor-risk questionnaire, the evidence it can use is an attestation letter and an executive summary, which is where the enterprise security review guide starts. Insurers are the third reader: 75 percent of RSM's US respondents carry a cyber insurance policy.
Rule | Who it reaches | Names penetration testing? | Cadence | What the evidence has to show |
|---|---|---|---|---|
PCI DSS v4.0.1, Requirement 11.4 | Merchants and service providers that handle card data | Yes | At least every 12 months and after significant change; segmentation every 12 months (six for service providers) | A defined methodology, tester independence, corrections retested |
SOC 2, criterion CC4.1 | Service organizations reporting to customers | Listed among evaluations that "may include" it | None set | Monitoring that shows controls are present and functioning |
ISO/IEC 27001:2022 | Certified management systems | No; evidence for controls 8.8 and 8.29 | None set | Technical vulnerabilities found, fixed and retested |
HIPAA Security Rule | Covered entities and business associates | Not today; proposed at 90 FR 898, not final | Proposed: at least every 12 months | A periodic technical and nontechnical evaluation |
FTC Safeguards Rule, 314.4(d)(2) | Non-bank financial institutions (testing clause does not apply below 5,000 consumers) | Yes | Annual, absent effective continuous monitoring | Testing based on the risk assessment, plus six-monthly vulnerability assessments |
NYDFS 23 NYCRR 500.5 | New York-regulated covered entities | Yes | At least annually | Inside and outside the boundaries, by a qualified party |
SEC Regulation S-K, Item 106 | US-listed companies | No | Annual report disclosure | Whether third-party assessors are engaged |
PIPEDA and Quebec's private sector act | Private-sector organizations in Canada | No | None set | Safeguards appropriate to the sensitivity of the information |
OSFI Guideline B-13 | Federally regulated financial institutions | Yes, as an example | Regularly | Tests and exercises using an intelligence-led approach; defined triggers and minimum frequencies for threat assessments |
The mid-market attack surface: what a program has to cover
The perimeter is still where many intrusions start. Describing RSM's incident response work in the 2026 report, RSM director Rich Servillas said: "Exposed edge devices are the dominant initial access vector. Many events are also attributed to gaps in a victim's firewall, as well as virtual private network (VPN) and multifactor authentication (MFA) issues." What happens after that first foothold depends on identity, which is where a perimeter-only scope misses the most.

Customer-facing web applications and APIs. Authorization between tenants, accounts and roles, business logic, file handling and the APIs behind each application. These flaws need a tester logged in as each role; scanners rarely find them.
Internal and lower-risk applications. HR portals, intranets and admin tools that hold less sensitive data but still sit behind single sign-on, where continuous or autonomous coverage is usually enough.
The external perimeter and remote access. VPN appliances, firewalls, remote desktop gateways and management interfaces exposed to the internet, the edge devices an RSM incident response director calls the dominant initial access vector.
Active Directory and the internal network. ACL abuse, Kerberos and delegation paths and certificate template misconfigurations turn one phished workstation into domain admin. Test from an assumed-breach starting point.
Microsoft 365, Entra ID and cloud accounts. Conditional Access exceptions, legacy authentication, OAuth consent grants, guest access, mailbox rules and cloud roles. "Most threat actors don't break in. They log in," RSM principal Alden Hutchison says in the same report. The largest group of RSM's US respondents, 30 percent, run 21 to 50 percent of their environment in the cloud.
Cardholder data and segmentation. Where segmentation keeps systems out of PCI scope, PCI DSS 11.4.5 requires it to be tested.
People and the help desk. RSM reports that automation has improved business email compromise and "spear phishing and vishing attacks, where an attacker may pretend to be a help desk employee." Phishing, vishing and the password reset process belong in scope.
SaaS integrations and AI features. OAuth-connected apps, service accounts with broad API scopes, and AI assistants that can reach company data or act on instructions planted in a document.
How to scope a program across many assets
A mid-market company rarely buys one test. It buys a program, and the scope decides whether the quotes it receives are comparable.
Start from an inventory, not a vendor's package. List every internet-facing application and API with its user roles and the data it holds, every Active Directory domain and Entra tenant, every cloud account, the remote access points, and the systems inside PCI, SOC 2, ISO 27001 or HIPAA scope.
