main logo icon

Published on

October 1, 2026

|

25 min read

Best Penetration Testing Companies for Small Businesses (2026): Ranked for Budget, Compliance and Cyber Insurance

Ranked guide to the best penetration testing companies for small businesses in 2026, with what the FTC Safeguards Rule, PCI DSS v4.0.1 SAQs, HIPAA, cyber insurers and Canada's baseline controls actually require, verified 1 October 2026.

Arafat Afzalzada

Arafat Afzalzada

Founder

Network SecurityWeb App SecuritySocial Engineering

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

No single rule makes every small business run a penetration test. The FTC Safeguards Rule requires annual testing under 16 CFR 314.4(d)(2) unless a covered financial institution has effective continuous monitoring, and section 314.6 lifts that duty for institutions holding customer information on fewer than 5,000 consumers. PCI DSS v4.0.1 puts penetration testing in SAQ A-EP and SAQ D, puts only segmentation testing in SAQ B-IP and SAQ C, and leaves it out of SAQ A, B, C-VT, P2PE and SPoC. HIPAA requires a risk analysis and would require a test only if the proposed rule at 90 FR 898 is finalized, and the Canadian Centre for Cyber Security's baseline controls for small and medium organizations name no test. In practice the request arrives through a cyber insurance application, a customer's vendor review or a card questionnaire. The best penetration testing companies for small businesses in 2026 are Stingrai, CBIZ Pivot Point Security, Kobalt.io, Triaxiom Security, Raxis, Sherlock Forensics, Compass IT Compliance, VikingCloud, RSI Security, Defendify and PurpleSec. Every vendor entry links to a page on the vendor's own site and was verified on 1 October 2026.

Exploitation of vulnerabilities was the initial access vector in 26 percent of breaches at organizations with fewer than 1,000 employees in the Verizon 2026 Data Breach Investigations Report, ahead of credential abuse at 13 percent and phishing at 9 percent, and among ransomware cases where Verizon knew the victim's size, "about 96% of Ransomware victims were SMBs." The companion Verizon 2026 Breach Impact Study, built on 69,683 US cyber insurance claims pooled by CyberAcuView from its member companies, found ransomware in 39 percent and business email compromise in 19 percent of the 15,431 claims from businesses with revenue under US$25 million. For a business with 10 to 250 staff, the reason to test rarely comes from a rule that names a penetration test. It comes from a financial regulator's exemption line, a payment card questionnaire, an insurance application or a customer's vendor review, and that decides what the test has to prove. The small business cybersecurity statistics collect the wider numbers.

Where Stingrai fits: Stingrai is a CREST-accredited penetration testing service provider at firm level, founded in Toronto in 2021 with a London office, and it publishes an entry price a small business can check before any call: US$3,000 for an Autonomous Pentest of one web application and its APIs, such as an online store, booking site or client portal, with the No High or Critical Finding = Don't Pay guarantee on that tier (pricing). Office networks, Microsoft 365, Wi-Fi and phishing are tested by two named penetration testers from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP certifications, quoted to scope, as a one-time annual engagement or a continuous program. Human-led and hybrid engagements include retesting and an attestation letter a customer, insurer or auditor can file.

Quick answer: who are the best penetration testing companies for small businesses in 2026?

The best penetration testing companies for small businesses in 2026 are Stingrai, CBIZ Pivot Point Security, Kobalt.io, Triaxiom Security, Raxis, Sherlock Forensics, Compass IT Compliance, VikingCloud, RSI Security, Defendify and PurpleSec. Stingrai ranks first for a published US$3,000 entry price for one web application and its APIs, firm-level CREST accreditation, and named, certified penetration testers for the office network, Microsoft 365 and staff, with retesting and an attestation letter on human-led and hybrid engagements, one-time or continuous. CBIZ Pivot Point Security, Kobalt.io and Triaxiom Security follow for an accredited tester that says it guides small and medium-sized businesses, fixed published prices for small scopes, and published small-organization price guidance with retesting included in its quotes.

Two-column chart of what each US and Canadian rule and contract asks of a small business penetration test in 2026

What small businesses are actually required to test

Three of the rules below name a penetration test: the FTC Safeguards Rule, New York's cybersecurity regulation and PCI DSS. Two of them carve out small firms by size, and the third depends on which self-assessment questionnaire a merchant files. Everything else asks for reasonable safeguards and leaves the test to insurers and customers.

The FTC Safeguards Rule (16 CFR Part 314)

The Safeguards Rule covers financial institutions under the Federal Trade Commission's jurisdiction, and section 314.1(b) names, among others, mortgage lenders and brokers, payday lenders, finance companies, collection agencies, credit counselors and other financial advisors, tax preparation firms, investment advisors that are not required to register with the SEC, and finders. The examples in 314.2(h) add "An accountant or other tax preparation service that is in the business of completing income tax returns," auto dealers that lease vehicles for longer than 90 days, appraisers and real estate settlement services. A shop is not covered merely because it "accepts payment in the form of cash, checks, or credit cards that it did not issue." The accounting and CPA firm ranking covers tax preparers in depth.

