main logo icon

Published on

August 18, 2026

|

18 min read

Network Penetration Testing Services (2026): Internal, External and What to Expect

A buyer's guide to network penetration testing services in 2026: internal, external, wireless and segmentation testing explained, five delivery models compared, real cost ranges, timelines, report contents, compliance mapping and a provider checklist.

Arafat Afzalzada

Arafat Afzalzada

Founder

Network Security

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

A network penetration testing service is a contracted, time-boxed engagement in which qualified testers attempt to compromise your network infrastructure the way an attacker would, then hand back validated findings with reproduction evidence and proven attack paths. Four purchases sit under the category and they are not interchangeable: external testing against the internet-facing perimeter, internal testing from inside the LAN, wireless testing of the radio estate, and segmentation testing that proves isolation boundaries hold. Vulnerability exploitation is now the leading initial access vector at 31 percent of breaches, and edge devices and VPNs jumped from 3 percent to 22 percent of exploitation-driven breaches in one year, per the Verizon 2026 DBIR. Market pricing runs about US$5,000 to US$40,000 and above, driven by live host count, subnet and VLAN count, Active Directory footprint, physical sites and how many start positions you buy. PCI DSS v4.0.1 is the only mainstream framework that names network testing explicitly: internal (11.4.2), external (11.4.3), retest (11.4.4) and segmentation validation (11.4.5, and every six months for service providers under 11.4.6). Stingrai delivers network penetration testing with its certified human pentest team, as a one-time annual engagement or as a continuous program.

Vulnerability exploitation is now the single most common way attackers get in, accounting for 31% of breaches and finally overtaking stolen credentials, per the Verizon 2026 Data Breach Investigations Report, which analysed more than 22,000 confirmed breaches across 145 countries. The devices carrying that traffic sit on your network edge, and the concentration there is stark: edge appliances and VPNs went from 3% to 22% of exploitation-driven breaches in a single year. Mandiant's M-Trends 2026, drawn from over 500,000 hours of incident response, puts exploits at 32% of initial infection vectors, the leading entry point for the sixth consecutive year.

A network penetration testing service is a contracted, time-boxed engagement in which qualified testers attempt to compromise your network infrastructure the way an attacker would, from outside the perimeter, from inside it, or both, and then hand back validated findings with reproduction evidence, proven attack paths and remediation guidance. The unit you are buying is tester attention directed at hosts, services, edge appliances, identity infrastructure and the trust relationships between network segments, plus a report your engineers can act on and your auditor and your largest customer will both accept.

This guide is about buying that service: which of the four network test types you actually need, what belongs in scope, the five delivery models on the market and how they genuinely differ, what the engagement costs and how long it takes, what the report should contain, and how the result maps to your compliance obligations.

Which guide you need

Stingrai publishes several resources on network security testing. They answer different questions, so start with the one that matches yours.

Your question

Read this

How do I buy this, and from whom?

This guide: test types, delivery models, pricing, timelines, verification checklist

What exactly is in scope on an internal test, and what drives the price?

Internal Network Penetration Testing: Scope, Cost and What It Actually Finds

What is in scope on an external test?

External Network Penetration Testing: What Is In Scope and What It Finds

What does a wireless assessment actually test?

Wi-Fi Penetration Testing: What a Wireless Security Assessment Actually Tests

What about Active Directory specifically?

Active Directory Penetration Testing Services (2026) and Active Directory Security Assessment: What It Covers

What does Stingrai specifically do?

Internal and External Network Penetration Testing service page

What a network penetration testing service includes

"Network penetration testing" is a category, not a product. Four distinct purchases sit underneath it, and they are not interchangeable. Buyers who assume a single quote covers all four are the buyers who discover in month eleven that their segmentation was never validated.

Test type

Where the tester starts

What it proves

Typical trigger

External network

The public internet, unauthenticated

What an attacker reaches from outside: exposed services, edge appliances, VPN and remote access, mail and DNS, forgotten hosts

Annual baseline, PCI DSS 11.4.3, customer security review, post-acquisition

Internal network

Inside the LAN, usually from an assumed-breach foothold

What an attacker does after the perimeter fails: credential relay, privilege escalation, lateral movement, path to domain compromise

Annual baseline, PCI DSS 11.4.2, insider-risk questions, post-incident

Wireless

On site, within radio range

Whether the radio estate is a route onto the wired network, plus rogue and evil-twin exposure and client behaviour off site

PCI DSS 11.2.1 obligations, office moves, guest and corporate SSID separation

Segmentation

Deliberately outside the protected zone

That networks designated out of scope genuinely cannot reach or influence the protected zone

PCI DSS 11.4.5 and 11.4.6, scope-reduction claims, zero-trust programs

Active Directory work sits alongside these rather than inside any single one. Most internal engagements enumerate and prove identity attack paths as a matter of course, but a dedicated Active Directory assessment goes deeper into delegation, certificate services, tier boundaries and trust relationships. Our walkthrough of one low-privilege account to domain admin shows what that depth looks like in practice, and hybrid estates need Entra ID scope named separately again.