Tier the applications. Customer-facing applications that hold regulated or customer data get a human-led or hybrid test, authenticated across every role, at least annually and after major releases. Internal and lower-risk applications can run on autonomous or hybrid coverage. Brochure sites need scanning, not a penetration test.
Map each asset to the framework that asks for evidence. One test can serve PCI DSS, SOC 2 and ISO 27001 if the scope statement names the systems and the report dates fall where each auditor needs them.
Test identity once, properly. Treat Active Directory, Entra ID and Microsoft 365 as one attack path from an assumed-breach starting point rather than three separate assessments.
Write one statement of work with a scope line per asset. Give each line a test type, perspective (black, grey or white box), the roles to test and the exclusions, so quotes can be compared line by line.
Schedule backward from the deadlines. Work back from the SOC 2 period end, the PCI assessment date, the ISO surveillance audit, the insurance renewal and the largest customer's security review, and leave time to fix and retest before each.
One-time annual testing or continuous coverage?
The rules set a floor, not a delivery model. PCI DSS asks for a test at least every 12 months and after significant change, NYDFS asks for one at least annually, and the FTC rule treats effective continuous monitoring as the alternative to an annual test. An annual engagement meets the floor and gives auditors and customers a dated report. It does not cover the rest of the year, when teams ship releases, change Conditional Access policies and add cloud accounts.
Many mid-market programs end up with both: a human-led annual test of the full scope timed to the audit calendar, and continuous coverage of the applications that change most. Continuous testing earns its cost where release frequency is high, where PCI's significant-change trigger keeps firing, or where customers ask for fresh evidence during the year. It earns less on a stable internal network, where an annual assumed-breach test plus a test after major changes is usually enough. The continuous PTaaS explainer compares the delivery models.
Stingrai runs both: one-time annual engagements across the full scope, and continuous programs at US$650 a month for Autonomous or US$1,275 a month for Hybrid on 12-month plans for one web application and its APIs, with every other continuous scope quoted.
Retest and remediation support for a lean team
A finding closes when someone fixes it and someone else confirms the fix. In RSM's survey, 46 percent of US respondents have 10 or fewer employees dedicated to data security and data privacy, and the functions respondents most often outsource are cloud security management (50 percent), security awareness training (44 percent), the security operations center (43 percent) and cybersecurity risk and compliance management (41 percent). For a team that size, the testing vendor's remediation support decides how quickly findings close.

Retest terms vary more than most buyers expect. Among the firms ranked here, BreachLock's pricing page lists one free manual retest on its Standard tier and two on Extended, Cobalt lists free retesting for six months on its Standard tier and 12 months on Premium and Enterprise, Sprocket Security advertises unlimited retests, and Stingrai includes retesting of remediated findings. PCI DSS 11.4.4 requires the retest, so get the terms in writing. Then ask four more questions: do findings arrive as they are confirmed or only in the final report, do they flow into your ticketing system, can your developers talk to the testers during the test, and will the retest result be documented in a report or letter you can hand to an auditor?
How we ranked them
Ten vendors were scored against ten criteria. Every accreditation was checked on the CREST Marketplace, and every vendor entry links to a page on the vendor's own site, verified on 1 October 2026.
Published mid-market evidence on the vendor's own site: a page, package, program, case study or client evidence for mid-market buyers.
Firm-level accreditation on the CREST Marketplace, plus the company certifications listed there.
Coverage of the mid-market surface: applications and APIs, Active Directory and Microsoft 365, cloud, the perimeter and people.
Named testers, identified with their certifications before signing.
Retest terms stated in writing.
Delivery: a findings portal and integrations, and both one-time and continuous options.
Evidence for auditors and customers, such as an attestation letter and an executive summary.
Pricing transparency.
North American delivery in the United States, Canada or both.
Independence from the company's IT provider and from its SOC 2 or financial statement auditor.
