Retail recorded 997 security incidents and 806 breaches with confirmed data disclosure in the 2026 Verizon Data Breach Investigations Report, roughly double the prior year's breach count. Three patterns account for 95 percent of them: System Intrusion, Basic Web Application Attacks and Social Engineering. 85 percent were financially motivated, and 42 percent began with exploitation of a vulnerability, 14 percent with credential abuse and 9 percent with phishing. Those figures are Verizon's own, from the report's retail snapshot for NAICS codes 44 and 45.
Where Stingrai fits: For the test itself, Stingrai is a CREST-accredited offensive security company headquartered in Toronto with a London office, founded in 2021. Two named penetration testers run each engagement, holding OSCE³, OSWE, OSEP, CREST CRT and CISSP, with 18 published CVEs across the team and bug bounty Hall of Fame listings at Apple, Google, the US Department of Defense and PaySafe. For a retailer that means human-led testing of the storefront and checkout authenticated as every customer and staff role, the APIs behind a headless build, the mobile app under MASVS and MASTG with its backend, the corporate and in-store networks either side of the PCI segmentation boundary, and phishing against the people who handle orders and refunds, delivered one-time or continuously through its PTaaS platform, with published pricing from US$3,000 per assessment for one web application and its APIs (pricing) and every other scope quoted.
Retail is also the one vertical where penetration testing is not a judgement call. PCI DSS names it, dates it and tells you how often. The ranking below is built around what the standard actually says, and every vendor entry links to the page on the vendor's own site that supports the claim, last verified on 19 September 2026.
Quick answer: who are the best retail and e-commerce penetration testing companies in 2026?
The best retail and e-commerce penetration testing companies in 2026 are Stingrai, VikingCloud, Coalfire, Optiv, Praetorian, BreachLock, ControlCase, Schellman, Bishop Fox, LevelBlue, GuidePoint Security and NCC Group. Stingrai is a CREST-accredited offensive security company. Two named penetration testers run each engagement, holding OSCE³, OSWE, OSEP, CREST CRT and CISSP, with 18 published CVEs across the team and bug bounty Hall of Fame listings at Apple, Google, the US Department of Defense and PaySafe. For a retailer that means human-led testing of the storefront and checkout authenticated as every customer and staff role, the APIs behind a headless build, the mobile app under MASVS and MASTG with its backend, the corporate and in-store networks either side of the PCI segmentation boundary, and phishing against the people who handle orders and refunds, with findings posted to its PTaaS portal as they are confirmed, live chat with the assigned testers, Jira and Slack integration, retesting and an attestation letter with every report. VikingCloud, Coalfire and Optiv follow for a published retail industry practice, PCI assessment scale, and PCI testing that names e-commerce respectively.

What retailers are actually required to test
Four regimes show up in retail procurement, and only one names penetration testing. The difference matters, because a merchant buying a PCI-shaped test and a platform vendor buying a SOC 2-shaped test are buying different scopes for different readers.
Does PCI DSS require penetration testing?
Yes, by name, with a stated frequency. PCI DSS v4.0.1, published 11 June 2024, sets out requirement 11.4 in seven parts:
11.4.1 requires a documented methodology covering the full cardholder data environment perimeter, testing from inside and outside, segmentation validation, application-layer testing aligned to requirement 6.2.4, network-layer testing, a review of the last 12 months of threats, and 12-month retention of results.
11.4.2 and 11.4.3 require internal and external penetration testing at least once every 12 months and after any significant infrastructure or application change.
11.4.4 requires exploitable findings to be corrected and the testing repeated to verify the corrections. A retest is not an upsell in a PCI engagement. It is the requirement.
11.4.5 requires segmentation controls tested at least every 12 months and after any change, confirming they isolate the cardholder data environment from out-of-scope systems. 11.4.6 halves that to every six months for service providers, and 11.4.7 requires multi-tenant providers to support their customers' testing.
Two points get lost in vendor marketing. First, 11.4.2 and 11.4.3 state plainly that the tester is not required to be a QSA or an ASV, asking instead for a qualified tester with organizational independence. Second, the quarterly ASV scan under requirement 11.3.2 is a different control and does not satisfy requirement 11.4. A clause-by-clause treatment is in the PCI DSS penetration testing requirements guide.
What do PCI DSS 6.4.3 and 11.6.1 require of a payment page?
These two requirements changed e-commerce testing, and both became mandatory on 31 March 2025. Requirement 6.4.3 requires every script loaded and executed on a payment page to be authorized, to have its integrity assured, and to be held in an inventory with written business justification. Requirement 11.6.1 requires a change and tamper detection mechanism on payment pages, alerting on unauthorized modification of security-impacting HTTP headers and page content, evaluated at least every seven days.
