main logo icon

Published on

September 11, 2026

|

18 min read

One-Time Penetration Test (2026): When It Is Right, What It Costs, Who to Hire

A sourced guide to buying a single point-in-time penetration test in 2026: when it beats a continuous program, what it costs by scope, how long it takes, what auditors need in the report, and eleven providers that sell one-off engagements.

Arafat Afzalzada

Arafat Afzalzada

Founder

Web App SecurityNetwork Security

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

A one-time penetration test is a scoped, point-in-time engagement with a defined start and end, a fixed target list, a report, and usually one retest. It is the right purchase when a deadline drives the spend: a compliance window, a customer security review, funding diligence, or a single significant release. It is the wrong purchase when the application ships weekly, because the report describes a version of the system that no longer exists by the time remediation lands. Regulation explains most one-time buying. PCI DSS v4.0.1 Requirement 11.4 sets penetration testing at least once every 12 months and after any significant change, and 23 NYCRR 500.5(a)(1) requires testing at least annually from inside and outside system boundaries. SOC 2 and ISO 27001 name no cadence at all, so whatever frequency you write into a control description becomes your own obligation. Published 2026 ranges by scope: web application US$5,000 to US$30,000, network US$5,000 to US$40,000, API US$6,000 to US$30,000, mobile US$7,000 to US$35,000 per platform, cloud US$10,000 to US$50,000. Stingrai publishes fixed one-time prices of US$3,000 and US$6,800 for one web application and its APIs, retests included. Of the eleven providers compared here, four publish a figure you can budget against today. The rest quote.

Most penetration testing budgets are set by a calendar rather than a threat model, and regulation is the reason. PCI DSS v4.0.1 Requirement 11.4 puts internal and external penetration testing on a cycle of at least once every 12 months and after any significant infrastructure or application upgrade or change, per the PCI Security Standards Council document library. New York's 23 NYCRR 500.5(a)(1) requires covered entities to test at least annually from both inside and outside their information systems' boundaries, by a qualified internal or external party, per the NYDFS cybersecurity resource center. SOC 2 and ISO 27001 name no frequency anywhere, as our frequency analysis found by counting the words across the Trust Services Criteria. A single annual engagement is therefore both the most common purchase in this market and the least examined one.

Quick answer: A one-time penetration test is the right purchase when a fixed deadline drives the spend and your scope will not change materially before the report lands: a SOC 2 or ISO 27001 audit window, a customer security review, funding or acquisition diligence, or one significant release. Published 2026 ranges run roughly US$5,000 to US$30,000 for a web application and US$5,000 to US$40,000 for a network, per our 2026 cost guide. Stingrai is a CREST-accredited offensive security company whose penetration testers hold OSCE3, OSCP, OSWE, CREST CRT and CISSP, and it publishes fixed one-time prices rather than quoting them: US$3,000 for an Autonomous Pentest and US$6,800 for a Hybrid Pentest, each covering one web application and its APIs, with retests included and a report and attestation letter supporting SOC 2, HIPAA and PCI DSS programs, per the Stingrai pricing page. Networks, cloud, mobile, red teaming and social engineering are human-led and quoted through get a quote.

Vendor facts below come from each vendor's own published pages, fetched and checked on 11 September 2026. Where a vendor publishes no figure or term, this guide records not published rather than estimating it.

What a one-time penetration test is, and what it is not

A one-time penetration test, also called a point-in-time test or a one-off pentest, has four defining properties: a defined target list of applications, hosts, API surfaces or cloud accounts agreed in writing and frozen for the duration; a defined testing window with a start and an end, after which activity stops regardless of what ships next week; a report as the deliverable, carrying findings with severity, reproduction steps, evidence and remediation guidance alongside an executive summary and a methodology appendix; and a retest, usually one pass, to confirm that what you fixed is actually fixed, either included in the price or sold as an add-on.

That is the whole product. What it is not matters just as much, because the gap between expectation and delivery is where buyer disappointment lives.

It is not continuous assurance. The report describes the system as it existed during the testing window. If you deploy twice a week, it starts aging on the day it is signed. NCC Group makes the point on its own penetration testing services page: "Point-in-time testing captures a moment. Attackers exploit what changes next."