Network Pentest Scope Layers 2026

What is normally excluded

Denial-of-service testing, destructive exploitation, physical entry, social engineering of your staff, and third-party systems you do not own sit outside a standard network engagement. Testing against production during business hours, exploitation of anything that could interrupt operational technology, ransomware simulation and data exfiltration to external infrastructure are in scope only when agreed in writing. Cloud provider infrastructure has its own rules of engagement and belongs in a cloud penetration test rather than a network one. Settle all of these during scoping rather than in week two.

External network penetration testing: what is actually in scope

An external network penetration test covers everything an unauthenticated attacker can reach from the internet against the address space and hostnames you own. In 2026 that surface is wider than the firewall rule set suggests, because it includes assets acquired through subsidiaries, cloud accounts opened by a product team, and hosts that survived a migration nobody documented.

A complete external engagement covers:

  • Attack-surface discovery. Address blocks, domains and subdomains, cloud tenancies, certificate transparency records and third-party hosted assets. Discovery frequently produces the first real finding, which is that your inventory is wrong.

  • Edge and remote access appliances. VPN concentrators, firewalls, load balancers, secure gateways and remote-access portals. This is the category the DBIR now puts at 22% of exploitation-driven breaches, and it deserves disproportionate attention.

  • Exposed management planes. Administrative interfaces, hypervisor and out-of-band management, database ports, monitoring consoles and CI runners that were never meant to answer from the internet.

  • Mail, DNS and transport. SPF, DKIM and DMARC posture, zone transfer and subdomain takeover conditions, TLS configuration and certificate hygiene.

  • Authentication surfaces. Portals, single sign-on endpoints and remote-access logins, tested for credential-stuffing exposure, missing multi-factor enforcement and account enumeration.

  • Web applications reachable from the perimeter, at least to the depth of identifying exposure. Full application coverage is a separate purchase covered in our web application penetration testing services guide.

The remediation gap is the reason this test keeps earning its budget. The Verizon 2026 DBIR found only 26% of CISA known exploited vulnerabilities were fully remediated, down from 38% the prior year, with a median remediation time of 43 days against 32 days a year earlier. An external test tells you which of those unpatched edges is actually reachable and actually exploitable in your environment, which is a different question from which CVEs your scanner listed. For the layer-by-layer treatment, see the external network scope and cost guide.

Internal network penetration testing: what is actually in scope

An internal test answers a different question: once someone is inside, how far do they get, and how fast? A clean external report predicts almost nothing about this, because the controls that stop an outsider at the edge are not the controls that stop lateral movement.

A complete internal engagement covers:

  • Enumeration of the live estate. Hosts, services, shares, printers, hypervisors, backup infrastructure and network devices across every in-scope subnet and VLAN.

  • Credential capture and relay. Broadcast name resolution poisoning, SMB signing posture, NTLM relay paths and coerced authentication.

  • Identity and Active Directory attack paths. Kerberos abuse, delegation misconfiguration, certificate services templates, ACL chains, service account exposure and the route from a standard user to a tier-zero asset.

  • Privilege escalation on hosts. Local misconfiguration, unquoted paths, writable services, stale software and credential material left in scripts, shares and configuration management.

  • Lateral movement and containment. Whether host isolation, endpoint controls and network policy actually stop the movement they are supposed to stop.

  • Data reachability. Which crown-jewel systems and datasets are reachable from the start position, which is the finding that turns a technical report into a board conversation.

The starting position you buy changes the result more than any other single variable. A test that starts from an unauthenticated network drop measures your network controls. A test that starts from a standard domain account measures your identity controls. Most buyers need the second and purchase the first. Our internal network scope and cost guide walks through the start positions in detail.

Wireless and segmentation: the two most under-scoped purchases

These two are chronically left out of network pentest quotes, and both have compliance consequences.

Wireless testing requires someone physically on site within radio range, which means it has calendar and travel implications that a remote engagement does not. A real wireless assessment probes the authentication method behind each SSID, tests whether the guest network is genuinely isolated from corporate, looks for rogue and evil-twin conditions, and examines client behaviour: what your laptops and handsets probe for when they leave the building. PCI DSS v4.0.1 Requirement 11.2.1 obliges in-scope entities to test for the presence of wireless access points and identify authorized and unauthorized ones at least once every three months, and that obligation applies even where policy prohibits wireless entirely, precisely because an unauthorized access point is easy to attach and hard to spot. See what a wireless security assessment actually tests.