The 10 companies at a glance
# | Company | Based (own site) | CREST Marketplace | Mid-market evidence | Delivery model | Retest | Published pricing | Best for |
|---|---|---|---|---|---|---|---|---|
1 | Stingrai | Toronto, ON (London, UK office) | Penetration Testing, firm level | Founder leads engagements for start-ups, mid-market and enterprises; multi-scope case study | Human-led, hybrid or autonomous; one-time or continuous; PTaaS portal | Included | Yes, US$3,000 and US$6,800 for one web app and its APIs | Apps, Active Directory, Microsoft 365 and cloud in one engagement with named testers |
2 | RSM | Chicago, IL (RSM Canada member firm) | Not listed for the US or Canadian firm | Firm built around the middle market; publishes the middle market cybersecurity survey | Consultant-led testing, red and purple teaming | Not stated | No | Testing from a middle market adviser in both countries |
3 | BreachLock | New York, NY (London and Amsterdam offices) | Penetration Testing (Breachlock Ltd, UK); ISO 27001; US SOC 2 Type 2 | Medium enterprise section on its offensive security page | In-house testers, project manager, optional platform | 1 free manual retest (Standard), 2 (Extended), custom (Extensive) | No | Regular compliance testing with a dedicated project manager |
4 | Cherry Bekaert | Raleigh, NC | Not listed | Testing and red teaming page for middle-market companies | Advisory-led testing, including AI, cloud and social engineering | Not stated | No | Testing and threat-based red teaming from one adviser |
5 | Sprocket Security | Madison, WI | Penetration Testing | Mid-market customer reviews on its pricing page | Continuous testing by AI agents and penetration testers | Unlimited | Yes, Starter Package at US$15,000 | Continuous external testing at a published price |
6 | CBIZ Pivot Point Security | Hamilton, NJ | Penetration Testing; ISO 27001 | Serves small and middle market businesses | Consultant-led testing beside compliance consulting | Not stated | No | Testing next to ISO 27001 or SOC 2 readiness work |
7 | Cobalt | Boston, MA (US headquarters) | Penetration Testing (Cobalt Labs, Germany); ISO 27001 | Mid-size firm section on its offensive security services page | PTaaS on annual credit packages | Free for 6 months (Standard) or 12 months (Premium, Enterprise) | No | Many application tests scheduled through one platform |
8 | Baker Tilly | Chicago, IL | Not listed | Firm "built for the middle market" | Advisory-led testing; internal work is vulnerability scanning | Not stated | No | Companies already working with a middle market adviser |
9 | Sikich | Chicago, IL | Not listed | Solution portfolio in the middle market | Testing inside a professional services firm | Not stated | No | Companies already using Sikich for technology or compliance |
10 | Rapid7 | Boston, MA | Not listed | Published engagement for a midsize company | Point-in-time testing plus a continuous red team service | Not stated | No | Companies already running Rapid7's platform |
"Not stated" means the vendor's own site does not say. Ask for it in writing.
1. Stingrai
Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.
What a mid-market buyer can check. The firm-level accreditation is on the CREST Marketplace supplier page for Stingrai Inc, separate from the CREST CRT certifications individual testers hold. The Clutch profile shows 5.0 out of 5 from 20 reviews when checked on 1 October 2026. The team has published 18 CVEs, including CVE-2025-50674, a privilege escalation to root in OpenMediaVault, and CVE-2024-32136, an SQL injection in the BWL Advanced FAQ Manager plugin. Two named penetration testers, from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP, run each human-led engagement, reviewed by the team lead and an engagement partner, under founder Arafat Afzalzada, who has led penetration testing engagements for start-ups, mid-market companies and enterprises over 11 years in offensive security. A Clutch-verified case study for an automotive aftermarket services company in Quebec, which its Clutch review lists at 201 to 500 employees, describes security testing "across our environment covering multiple scopes," with weekly updates on findings for each section.
How a mid-market program is tested. Web application testing covers each application and its APIs, black, grey or white box, authenticated across every role, for broken authorization, IDOR and business logic under OWASP Top 10 and ASVS. Cloud testing treats Microsoft 365 and Entra ID as an attack path: app registrations, service principals, consent grants, Conditional Access gaps and hybrid-join trust, plus AWS and Google Cloud roles and policies. The Active Directory assessment follows ACL abuse and Kerberos and delegation paths to domain admin, and network testing covers the external perimeter, internal lateral movement and segmentation. Phishing and vishing campaigns test the help desk and the password reset process.
Evidence and delivery. Findings post to the PTaaS portal as they are confirmed, each with a working proof of concept and remediation guidance, with live chat to the assigned testers and Jira and Slack integration, which is what lets a two-person security team keep up. Reports are redactable for customers, retesting of remediated findings is included, and human-led and hybrid engagements include an attestation letter and a verified badge. Stingrai's penetration testing supports your SOC 2, ISO 27001, PCI DSS and HIPAA programs, delivered as a one-time annual engagement timed to the audit window or as a continuous program that tests every release.