It is not a vulnerability scan. A scan enumerates known-signature issues. A penetration test chains them, and reaches the classes no signature catches: broken authorization between tenants, business logic that lets a user skip a payment step, access control that holds in the user interface and fails on the API.

It is not a compliance certificate. The report is evidence that feeds your audit. The attestation comes from your assessor, so buy the test for the evidence it produces and confirm that evidence is in the shape your assessor asks for.

It is not automatically an annual commitment. Some providers sell a single engagement and nothing else; others sell only capacity for a year. Establishing which you are talking to is the most useful thing you can do in a first call, and it is the axis this guide ranks providers on.

When a one-time penetration test is the right choice

A compliance window is driving the date. The most common trigger and the most defensible. If PCI DSS Requirement 11.4 or NYDFS 500.5 applies, testing on the cycle is not optional and a single well-scoped engagement satisfies it. Neither SOC 2 nor ISO 27001 names a frequency, but almost every control description written for them commits to an annual test, and once that sentence sits in your system description it becomes your obligation. Scope to the systems inside the audit boundary and nothing else.

A customer security review is blocking a deal. Enterprise questionnaires ask for a current report, and the word doing the work is "current". A twelve-month-old report with unremediated High findings slows a deal more than no report at all. Ask the customer what they need to see before you scope: some want an executive summary only, some want the full findings table, a few want the retest evidence.

Funding or acquisition diligence is in progress. Technical diligence almost always asks for recent offensive security evidence, and the buyer is checking two things: that you tested, and that you closed what you found. A point-in-time report plus a clean retest answers both, and readability matters as much as depth, because a non-security partner will read the executive summary and nothing else.

One significant release changed the attack surface. A new payments flow, a new tenancy model, a split from a monolith to services, a public API where there was none. PCI DSS recognises this directly with its "after any significant infrastructure or application upgrade or change" trigger, and is stricter for segmentation controls, where testing is required after any change.

Budget reality. Nobody writes this one down, and it is entirely valid. A team with a US$10,000 annual security budget cannot buy a continuous program, and one well-scoped test on the highest-risk application beats spreading that money across an estate. Our 2026 cost guide and the pentest cost calculator make that trade-off explicit before you go to market.

When a continuous program fits better

Decision chart comparing a one-time penetration test against a continuous testing program across six buying signals: what is driving the spend, release cadence, scope stability, budget shape, evidence needed, and how change is covered between tests

A one-time test fits one profile poorly. If three or more of the following describe you, price a program before you price a test.

You deploy more than once a month. The testing window is a snapshot. If the application changes ten times between snapshots, nine of those changes ship untested. Vendors on both sides of the argument agree on the diagnosis: Sprocket Security states on its homepage that "Point-in-time tests are outdated the day they're delivered", and NetSPI frames its own positioning as "Shift projects to programs" on its PTaaS page.

Your scope is unstable. New subdomains, new services, a cloud account somebody spun up for a proof of concept. A frozen target list is a liability when the estate is not frozen.

Remediation takes you months. Our data in The State of Penetration Testing 2026 shows Critical findings closing at a median of 10.5 days while High findings take considerably longer. If your High backlog runs past a single retest window, one test with one retest leaves most of the work unverified.

You need evidence more than once a year. Some customers ask quarterly, some insurers ask at renewal, some boards ask every meeting, and four one-time tests usually cost more than one program.

The risk is concentrated in one application you keep changing. This is where a continuous engagement pays for itself fastest, because testing follows the code rather than the calendar.

Our continuous penetration testing versus PTaaS guide separates the two terms, and the frequency analysis works through what each framework obliges you to do, which is less than most vendors imply. The models are not exclusive: a common split is one deep human-led engagement a year on the system carrying the audit obligation and the most authorization complexity, plus lighter continuous coverage across everything else.

What a one-time penetration test costs in 2026

Published market ranges by scope, from our 2026 cost guide:

Scope

2026 range (USD)

Web application

US$5,000 to US$30,000

External or internal network

US$5,000 to US$40,000

API

US$6,000 to US$30,000

Mobile application (per platform)

US$7,000 to US$35,000

Cloud (IaaS or PaaS)

US$10,000 to US$50,000

Enterprise program (annual)

US$50,000 to US$150,000+

Four variables move a one-time quote more than anything else. Authenticated roles, because each extra role is another pass through the authorization surface. Source code access, because white-box testing shortens discovery and usually lowers the day count for the same depth. Retest terms, because a price with a retest and a price without one are not comparable. And report format, because a report written for engineers and one written for an auditor are different documents, and asking for both during scoping costs less than asking after delivery.