Section 314.4(d)(2) is the testing clause. "Absent effective continuous monitoring or other systems to detect, on an ongoing basis, changes in information systems that may create vulnerabilities," a covered institution must conduct "Annual penetration testing of your information systems determined each given year based on relevant identified risks in accordance with the risk assessment" and vulnerability assessments "at least every six months." Section 314.2(n) defines the test as one in which assessors "attempt to circumvent or defeat the security features of an information system by attempting penetration of databases or controls from outside or inside your information systems," and the Commission's 2021 final rule added that "Attempted social engineering and phishing are important parts of testing the security of information systems and would not be excluded by this definition" (86 FR 70277). The clause has applied since 9 June 2023, when the FTC's delay at 87 FR 71509 ended.

The small-business line is section 314.6: "Section 314.4(b)(1), (d)(2), (h), and (i) do not apply to financial institutions that maintain customer information concerning fewer than five thousand consumers." Below that line the written risk assessment, the annual penetration test and six-month vulnerability assessments, the written incident response plan and the annual board report fall away. The Commission counts "both current and former customers," and counts consumers rather than transactions (86 FR 70301). Everything else still applies at any size: section 314.4(d)(1) still requires an institution to "Regularly test or otherwise monitor the effectiveness of the safeguards' key controls," the multi-factor authentication and encryption requirements still apply, and since 13 May 2024 a notification event involving at least 500 consumers must be reported to the FTC no later than 30 days after discovery.

Many small institutions run the program through their managed service provider (MSP). Section 314.4(a) allows the Qualified Individual to work for a service provider, but the institution must "Retain responsibility for compliance," and the FTC's small entity compliance guide (December 2024) puts it plainly: "If your company brings in a service provider to implement and supervise your program, the buck still stops with you." Section 314.4(f)(3) also requires "Periodically assessing your service providers based on the risk they present and the continued adequacy of their safeguards." A test from a firm that does not run the network is the cleanest way to assess the MSP's work.

New York: NYDFS Part 500 and its small-firm exemption

Insurance agencies, mortgage brokers and other firms licensed by New York's Department of Financial Services answer to 23 NYCRR 500. Section 500.5(a)(1) requires "penetration testing of their information systems from both inside and outside the information systems' boundaries by a qualified internal or external party at least annually." The amended section 500.19(a) exempts covered entities with fewer than 20 employees and independent contractors (counting affiliates), less than US$7.5 million in gross annual revenue in each of the last three fiscal years, or less than US$15 million in year-end total assets from 500.5 and several other sections. The NYDFS guide covers the rest of Part 500.

PCI DSS v4.0.1: the SAQ you file decides whether 11.4 applies

Merchants eligible to self-assess validate PCI DSS with a self-assessment questionnaire (SAQ) matched to how they take payments, and requirement 11.4, "External and internal penetration testing is regularly performed, and exploitable vulnerabilities and security weaknesses are corrected," appears in only some of them. Reading all ten v4.0.1 SAQs published in the PCI SSC document library:

  • SAQ A (revision 1, January 2025), for fully outsourced e-commerce and mail or telephone orders, contains no 11.4 requirement. It does require quarterly external scans by an Approved Scanning Vendor (ASV) under 11.3.2 for the merchant webpage that redirects to, or embeds, the processor's payment page.

  • SAQ A-EP, for e-commerce sites that do not receive card data but affect the payment page, contains 11.4.1, 11.4.3, 11.4.4 and 11.4.5. The external test runs at least once every 12 months and after any significant infrastructure or application change, by a qualified internal resource or external third party, with "Organizational independence of the tester" required, and fixed findings are retested: "Penetration testing is repeated to verify the corrections."

  • SAQ B-IP (standalone, IP-connected payment terminals) and SAQ C (internet-connected point-of-sale systems that do not store card data) contain only 11.4.5, which applies "If segmentation is used to isolate the CDE from other networks."

  • SAQ B, SAQ C-VT, SAQ P2PE and SAQ SPoC contain no penetration testing requirement.

  • SAQ D is the only questionnaire with internal penetration testing (11.4.2). SAQ D for Merchants carries 11.4.1 to 11.4.5 and lists 11.4.6 and 11.4.7 as service provider requirements; SAQ D for Service Providers carries all seven.

Matrix of the ten PCI DSS v4.0.1 SAQs against the ASV scan and penetration testing requirements

The practical rule for a small merchant: confirm the SAQ with the acquirer first, then buy the test that SAQ names. An online store on SAQ A-EP needs an external test of its site and payment flow; a restaurant on SAQ C that segments its point-of-sale network needs a segmentation test, not a full internal test. The PCI DSS ranking covers providers for larger card environments.

HIPAA for clinics and their business associates

The Security Rule in force today does not name penetration testing. Section 164.308(a)(1)(ii)(A) requires every covered entity and business associate to "Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information," and 164.308(a)(8) requires a periodic technical and nontechnical evaluation. Section 164.306(b)(2) requires a practice to take into account "The size, complexity, and capabilities of the covered entity or business associate" and "The costs of security measures" when choosing safeguards. The Security Risk Assessment Tool that HHS's Office of the National Coordinator built with the Office for Civil Rights says "The target audience of this tool is medium and small providers."

That may change. The proposed rule published at 90 FR 898 on 6 January 2025 would require a practice to "Perform penetration testing of the covered entity's or business associate's relevant electronic information systems by a qualified person" at least once every 12 months. Its most recent Unified Agenda entry lists it as a long-term action with final action dated July 2027, and the Federal Register shows no final rule as of 1 October 2026. The HIPAA requirements guide tracks it.