The PCI Security Standards Council published a dedicated information supplement, Payment Page Security and Preventing E-Skimming, on 10 March 2025. For a penetration test this is the difference between testing your own code and testing the third-party tags marketing added to checkout last quarter. Ask any vendor how they enumerate script inclusion on the payment page, and whether they test the tamper detection mechanism itself rather than taking its existence on trust.
Does SOC 2 require penetration testing for retailers?
No trust services criterion names penetration testing. It matters anyway for marketplaces and omnichannel brands that sell software or data services alongside goods, and for the commerce platform vendors they depend on. CC4.1 asks for ongoing and separate evaluations of internal control, and CC7.1 asks for monitoring to detect changes that introduce vulnerabilities. Auditors routinely accept a penetration test report as the evidence behind both. The SOC 2 penetration testing vendor guide covers how that evidence is scoped.
What do privacy laws require of a retailer's security testing?
Nothing by name, and something in substance. Cal. Civ. Code 1798.81.5(b) requires a business that owns, licenses or maintains personal information about a California resident to "implement and maintain reasonable security procedures and practices appropriate to the nature of the information." Under the CPRA amendments, section 1798.150 attaches a statutory private right of action to breaches caused by a failure to maintain those practices.
In Canada, PIPEDA's safeguards principle requires protection proportionate to the sensitivity of the information, and Quebec's Law 25 layered on governance policies, privacy impact assessments and mandatory incident reporting in phases through 22 September 2024. Neither publishes a testing cadence. Both make an undocumented security programme expensive to defend. Canadian buyers will find market context in the Canadian penetration testing companies ranking.
Regime | Is penetration testing required? | Named cadence | What the evidence has to look like |
|---|---|---|---|
PCI DSS 11.4.2 and 11.4.3 | Yes, by name | At least once every 12 months and after any significant change | Internal and external testing by a qualified tester with organizational independence, not necessarily a QSA or ASV |
PCI DSS 11.4.5 and 11.4.6 | Yes, for segmentation | 12 months for merchants, 6 months for service providers, plus after any change | Proof that every segmentation control isolates the cardholder data environment from out-of-scope systems |
PCI DSS 6.4.3 and 11.6.1 | Not a penetration test, but a testable control | Payment page tamper check evaluated at least every 7 days | An authorized, integrity-assured, justified script inventory and a working change detection mechanism |
SOC 2 | Not by name. CC4.1 and CC7.1 are the operative criteria | Set by your own policy | A report an auditor will accept as evidence of evaluation and monitoring |
CCPA and CPRA, PIPEDA, Quebec Law 25 | Not by name | None published | A documented, proportionate security programme that survives a plaintiff's expert |
The retail attack surface, and where tests stop short
Retail's exposure is wider than its cardholder data environment, and the PCI scope boundary is exactly where weak engagements end.
Checkout and payment flows. Price, quantity, currency and rounding manipulation, tax and shipping recalculation on a tampered request, and order state transitions that skip payment capture.
Third-party scripts on the payment page. Tag managers, analytics, personalization, chat and session replay all inject JavaScript into checkout, and enumerating what actually loads is often the most uncomfortable slide in the readout.
Loyalty programmes and gift cards. Points balance manipulation, transfer and merge abuse, and brute force against short card and PIN spaces. Loyalty is stored value with retail's weakest authentication, and it monetizes without touching a card number.
Account takeover and credential stuffing. Akamai's July 2026 research, Securing the Agentic Storefront, found 47.9 percent of all AI bot traffic on its network between July and December 2025 sat in commerce. Test credential stuffing resistance, rate limiting, and the password reset and recovery flows.
Promotion and coupon logic. Stacking, reuse after expiry, per-customer limit evasion, referral self-dealing and the race conditions that let one code redeem many times. Scanners do not find this.
Headless commerce and storefront APIs. In the same research, 85 percent of commerce respondents reported an API-related incident in the past year while only 22 percent knew which of their APIs expose sensitive data. See the API penetration testing vendor guide.
POS and store networks. In-store networks, back-office servers, payment terminals and the segmentation supposed to keep a compromised store from reaching the cardholder data environment. Requirement 11.4.5 exists because that segmentation is regularly assumed rather than proven.
Mobile applications. Scan-and-go, in-app payment, stored cards, loyalty wallets and deep links, with the backend API as the real target. See the mobile application testing vendor guide.
Warehouse, OMS and supplier integrations. Order management, fulfilment, EDI and supplier portals authenticate weakly because they were built for a trusted network. Verizon records third-party involvement in 68 percent of retail breaches.