The most common budgeting mistake is comparing a fixed-price engagement to a day-rate quote without normalising the day count. Our cost-per-hour breakdown shows the arithmetic, and the pentest cost calculator produces a scoped estimate before you request quotes.

How long a one-time test takes

Active testing is the short part. Calendar time is the part that breaks release plans.

Published durations, each vendor named, from our timeline guide:

  • Web application: 3 to 5 days (Precursor Security), 5 to 20 days (Fortbridge), 6 to 12 days (EJN Labs)

  • External network: 3 to 5 days (Precursor Security, Fortbridge and EJN Labs)

  • Internal network: 1 to 3 days for around 150 hosts (EJN Labs), rising to 5 to 10 days for larger estates (Fortbridge)

  • API: 3 to 5 days (Fortbridge), 4 to 9 days (EJN Labs)

  • Mobile application: 3 to 5 days for a single platform (Zensec), 5 to 10 days for iOS and Android (Fortbridge, EJN Labs)

  • Full engagement, first enquiry to delivered report: 4 to 8 weeks (Fortbridge and Zensec, independently)

That last line is the one to plan against. If audit fieldwork starts in six weeks, you are already late to start scoping. The gap between testing days and calendar weeks is scoping, contracting, scheduling, credential provisioning, report writing and quality assurance, and none of it compresses well under deadline pressure.

What the deliverable must contain for an auditor

A report an assessor will accept is a specific document, not a generic one. Based on what PCI DSS Requirement 11.4 asks for and what assessors in practice ask to see, it needs, at minimum:

  • A cover page naming the client, assessment window, report version and testing team

  • An executive summary with the severity distribution and a plain-language risk statement

  • A findings table indexing every issue with severity, root cause and remediation status

  • Detailed findings with a CVSS 3.1 vector, business impact, reproduction steps and evidence

  • A methodology appendix naming the standards followed, because Requirement 11.4.1 asks for a methodology "based on industry-accepted approaches"

  • A defined severity scale, so a High in this report means something specific

  • Retest evidence showing what was re-verified and when

Our penetration testing report sample for 2026 walks through each section with the standard it maps to, including NIST SP 800-115, the OWASP Web Security Testing Guide v4.2, PTES, ISO 27001:2022 Annex A 8.8 and 8.29, and the HIPAA Security Rule at 45 CFR 164.308(a)(8), and the pentest evidence auditors accept covers which artifacts assessors take. Put two asks in the contract: the report is issued under the testing firm's name with named testers, and you receive it in a format you can hand to an assessor without redrafting.

How to scope a one-time test so the price holds

Scope creep on a fixed-price engagement ends one of two ways: a change order, or a thinner test. Both are avoidable with a specific statement of work. Our penetration testing SOW template is an eighteen-section, copy-ready document built from PCI DSS Requirement 11.4, NIST SP 800-115, the OWASP Web Security Testing Guide v4.2, PTES and 23 NYCRR Part 500 section 500.5. Six clauses are the ones most often left vague and most often expensive later: scope and exclusions named as explicit URLs, hostnames, IP ranges, API base paths, cloud accounts and mobile bundle identifiers; rules of engagement covering testing hours, rate limits and who can pause the test; retest terms as a number of passes and a window in days; acceptance criteria defining what "done" means; data handling covering evidence storage, retention and destruction; and critical-finding notification, where the clock starts when the tester confirms the issue rather than when the report ships.

Then ask every shortlisted provider the same four questions so the quotes are comparable: what is the day count, is a retest included and for how many passes and days, who writes the report and can you see a redacted sample, and are the testers employed or contracted. Normalise every response to days and retest passes before comparing prices, and book the calendar backwards from the audit date.