Cyber insurance applications

Insurers ask directly. Corvus's Smart Cyber Insurance Application (version 3.2, September 2024) asks: "Do you conduct penetration testing of your network at least annually?" AXIS's Cyber Technology and MPL application (form 1012098 0623) asks whether "The Applicant conducts regular penetration testing?" and then by type, external network, internal network, social engineering, physical and web application, and frequency, and whether testing is done internally or outsourced. Beazley Canada's breach response application lists penetration testing among the "procedures" used "to test computer security controls," with continuous, semi-annual and quarterly boxes. The Corvus form also asks whether payment change requests are verified "via a separate means of communication," which a social engineering test can check.

The claims data explains the interest. In the Verizon 2026 Breach Impact Study, the median economic impact of a claim from a business with revenue under US$25 million was about US$38,000, and in the top 2.5 percent of those claims the impact exceeded 7 percent of insured revenue. The underwriting questions guide covers how a report answers each form.

Customer and vendor security questionnaires

Rules aimed at a customer flow down to its suppliers. A financial institution under the Safeguards Rule must assess its service providers, a HIPAA covered entity may let a business associate handle electronic protected health information only if it "obtains satisfactory assurances," and law firms and other professional services firms meet client contract controls, of which the Association of Corporate Counsel's model controls for outside counsel (2017) are a published example. Section 7 of that model asks for vulnerability tests "At least annually" of all systems holding company confidential information, and manual penetration tests of applications that process it "at least annually or upon any major software change." Verizon's 2026 report puts third-party involvement at 55 percent of breaches at organizations under 1,000 employees, which is why the questions keep coming.

Canada: Cyber Centre baseline controls, CyberSecure Canada and PIPEDA

The Canadian Centre for Cyber Security's Baseline Cyber Security Controls for Small and Medium Organizations (version 1.2) is written for organizations with fewer than 500 employees and applies "the 80/20 rule (achieve 80% of the benefit from 20% of the effort)." Its thirteen control areas include an incident response plan, automatic patching "OR" full vulnerability and patch management, two-factor authentication for remote access, isolated point-of-sale systems and websites that "address the OWASP top 10 vulnerabilities." It does not mention penetration testing.

CyberSecure Canada is the national certification for the same audience. Innovation, Science and Economic Development Canada says that "As of March 31, 2023," it "is no longer the program authority" and points organizations to the Standards Council of Canada. Certification is to the National Standard of Canada CAN/DGSI 104, which its publisher describes as a minimum set of controls for organizations that "typically have less than 500 employees"; the second revision, announced on 2 July 2026, added expanded guidance on vulnerability assessments. The publisher's summaries of the standard do not mention penetration testing.

PIPEDA principle 4.7 requires "security safeguards appropriate to the sensitivity of the information," including technological measures; section 10.1 requires a report to the Privacy Commissioner of any breach creating "a real risk of significant harm," and the Breach of Security Safeguards Regulations require a record of every breach for 24 months. Canadian merchants file the same PCI DSS SAQs, and the Beazley Canada form above is a Canadian application.

Driver

Names penetration testing?

Cadence

Small-business carve-out

FTC Safeguards Rule, 16 CFR 314.4(d)(2)

Yes, unless effective continuous monitoring

Annual, with vulnerability assessments every six months

Not required below 5,000 consumers (314.6)

NYDFS 23 NYCRR 500.5(a)(1)

Yes

At least annually

Exempt below 20 staff, US$7.5 million revenue or US$15 million assets (500.19(a))

PCI DSS v4.0.1 requirement 11.4

Yes in SAQ A-EP and SAQ D; segmentation only in SAQ B-IP and C

At least every 12 months and after significant change

None in SAQ A, B, C-VT, P2PE and SPoC

HIPAA Security Rule, 45 CFR 164.308

Not today; proposed at 90 FR 898

Proposed: at least every 12 months

Size, capability and cost weighed (164.306(b))

Cyber insurance applications

Asked on the form

Annually on the Corvus form

None

Customer contracts and questionnaires

Sometimes; the ACC model controls do

At least annually and on major change

None

Cyber Centre baseline controls v1.2

No

None

Written for organizations under 500 employees

CyberSecure Canada (CAN/DGSI 104)

Not in the publisher's summaries

Not stated in the summaries

Written for organizations typically under 500 employees

PIPEDA principle 4.7

No

None

Safeguards scale with sensitivity

The small business attack surface: what a good scope covers

A small business test should follow the money and the mailbox, not just the firewall.

Scope map of eight areas a small business penetration test should cover, from Microsoft 365 and remote access to payment terminals and MSP tools
  • Microsoft 365 or Google Workspace and email. Multi-factor authentication gaps, legacy authentication, mailbox forwarding rules, OAuth consent grants and admin roles. Business email compromise was 19 percent of SMB claims in the Breach Impact Study.

  • Internet-facing firewalls and remote access. VPN appliances, remote desktop, file transfer servers and anything left exposed for remote support. Exploitation of vulnerabilities was the initial access vector in 26 percent of SMB breaches in Verizon's 2026 report, and external network testing is where to start.