How we ranked them
Twelve vendors were scored against six retail-specific criteria, each claim traced to a page the vendor publishes itself and read on 19 September 2026: a published retail, e-commerce or PCI testing practice; coverage of requirement 11.4 as a whole rather than an external perimeter test sold as PCI compliance; business logic and authorization depth across checkout, loyalty and promotions; payment page and third-party script capability; store estate and network reach tested against the segmentation claim; and delivery model fit, meaning one-time and continuous options, retest inclusion, and findings that reach engineers.
Vendors whose primary product is vulnerability management, attack surface discovery or compliance attestation without offensive testing were not ranked here. Two are noted after the ranking.
Quick comparison: best retail and e-commerce penetration testing companies
Company | HQ | Delivery model | Retail positioning | Retest | Pricing transparency | Best for |
|---|---|---|---|---|---|---|
1. Stingrai | Toronto, Canada | Human-led, one-time or continuous PTaaS | Firm-level CREST accreditation; storefront and checkout logic, storefront APIs, mobile app and backend, cloud, and internal and store networks with segmentation testing, run by two named penetration testers | Included | Retailers that need 11.4.2, 11.4.3 and 11.4.5 evidence with named penetration testers, a portal and an attestation letter, annually or continuously | |
2. VikingCloud | Dublin, Ireland | Consultancy plus platform | Named retail industry page covering network, segmentation, mobile and web application testing, with a large QSA bench | Not published | Quote | Multi-store chains wanting testing and PCI assessment from one payments-native firm |
3. Coalfire | Westminster, Colorado | Consultancy plus SaaS | PCI DSS page framing penetration testing against requirement 11.4, backed by one of the largest QSA practices | Not published | Quote | Enterprise merchants whose testing budget sits inside a PCI assessment relationship |
4. Optiv | Denver, Colorado | Consultancy | PCI page naming retail and e-commerce explicitly, covering segmentation testing and merchant validation levels | Not published | Quote | Large omnichannel estates buying PCI programme work and testing together |
5. Praetorian | Austin, Texas | Consultancy plus continuous service | PCI testing page naming e-commerce platforms and payment gateways, with external, internal, segmentation and application testing in one engagement | Included at no extra cost | Quote | Retailers wanting PCI coverage and offensive depth in the same engagement |
6. BreachLock | New York, United States | PTaaS | Dedicated PCI DSS penetration testing page mapped to the requirement numbers | Included | Quote | E-commerce and digital-first brands needing a fast, framework-mapped, audit-ready report |
7. ControlCase | Fairfax, Virginia | Platform-led compliance | Named retail industry page pairing PCI DSS assessment with continuous compliance monitoring | Not published | Quote | Retailers wanting testing folded into a year-round compliance programme |
8. Schellman | Tampa, Florida | Consultancy inside an audit firm | Broad testing portfolio alongside QSA and PA-QSA practices, with payment card processing named as a client vertical | Not published | Quote | Organisations already using the firm for payment certification work |
9. Bishop Fox | Tempe, Arizona | Consultancy plus continuous platform | Compliance and frameworks page covering PCI DSS annual and post-change testing, with an ASV credential | Not published | Quote | Buyers wanting offensive depth who treat the PCI report as a by-product |
10. LevelBlue | Dallas, Texas | Consultancy and managed security | Penetration testing practice with retail and hospitality among industries served, carrying the SpiderLabs heritage | Included as findings validation | Quote | Retailers wanting testing inside an existing managed security relationship |
11. GuidePoint Security | Reston, Virginia | Consultancy and reseller | PCI DSS compliance page with penetration testing and compliance management between assessments | Not published | Quote | Retailers wanting one partner across PCI advisory, tooling and testing |
12. NCC Group | Manchester, United Kingdom | Consultancy, tiered to continuous | Penetration testing services naming PCI DSS among the frameworks supported, with transatlantic delivery | Not published | Quote | Retailers with US, Canadian and European estates needing one provider |
1. Stingrai (top rated for retail and e-commerce)
World-Class Offensive Security.
Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.
For a retailer that means testing of the storefront and checkout authenticated as every customer and staff role, the APIs behind a headless build, the mobile app under MASVS and MASTG with its backend, the corporate and in-store networks either side of the PCI segmentation boundary, and phishing against the people who handle orders and refunds. The team has published 18 CVEs and holds bug bounty Hall of Fame listings at Apple, Google, the US Department of Defense and PaySafe. Findings are posted to its PTaaS portal as they are confirmed, with live chat with the assigned testers, Jira and Slack integration, retesting and an attestation letter with every report. Explore the PTaaS platform.