Where Snipe fits. Snipe, Stingrai's autonomous AI penetration testing agent for web applications and their APIs, keeps applications covered between annual human-led tests and on every release. It hunts broken authorization, IDOR and business logic flaws, reviews code, and opens AutoFix pull requests. The Autonomous tier is Snipe alone, with no penetration testers; in a Hybrid engagement Snipe and the penetration testers test together throughout, with the testers directing its focus. Active Directory, Microsoft 365, network, cloud and social engineering scopes are tested by penetration testers.
Pricing: US$3,000 for an Autonomous Pentest and US$6,800 for a Hybrid Pentest per assessment of exactly one web application and its APIs, or US$650 and US$1,275 per month on 12-month continuous plans, on the pricing page. Every other scope is quoted through get a quote.
Strength: one engagement and one portal across applications, identity, network and cloud, with named testers and published per-application prices. Limitation: a small team, so programs needing many concurrent engagements need scheduling lead time, and the fixed-price packages cover one web application and its APIs only. Best for: mid-market companies in the US and Canada that need named, certified penetration testers across apps, Active Directory, Microsoft 365 and cloud, with an attestation letter for auditors and customers, one-time or continuous.
2. RSM
RSM US LLP, which announced the move of its headquarters to Chicago in 2013, marks its centenary on its about page with the line "For 100 years we have been serving the middle market," and RSM Canada, whose consulting arm is an affiliate of RSM US LLP, sells the same testing service in Canada. Its US penetration testing page promotes RSM's Attack Vectors Report with the line "With breaches on the rise in the middle market," and says "RSM's cyber testing team performs hundreds of offensive security assessments each year." Its security testing page lists mobile application, web services and API testing, network testing that is external, internal, wireless, ICS/SCADA, cloud and PCI, physical security testing, social engineering and red and purple team services. RSM also publishes the middle market cybersecurity survey cited above. CREST lists RSM Australia rather than the US or Canadian firm, and named testers, retest terms, a findings portal and pricing are not stated.
Strength: hundreds of offensive security assessments a year from a firm built around the middle market, delivered in both the United States and Canada. Limitation: RSM is also an audit and tax firm, so if it audits your financial statements or issues your SOC 2 report, confirm how the testing team is separated, and get retest terms in writing. Best for: mid-market companies that want testing, red teaming and middle market advisory from one firm in both countries.
3. BreachLock
BreachLock Inc. lists its address at 1350 Avenue of the Americas in New York, with offices in London, Amsterdam and Noida, India. Its offensive security page has a section for medium enterprises: "With the expansion of mid-size businesses and their digital presence, their vulnerability to threats also expands," it says, "underscoring the importance of implementing ongoing and proactive security testing." Its penetration testing pricing page says testing is "performed by in-house, OSCP and CREST-certified testers," describes a Standard tier for "Small to medium-sized web apps, basic internal networks & external network infrastructure" and an Extended tier for "Medium-sized apps, complex networks, and APIs needing advanced testing," and lists one free manual retest on Standard, two on Extended and a custom number on Extensive, with no dollar figures. A dedicated project manager is assigned and platform access is optional. CREST lists Breachlock Ltd, a UK entity, for penetration testing, with five years of membership, ISO 27001, Cyber Essentials, US SOC 2 Type 2 and 26 to 50 technical people. Named testers are not stated.
Strength: a medium enterprise section, firm-level CREST accreditation and retest terms written per tier. Limitation: no prices are published, and the offensive security page also advertises "free unlimited vulnerability retesting," so confirm which retest terms your contract carries before scoping a multi-application program. Best for: mid-market companies that need regular compliance testing with a dedicated project manager. The BreachLock alternatives guide compares it with other PTaaS providers.