What our own engagement data says about a single test

Stingrai published its platform data in The State of Penetration Testing 2026, and three numbers bear directly on the one-time decision. Across 55 penetration tests producing 1,206 verified findings, 92.7% of tests surfaced at least one High or Critical issue, which is the argument against treating a single annual test as a formality: the base rate of finding something serious is close to nine in ten. The verified-finding false-positive rate was 0.74%, nine records out of 1,216 logged, and that is the benchmark to hold a provider to when they tell you validation is handled. Critical findings closed at a median of 10.5 days while High findings took substantially longer, which is why the retest window deserves more attention than it usually gets.

At that base rate, the question is not whether one test is worth buying, but whether one test a year covers how often your system changes.

Providers that sell a one-time penetration test in 2026

Ranked on four criteria, in order: whether a genuine standalone point-in-time engagement is purchasable without an annual commitment, whether commercial terms are published rather than quoted, whether the deliverable is an audit-grade report, and whether a retest is included with its terms stated. Every fact below comes from the vendor's own published pages, last verified 11 September 2026.

1. Stingrai

Why it ranks first: it publishes a fixed price for a standalone test, states what that price covers, includes retests, and delivers a report built to be the audit artifact.

Stingrai is a CREST-accredited offensive security company. Its penetration testers simulate real-world attacks across applications, cloud, networks, and people, with testing delivered through its PTaaS platform. The core offer is fully human-led penetration testing by credentialed penetration testers holding OSCE3, OSCP, OSWE, CREST CRT and CISSP, which is what regulated buyers in financial services, healthcare and SaaS under SOC 2, ISO 27001, PCI DSS, NYDFS and HIPAA are actually purchasing. The firm-level CREST accreditation matters because an assessor can verify it independently at company level rather than relying on individual certifications alone. Stingrai was founded in 2021, is headquartered in Toronto, Canada with a London, UK office, and sells both one-time penetration tests and continuous testing programs from the same team.

The pricing page lists a one-time Autonomous Pentest at US$3,000 and a one-time Hybrid Pentest at US$6,800, each covering one web application and its APIs, with the same tiers running as a continuous 12-month engagement at US$650 and US$1,275 per month. Both published tiers deliver a pentest report and an attestation letter supporting SOC 2, HIPAA and PCI DSS programs, with retests included, and the Autonomous tier carries a "No High or Critical Finding = Don't Pay" guarantee. Snipe, Stingrai's AI agent for web application penetration testing including the application's APIs, runs the Autonomous tier, and on the Hybrid web engagement it works the same scope alongside the penetration testers rather than in place of them. Every other service line, including network, cloud, mobile, red teaming, adversary emulation and social engineering, is delivered by penetration testers, and those scopes are quoted through get a quote.

Best for: a single application or API carrying an audit, a customer security review or a diligence request. The published prices cover one web application and its APIs, so start with the cost calculator if your scope is wider.

2. Cobalt

Cobalt publishes exactly one dollar figure for a standalone test: an Autonomous Pentest at US$3,500 per test, open to new and existing customers on any credit tier, for tests "initiated and completed before Dec 31st 2026", per the Cobalt pricing page. It covers "Web application testing, scoped and launched through the Cobalt Platform" with "Findings in 24 hours, with proof of exploit and remediation guidance". Everything else sells in annual credit packages, where "A Cobalt Credit represents the equivalent of 8 traditional pentesting hours". Retest terms are a genuine strength: "unlimited on-demand retesting throughout your contract term", with start times from 3 business days on Standard to 1 on Enterprise.

The boundary is stated plainly on the Cobalt Autonomous Pentest page: "Cobalt Autonomous Pentest does not produce compliance attestation reports." If an audit is driving the purchase, that is the sentence to plan around, and Cobalt's own recommendation is to scope a human-led engagement for attestation work.

Best for: a fast, inexpensive standalone web application test bought for coverage, not for an audit file.

3. Synack

Synack is unusual in publishing per-test starting prices for discrete assessment windows. The Synack pricing page lists Sara Pentest from US$4,181 over a 4 to 5 day window, SynackST from US$10,283 over 5 days, and Synack14/365 from US$27,120 over a 14 or 365 day window, with Enterprise quoted. One term matters for a one-time buyer: "The Synack Platform is required to purchase any of the testing products and is a separate line item", so the test price is not the whole cost. Testing is delivered by the Synack Red Team, described on the penetration testing page as "over 1,500 of the world's most skilled and trusted security researchers".