Stingrai delivers one-time penetration tests and continuous testing programs, so a retailer can buy a single annual PCI-scoped engagement, a continuous programme across a release-heavy storefront, or both. Scope spans web applications and APIs, mobile applications, internal and external networks, Wi-Fi, cloud environments, phishing campaigns and red teaming. For a retail buyer that maps onto the storefront and checkout, the APIs behind a headless build, the mobile app and its backend, the corporate and in-store networks either side of the segmentation boundary, and the staff who receive the phishing email that starts 9 percent of retail breaches.
Delivery and evidence. Engagements include documented findings, remediation guidance and retesting, which is a PCI necessity rather than a differentiator: requirement 11.4.4 requires exploitable findings to be corrected and the testing repeated, so a quote pricing retesting separately is quoting an incomplete engagement. Clients get named penetration testers rather than an anonymous bench, and the PTaaS portal gives live findings, direct communication with those testers, and remediation tracking in an engineering tracker. CREST accreditation applies to Stingrai as a penetration testing service provider, separate from the OSCE3, OSCP, OSWE, OSEP, CREST CRT and CISSP certifications its testers hold. The team has published 18 CVEs.
Stingrai's penetration testing supports PCI DSS 4.0.1, SOC 2 and ISO 27001 programmes by producing the scope statement, technical report, remediation record and retest evidence those programmes consume, which your assessor then reads.
Where Snipe fits. Snipe is Stingrai's AI agent for web application penetration testing, including the application's APIs. Trained on 6,000-plus HackerOne Hacktivity disclosure reports and on skills distilled from Stingrai's own penetration testers' methodology, it hunts the classes generic AI scanners miss: IDOR, broken authorization, access control flaws and business logic abuse, precisely the family checkout, loyalty and coupon logic produces. Stingrai's penetration testers work concurrently with Snipe throughout an engagement, directing its focus and extending its attack paths. Mobile, cloud, network, store estate and red team scopes are tested by those penetration testers.
Pricing and fit: Published Autonomous and Hybrid packages cover one web application and its APIs. Multi-storefront brands, store network estates and full PCI scopes are quoted individually. Request a scoped quote.
2. VikingCloud
VikingCloud publishes a retail industry page covering network, segmentation, mobile and web application penetration testing for retail environments, alongside PCI DSS assessment and monitoring across store locations. It operates as both a QSA company and an ASV.
Pros: one of the few vendors with a genuine retail vertical page rather than a retail logo; payments-native, with multi-store segmentation testing as a named capability.
Cons: compliance is the centre of gravity, so confirm manual depth on checkout business logic; neither pricing nor retest terms are published.
Best for: multi-store chains and omnichannel retailers wanting penetration testing and PCI assessment from one payments-native firm.
3. Coalfire
Coalfire's PCI DSS assessment page frames penetration testing directly against requirement 11.4 under v4.0.1, and the firm describes performing over a thousand PCI DSS assessments annually as one of the largest QSA companies globally.
Pros: requirement-level framing on the vendor's own page rather than generic compliance marketing; assessment volume means the report is written by a firm that knows what an assessor will question.
Cons: assessment-led procurement can scope the test to the framework boundary rather than the storefront's real attack surface; segmentation depth and retest terms are not published.
Best for: enterprise merchants whose penetration testing budget already sits inside a PCI assessment relationship.
4. Optiv
Optiv's PCI DSS compliance page is one of the few that names retail and e-commerce explicitly inside the testing copy rather than in a logo wall. It covers PCI penetration testing and segmentation testing, walks through merchant validation levels, and publishes retail and restaurant chain work involving point-of-sale estates.
Pros: retail and e-commerce named inside a PCI testing page, the clearest published signal of vertical fit in this group; segmentation testing and merchant level guidance addressed together.
Cons: large integrator delivery means the bench varies by region, so name the testers in the statement of work; pricing is not published.
Best for: large omnichannel estates buying PCI programme work, segmentation testing and application testing together.
5. Praetorian
Praetorian publishes a PCI DSS penetration testing page naming e-commerce platforms and payment gateways among the systems it tests, bundling external, internal, segmentation and application testing into one engagement with reports written for a QSA.
Pros: retesting included at no additional cost, which is the requirement 11.4.4 obligation rather than a change order; the four PCI testing types sold as one engagement, so segmentation is not an afterthought.
Cons: not a QSA company, so the assessment relationship has to come from elsewhere; no published pricing.
Best for: retailers wanting PCI coverage and genuine offensive depth from one engagement, with the retest already in the price.
6. BreachLock
BreachLock publishes a PCI DSS penetration testing page mapping its service to the requirement numbers rather than asserting a vague compliance benefit, delivered through a PTaaS platform. It lists offices in New York and Amsterdam.
Pros: the compliance page cites the requirements, a useful signal about how the report will be written; PTaaS delivery gets findings into an engineering workflow quickly.