4. Cherry Bekaert
Cherry Bekaert, with its corporate headquarters at 3800 Glenwood Avenue in Raleigh, North Carolina, publishes a testing page that names the segment in its heading: "Threat Based Penetration Testing and Red Teaming Services for Middle-market Companies." The page covers AI red teaming and penetration testing mapped to the OWASP Top 10 for LLM Applications, MITRE ATLAS and the NIST Generative AI Risk Management Framework; external, internal and network penetration testing, with the internal test simulating "an attacker who has already gained a foothold"; web and mobile application testing for business logic, APIs and user workflows; cloud testing across "single-cloud and complex hybrid and multi-cloud environments"; social engineering; and threat-based red teaming. Its vulnerability assessment page promises services "Right-sized for Mid-market Complexity" and lists remediation support and an optional re-test. Cherry Bekaert is not on the CREST Marketplace, and named testers, retest terms for penetration tests and pricing are not stated.
Strength: a testing and red team practice written for middle-market companies, including AI systems and multi-cloud environments. Limitation: no firm-level CREST accreditation, and as an accounting and advisory firm it may also audit or advise you, so settle independence in writing. Best for: middle-market companies that want penetration testing and threat-based red teaming from one adviser.
5. Sprocket Security
Sprocket Security lists its office at 821 East Washington Avenue in Madison, Wisconsin, and sells continuous penetration testing. Its homepage says its "AI agent fleet runs discovery, recon, and exploitation under a published safety framework" while its penetration testers "close out the rest," and that findings "are supervised by a human tester with proof of exploitation before they reach you." Its pricing page lists a Starter Package at US$15,000, sold on a subscription that tests "throughout the year," covering continuous testing of up to 20 external hosts with unlimited retests. Internal network testing is a US$13,000 add-on, and web application and social engineering testing come in a quoted Custom Package. The same page labels its reviews by customer size, including G2 reviews from mid-market companies with 51 to 1,000 employees and a SourceForge review from an IT infrastructure manager at a company with US$50 million to US$250 million in revenue; one G2 reviewer in manufacturing credits the team's help with hard-to-fix findings for organizations short of time or staff. CREST lists Sprocket Security Inc for penetration testing, with one year of membership. Named testers are not stated.
Strength: a published price, unlimited retests and continuous coverage of a changing perimeter. Limitation: the Starter Package covers external hosts only, so internal, application and social engineering testing are add-ons or quoted. Best for: lean teams that want their external perimeter tested continuously at a known price.
6. CBIZ Pivot Point Security
CBIZ Pivot Point Security is based in Hamilton, New Jersey, and has been part of CBIZ since 1 June 2023. The acquisition announcement, published on Pivot Point's own site, says the firm, founded in 2001, "helps small and middle market businesses navigate the complex challenges of information security and compliance," with services spanning certification and compliance preparation, vulnerability assessments, penetration testing and vendor risk management. CBIZ, its parent, says on its Built for the Middle Market page that the middle market is the core of whom it serves. Its penetration testing page covers networks, wireless local area networks, applications and people through social engineering. CREST lists Penetration Testing with nine years of membership, plus ISO 27001. Named testers, retest terms, a findings portal and pricing are not stated.
Strength: firm-level CREST accreditation and two decades of compliance-driven testing for smaller and mid-market companies. Limitation: testing sits beside certification and compliance preparation work, so keep the testers separate from any consultants who designed your controls. Best for: companies preparing for ISO 27001 certification or a SOC 2 report that want testing from an adviser fluent in both.
7. Cobalt
Cobalt lists its US headquarters at One Boston Place in Boston. Its offensive security services page has a section for the mid-size firm, which says a growing customer base and operational complexity widen the attack surface and make continuous, proactive security testing critical. Cobalt sells tests through annual credit packages, in which a credit "represents the equivalent of 8 hours of offensive security testing," and its pricing page lists Standard, Premium and Enterprise tiers with free retesting for six months on Standard and 12 months on the other two, start times of three, two and one business days, and native integrations such as Jira and GitHub on Premium and Enterprise. Credits do not roll over between contract years, except up to 10 percent on the Enterprise tier. CREST lists Cobalt Labs for penetration testing, with Germany as its headquarters country, eight years of membership and ISO 27001. Tier prices are quoted, and named testers are not stated.
Strength: a CREST-accredited PTaaS platform with written retest windows and integrations for application-heavy teams. Limitation: credits are spent per asset by complexity and mostly expire each contract year, so model a year of releases before buying. Best for: mid-market software teams that schedule many application tests through one platform.