Segmentation testing is the one buyers quietly skip and auditors reliably ask about. It is active technical testing performed from outside a protected zone to prove that networks designated out of scope cannot reach or influence the protected zone. If you claim segmentation to reduce your PCI scope, that claim has to be validated by testing under Requirement 11.4.5, at least every 12 months, and every six months for service providers under 11.4.6. The same logic applies well beyond payments: any zero-trust or crown-jewel isolation program that has never been tested from the untrusted side is an architecture diagram, not a control.

Assumed breach: the starting position that changes the result

The most useful framing question in a network scoping call is not "internal or external", it is "where does the tester start?". Assumed breach means the engagement begins from a realistic internal foothold that is granted rather than earned: a standard domain account, a managed laptop, or network access on a user VLAN.

The argument for it is arithmetic. M-Trends 2026 reports that the median time between initial access and hand-off to a secondary threat group has collapsed from more than eight hours in 2022 to 22 seconds in 2025, while global median dwell time rose to 14 days. Spending a third of a fixed engagement budget re-proving that a phishing email can land tells you nothing you did not already assume, and burns the days you needed for the part that is genuinely uncertain, which is what happens next.

Assumed breach is not a red team. It optimises for coverage of the internal estate rather than for stealth and detection testing. If your question is whether your security operations team notices and responds, that is red team scope, and the two engagements answer different questions. Buy the one that matches the question you actually have.

Methodology and standards a real provider names

A network provider who says "we follow industry best practice" without naming a standard is describing a marketing position. Ask for the standard by name.

Standard

What it gives you

How to use it in an RFP

NIST SP 800-115

The technical guide to information security testing, with a four-phase structure: planning, discovery, attack, reporting

Require the report to map findings to a documented phase structure and state coverage per phase

PTES

Seven phases from pre-engagement through post-exploitation and reporting

Use for engagement structure, rules of engagement and post-exploitation boundaries

OSSTMM

Operational security testing methodology covering data networks, wireless and telecommunications

Useful where wireless and telecom surfaces are in scope alongside the wired estate

MITRE ATT&CK

A shared vocabulary for the techniques used during the engagement

Require findings and attack chains to reference technique IDs so your detection team can map coverage

PCI DSS v4.0.1 Requirement 11.4.1

A documented penetration testing methodology is itself a requirement

If PCI applies, the methodology document is an audit artefact, so ask to see the provider's

Named standards are not a substitute for tester skill, but their absence is a reliable signal. Our overview of penetration testing methodologies covers how each one maps to different engagement types.

Quick comparison: the five delivery models

Almost every provider you shortlist for network work fits one of five delivery models. The model determines who actually touches your network, how much of the coverage is human judgement versus automation, and how predictable your cost is. Each entry is described from the vendor's own current public pages, reviewed in August 2026.

Delivery model

Who performs the testing

Strengths

Structural trade-offs

Published pricing

Examples

Specialist offensive security firm with an in-house bench

The firm's own employed, certified testers

Named testers, continuity across retests, depth on identity and lateral movement, comfortable with assumed-breach scoping

Capacity is bounded by one firm's bench, so book multi-site work early

Varies; Stingrai publishes fixed tiers for application scope and quotes network individually

Stingrai, Bishop Fox, NetSPI

Researcher-network PTaaS

A vetted community matched to your project by the platform

Fast start, platform tooling and integrations, published methodology for internal and external network work

Testers are matched per engagement by design, so continuity across a year varies

Not published on vendor pages reviewed

Cobalt, Synack

Broad security and compliance consultancy

Employed consultants, often alongside assessment credentials

Enterprise process maturity, accreditation coverage, useful where the same firm's assessors understand the compliance context

Lead time and price track senior consultant availability

Not published

NCC Group, Coalfire

Autonomous network testing software

Software you or your team operate

Repeatable on-demand runs, low marginal cost, strong regression coverage between human engagements

Output is software-generated, so confirm what a human signs and what your auditor or customer accepts

Not published

Horizon3.ai (NodeZero)

Vulnerability management platform

Software, positioned by its vendors as scanning rather than penetration testing

Excellent breadth on known-signature issues, asset inventory and patch prioritisation at scale

Vendors do not position these as penetration tests, and a scan report is not a pentest report

Not published for enterprise tiers

Qualys, Tenable, Rapid7 InsightVM

A note on fairness: "not published" means the vendor did not publish a price on the pages reviewed for this guide in August 2026, not that the vendor is expensive or evasive. Enterprise security services are commonly quoted rather than listed.

1. Specialist offensive security firm with an in-house bench

Network testing is human work. There is no equivalent of a web application scanner that can decide whether a delegation relationship should exist or whether a reachable backup server matters, so this model is the default for internal and Active Directory scope in particular.

Bishop Fox (Tempe, Arizona) lists external and internal penetration testing among its specialisms alongside continuous testing, red teaming and attack surface management. NetSPI (Minneapolis, Minnesota) describes 350-plus pentesters who are employed rather than outsourced, covering both internal and external network testing, delivered human-led with an AI-accelerated platform and remediation tracking. Neither publishes pricing.