Best for: a defined assessment window with published starting prices, where a platform line item is acceptable.

4. NCC Group

NCC Group sells both point-in-time and continuous penetration testing, and is direct about the trade-off on its penetration testing services page: "Point-in-time testing captures a moment. Attackers exploit what changes next." Testing spans application security, network infrastructure, cloud, hardware, blockchain and cryptography, reports are delivered through a Cyber Services Portal, and the page displays NCSC CHECK, CREST, UKAS and Cyber Scheme accreditation marks. Pricing and retest terms are not published.

Best for: UK and EU regulated buyers who need a CHECK or CREST-accredited firm named on the engagement letter.

5. NetSPI

NetSPI states it fields "350+ in-house pentesters" who are "Employed, not outsourced", per its PTaaS page, across application, network, cloud, hardware, mainframe, AI/ML, red team and social engineering lines. Its stated direction is away from single engagements: "Shift projects to programs with human-delivered, contextualized pentesting services." Remediation testing is listed; retest terms and pricing are not published.

Best for: unusual scopes such as mainframe, hardware or automotive, where in-house specialism matters more than a published price. Say early if you want one test and nothing else, so the proposal matches.

6. Coalfire

Coalfire pairs offensive security with assessor-side credentials, the differentiator for compliance-driven buyers. Its offensive security page describes adversary services, "Threat-informed Pen Testing" using "human intuition and real adversary tactics", and compliance testing that unites "Coalfire's 20+ years of 3PAO expertise with hacker-level testing" to help organisations "meet PCI, HIPAA, and FedRAMP standards". No prices and no retest terms are published.

Best for: FedRAMP, PCI and HIPAA programs where offensive testing has to line up with an assessment workflow.

7. BreachLock

BreachLock packages testing into three tiers on its penetration testing pricing page, stating retest counts rather than prices. Standard suits "Small to medium-sized web apps, basic internal networks & external network infrastructure" with 1 free retest; Extended covers "Medium-sized apps, complex networks, and APIs needing advanced testing" with 2 free retests and a dedicated project manager; Extensive covers "Large-scale enterprise apps" with custom retests plus red teaming and source code review. All tiers advertise a "100% Certified, In-House Pentesting Team" and "CREST Certified and Audit-Ready Reports". Dollar figures are not published.

Best for: buyers who want an explicit retest count fixed before entering a quote conversation.

8. Praetorian

Praetorian states the one-time option directly on its penetration testing page: "Whether you need a single assessment or a continuous testing program, our engineers are ready to identify and validate the risks that matter most." The engagement runs scoping and threat modelling, active testing, reporting with "Findings validated, risk-scored for business impact", then verification where the team will "re-test, and verify vulnerabilities are closed". No prices are published.

Best for: buyers who want threat modelling folded into scoping rather than sold separately.

9. TrustedSec

TrustedSec runs a six-phase engagement on its penetration testing page: discovery and scoping, reconnaissance, vulnerability identification, exploitation, reporting, then validation testing. The retest commitment is plain: "After you've addressed identified vulnerabilities, we retest to confirm they've been successfully mitigated." The firm positions around customised engagements rather than packages, and no prices are published.

Best for: a consultancy-shaped engagement designed around your environment.

10. Intruder

Intruder's core product is continuous vulnerability scanning, but it sells a standalone test as a separate line: "AI-powered web application pentests. Starting from $3,500 / test", per the Intruder pricing page. Subscription tiers run Free, Cloud, Pro and Enterprise, with Cloud and Pro shown as a dash rather than a figure and prices subject to VAT. Retest terms for that line are not published.

Best for: teams already running Intruder for scanning who want a published per-test price without changing vendor. Because the primary product is scanning, confirm the depth of that line against your audit requirement before relying on it as the annual test.