8. Baker Tilly
Baker Tilly, headquartered in Chicago according to its own news releases, says on its about page that it "is built for the middle market," and its April 2025 announcement of the combination with Moss Adams describes "advisory and accounting services for the middle market." Its penetration testing and vulnerability assessment page covers external penetration testing, internal vulnerability scanning, wireless network security testing, web application security testing and social engineering, and links client case studies, among them a debt consolidation company's external penetration test, a financial services company's web-facing applications and a software company's web portal. Baker Tilly is not on the CREST Marketplace, and named testers, retest terms and pricing are not stated.
Strength: a national middle market firm with published testing case studies across sectors. Limitation: the internal service is described as vulnerability scanning, so write an internal penetration test and Active Directory testing into the statement of work, and if Baker Tilly audits you, settle independence first. Best for: companies already working with Baker Tilly that want testing from a middle market adviser.
9. Sikich
Sikich describes itself as "a Chicago-based leading global technology-enabled professional services company," and its technology page says it "owns one of the deepest, most diverse solution portfolios in the middle market." Its cyber offense page covers "network and application penetration testing, social engineering, and wireless network reviews," and its October 2024 announcement of being named "2024 Pentesting Solution Provider of the Year" by CyberSecurity Breakthrough says Sikich performs "internal, external and cloud/hybrid penetration testing." Sikich is not on the CREST Marketplace, and named testers, retest terms, a findings portal and pricing are not stated.
Strength: testing inside a professional services firm that already serves the middle market in technology and compliance. Limitation: an industry award is not an accreditation, and if Sikich also manages your IT or audits you, independence needs settling in writing. Best for: companies already using Sikich for technology or compliance work.
10. Rapid7
Rapid7 lists its global headquarters at 120 Causeway Street in Boston. Its penetration testing services page offers point-in-time network testing, external or internal, plus web application, IoT and internet-aware device, social engineering, red team and wireless testing, says its testers contribute to the Metasploit Project, and links a continuous red team service, Vector Command. Its mid-market evidence is an engagement write-up: a July 2023 PenTales post by a Rapid7 tester begins, "I was tasked with performing an external penetration test for a midsize company," and describes how exposed webmail, weak passwords that still met the password policy and internet-facing remote access without multifactor authentication added up to an internal foothold in under an hour that the client did not detect. Rapid7 is not on the CREST Marketplace, and named testers, retest terms and pricing are not stated.
Strength: point-in-time tests and a continuous red team service from one vendor, with testers who contribute to Metasploit. Limitation: testing is one service line beside a large security platform, and the services page publishes no delivery or retest terms. Best for: companies already running Rapid7's platform that want testing from the same vendor.
Firms considered and not ranked
Several capable testers were left out because their own sites do not address mid-market buyers as directly, or because another of our rankings covers them better. NetSPI, Coalfire, Praetorian, TrustedSec, Synack and NCC Group appear in our USA ranking, and our enterprise ranking covers multi-region programs; both are linked under related reading. GuidePoint Security, CREST-accredited for penetration testing and also in our USA ranking, says its customers span small and mid-sized businesses, global enterprises and government agencies, but its site has no testing page, package or case study aimed at mid-market buyers. Plante Moran, CREST-accredited for penetration testing since December 2024, came close and appears in our mortgage lender ranking. BDO USA launched its BDO Digital unit in January 2020 for middle market organizations, but its cybersecurity assurance page describes testing only in general terms. In Canada, Kobalt.io calls itself a "fractional security and compliance team for growing companies," a better fit for smaller organizations, and Canadian testing specialists are covered in our Canada ranking. A company's managed IT or managed security provider is a different case: whoever runs the network should not test it.
How much does mid-market penetration testing cost in 2026?
Mid-market scopes usually combine several web applications and APIs, Active Directory and Microsoft 365, the external perimeter, one or two cloud environments and a social engineering campaign. Stingrai publishes its package prices: US$3,000 for an Autonomous Pentest, which is Snipe alone with no penetration testers, and US$6,800 for a Hybrid Pentest, where penetration testers and Snipe test together, each per assessment of exactly one web application and its APIs. The same tiers run at US$650 and US$1,275 per month on 12-month continuous plans. The No High or Critical Finding = Don't Pay guarantee applies to the Autonomous tier only. Additional applications and every network, Active Directory, cloud, red team and social engineering scope are quoted through get a quote, with current figures on the pricing page.
The bands below are indicative, taken from our penetration testing cost guide for US dollars and the Canadian cost guide for standard Canadian scopes.