Cons: strong automation component, so confirm the manual proportion for checkout, loyalty and promotion logic; a general-purpose compliance practice rather than a retail bench.
Best for: e-commerce and digital-first retail brands needing a fast, framework-mapped, audit-ready PCI report.
7. ControlCase
ControlCase publishes a retail industry page pairing PCI DSS assessment with its Continuous Compliance service and Compliance Hub platform. Penetration testing sits in the service menu rather than the retail page's foreground, which reflects where the firm's weight sits.
Pros: a named retail vertical page, and a year-round compliance model rather than an annual scramble, with one platform carrying evidence across PCI and other frameworks.
Cons: testing is secondary to assessment in the published material, so ask for the methodology and a redacted sample report; no published pricing or retest terms.
Best for: retailers wanting penetration testing folded into a continuous compliance programme rather than bought as an isolated project.
8. Schellman
Schellman, headquartered in Tampa, Florida, publishes a broad penetration testing portfolio spanning application, network, mobile, social engineering, cloud, physical and hardware testing. It also operates QSA and PA-QSA practices and names payment card processing among its verticals.
Pros: payment certification and penetration testing from one firm, useful where a retailer is also a payment application vendor; a broad portfolio including physical and social engineering, both relevant to a store estate.
Cons: the testing page does not reference retail or e-commerce, so vertical specificity is not published; certification-first firm, so confirm which team tests and how independence is documented if both engagements run together.
Best for: organisations already using the firm for payment or certification work who want testing under one contract.
9. Bishop Fox
Bishop Fox publishes a compliance and frameworks page covering PCI DSS annual and post-change penetration testing, and holds an ASV credential. Its positioning is deliberately beyond-compliance: the PCI report is a by-product of offensive testing rather than the point of it.
Pros: strong offensive reputation and research output, with a continuous testing platform alongside project work; post-change testing is addressed explicitly, which is the half of 11.4.2 and 11.4.3 most programmes forget.
Cons: no published retail or e-commerce vertical page, so commerce context comes from your scoping brief; not a QSA company, and pricing is not published.
Best for: retail buyers who want offensive depth first and are content for the PCI evidence to fall out of it.
10. LevelBlue
LevelBlue, formerly trading as Trustwave and carrying the SpiderLabs research heritage, publishes a penetration testing service page with retail and hospitality among the industries served, and includes free retesting under its findings validation model. Note the history when comparing quotes: trustwave.com now redirects to levelblue.com, so older retail references to Trustwave point here.
Pros: retesting included, which matters for requirement 11.4.4; SpiderLabs heritage in payment card forensics and retail incident work.
Cons: no PCI-specific copy on the testing page itself, so requirement mapping has to be agreed in scoping; managed services are the centre of gravity.
Best for: retailers wanting penetration testing delivered inside an existing managed security relationship.
11. GuidePoint Security
GuidePoint Security publishes a PCI DSS compliance page covering penetration testing alongside advisory work and a compliance management service running between assessments. It combines consulting with product reselling, so a retailer can buy the test and the tooling from one counterparty.
Pros: compliance management between assessments, which fits the continuous obligations in 11.4.1 and 11.6.1; one partner across PCI advisory, tooling and testing for a lean retail security team.
Cons: QSA status is not stated on the published page, so confirm who signs the assessment; reseller economics can influence recommendations, so scope the test independently of tooling.
Best for: retailers wanting a single partner across PCI advisory, security tooling and penetration testing.
12. NCC Group
NCC Group, headquartered in Manchester, United Kingdom, publishes a penetration testing services page naming PCI DSS among the frameworks its testing supports, with tiers from automated through manual to continuous across North America and Europe.
Pros: transatlantic delivery for retailers with United States, Canadian and European estates under different privacy regimes; a deep research bench with hardware and embedded experience that reaches POS terminals.
Cons: compliance framing on the page is generic, with no retail vertical content; large consultancy delivery, so tester continuity belongs in the statement of work.
Best for: multinational retailers needing one provider across North American and European estates.
Two firms worth knowing that are not retail penetration testing vendors
Category fit matters because a QSA will ask for a penetration test report, and a vulnerability scan presented as one will come back. Rapid7 publishes a named retail industry page, but its centre of gravity is vulnerability and exposure management through InsightVM, and its PCI ASV work runs through a partner. Black Duck, the application security business formerly inside Synopsys, sells SAST, SCA and software composition tooling. Both are reasonable purchases for a retailer, and neither produces a requirement 11.4 report. The mistake sits on the buyer's side when a scanning subscription is booked expecting one.
How much does retail penetration testing cost in 2026?