Stingrai (Toronto, Ontario, with a London, UK office) runs the same structural model, delivering network engagements with its certified human pentest team. What to check in this model generally, and what we would expect you to check with us: who specifically is testing, their certifications, how many start positions the quote includes, and whether retests are inside the fee.

Best for: buyers who want named, accountable testers with depth on identity and lateral movement, and who care that the same firm handles the retest. Not ideal for: organizations needing a dozen simultaneous international sites tested inside a two-week window.

2. Researcher-network PTaaS

Platforms in this model maintain a vetted community and match researchers per engagement. Cobalt (San Francisco, California) offers internal and external network pentests as named services, describes an OSSTMM-aligned methodology naming tools including Nmap, Nessus and Metasploit, states pentesters average 11 years of experience, and advertises launching an internal network pentest within 24 hours with retesting in 7 days or less. Synack (Redwood City, California) covers host assets alongside web, mobile, API and cloud surfaces, describes the Synack Red Team as over 1,500 researchers vetted through background checks and skill assessments, and offers Sara, its own autonomous agent. Neither publishes pricing.

The genuine strength is speed to start and breadth of specialisms. The structural consideration is that matching is the design, so the researcher who learned your VLAN topology in March may not be the one assigned in September. If continuity matters across a multi-site program, ask in writing how each platform handles it.

Best for: teams that need to start quickly, value platform tooling and integrations, and have a well-documented environment. Not ideal for: buyers whose priority is the same senior tester carrying environment context across a year.

3. Broad security and compliance consultancy

Consultancies deliver with employed staff and typically bring accreditation breadth and enterprise process maturity. NCC Group is headquartered in Manchester, United Kingdom, and is publicly listed. Coalfire (Westminster, Colorado, founded 2001) pairs offensive security with a large compliance assessment practice spanning PCI DSS, HITRUST, SOC and federal programs including CMMC assessment as a C3PAO.

This model earns its place when procurement, governance and regional accreditation requirements are as demanding as the technical work. The trade-offs are structural rather than qualitative: lead times and pricing track the availability of the specific senior consultants you want. Where accreditation is the driver, our CREST-accredited penetration testing companies guide explains what firm-level accreditation actually certifies.

Best for: enterprise and regulated buyers where governance, accreditation and multi-country delivery are first-order requirements. Not ideal for: a mid-market team that needs an internal test scoped and started this month.

4. Autonomous network testing software

Here you licence software and run it yourself. Horizon3.ai (San Francisco, California, founded 2019) describes NodeZero as running internal tests from a free Docker host or virtual appliance and external tests from its cloud, without agents, chaining weaknesses to demonstrate impact beyond CVEs, and covering internal, external, cloud, Kubernetes and Active Directory password auditing, with PCI and NIS 2 compliance modules. Pricing is not published.

Autonomous network software is genuinely useful and genuinely different from a service. It is repeatable, inexpensive per run and excellent at catching regressions between human engagements. The question to settle before you buy is what your counterparty needs. If a customer questionnaire asks for an independent third-party penetration test, or your QSA wants a report attributable to named testers, confirm in advance what the vendor signs and what your customer accepts. That is a contracting question, not a technical one.

Best for: continuous internal validation and regression coverage in teams with the in-house skill to triage output. Not ideal for: buyers whose primary deliverable is third-party independence, unless the vendor confirms that in writing.

5. Vulnerability management platform

Qualys, Tenable and Rapid7 InsightVM are vulnerability management products and their vendors position them as such. They are strong at what they target: continuous asset discovery, authenticated scanning at scale, and patch prioritisation across large estates. Buyers get into trouble only when a procurement process treats a scan report as a pentest report, which is a mismatch worth settling internally before the requirement is written. Our breakdown of penetration testing versus vulnerability assessment covers what each framework actually accepts.

Best for: continuous visibility and remediation workflow across a large asset estate. Not ideal for: satisfying a requirement that specifies an independent penetration test.

What network penetration testing services cost in 2026

A network penetration test in 2026 runs approximately US$5,000 to US$40,000 and above, with live host count, internal segmentation depth and Active Directory scope as the primary drivers, per our 2026 penetration testing cost guide. PCI DSS engagements, which bundle internal, external and segmentation testing, commonly land at US$12,000 to US$25,000. Annual program spend across all testing types typically runs US$8,000 to US$20,000 for small businesses, US$20,000 to US$50,000 for mid-market and US$50,000 to US$150,000 or more for enterprise. Canadian buyers can compare local benchmarks in the average cost of a pentest in Canada.