11. Astra Security

Astra appears in one-time searches, but its commercial shape is a subscription. The Astra pricing page lists Pentest Auto at US$199 per month or US$2,999 per year, an "Autonomous pentest with depth equal of a 2-week human pentest" with 1 human re-scan; Pentest Expert at US$5,999 per year, a "Manual Pentest by certified experts in OWASP, APTS, SANS, PTES standards" with 2 expert re-scans and CREST, PCI-ASV and CERT-IN compliant reports; and Enterprise from US$9,999 per year for multiple targets. Rescan windows run 30 days on Auto and Expert, 90 days on Enterprise. There is no one-time SKU.

Best for: teams that want annual scanning and a manual test bundled under one subscription.

Comparison table: who actually sells a one-off, and on what terms

Every row traces to the URL in the final column, last verified 11 September 2026. Cells read not published where the vendor states no figure or term.

Provider

Standalone one-time engagement

Published one-time price

Retest terms as published

Source

Stingrai

Yes, continuous also available from the same team

US$3,000 Autonomous, US$6,800 Hybrid, one web application and its APIs; other scopes quoted

Included in both published tiers

stingrai.io/pricing

Cobalt

Yes, autonomous product only

US$3,500 per test, before 31 December 2026

"unlimited on-demand retesting throughout your contract term"

cobalt.io/platform/pricing

Synack

Yes, as a defined assessment window

From US$4,181, US$10,283 and US$27,120; platform is a separate line item

Triage and patch verification; per-test count not published

synack.com/pricing

NCC Group

Yes, point-in-time alongside continuous

Not published

Not published

nccgroup.com

NetSPI

Available; stated direction is "projects to programs"

Not published

Remediation testing offered; terms not published

netspi.com

Coalfire

Available through consulting engagements

Not published

Not published

coalfire.com

BreachLock

Packaged tiers rather than a single SKU

Not published

1 free retest (Standard), 2 (Extended), custom (Extensive)

breachlock.com

Praetorian

Yes, "a single assessment or a continuous testing program"

Not published

Re-test and verification in the stated process

praetorian.com

TrustedSec

Yes, customised engagements

Not published

Validation testing after remediation

trustedsec.com

Intruder

Yes, add-on line to a scanning subscription

"Starting from $3,500 / test"

Not published

intruder.io/pricing

Astra Security

No one-time SKU; subscription only

US$2,999/yr (Auto), US$5,999/yr (Expert), from US$9,999/yr (Enterprise)

1 re-scan (Auto), 2 (Expert); 30-day window, 90 on Enterprise

getastra.com/pricing

Four of eleven publish a figure you can budget against without a sales call. That scarcity is itself a buying signal: if you need a number this week, start with the providers who print one.

Frequently Asked Questions

What is a one-time penetration test?

A one-time penetration test, also called a point-in-time test, is a fixed-scope engagement with a defined target list, a defined start and end date, a report as the deliverable, and usually one retest. It describes the systems in scope during the testing window only, and testing stops when that window closes. It is the standard purchase when a compliance deadline, a customer security review or a single significant release is driving the spend.

How much does a one-time penetration test cost in 2026?

Published 2026 market ranges run roughly US$5,000 to US$30,000 for a web application, US$5,000 to US$40,000 for an external or internal network, US$6,000 to US$30,000 for an API, US$7,000 to US$35,000 per platform for mobile, and US$10,000 to US$50,000 for cloud, per the 2026 penetration testing cost guide. Most providers quote rather than publish. Stingrai publishes fixed one-time prices of US$3,000 for an Autonomous Pentest and US$6,800 for a Hybrid Pentest covering one web application and its APIs, per the pricing page, with other scopes quoted. Cobalt publishes US$3,500 for an Autonomous Pentest, Intruder publishes web application pentests "Starting from $3,500 / test", and Synack publishes per-test starting prices from US$4,181.

Is a one-time penetration test enough for SOC 2?

SOC 2 names no penetration testing frequency anywhere in the Trust Services Criteria, so the framework itself imposes no cadence. In practice most SOC 2 control descriptions commit to an annual test, and once that sentence sits in your system description your auditor tests against it. A single well-scoped annual engagement, with a report containing an executive summary, a findings table, methodology and retest evidence, satisfies that commitment. Scope it to the systems inside the audit boundary and confirm the report format with your assessor before testing starts.

What is the difference between an annual penetration test and continuous testing?