  • The website, online store and customer portal. The payment page and the scripts around it for SAQ A-EP merchants, plus logins, password resets and whether one customer can see another's orders or records, tested through web application penetration testing.

  • Payment terminals and point of sale. Whether segmentation really keeps the card environment apart from the office network, which is what 11.4.5 tests.

  • The office network and Wi-Fi. Guest Wi-Fi joined to the business network, flat networks, shared printers and storage devices; the Cyber Centre baseline says organizations should "never connect public Wi-Fi networks to their corporate networks."

  • MSP tools and accounts. Remote monitoring and management agents, shared administrator accounts and the provider's own access paths.

  • People and payment instructions. Phishing, and calls to whoever can change a supplier's bank details, through phishing campaigns and vishing.

  • Practice and line-of-business software. Practice management and patient records systems, tax and accounting portals, and cloud file shares holding client documents.

How we ranked them

Eleven vendors were scored against ten criteria. Every accreditation was checked on the CREST Marketplace, and every vendor entry links to a page on the vendor's own site, verified on 1 October 2026.

  1. Small-business evidence on the vendor's own site: a package, published price, program or customer evidence aimed at small businesses.

  2. Human penetration testing as a core service, not only scanning.

  3. Firm-level accreditation on the CREST Marketplace.

  4. Published prices or published price guidance.

  5. Retest terms stated in writing.

  6. Named testers or a named lead engineer before signing.

  7. Coverage of the small business attack surface described above.

  8. Evidence a small business can hand over: a report, executive summary or attestation letter for an insurer, acquirer or customer.

  9. Delivery in the United States, Canada or both.

  10. Independence from the buyer's MSP and compliance consultant.

The 11 companies at a glance

#

Company

HQ

Small-business evidence

Firm-level CREST

Published pricing

Retest

Best for

1

Stingrai

Toronto, ON (London, UK office)

Published US$3,000 price for one web app and its APIs

Penetration Testing

Yes, US$3,000 and US$6,800

Included; automated on Autonomous

A priced web app test plus named testers for the office

2

CBIZ Pivot Point Security

Hamilton, NJ

Says it guides small and medium-sized businesses

Penetration Testing (ISO 27001 company certification also listed)

No

Not stated

An accredited US tester focused on smaller firms

3

Kobalt.io

Vancouver, BC

Pentest page built for startups and SMBs

Not listed

Yes, US$3,000 to US$7,500

20% of the fee within 3 months

Fixed-price web app tests

4

Triaxiom Security

Charlotte, NC

Price guidance for small organizations

Not listed

Guidance, from as little as US$5,000

Included in flat-rate quotes

Fixed quotes for network and wireless

5

Raxis

Atlanta, GA

Maturity assessment priced for small and mid-size businesses; Safeguards Rule page for mortgage, tax and auto finance firms

Not listed

No

Unlimited on Raxis Attack

Financial firms under the Safeguards Rule

6

Sherlock Forensics

Vancouver and Burnaby, BC

Fixed CAD packages, one aimed at smaller environments

Not listed

Yes, C$1,500 to C$12,000

Listed only in the C$12,000 package (90 days); another Sherlock page says every engagement includes one

British Columbia firms wanting CAD-priced packages

7

Compass IT Compliance

North Providence, RI

Testing "built to meet small business needs"

Not listed

No

Not stated

Small offices needing internal, external and wireless

8

VikingCloud

Chicago, IL and Dublin, Ireland

PCI program for small merchants

CREST Pathway+, not yet accredited

No

Not stated

Small merchants validating PCI DSS

9

RSI Security

Southlake, TX

Online store prices; automated tests aimed at small to mid-sized businesses

Not listed

Yes, US$4,900 to US$12,570

One retest on each network test

Buying at a fixed price online

10

Defendify

Portland, ME

All-in-one platform for small and medium-sized businesses

Not listed

Yes, packages starting at US$450 a month

Not stated

One platform for a small IT team

11

PurpleSec

Washington, DC

Pentest page offers solutions "Built For Small Business"

Not listed

No

Included on every engagement

A retest on every engagement

"Not stated" means the vendor's own site does not say. Ask for it in writing.


1. Stingrai

Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.

What a small business can check before signing. The firm-level accreditation is on the CREST Marketplace supplier page for Stingrai Inc, separate from the CREST CRT certifications individual testers hold. Stingrai is rated 5.0 from 20 reviews on Clutch. The team has published 18 CVEs, including CVE-2025-50674, a privilege escalation to root in OpenMediaVault, and CVE-2024-32136, an SQL injection in the BWL Advanced FAQ Manager plugin. Two named penetration testers from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP certifications run each human-led engagement, reviewed by the team lead and an engagement partner.

How a small business engagement is tested. Network testing covers the external perimeter, VPN and remote access, then lateral movement and segmentation from a standard office workstation, which is the evidence SAQ C and B-IP merchants need for 11.4.5. Cloud testing treats Entra ID, the identity layer behind Microsoft 365, as an attack path: app registrations, consent grants and Conditional Access gaps. The Wi-Fi assessment runs on-site or remotely with a Wi-Fi Pineapple, and phishing campaigns and vishing test whoever can change a supplier's bank details. Online stores and client portals are tested black, grey or white box, authenticated across every role, for broken authorization, IDOR and business logic under OWASP Top 10 and ASVS.