Network Pentest Cost Ranges 2026

The variables that actually move a network quote are narrower than most RFPs assume:

Cost driver

Why it moves effort

Live host count

The real unit of work. A /24 with nine responsive hosts is nine hosts, not 256

Subnet and VLAN count

Each segment adds discovery and reachability testing, and each pair you want proven adds more

Active Directory footprint

Domain and forest count, trusts, certificate services and object counts drive the identity workstream

Physical sites

Each site needs its own start position and logistics, and this dominates wireless pricing

Start positions purchased

Each start position is a fresh run of the methodology, not a variation on the last one

Evasive versus open testing

Evasion buys realism and costs coverage, because quiet work is slower

Evidence requirements

Auditor-grade packs and questionnaire mapping add real reporting effort

Retest scope

Retesting everything is different work from retesting criticals and highs

For context on why the spend is defensible: the IBM Cost of a Data Breach Report 2026 puts the global average breach at a record US$4.99 million, up 12% year over year, with the United States average at US$11.5 million. The broader market is growing accordingly, from US$2.72 billion in 2026 to a projected US$5.54 billion by 2031 at a 15.29% CAGR, per Mordor Intelligence.

Making network quotes comparable

Network quotes are rarely comparable as received, because vendors price different units. Normalize them before you compare:

  1. Ask for tester days, not just a total. A price with no day count cannot be compared to anything.

  2. Ask what the day count is tied to. Live hosts, subnets, domains and sites. A vendor who cannot map days to those has estimated by feel.

  3. Ask how many start positions are included on an internal test, and what each one is.

  4. Ask whether segmentation testing is in or out. This is the single most common omission, and the one your assessor will ask about.

  5. Ask whether wireless is in or out, and if in, how many physical sites and whether travel is included.

  6. Ask whether Active Directory is enumerated or genuinely tested, including certificate services and delegation.

  7. Ask whether retests are inside the fee, how many, and for how long after the report.

  8. Ask what happens if nothing is found. Stingrai publishes a "No High or Critical Finding equals Don't Pay" position on its pricing page.

Our guide to comparing penetration testing quotes has a worked side-by-side example.

Timelines: what to plan for

Elapsed time always exceeds tester days, because authorization, access provisioning, scheduling and report review are real. Plan against elapsed working days rather than the number in the statement of work.

Engagement profile

Tester effort

Typical elapsed time, kickoff to final report

External only, single entity, under 50 live hosts

3 to 5 tester days

1–2 weeks

External plus internal, single site, single domain

1 to 2 tester weeks

2–4 weeks

Internal across multiple sites, multi-domain forest

2 to 4 tester weeks

4–8 weeks

PCI scope: internal, external and segmentation validation

2 to 3 tester weeks

3–6 weeks

Wireless added, per additional physical site

1 to 2 tester days per site

Adds 1–2 weeks for travel and scheduling

Continuous program

Ongoing

Findings arrive as they are confirmed, not at a report date

The three stages buyers underestimate are the authorization chain when subsidiaries or hosting providers are involved, physical or VPN access provisioning for internal testing, and remediation-to-retest, which is bounded by your engineering team rather than your vendor. Build all three into the date you promise your auditor or your customer. If your trigger is an incident rather than a calendar, see emergency pentest after a security incident for how compressed timelines actually work.

What a network penetration test report contains

A network penetration testing service is only as good as what it hands back. Specify the deliverable list in the contract rather than hoping.

Deliverable

What good looks like

Executive summary

Two pages a non-technical reader can act on: what was tested, what the material risk is, what to do first

Scope and coverage statement

Exact CIDRs, hostnames, domains, VLANs, sites and start positions tested, plus what was excluded and why

Technical findings

Per finding: severity with rationale, affected hosts and services, evidence, reproduction steps, business impact and specific remediation

Attack path narrative

The chain from start position to impact, step by step, with the specific control failure at each hop. This is the part that separates a pentest from a scan

Identity and Active Directory findings

Delegation, certificate templates, ACL chains and service account exposure treated as their own section, not buried in host findings

Segmentation results

Which boundaries were tested from which side, what was reachable, and an explicit statement of whether isolation held

Methodology and tooling

Which standard was followed, which phases were completed, which tools were used and where manual testing took over

Completion letter

A short signed letter stating scope, dates and remediation status, suitable for enterprise customers and your assessor

Retest results

Updated status per finding and a revised letter after fixes land

Two of these get forgotten and then needed urgently. The completion letter is what you hand a prospect mid-security-review, and the segmentation statement is what your QSA asks for. Confirm both exist before you sign. For scoring the report you receive, use our guide to evaluating a penetration test report.

Compliance mapping: what the frameworks actually require

Buyers frequently over-read framework language on network testing. Here is what each one actually says, so you can scope to the requirement rather than to a rumour.