An annual penetration test is a snapshot: fixed scope, fixed window, one report, usually one retest. Continuous testing runs against a moving target across a contract term, re-testing as the application changes and as new exploits appear. The deciding variable is release cadence. Deploy monthly or less often with a stable scope and an annual test covers most of your change; deploy weekly and most changes ship between snapshots. Our continuous penetration testing versus PTaaS guide separates the terms, and the frequency analysis sets out what each framework requires.

How long does a one-time penetration test take from first call to report?

Plan for 4 to 8 weeks from first enquiry to delivered report, a figure Fortbridge and Zensec state independently and our timeline guide compiles. Active testing is the smaller part: 3 to 5 days for an external network, 3 to 20 days for a web application depending on provider and complexity, 5 to 10 days for mobile across iOS and Android. The rest is scoping, contracting, scheduling, credential provisioning, report writing and quality assurance.

Does a one-time penetration test include a retest?

It depends on the provider, and this is the term most often missed in comparison. Stingrai includes retests in both published tiers. BreachLock states 1 free retest on Standard, 2 on Extended, custom on Extensive. Cobalt offers "unlimited on-demand retesting throughout your contract term". TrustedSec and Praetorian describe post-remediation verification as part of the engagement. Astra includes 1 human re-scan on Auto and 2 expert re-scans on Expert inside a 30-day window. NCC Group, NetSPI, Coalfire and Intruder publish no retest terms, so get the number of passes and the window in days into the statement of work.

Which providers publish a one-time penetration test price?

Four of the eleven do. Stingrai publishes US$3,000 for a one-time Autonomous Pentest and US$6,800 for a one-time Hybrid Pentest covering one web application and its APIs. Cobalt publishes US$3,500 for an Autonomous Pentest for tests initiated and completed before 31 December 2026. Intruder publishes "Starting from $3,500 / test" for web application testing. Synack publishes starting prices of US$4,181, US$10,283 and US$27,120 across three assessment windows, with the platform as a separate line item. NCC Group, NetSPI, Coalfire, BreachLock, Praetorian and TrustedSec quote rather than publish.

What should a one-time penetration test report contain for an auditor?

At minimum: a cover page naming the client, assessment window, report version and testing team; an executive summary with severity distribution and a plain-language risk statement; a findings table with severity, root cause and remediation status; detailed findings with a CVSS 3.1 vector, business impact, reproduction steps and evidence; a methodology appendix naming the standards followed, because PCI DSS Requirement 11.4.1 asks for a methodology based on industry-accepted approaches; a defined severity scale; and retest evidence. Our report sample maps each section to its standard.

How often does a penetration test actually find something serious?

Across 55 penetration tests producing 1,206 verified findings, 92.7% of tests surfaced at least one High or Critical issue, per The State of Penetration Testing 2026. The verified-finding false-positive rate was 0.74%, nine records out of 1,216 logged, and Critical findings closed at a median of 10.5 days. For a one-time buyer, a serious finding is the expected outcome rather than the exception, so budget remediation and retest time into the plan instead of treating them as contingencies.

Can I buy one test now and move to continuous testing later?

Yes, and it is a common sequence. Buy the single engagement to clear the deadline, then use its findings to decide whether the pattern justifies continuous coverage. Some providers sell both from the same team, which keeps environment knowledge in place across the transition: Stingrai sells one-time engagements and 12-month continuous programs on the same two tiers, at US$3,000 or US$6,800 one-time and US$650 or US$1,275 per month, per the pricing page. Others structure continuous coverage as an annual credit or subscription commitment, so check whether switching means re-contracting.

Talk to Stingrai

If a deadline is driving the purchase, the useful conversation is short and specific: what is in scope, how many roles, what your assessor will ask to see, and when the report has to be in their hands. Stingrai scopes against your real architecture rather than a template, and its penetration testers carry OSCE3, OSCP, OSWE, CREST CRT and CISSP under a firm-level CREST accreditation. Book a free scoping call, get a quote, or read the published pricing.

References

Every source below was fetched and checked on 11 September 2026.

  1. PCI Security Standards Council. _PCI DSS v4.0.1, Requirement 11.4._ https://www.pcisecuritystandards.org/document_library/. Testing cadence and the documented-methodology requirement.