Retail engagements price above a generic web application test because scope usually spans a storefront, its APIs, a mobile application, the segmentation boundary around store networks, and reporting shaped for an assessor. The bands below are Stingrai's 2026 benchmarks, aggregated from published vendor pricing and industry cost guides.
Retail scope | Typical range, US$ | Typical range, C$ |
|---|---|---|
Single storefront web application and its APIs | US$5,000 to US$30,000 | C$7,000 to C$40,000 |
PCI DSS scoped engagement, internal and external | US$12,000 to US$25,000 | C$16,000 to C$34,000 |
Segmentation testing across a store estate | US$10,000 to US$35,000 | C$14,000 to C$48,000 |
Mobile application, per platform, plus backend | US$7,000 to US$35,000 | C$10,000 to C$48,000 |
Cloud and fulfilment environment | US$10,000 to US$50,000 | C$14,000 to C$68,000 |
Annual continuous programme across the estate | US$50,000 to US$150,000+ | C$40,000 to C$120,000 |
Stingrai publishes package pricing openly. A one-time Autonomous Pentest with Snipe starts at US$3,000 and a one-time Hybrid Pentest with certified penetration testers is US$6,800, both covering exactly one web application and its APIs. The same tiers run as subscriptions from US$650 and US$1,275 per month on a 12-month engagement. The Autonomous tier carries a No High or Critical Finding, Don't Pay guarantee, and retesting is included. Store estates and full PCI scopes are quoted individually, and current figures are on the pricing page. For a wider view, see the penetration testing cost guide and the cost calculator.
The retail buyer's checklist
Does the quote cover all four PCI testing types? External, internal, segmentation and the retest.
Is retesting included in the price? Requirement 11.4.4 makes it mandatory; priced separately it becomes a change order at the worst moment.
Who are the named penetration testers? Names and certifications in the statement of work, not a bench description.
How is the payment page handled? How are third-party scripts enumerated, and is the 11.6.1 tamper detection mechanism tested or assumed?
Is checkout and loyalty business logic explicitly in scope? Price manipulation, coupon stacking, gift card enumeration and points transfer abuse belong in the methodology.
Is the segmentation claim being tested or accepted? If store networks are out of scope because of segmentation, that segmentation is the thing under test.
Does the vendor test storefront APIs directly? Headless commerce moves authorization into APIs; testing only the rendered site misses them.
Will findings reach engineers in their tracker? A PDF in a shared drive is not a remediation workflow.
Does the cadence match your release rate? A storefront shipping weekly has fifty-one untested weeks after an annual test.
Will the report survive your assessor? Scope statement, methodology, reproduction steps, evidence, remediation record and retest result.
The paperwork lives in the statement of work template and the penetration testing RFP template.
What this means for retail security buyers in 2026
Buy the whole of requirement 11.4, not the cheapest quarter of it. The commonest procurement failure in retail is an external-only test sold as PCI compliance. Internal testing, segmentation testing and the retest are separate obligations.
Test the logic, not the perimeter. What turns a foothold into a loss is authorization and business logic: whose order you can read, whose points you can move, which coupon you can reuse. Across the engagements analysed in the 2026 state of penetration testing report, 1,206 verified findings across 55 tests carried a 0.74 percent false-positive rate and 92.7 percent of tests surfaced at least one High or Critical issue.
Treat the payment page as someone else's code. Since 31 March 2025 the standard has assumed exactly that. Enumerate what executes on checkout, justify every script in writing, and test the tamper detection mechanism rather than trusting its dashboard.
Frequently Asked Questions
Who are the best retail and e-commerce penetration testing companies in 2026?
The best retail and e-commerce penetration testing companies in 2026 are Stingrai, VikingCloud, Coalfire, Optiv, Praetorian, BreachLock, ControlCase, Schellman, Bishop Fox, LevelBlue, GuidePoint Security and NCC Group. Stingrai is a CREST-accredited offensive security company. Two named penetration testers run each engagement, holding OSCE³, OSWE, OSEP, CREST CRT and CISSP, with 18 published CVEs across the team and bug bounty Hall of Fame listings at Apple, Google, the US Department of Defense and PaySafe. For a retailer that means human-led testing of the storefront and checkout authenticated as every customer and staff role, the APIs behind a headless build, the mobile app under MASVS and MASTG with its backend, the corporate and in-store networks either side of the PCI segmentation boundary, and phishing against the people who handle orders and refunds, with testing delivered through its PTaaS platform, one-time or continuously. VikingCloud, Coalfire and Optiv follow for a published retail industry practice, PCI assessment scale, and PCI testing that names retail and e-commerce respectively. Every entry links to the vendor's own published page and was last verified on 19 September 2026.
Does PCI DSS require penetration testing?