Pci Dss Network Testing Cadence 2026

Framework

What it requires on network penetration testing

Practical implication

PCI DSS v4.0.1

The only mainstream framework that names network testing explicitly. Requirement 11.4.1 mandates a documented methodology, 11.4.2 internal testing, 11.4.3 external testing, both at least every 12 months and after significant change, 11.4.4 correction of exploitable vulnerabilities with testing repeated to confirm, 11.4.5 segmentation validation at least every 12 months where segmentation isolates the cardholder data environment, and 11.4.6 the same every six months for service providers. Requirement 11.2.1 separately obliges wireless access point detection at least once every three months.

If cardholder data is in play, internal, external and segmentation testing are stated requirements. See PCI DSS penetration testing

SOC 2

Does not mandate penetration testing and sets no frequency. Auditors, enterprise customers and insurers commonly expect it as evidence for the monitoring and risk-assessment criteria.

Cadence is driven by your auditor and your customers. See SOC 2 penetration testing

ISO 27001

Does not mandate a frequency. Technical vulnerability management and network security controls are where network testing evidence lands.

Annual plus after significant infrastructure change is the common settlement

HIPAA

Requires a risk analysis rather than a named test. Network testing is the usual way organizations evidence technical safeguards over systems handling ePHI.

Scope follows the ePHI boundary, which is usually wider than teams expect

NIST SP 800-53 / 800-171

Control CA-8 addresses penetration testing for in-scope systems.

Applies where a contract or agency requirement invokes the catalogue. See does CMMC require penetration testing

NIS2 and DORA

Threat-led testing obligations apply to in-scope essential entities and financial entities in the EU, at a level above a standard network test.

Scope depends on entity classification. See does NIS2 require penetration testing

Stingrai's penetration testing supports your SOC 2, ISO 27001, HIPAA, PCI DSS 4.0, NIST SP 800-53 / 800-171, DORA and NIS2 compliance programs by producing the evidence those programs need: a scoped report, reproduction evidence per finding, documented remediation status and a completion letter. Our guide to pentest evidence auditors accept covers what each framework's assessors actually ask to see.

How to choose a network penetration testing service: a nine-step verification

Marketing claims in this market are close to uniform. Verification is what separates providers. Run these nine steps against every shortlisted vendor and score them side by side.

  1. Name the testers. Ask who specifically will test, their certifications, and for redacted CVs. "We will assign qualified staff" with no names is a red-flag answer.

  2. Get a redacted sample network report. Read it as an engineer would: is there an attack path narrative, or only a host-by-host list? Can you reproduce a finding from the evidence alone?

  3. Check the start position plan. Ask how many start positions are included on the internal test and what each one is. A single unauthenticated network drop is a thinner test than most buyers realise.

  4. Ask how Active Directory is handled. Enumeration with a graph tool is not the same as proving a path. Ask specifically about certificate services, delegation and tier boundaries.

  5. Confirm segmentation testing explicitly. In or out, from which side, and what statement you get in the report.

  6. Ask for the automated-to-manual split in writing, and which findings come from which side.

  7. Verify accreditations at the firm level. Firm-level accreditation such as CREST for a penetration testing service provider is a different thing from individual tester certifications. Both are worth having. Ask which one they mean and check the accrediting body's own register.

  8. Verify independent research output. Published CVEs, conference talks and disclosure history show a firm finds new things rather than re-running known checks. Stingrai's team holds 18 published CVEs and presents at DEFCON and BSIDES, listed on the about page.

  9. Settle authorization, data handling and retest before the technical evaluation. Who signs the authorization to test for each legal entity, where evidence lives, how long it is retained, what insurance is carried, and how many retests you get in what window.

For a scored version of this process, our pentest and red team RFP question bank provides 75 questions across seven weighted sections totalling 100 points, with documented red-flag answers.

Red flags in a network pentest proposal

  • A quote priced per IP address in the allocated range rather than per live host. It inflates the number and tells you the vendor has not looked.

  • No start position named on the internal test. The result depends on it entirely.

  • Segmentation testing absent from the scope on an engagement that claims to be PCI-ready.

  • Findings with tool names in the titles and no exploitation narrative. That is a scan with a cover page.

  • No attack path section in the sample report. Chained impact is the product.

  • Retests priced separately with no explanation. A fix you cannot verify is not a fix.

  • Wireless quoted remotely. Radio testing requires physical presence, so a remote wireless quote is testing something else.

  • Refusal to name who is testing. Every other answer depends on this one.

Where Stingrai fits

Stingrai is a Toronto-headquartered offensive security firm founded in 2021, with a London, UK office, a CREST-accredited penetration testing service provider at the firm level, holding 18 published CVEs across the research team and a 5.0/5.0 average across 19 Clutch reviews.