Evidence and delivery. On human-led and hybrid engagements, findings post to the PTaaS portal as they are confirmed, each with a working proof of concept and remediation guidance, with live chat to the assigned testers and Jira and Slack integration. Human-led and hybrid engagements include retesting and an attestation letter. Stingrai runs both one-time annual engagements timed to an insurance renewal or audit and continuous programs that test every release, and its penetration testing supports clients' PCI DSS, HIPAA and FTC Safeguards programs.

Where Snipe fits. Snipe, Stingrai's autonomous AI penetration testing agent, covers web applications and their APIs only. The Autonomous tier is Snipe alone, with no penetration testers, and delivers a penetration test report with automated retests and AutoFix pull requests; in a Hybrid engagement Snipe and the penetration testers test together throughout, with the testers directing its focus. Office networks, Microsoft 365, Wi-Fi and social engineering are tested by penetration testers.

Pricing: US$3,000 for an Autonomous Pentest and US$6,800 for a Hybrid Pentest per assessment of one web application and its APIs, or US$650 and US$1,275 per month on 12-month continuous plans, on the pricing page. The No High or Critical Finding = Don't Pay guarantee applies to the Autonomous tier. Every other scope is quoted through get a quote.

Strength: a published entry price, firm-level accreditation and named testers in one provider, with each claim backed by a public source. Limitation: a small team, so on-site Wi-Fi and physical work needs scheduling lead time, and the fixed-price packages cover one web application and its APIs only. Best for: US and Canadian small businesses that need a priced web application test now and named, certified penetration testers for the office, Microsoft 365 and staff, one-time or continuous.

2. CBIZ Pivot Point Security

CBIZ Pivot Point Security lists its address at 1245 Whitehorse Mercerville Road in Hamilton, New Jersey, and its homepage says: "We guide small & medium-sized businesses to data security, and give you peace of mind." Its penetration testing page covers networks, wireless LANs, applications, people through social engineering, and physical security, using "a variety of manual techniques supported by automated tools." CREST lists Penetration Testing with nine years of membership, plus an ISO 27001 company certification. Published prices, retest terms and named testers are not stated.

Strength: the only firm in this list after Stingrai with firm-level CREST accreditation and an explicit small and medium-sized business focus. Limitation: testing sits beside ISO 27001 and ISMS consulting, so keep the testers separate from any consultants who designed your controls, and no Canadian office is listed. Best for: US small businesses that want an accredited tester used to working with smaller firms.

3. Kobalt.io

Kobalt.io says it was "Created in Vancouver, available worldwide." Its penetration testing page has a section headed "Built for Startups and SMBs" that says: "If you run a 20-to-500-person company, that process is not designed for you." Black box and grey box tests are priced by scope: "Small: $3,000. Medium: $5,750. Grey Box Large: $7,500," in US dollars, with larger scopes quoted, and "White Box, network, mobile, and AI/LLM tests are scoped individually." Within three months, a retest of remediated findings costs 20 percent of the original fee. The page describes an "OSCP and GWAPT-certified" team that combines automated scanning with hands-on analysis, and "1,600+ organizations served." Kobalt.io is not on the CREST Marketplace.

Strength: fixed, published prices and retest terms for small web application scopes. Limitation: network tests are not priced, and Kobalt.io also sells fractional security and compliance programs, so a client whose program it runs should ask how testers are kept separate. Best for: small software-led businesses, especially in Canada, that need a priced web application test for a customer or audit.

4. Triaxiom Security

Triaxiom Security is "Based out of Charlotte, NC" and serves "customers of all sizes and across all industries throughout the United States." Its penetration testing page publishes small-organization guidance: "a small external penetration test can cost as little as $5,000, but a comprehensive test including external, internal, social engineering may cost up to $30,000 for the same small organization," and its internal test cost article says "a small to midsize business with 100 systems can expect to pay $5,670." It promises flat-rate quotes "with no hidden fees and retesting included," and every proposal includes "the biography of a lead engineer who will be directly involved with your assessment." Triaxiom is not on the CREST Marketplace.

Strength: the clearest small-organization price guidance in this list, with retesting in the quote and the lead engineer named in the proposal. Limitation: United States only, and the published figures are guidance; the binding price comes in the proposal after a scoping call. Best for: US small businesses that want external, internal and wireless testing on a flat-rate quote.

5. Raxis

Raxis lists 2870 Peachtree Road in Atlanta and describes "Manual penetration testing by senior U.S. engineers since 2011." Its Security Framework Analysis, which Raxis describes as "a scaled-down maturity analysis tailored for small and mid-size businesses" rather than a penetration test, is offered "at a scope and price that make sense for small and mid-size businesses," noting that smaller organizations face "the same customer security questionnaires as the Fortune 500." Its partner program lets MSPs add human-led testing to their catalog, and Raxis says it does not sell managed security, hardware, monitoring or remediation services. Its Safeguards Rule page addresses mortgage lenders, auto dealers, tax preparers and financial advisors, with a report built for the Qualified Individual's board report and a PTaaS option, Raxis Attack, with unlimited retesting. Raxis is not on the CREST Marketplace.