Mid-market scope | Indicative US band | Indicative Canadian band (standard scope) |
|---|---|---|
Each customer-facing web application | US$5,000 to US$30,000 | C$12,000 to C$25,000 |
Each API | US$6,000 to US$30,000 | C$15,000 to C$25,000 |
External network and remote access | US$5,000 to US$40,000 (network) | C$15,000 to C$35,000 |
Internal network and Active Directory | US$5,000 to US$40,000 (network) | C$20,000 to C$35,000 internal; C$25,000 to C$35,000 Active Directory |
Microsoft 365, Entra ID and cloud | US$10,000 to US$50,000 (cloud) | C$25,000 to C$40,000 (cloud) |
Annual program, 150 to 500 employees | US$20,000 to US$50,000 | Quoted per scope |
Annual program, more than 500 employees | US$50,000 to US$150,000 or more | Quoted per scope |
Annual PTaaS subscription, standard scope | Not banded | C$60,000 to C$90,000 |
Three things move a mid-market quote most: how many applications need authenticated testing across roles, how many Active Directory domains, Entra tenants and cloud accounts are in scope, and whether testing is one annual engagement or a continuous program. The cost calculator gives a starting figure.
How to compare quotes
Two quotes for the same company can differ several times over because they price different things. Before comparing totals, put every quote into the same shape, as the quote comparison guide shows.
One line per asset. Each application, API, domain, tenant, cloud account and external range with its own test type, perspective and number of roles.
The unit of effort. Tester-days, hours, credits (a Cobalt credit is eight hours of testing) or a subscription. Convert them to tester-days per asset.
Who tests. Named testers with certifications, in-house or crowd-sourced, and how much of the work is automated.
Retest terms. How many rounds, for how long, and whether the retest result is documented.
Deliverables. Full report, executive summary, attestation letter, redacted version, portal access and ticketing integration.
Timing. Lead time to start, testing window and days from test end to report, set against your audit dates.
What to demand from the report for auditors and customers
The report is the product a mid-market company actually buys, because auditors and customers read it, not the testers. Ask for these before you sign, and check them against the report scorecard.
A scope statement listing every asset, environment and exclusion, with the test dates.
The methodology, such as the OWASP testing guide and ASVS for applications, PTES or NIST SP 800-115 for networks.
The testers' names and certifications, and a statement of independence, since PCI DSS 11.4.2 and 11.4.3 require the tester to be organizationally independent.
An executive summary written for leadership and customers.
For each finding: severity with its rationale, the affected asset, evidence such as a proof of concept, business impact and remediation guidance.
Retest results with dates, which document the repeat test PCI DSS 11.4.4 requires and turn a finding list into closed evidence.
An attestation letter, separate from the full report, that a customer or auditor can file.
A redacted version you can share in a security review without exposing every detail.
Buyer checklist: questions to put to every vendor
Who exactly will test, and can we see their names and certifications before we sign?
Which entity holds your CREST accreditation, and is it the entity signing our statement of work?
How do you price many applications: per application, per day, by credit or by subscription, and what counts as one application?
Will you test every customer-facing application authenticated across every role and tenant?
Will you test Active Directory, Entra ID and Microsoft 365 as one attack path from an assumed-breach starting point?
Is retesting included, how many rounds, and within what window?
Do findings reach our ticketing system as they are confirmed, or only in the final report?
What can we hand auditors and customers: an attestation letter, an executive summary and a redacted report?
Are you independent of our IT provider, managed security provider and SOC 2 auditor?
Can we run an annual full-scope test and keep our most-changed applications under continuous testing?
Frequently Asked Questions
Who are the best penetration testing companies for mid-market companies in 2026?
The best penetration testing companies for mid-market companies in 2026 are Stingrai, RSM, BreachLock, Cherry Bekaert, Sprocket Security, CBIZ Pivot Point Security, Cobalt, Baker Tilly, Sikich and Rapid7. Stingrai ranks first: a CREST-accredited penetration testing service provider at firm level whose two named penetration testers, from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP, test web applications and APIs, Active Directory, Microsoft 365 and cloud in one engagement, with retesting included and published prices for one web application and its APIs, one-time or continuous. RSM, BreachLock and Cherry Bekaert follow.
Is BreachLock suitable for mid-market companies that need regular pentesting?