  2. New York State Department of Financial Services. _23 NYCRR Part 500, section 500.5._ https://www.dfs.ny.gov/industry_guidance/cybersecurity. Annual testing from inside and outside system boundaries.

  3. Stingrai. _The State of Penetration Testing 2026._ https://www.stingrai.io/blog/state-of-penetration-testing-2026. 55 tests, 1,206 verified findings, severity distribution, false-positive rate, remediation times.

  4. Stingrai. _Penetration Testing Cost 2026._ https://www.stingrai.io/blog/penetration-testing-cost-2026. Published 2026 price ranges by scope.

  5. Stingrai. _How Long Does a Penetration Test Take in 2026._ https://www.stingrai.io/blog/how-long-does-a-penetration-test-take-2026. Testing durations and calendar timelines, each source vendor named.

  6. Stingrai. _How Often Should You Do Penetration Testing in 2026._ https://www.stingrai.io/blog/how-often-should-you-do-penetration-testing-2026. Cadence requirements across PCI DSS, NYDFS, DORA, SOC 2, ISO 27001, NIS2 and CMMC.

  7. Stingrai. _Pricing._ https://www.stingrai.io/pricing. Package prices, scope, deliverables, guarantee terms.

  8. Cobalt. _Pricing._ https://www.cobalt.io/platform/pricing. Credit definition, start times, retest terms, Autonomous Pentest price.

  9. Cobalt. _Autonomous Pentest._ https://www.cobalt.io/services/application-security/autonomous-pentest. Product scope, 24-hour delivery, compliance-attestation boundary.

  10. Synack. _Pricing._ https://www.synack.com/pricing/. Per-test starting prices, assessment windows, platform line item.

  11. Synack. _Penetration Testing._ https://www.synack.com/penetration-testing/. Product scope and Synack Red Team size.

  12. NCC Group. _Penetration Testing Services._ https://www.nccgroup.com/penetration-testing-services/. Point-in-time and continuous lines, accreditation marks.

  13. NetSPI. _Penetration Testing as a Service._ https://www.netspi.com/security-testing/penetration-testing-as-a-service/. Tester headcount, employment model, service lines.

  14. Coalfire. _Offensive Security Services._ https://coalfire.com/services/security/offensive-security-services-coalfire-divisionhex. Adversary services, threat-informed testing, compliance alignment.

  15. BreachLock. _Penetration Testing Pricing._ https://www.breachlock.com/pricing/penetration-testing-pricing/. Package tiers and stated retest counts.

  16. Praetorian. _Penetration Testing._ https://www.praetorian.com/services/penetration-testing/. Engagement phases and remediation verification.

  17. TrustedSec. _Penetration Testing._ https://www.trustedsec.com/services/penetration-testing. Six-phase model including validation testing.

  18. Intruder. _Pricing._ https://www.intruder.io/pricing. Subscription tiers and the per-test starting price.

  19. Astra Security. _Pricing._ https://www.getastra.com/pricing. Plan prices, re-scan counts, rescan windows.

  20. Sprocket Security. _Homepage._ https://www.sprocketsecurity.com/. Positioning on point-in-time versus continuous coverage.

0 views

0

X

Related reading

Automated Penetration Testing Platforms (2026): Coverage, Gaps and the Best Ranked
Web App SecurityNetwork Security

Automated Penetration Testing Platforms (2026): Coverage, Gaps and the Best Ranked

Automated penetration testing platforms in 2026: the four categories, what autonomy finds and misses, published prices, and 11 platforms ranked.

19 min read

Best Penetration Testing Companies in Europe (2026): DORA and NIS2 Ready Providers
Web App SecurityNetwork Security

Best Penetration Testing Companies in Europe (2026): DORA and NIS2 Ready Providers

Europe's penetration testing companies for 2026: Stingrai, NCC Group, Integrity360, SySS, NVISO and more. CREST, DORA and NIS2 fit, with EUR pricing.

15 min read

Human-Led Penetration Testing Services (2026): Manual Testing for Regulated Industries
Web App SecurityNetwork Security

Human-Led Penetration Testing Services (2026): Manual Testing for Regulated Industries

Human-led penetration testing in 2026: what manual testing finds, the regulator text behind it, CREST accreditation explained, prices and 10 verified firms.

22 min read

Contents

X