Strength: a firm focused on offensive security that says it does not sell managed security, hardware, monitoring or remediation services, with a small-business assessment program and a Safeguards Rule focus. Limitation: no prices are published, no Canadian office is listed, and its partner program lets MSPs resell co-branded Raxis tests at a margin, so if your MSP offers a Raxis test of the network it runs, contract with Raxis directly. Best for: US mortgage, tax, auto finance and advisory firms with 5,000 or more consumers, where the Safeguards Rule's annual test applies.

6. Sherlock Forensics

Sherlock Forensics is "Headquartered in the Greater Vancouver area with an office in Burnaby," has operated since 2006, and says its lead examiner holds the CISSP with the ISSAP and ISSMP concentrations. Its Canadian cost page lists "Three fixed-price packages," orderable online: a Quick Audit at C$1,500, a Standard package at C$5,000 and a Full Assessment at C$12,000. The page says "For smaller environments, Sherlock Forensics offers a Quick Security Audit," which is automated scanning with manual validation of one external target; the Standard package adds manual exploitation, and the Full Assessment adds internal testing, social engineering and a retest "at no additional cost within 90 days of report delivery." Sherlock's pages disagree on retesting: its package tables list a retest only in the C$12,000 package, while its penetration testing page says "Every engagement includes actionable remediation guidance and a retest to verify your fixes," so get the retest terms for your package in writing. It says client data stays in Canadian jurisdiction, offers on-site testing across British Columbia, and describes itself as recognized by multiple Canadian cyber insurance providers. Sherlock Forensics is not on the CREST Marketplace.

Strength: fixed Canadian-dollar packages a small business can order online, with a 90-day retest in the full package. Limitation: the C$1,500 audit is a scan with manual validation rather than a penetration test, and on-site work centers on British Columbia. Best for: British Columbia small businesses that want CAD-priced packages and data kept in Canada (confirm the currency at checkout).

7. Compass IT Compliance

Compass IT Compliance lists 2 Asylum Road in North Providence, Rhode Island. Its November 2025 article on penetration test costs for a small business defines a small business as one or two offices, a handful of internet-facing systems and "perhaps one or two critical web applications," with staff of "tens to a few hundred," and says its penetration testing services "are built to meet small business needs." Its service page covers internal, external, wireless, web application, cloud and social engineering tests, plus white-label testing that partners can resell under their own brand. The article's dollar ranges are labelled market benchmarks, not Compass prices. Compass is not on the CREST Marketplace.

Strength: a definition of "small business" that matches this guide's reader, and a full menu of office-scale tests. Limitation: the firm also sells compliance consulting, and if an MSP resells a Compass test under its own brand, ask for the testing firm's name on the report cover. Best for: small offices that need internal, external and wireless testing from one provider.

8. VikingCloud

VikingCloud lists headquarters in Dublin, Ireland and Chicago. Its PCI Compliance for Small Business program, which includes ASV-certified external scanning, says it is "Already trusted by millions of small business locations around the globe," and its site lists clinics, pharmacies, restaurants, fuel and convenience stores and retail among the industries it serves. Its penetration testing page describes a Cyber Threat Unit of certified testers, with OSCP, CRTP and CISSP among the listed credentials, who "span three continents," and says VikingCloud is a CREST Pathway+ organization "progressing toward full CREST Membership." Penetration test prices are not published.

Strength: a PCI program built for small merchants (guided SAQ and ASV scanning) from a provider that also runs a certified penetration testing team. Limitation: the small-business PCI program does not itself include a penetration test, VikingCloud is not yet CREST-accredited, and testers sit on three continents, so ask for a quote for the 11.4 test your SAQ names and where your testers are based. Best for: small retailers, restaurants and clinics validating PCI DSS.

9. RSI Security

RSI Security lists its headquarters at 1900 West Kirkwood Boulevard in Southlake, Texas, and sells tests from an online store at fixed prices: US$4,900 for a web application penetration test, and US$11,310 for an external network test and US$12,570 for an internal network test, each covering up to 50 IP addresses with one follow-up retest included. Its automated internal network test at US$3,960 is described as "A lightweight alternative to full-scope penetration testing" and "perfect for small to mid-sized businesses." RSI also describes itself as a PCI Qualified Security Assessor, HITRUST External Assessor and authorized C3PAO. It is not on the CREST Marketplace.

Strength: fixed prices a buyer can see before any call. Limitation: the web application listing does not define its scope, the automated tests are not manual penetration tests, and a firm that also assesses you should not test you, so settle independence in writing. Best for: small businesses that want to buy a defined test at a known price.

10. Defendify

Defendify lists 5 Moulton Street in Portland, Maine. Its article on helping small and medium-sized businesses describes an all-in-one platform of 13 modules "to protect your small business," and its assessments and testing page says certified ethical hackers test internally and externally across networks, devices, mobile applications and web applications. Its pricing page lists an Assessments and Testing package, which includes penetration testing, "starting at" US$450 a month, and the full All-In-One package "starting at" US$925 a month. Defendify is not on the CREST Marketplace.

Strength: testing inside a subscription platform that small IT teams already use for training and scanning. Limitation: if Defendify also runs your detection and response, the tester is checking its own provider's coverage, per-test scope is not stated, and Defendify is also resold through MSP partners, so if your MSP supplies it, ask who performs the test. Best for: small IT teams that want one subscription for awareness training, scanning, detection and periodic testing.