Signal

Detail

Headquarters

Toronto, Ontario, Canada, plus a London, UK office

Accreditation

Stingrai Inc is a CREST-accredited Penetration Testing service provider at the firm level, separate from the individual CREST CRT certifications held by team members

Team certifications

OSCE3, OSCP, OSWE, OSED, OSEP, CREST CRT, CISSP, CRTO, GCPN, CRTE, eWPTX

Network delivery

Network penetration testing is delivered by Stingrai's certified human pentest team. Snipe, Stingrai's autonomous agent, is a web application agent, so where an engagement also covers web applications and APIs, Snipe works that surface at the same time as the human testers work the network

Network scope covered

External perimeter, internal network with assumed-breach start positions, Active Directory and identity attack paths, wireless and segmentation validation

Engagement models

Annual one-time penetration tests and continuous testing programs, both available

Research output

18 published CVEs; research presented at DEFCON and BSIDES

Reputation

5.0/5.0 across 19 Clutch reviews

Published pricing

Fixed published tiers cover application scope: Autonomous Pentest (Snipe) from US$3,000 one-time or US$450 per month, and Hybrid Pentest with certified experts at US$6,800 one-time or US$1,275 per month on a twelve-month engagement. Network, social engineering and adversary simulation sit in the Enterprise tier and are scoped individually (pricing)

Compliance support

Penetration testing evidence supporting SOC 2, ISO 27001, HIPAA, PCI DSS 4.0, NIST SP 800-53 / 800-171, DORA and NIS2 programs

Best for

Enterprise-grade PTaaS powered by Snipe, its proprietary AI pentesting agent, working alongside certified human pentesters throughout every engagement (CREST-accredited firm), for one-time or continuous testing in highly regulated industries with SOC 2, ISO 27001, PCI DSS and CMMC compliance programs.

Not ideal for: buyers who need a dozen international sites tested simultaneously inside a two-week window, and buyers whose contract requires testers holding a specific national clearance. Confirm delivery-team restrictions in writing during scoping.

Start here: Get a Quote | Book a Free Scoping Call | Network Penetration Testing service page

Frequently Asked Questions

What is included in a network penetration testing service?

A network penetration testing service includes attack-surface discovery, exploitation of reachable services and appliances, and a written report with validated findings. Four distinct test types sit under the category: external testing against your internet-facing perimeter including edge appliances, VPN and remote access, mail and DNS; internal testing from inside the LAN covering credential relay, privilege escalation, Active Directory attack paths and lateral movement; wireless testing of your radio estate on site; and segmentation testing that proves out-of-scope networks cannot reach a protected zone. Deliverables normally include an executive summary, a scope and coverage statement, technical findings with reproduction evidence, an attack path narrative, segmentation results, a completion letter and a retest. Denial-of-service, destructive exploitation, physical entry, social engineering and third-party systems you do not own are typically excluded unless agreed in writing.

How much does a network penetration test cost in 2026?

A network penetration test in 2026 typically costs US$5,000 to US$40,000 and above, driven by live host count, subnet and VLAN count, Active Directory footprint, number of physical sites and how many start positions the engagement includes. PCI DSS engagements that bundle internal, external and segmentation testing commonly land at US$12,000 to US$25,000. Annual program spend across all testing types runs roughly US$8,000 to US$20,000 for small businesses, US$20,000 to US$50,000 for mid-market and US$50,000 to US$150,000 or more for enterprise. Stingrai scopes network engagements individually and publishes fixed application-testing tiers on its pricing page, from US$3,000 one-time or US$450 per month for an Autonomous Pentest and US$6,800 one-time or US$1,275 per month for a Hybrid Pentest with certified experts.

What is the difference between internal and external network penetration testing?

External network penetration testing starts from the public internet with no credentials and measures what an attacker reaches from outside: exposed services, edge and VPN appliances, mail and DNS, management planes and forgotten hosts. Internal network penetration testing starts inside the LAN, usually from an assumed-breach foothold such as a standard domain account or a network drop, and measures what happens after the perimeter fails: credential relay, privilege escalation, Active Directory attack paths, lateral movement and reachability of crown-jewel data. They test different control sets, so a clean external report predicts almost nothing about internal resilience. PCI DSS v4.0.1 requires both, internal under Requirement 11.4.2 and external under 11.4.3, at least every 12 months and after significant change.

What do external penetration testing services cover?

External penetration testing services cover every asset an unauthenticated attacker can reach from the internet against the address space and hostnames you own. That means attack-surface discovery across address blocks, domains, subdomains, cloud tenancies and certificate transparency records; edge and remote-access appliances including VPN concentrators, firewalls and gateways; exposed management planes such as administrative interfaces, hypervisor consoles and database ports; mail, DNS and transport posture including SPF, DKIM, DMARC and TLS configuration; and authentication surfaces tested for credential stuffing, missing multi-factor enforcement and account enumeration. Edge appliances deserve disproportionate attention: the Verizon 2026 DBIR found edge devices and VPNs jumped from 3% to 22% of exploitation-driven breaches in a single year.

What do internal network penetration testing services cover?