Yes. PCI DSS v4.0.1 requirement 11.4.2 requires internal penetration testing and 11.4.3 requires external penetration testing, both at least once every 12 months and after any significant infrastructure or application change. Requirement 11.4.1 requires a documented methodology, 11.4.4 requires exploitable findings to be corrected and the testing repeated to verify the corrections, 11.4.5 requires segmentation controls tested at least every 12 months, and 11.4.6 shortens that to every six months for service providers. The standard also states the tester need not be a QSA or an ASV, only qualified and organizationally independent.
What do PCI DSS 6.4.3 and 11.6.1 require of a payment page?
Requirement 6.4.3 requires every script loaded and executed on a payment page to be authorized, to have its integrity assured, and to be inventoried with written business justification. Requirement 11.6.1 requires a change and tamper detection mechanism alerting on unauthorized modification of security-impacting HTTP headers and page content, evaluated at least every seven days. Both became mandatory on 31 March 2025.
Does SOC 2 require penetration testing for retailers?
No trust services criterion names penetration testing. It still matters for retailers that sell software or data services alongside goods, and for the commerce platform vendors they depend on, because CC4.1 asks for ongoing and separate evaluations of internal control and CC7.1 asks for monitoring to detect changes that introduce vulnerabilities. Auditors routinely accept a penetration test report as the evidence behind both criteria.
How much does retail penetration testing cost in 2026?
Cost tracks scope. A single storefront web application and its APIs typically runs US$5,000 to US$30,000, a PCI DSS scoped internal and external engagement US$12,000 to US$25,000, and an annual continuous programme US$50,000 to US$150,000 or more. Stingrai publishes package pricing openly, with a one-time Autonomous Pentest from US$3,000 and a one-time Hybrid Pentest with certified penetration testers at US$6,800, each covering one web application and its APIs, and the same tiers as subscriptions from US$650 and US$1,275 per month on a 12-month engagement. Store estates and full PCI scopes are quoted individually on the pricing page.
Does a retail penetration tester have to be a QSA?
No. PCI DSS v4.0.1 states within requirements 11.4.2 and 11.4.3 that the penetration tester is not required to be a QSA or an ASV. What the standard requires is a qualified internal resource or a qualified external third party with organizational independence from the systems being tested. In practice the QSA reads the report as evidence, and the testing firm and the assessing firm are often different organisations by design. Accreditations such as CREST, and certifications such as OSCP and CREST CRT, are the signals to ask for.
How often should an e-commerce retailer run a penetration test?
PCI DSS sets the floor at once every 12 months for internal and external testing, plus after any significant infrastructure or application change, with segmentation testing every 12 months for merchants and every six months for service providers. For a storefront shipping weekly, an annual test leaves fifty-one untested weeks, so the after-any-significant-change clause does most of the work. Retailers with a high release rate increasingly run a continuous programme alongside the annual engagement.
Related reading
References
Verizon Business. _2026 Data Breach Investigations Report, Retail snapshot._ NAICS 44 to 45. https://www.verizon.com/business/resources/reports/dbir/. Source of the 997 incidents and 806 breaches with confirmed data disclosure, the 95 percent three-pattern share, the 61 / 17 / 10 / 8 / 3 percent pattern split, the 85 percent financial motive, the 42 percent exploitation of vulnerabilities, 14 percent credential abuse and 9 percent phishing initial access figures, and the 68 percent third-party involvement figure. Verified 19 September 2026.
PCI Security Standards Council. _PCI DSS v4.0.1._ Published 11 June 2024. https://www.pcisecuritystandards.org/document_library/. Source of requirements 11.4.1 through 11.4.7, including the 12-month internal and external testing frequency, the six-month service provider segmentation cadence at 11.4.6, the correction and retest obligation at 11.4.4, and the statement that the tester need not be a QSA or an ASV.
PCI Security Standards Council. _Payment Page Security and Preventing E-Skimming: Guidance for PCI DSS Requirements 6.4.3 and 11.6.1._ Information supplement published 10 March 2025. https://blog.pcisecuritystandards.org/new-information-supplement-payment-page-security-and-preventing-e-skimming. Source of the payment page script authorization, integrity and tamper monitoring framing.
Akamai Technologies. _Securing the Agentic Storefront: Attacks on Commerce._ State of the Internet report, press release 15 July 2026. https://www.akamai.com/newsroom/press-release/akamai-research-commerce-becomes-the-epicenter-for-ai-bot-attacks-and-agentic-fraud-in-2026. Source of the 47.9 percent commerce share of AI bot traffic from July to December 2025, the nearly 3 trillion Layer 7 DDoS attacks on commerce in 2025 with retail bearing 84 percent, the 85 percent of commerce respondents reporting an API-related incident, and the 22 percent who know which APIs expose sensitive data.