11. PurpleSec

PurpleSec, founded in 2019 and listing an address at 1410 12th St NW in Washington, DC, says its team is made up of "certified U.S. based cybersecurity professionals holding an OSCP, OSWE, OSWP, OSCE, and more." Its penetration testing page offers "Affordable Solutions Built For Small Business," a dedicated point of contact, and a retest on every engagement: "all engagements include a retest as part of the initial scope of work." The page gives an average market range of US$8,000 to US$20,000 for most organizations rather than its own prices. PurpleSec is not on the CREST Marketplace.

Strength: a retest on every engagement and a single point of contact. Limitation: no published penetration testing prices, and it also sells virtual CISO services for small businesses, so independence needs settling if it runs your security program. Best for: US small businesses that want a retest guaranteed in the scope.


Firms considered and not ranked

Rhyno Cybersecurity sells managed detection and response and cloud hosting, and its penetration testing page credits "BreachLock's manual penetration testing" team, so the testing is resold rather than delivered in-house. North Star, a managed IT provider in British Columbia, Alberta and Yukon, publishes small and mid-sized business penetration test pricing of C$2,500 to C$5,000; a business that already uses North Star to run its network should buy the test from someone else. Sprocket Security publishes a US$15,000 Starter package for continuous testing of up to 20 external hosts with unlimited retests, but its homepage positions it for "Mid-Market and Enterprise Security Teams," so it is not ranked for small businesses. SecurityMetrics runs PCI programs for small merchants, but its service pages could not be read for verification on 1 October 2026, so it is not ranked in this edition. Larger firms are covered in the Canada ranking.

How much does small business penetration testing cost in 2026?

Stingrai publishes its package prices: US$3,000 for an Autonomous Pentest, which is Snipe alone with no penetration testers, and US$6,800 for a Hybrid Pentest, where penetration testers and Snipe test together, each per assessment of one web application and its APIs. The same tiers run at US$650 and US$1,275 per month on 12-month continuous plans, and the No High or Critical Finding = Don't Pay guarantee applies to the Autonomous tier. Office networks, Microsoft 365, Wi-Fi and phishing are quoted through get a quote, with current figures on the pricing page.

Other vendors' published prices, as worded on their own pages on 1 October 2026:

Vendor

What the published price covers

Price

Retest terms

Stingrai

Autonomous Pentest, one web application and its APIs

US$3,000 per assessment, or US$650 a month for 12 months

Automated retests

Stingrai

Hybrid Pentest, one web application and its APIs

US$6,800 per assessment, or US$1,275 a month for 12 months

Retesting and attestation letter included

Kobalt.io

Black or grey box test, small scope

US$3,000 black box, US$3,000 to US$4,250 grey box (medium US$5,750; grey box large US$7,500)

20% of the original fee within 3 months

Sherlock Forensics

Standard package (manual testing); Full Assessment adds internal and social engineering

C$5,000; C$12,000

Listed in the Full Assessment, within 90 days; another Sherlock page says every engagement includes a retest

Triaxiom Security

Small external test

As little as US$5,000 (guidance)

Included in flat-rate quotes

RSI Security

Web application test; external and internal network tests of up to 50 IP addresses

US$4,900; US$11,310; US$12,570

One retest included on each network test

Defendify

Assessments and Testing package, including penetration testing

Starting at US$450 a month

Not stated

Read the table as a map of what money buys. About US$3,000 covers one web application. About US$5,000 starts an external perimeter test, and Triaxiom's guidance puts an internal test of 100 systems at US$5,670. A combined external, internal and social engineering engagement for a small organization can reach US$30,000 at Triaxiom's own top end. The penetration testing cost guide breaks down the drivers by scope.

Buyer checklist: questions to put to every vendor

Put these ten questions to every shortlisted firm and ask for the answers in writing.

  1. Are you independent of our MSP? Do you manage, resell for or white-label through the company that runs our network?

  2. Who exactly will test, and can we see their names and certifications before we sign?

  3. Which rule or form is this test for? Name the SAQ, the Safeguards Rule clause or the insurer's question, and match the scope to it.

  4. Is retesting included, and within what window?

  5. Will you test Microsoft 365 or Google Workspace, including mailbox rules, consent grants and multi-factor authentication gaps?

  6. Does the scope include the payment flow and, for segmented merchants, the segmentation controls?

  7. What will we get to hand over? Ask for an executive summary and an attestation letter an insurer, acquirer or customer will accept.

  8. What does the price include, in hosts, applications, user roles and days of testing?

  9. How will you coordinate with our MSP and cloud providers for permission, testing windows and emergency contacts?

  10. Where will our findings be stored, and for how long? Canadian businesses should confirm data residency.

Frequently Asked Questions

Who are the best penetration testing companies for small businesses in 2026?

The best penetration testing companies for small businesses in 2026 are Stingrai, CBIZ Pivot Point Security, Kobalt.io, Triaxiom Security, Raxis, Sherlock Forensics, Compass IT Compliance, VikingCloud, RSI Security, Defendify and PurpleSec. Stingrai ranks first: a CREST-accredited penetration testing service provider at firm level with a published US$3,000 Autonomous Pentest for one web application and its APIs, and two named penetration testers from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP certifications for office networks, Microsoft 365 and staff, one-time or continuous. CBIZ Pivot Point Security, Kobalt.io and Triaxiom Security follow.