Yes, for many. BreachLock's offensive security page has a section for medium enterprises, its penetration testing is performed by in-house testers with a dedicated project manager, and its Extended tier lists building structured pentest programs and increasing testing frequency among its use cases. CREST lists Breachlock Ltd for penetration testing with ISO 27001 and US SOC 2 Type 2. Its pricing page publishes tiers without dollar figures and lists one free manual retest on the Standard tier, two on Extended and a custom number on Extensive, while its offensive security page advertises free unlimited vulnerability retesting, so confirm which terms your contract carries. Companies that want named testers before signing or published prices should compare it with the alternatives in our BreachLock alternatives guide.
How often should a mid-market company run penetration tests?
At least once a year for most programs, plus after significant changes. PCI DSS v4.0.1 requires internal and external tests at least once every 12 months and after any significant infrastructure or application upgrade or change, NYDFS 500.5 requires testing at least annually, and the FTC Safeguards Rule requires annual testing absent effective continuous monitoring. HIPAA's proposed rule would add a 12-month test, but it is not final. Applications that change every week are better covered continuously between annual tests.
Is continuous penetration testing better than an annual pentest for a mid-market company?
Neither replaces the other. An annual human-led test across the full scope gives auditors and customers a dated report and covers Active Directory, Microsoft 365 and the network in depth, while continuous testing covers applications between releases and catches regressions. Many mid-market programs combine an annual full-scope engagement with continuous coverage of the applications that change most. Stingrai offers both one-time annual engagements and continuous programs.
How should a mid-market company scope penetration testing across many applications?
Start from an inventory of every application, API, domain, tenant and cloud account, tier the applications by the data they hold and how exposed they are, and give each asset its own scope line with test type, roles, perspective and exclusions. Test Active Directory, Entra ID and Microsoft 365 together as one attack path, map each asset to the framework that needs evidence for it, and schedule tests early enough before each audit to leave time for remediation and retest.
What should a penetration test report include for auditors and enterprise customers?
A scope statement listing every asset and the test dates, the methodology, the testers' names and certifications, an executive summary, and for each finding the severity, evidence, business impact and remediation guidance. Auditors also look for dated retest results that document the repeat test PCI DSS 11.4.4 requires, and for customers an attestation letter and a redacted summary they can file without seeing the full report.
How much does penetration testing cost for a mid-market company in 2026?
Stingrai publishes US$3,000 for an Autonomous Pentest (Snipe alone, no penetration testers) and US$6,800 for a Hybrid Pentest per assessment of one web application and its APIs, or US$650 and US$1,275 per month on 12-month continuous plans; every other scope is quoted. Indicative bands from our cost guides put an annual program at US$20,000 to US$50,000 for organizations of 150 to 500 employees and US$50,000 to US$150,000 or more above 500 employees.
Does SOC 2 or ISO 27001 require a penetration test?
Neither makes one mandatory. The AICPA's Trust Services Criteria list penetration testing among the evaluations that may support monitoring under CC4.1, and ISO/IEC 27001:2022 does not name it, though a test is the strongest evidence for technical vulnerability management (control 8.8) and security testing in development and acceptance (8.29). A dated report with retest results gives the auditor evidence for both.
Should our audit firm also run our penetration test?
It can, if the testers are independent of the people who audit or designed the controls. PCI DSS 11.4.2 and 11.4.3 require organizational independence of the tester, and several firms in this ranking also sell audit, compliance or managed services, so ask who will test, which entity signs the statement of work, and how the testing team is separated from your auditor or IT provider.
Related reading
Best Internal Network and Active Directory Penetration Testing Companies (2026)
PCI DSS Penetration Testing: Requirement 11.4 Explained (2026)
SOC 2 Penetration Testing: What Auditors Expect and How to Scope It (2026)
Ready to scope a mid-market penetration testing program?
The breach that reaches a mid-market board rarely starts with an exotic exploit. It starts with an exposed edge device, an Entra ID exception nobody reviewed, or a portal that shows one customer another customer's data. Stingrai is a CREST-accredited penetration testing service provider whose testing supports the evidence SOC 2, ISO 27001, PCI DSS and HIPAA programs ask for, delivered as a one-time annual engagement or as continuous coverage, with named penetration testers, retesting and an attestation letter on human-led and hybrid engagements. Book a free scoping call, get a quote for a multi-app program, or see the published package prices on the pricing page.