Internal network penetration testing services cover what an attacker achieves once inside your network. Scope includes enumeration of live hosts, services, shares, hypervisors, backup infrastructure and network devices across in-scope subnets and VLANs; credential capture and relay including broadcast name resolution poisoning, SMB signing posture and NTLM relay paths; Active Directory attack paths spanning Kerberos abuse, delegation misconfiguration, certificate services templates, ACL chains and service account exposure; local privilege escalation on hosts; lateral movement and whether containment controls actually stop it; and reachability of crown-jewel systems and data from the agreed start position. The start position matters more than any other variable, because a test beginning from an unauthenticated network drop measures network controls while one beginning from a standard domain account measures identity controls.

How do I choose a network penetration testing company?

Choose by verification rather than by marketing claims, because the claims are close to uniform. Ask who specifically will test and for their certifications and redacted CVs. Request a redacted sample network report and check whether it contains an attack path narrative rather than a host-by-host list, and whether you could reproduce a finding from the evidence alone. Confirm how many start positions the internal test includes, how Active Directory is handled beyond graph enumeration, and whether segmentation testing is explicitly in scope. Get the automated-to-manual split in writing. Verify firm-level accreditation such as CREST for a penetration testing service provider against the accrediting body's own register, which is a different thing from individual tester certifications. Check for published CVEs and conference research. Settle authorization, data handling, insurance and the retest window before the technical evaluation.

What network penetration testing methodology should a provider follow?

A credible provider names its methodology by standard and version rather than describing "industry best practice". NIST SP 800-115, the technical guide to information security testing, provides the four-phase structure of planning, discovery, attack and reporting that most network engagements follow. The Penetration Testing Execution Standard adds seven phases covering pre-engagement, intelligence gathering, threat modelling, vulnerability analysis, exploitation, post-exploitation and reporting. OSSTMM is useful where wireless and telecommunications surfaces sit alongside the wired estate. MITRE ATT&CK gives findings and attack chains a shared technique vocabulary your detection team can map coverage against. If PCI DSS applies, a documented penetration testing methodology is itself Requirement 11.4.1, so ask to see the provider's document rather than a description of it.

Does PCI DSS require internal, external and segmentation penetration testing?

Yes. PCI DSS v4.0.1 Requirement 11.4 requires a documented penetration testing methodology (11.4.1), internal penetration testing (11.4.2) and external penetration testing (11.4.3), both at least every 12 months and after any significant infrastructure or application change, correction of exploitable vulnerabilities with testing repeated to confirm the fix (11.4.4), and segmentation validation testing where segmentation is used to isolate the cardholder data environment (11.4.5), performed at least every 12 months and after any change to segmentation controls. Service providers must perform segmentation testing every six months under 11.4.6. Separately, Requirement 11.2.1 obliges in-scope entities to test for wireless access points and identify authorized and unauthorized ones at least once every three months, including where policy prohibits wireless entirely.

How long does a network penetration test take?

Elapsed time runs longer than tester days because authorization, access provisioning, scheduling and report review take real calendar time. As a planning shape, an external-only test of a single entity with fewer than 50 live hosts takes 3 to 5 tester days across one to two weeks. External plus internal on a single site and single domain takes one to two tester weeks across two to four weeks. Internal testing across multiple sites and a multi-domain forest runs four to eight weeks. A PCI scope bundling internal, external and segmentation validation typically runs three to six weeks. Each additional physical site for wireless adds one to two tester days plus travel and scheduling. Continuous programs replace the single window entirely, delivering findings as they are confirmed.


Ready to scope your network pentest?

Send us your CIDR ranges, your domain and site count, and the start positions you want tested, and we will come back with tester days and a fixed price rather than a discovery call. Network engagements are delivered by Stingrai's certified human pentest team and available as a one-time annual engagement or as a continuous program.

0 views

0

X

Related reading

Active Directory Penetration Testing Services (2026): Scope, Attack Paths and Cost
Network Security

Active Directory Penetration Testing Services (2026): Scope, Attack Paths and Cost

What an Active Directory penetration testing service covers, assumed-breach starting positions, four delivery models compared, 2026 pricing and timelines.

17 min read

Cloud Penetration Testing Services (2026): AWS, Azure and GCP Buyer's Guide
Network SecurityWeb App Security

Cloud Penetration Testing Services (2026): AWS, Azure and GCP Buyer's Guide

Cloud penetration testing services in 2026: what a cloud pentest covers, AWS, Azure and GCP testing rules, real cost ranges, and how to choose a provider.

17 min read

Red Team Services (2026): What They Include, Who to Hire and What They Cost
Network SecuritySocial Engineering

Red Team Services (2026): What They Include, Who to Hire and What They Cost

What red team services include, five delivery models compared fairly, 2026 pricing and timelines, and an eight-step check for choosing a red team provider.

19 min read

Contents

X