California Legislative Information. _Cal. Civ. Code 1798.81.5._ https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.81.5. Subdivision (b) requires reasonable security procedures and practices appropriate to the nature of the information. Section 1798.150 provides the statutory private right of action.
Office of the Privacy Commissioner of Canada. _Personal Information Protection and Electronic Documents Act, Schedule 1, principle 4.7, Safeguards._ https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/. Requires safeguards proportionate to the sensitivity of the information.
Commission d'acces a l'information du Quebec. _Law 25, Act to modernize legislative provisions as regards the protection of personal information._ Provisions in force in phases on 22 September 2022, 2023 and 2024. https://www.cai.gouv.qc.ca/. Source of the phased implementation dates including the data portability right effective 22 September 2024.
VikingCloud. _Retail._ https://www.vikingcloud.com/industries/retail. Published retail industry practice covering network, segmentation, mobile and web application penetration testing alongside PCI DSS assessment. Verified 19 September 2026.
Coalfire. _PCI DSS Assessment._ https://coalfire.com/services/assessment/pci-dss. Penetration testing framed against PCI DSS v4.0.1 requirement 11.4, with over a thousand PCI DSS assessments annually. Verified 19 September 2026.
Optiv. _PCI DSS Compliance._ https://www.optiv.com/services/risk/pci-dss-compliance. PCI penetration testing and segmentation testing naming retail and e-commerce, with merchant validation level guidance. Verified 19 September 2026.
Praetorian. _Penetration Testing for PCI DSS Compliance._ https://www.praetorian.com/security-101/penetration-testing-for-pci-dss-compliance/. External, internal, segmentation and application testing in one engagement, naming e-commerce platforms and payment gateways, with retesting at no additional cost. Verified 19 September 2026.
BreachLock. _PCI DSS Penetration Testing._ https://www.breachlock.com/compliance/pci-dss-penetration-testing/. Requirement-mapped PCI penetration testing delivered through a PTaaS platform. Verified 19 September 2026.
ControlCase. _Retail._ https://www.controlcase.com/industries/retail/. Retail industry page pairing PCI DSS assessment with continuous compliance monitoring and the Compliance Hub platform. Verified 19 September 2026.
Schellman. _Penetration Testing._ https://www.schellman.com/services/penetration-testing. Published testing portfolio spanning application, network, mobile, cloud, physical, social engineering and hardware, alongside QSA and PA-QSA practices. Verified 19 September 2026.
Bishop Fox. _Compliance and Frameworks._ https://bishopfox.com/services/compliance-and-frameworks. PCI DSS annual and post-change penetration testing, with an ASV credential. Verified 19 September 2026.
LevelBlue. _Penetration Testing._ https://levelblue.com/services/penetration-testing. Penetration testing practice with retail and hospitality among industries served and retesting included through findings validation. Verified 19 September 2026.
GuidePoint Security. _PCI DSS Compliance._ https://www.guidepointsecurity.com/pci-dss-compliance/. PCI DSS compliance and penetration testing services with compliance management between assessments. Verified 19 September 2026.
NCC Group. _Penetration Testing Services._ https://www.nccgroup.com/penetration-testing-services/. Penetration testing naming PCI DSS among supported frameworks, tiered from automated to manual and continuous. Verified 19 September 2026.
Rapid7. _Retail._ https://www.rapid7.com/solutions/industry/retail/. Named retail industry page from a firm whose primary product is vulnerability and exposure management. Verified 19 September 2026.
Stingrai. _The State of Penetration Testing 2026._ https://www.stingrai.io/blog/state-of-penetration-testing-2026. 1,206 verified findings across 55 penetration tests, severity mix, remediation timing and false positive rate.
Stingrai. _Pricing._ https://www.stingrai.io/pricing. Published one-time and continuous package prices for one web application and its APIs.
Ready to scope a retail penetration test?
The finding that turns into a breach notification is rarely a missing patch on the perimeter. It is an order endpoint that trusts the customer identifier in the request, a coupon that can be redeemed four hundred times in the same second, or a third-party tag on checkout that nobody can justify in writing. Stingrai is a CREST-accredited penetration testing service provider whose penetration testing supports PCI DSS 4.0.1, SOC 2 and ISO 27001 programmes by producing the scope statement, technical report, remediation record and retest evidence those programmes consume. Certified penetration testers work concurrently with Snipe, our autonomous AI agent for web application penetration testing, hunting the broken authorization, IDOR and business logic flaws that put one shopper's order on another shopper's screen. Book a free scoping call, get a quote for a store estate or multi-storefront scope, or read the published package prices on the pricing page.