Does the FTC Safeguards Rule require a small business to do penetration testing?

Only if the business is a financial institution under the rule and holds customer information on at least 5,000 consumers. Section 314.4(d)(2) requires annual penetration testing and vulnerability assessments every six months unless the institution has effective continuous monitoring, and section 314.6 exempts institutions with customer information on fewer than 5,000 consumers, counting current and former customers. Below that line the institution must still regularly test or monitor its key controls, meet the multi-factor authentication and encryption requirements, and report notification events involving 500 or more consumers to the FTC within 30 days.

Which PCI DSS self-assessment questionnaires require penetration testing?

Under PCI DSS v4.0.1, SAQ A-EP contains requirements 11.4.1, 11.4.3, 11.4.4 and 11.4.5, including an external test at least once every 12 months and after significant change. SAQ B-IP and SAQ C contain only 11.4.5, which applies if segmentation is used to isolate the cardholder data environment. SAQ A, B, C-VT, P2PE and SPoC contain no penetration testing requirement, and only SAQ D includes internal penetration testing.

Does HIPAA require penetration testing for a small medical or dental practice?

Not today. The Security Rule requires an accurate and thorough risk analysis and a periodic technical and nontechnical evaluation, and requires a practice to take into account its size, capabilities and costs when choosing safeguards. A proposed rule published at 90 FR 898 on 6 January 2025 would require penetration testing at least once every 12 months, but its most recent Unified Agenda entry lists it as a long-term action with final action dated July 2027, and no final rule had been published as of 1 October 2026.

Do cyber insurers require small businesses to have a penetration test?

Insurers ask about it on the application. Corvus asks whether the applicant conducts penetration testing of its network at least annually, AXIS asks about external, internal, social engineering, physical and web application testing and how often each runs, and Beazley Canada lists penetration testing among the procedures used to test security controls. How the answer affects terms is up to each insurer.

Do Canada's baseline cyber security controls or CyberSecure Canada require a penetration test?

The Canadian Centre for Cyber Security's baseline controls for small and medium organizations, version 1.2, do not mention penetration testing; they ask for controls such as automatic patching, two-factor authentication for remote access and websites that address the OWASP top 10. CyberSecure Canada certification is to CAN/DGSI 104, whose publisher's summaries mention vulnerability assessments but not penetration testing. A test is still the clearest evidence that those controls work.

How much does a penetration test cost for a small business in 2026?

Stingrai publishes US$3,000 for an Autonomous Pentest (Snipe alone, no penetration testers) and US$6,800 for a Hybrid Pentest per assessment of one web application and its APIs, or US$650 and US$1,275 per month on 12-month continuous plans; network, Microsoft 365 and phishing scopes are quoted. Other published prices start at US$3,000 for a small black or grey box test at Kobalt.io, C$5,000 for the Standard package at Sherlock Forensics and as little as US$5,000 for a small external test in Triaxiom Security's guidance.

Can our managed service provider run our penetration test?

It is better if it does not. Every PCI DSS SAQ that contains a penetration testing requirement also requires organizational independence of the tester, and the FTC Safeguards Rule requires institutions to periodically assess their service providers, which a provider cannot do for itself. Choose a testing firm that does not manage, resell for or white-label through your MSP, and ask the MSP to cooperate with the testers.


Ready to scope a small business penetration test?

The entry points in Verizon's 2026 data are ordinary ones: an exploited vulnerability, a stolen credential, a phishing email or a business email compromise. Stingrai is a CREST-accredited penetration testing service provider whose testing supports the evidence the FTC Safeguards Rule, PCI DSS, HIPAA programs and cyber insurers ask for, delivered as a one-time annual engagement or as continuous coverage, with named penetration testers on human-led work and a published US$3,000 entry price for one web application and its APIs. Book a free scoping call, get a quote for an office or network scope, or see the package prices on the pricing page.

0 views

0

X

Related reading

Best Penetration Testing Companies for Construction and Engineering Firms (2026)
Network SecuritySocial Engineering

Best Penetration Testing Companies for Construction and Engineering Firms (2026)

The best penetration testing companies for construction and engineering firms in 2026, ranked, with what CMMC, CPCSC, owners and insurers actually require.

30 min read

Best Enterprise Penetration Testing Companies (2026): Ranked for Global Programs, Procurement and Continuous Coverage
Network SecurityWeb App Security

Best Enterprise Penetration Testing Companies (2026): Ranked for Global Programs, Procurement and Continuous Coverage

The best enterprise penetration testing companies in 2026, ranked on capacity, CREST and threat-led schemes, vendor security, MSA terms and board reporting.

31 min read

Best Penetration Testing Companies for Hotels and Hospitality (2026): Ranked for PCI DSS, Guest Data and Franchise Networks
Network SecurityWeb App Security

Best Penetration Testing Companies for Hotels and Hospitality (2026): Ranked for PCI DSS, Guest Data and Franchise Networks

The best penetration testing companies for hotels and hospitality groups in 2026, ranked, with what PCI DSS 11.4, the FTC Marriott order and PIPEDA require.

31 min read

Contents

X