main logo icon

Published on

September 5, 2026

|

17 min read

PTaaS Pricing Compared (2026): Published Prices, Credit Models and What You Actually Get

Every penetration testing as a service vendor that publishes a price on its own site, verified 5 September 2026, with the unit each price is attached to, what the subscription includes, and the 12-month cost of covering one web application.

Arafat Afzalzada

Arafat Afzalzada

Founder

Web App SecurityNetwork Security

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

Ten penetration testing as a service vendors were checked on 5 September 2026 for a price published on their own site. Five publish a number: Astra (Pentest Auto at US$2,999 a year for one target, Pentest Expert at US$5,999 a year, Enterprise from US$9,999 a year), Cobalt (Autonomous Pentest at US$3,500 per test, a promotional rate that must be initiated and completed before 31 December 2026), Intruder (US$3,500 per test for platform subscribers, US$4,000 for a one-off), Stingrai (Autonomous from US$3,000 one-time and Hybrid at US$6,800 one-time for one web application and its APIs, or US$450 and US$1,275 per month on a 12-month engagement), and Synack (Sara Pentest from US$4,181, SynackST from US$10,283, Synack14/365 from US$27,120, with the platform itself a separate line item whose price is not published). Five publish no figure at all: BreachLock, Bugcrowd, HackerOne, NetSPI and OnSecurity. Four pricing models are in play and they are not comparable without arithmetic. Cobalt sells credits, where one credit is defined as the equivalent of eight hours of offensive security testing, sold in annual packages, with the credit count for an asset set by engagement complexity and the price of a credit not published. Astra and Intruder sell per-asset subscriptions where the unit is one target. Synack sells per-assessment packages that sit on top of a required platform line item. Stingrai sells a fixed package price for a defined scope. On the published numbers, covering one web application for twelve months ranges from US$2,999 to US$27,120, and five of the ten vendors cannot be placed on that range at all because they publish nothing.

Quick answer: Five of the ten penetration testing as a service vendors checked on 5 September 2026 publish a price on their own website. The lowest published 12-month cost for one web application is US$2,999 a year for Astra's Pentest Auto plan, which covers one target. The highest is US$27,120 for a Synack14/365 pentest, before the Synack Platform line item that the same page states is required and does not price. In between sit Stingrai at US$3,000 one-time for an Autonomous Pentest of one web application and its APIs, Cobalt at US$3,500 per test for an Autonomous Pentest on a promotional rate, Intruder at US$3,500 per test for platform subscribers and US$4,000 for a one-off, and Synack's Sara Pentest from US$4,181. BreachLock, Bugcrowd, HackerOne, NetSPI and OnSecurity publish no figure.

Every price on this page was read from the vendor's own pricing page on 5 September 2026 and links back to it. Where a vendor publishes nothing, this page says "not published" instead of substituting a third-party estimate.

Why PTaaS prices are hard to compare

The category sells four different things and calls them all pricing.

A credit model sells a pool of testing capacity in advance. The buyer purchases credits, and each engagement debits some number of them. The published fact is what a credit is worth in testing time. The unpublished fact, and the one that determines the invoice, is what a credit costs.

A per-asset model sells a subscription against a count of things. The unit is a target, an application, an IP range or a cloud account, and the price scales with how many of them you have. The published fact is the price per unit. The definition of the unit is where the money moves.

A subscription model sells time rather than tests. You pay monthly or annually and testing runs across the term. The published fact is the recurring price. What matters is how much testing the term actually contains.

A fixed-price model sells a defined scope for a defined number. The published fact is the whole invoice.

Three of these four produce a number that is not the price of the thing you want to buy, which is why a spreadsheet with a column labelled "price" is misleading unless it also carries a column labelled "unit". This page carries both.

Published 12-month cost of covering one web application under each PTaaS price published in 2026

The published price table

Vendors are listed alphabetically. This is a source table, not a ranking. Every cell links to the page the figure was read from on 5 September 2026, and every cell without a figure says "not published" rather than carrying an estimate.

Vendor

Published price

Unit the price is attached to

Model

Source

Astra

US$2,999 a year (Pentest Auto), US$5,999 a year (Pentest Expert), from US$9,999 a year (Enterprise)

1 target, defined as one web or SaaS app including all APIs consumed

Per-asset annual subscription

getastra.com/pricing

BreachLock

Not published. Three named packages, Standard, Extended and Extensive, all quote-only

Not published

Quote only

breachlock.com pentest pricing

Bugcrowd

Not published

Not published

Quote only

bugcrowd.com/pricing

Cobalt

US$3,500 per test (Autonomous Pentest, promotional). Standard, Premium and Enterprise credit tiers are quote-only

1 test for the promotional figure. Otherwise 1 credit, defined as the equivalent of 8 hours of offensive security testing

Credit consumption, plus one published fixed per-test price

cobalt.io/platform/pricing

HackerOne

Not published

Not published

Quote only

hackerone.com/pricing

Intruder

US$3,500 per test for platform subscribers, US$4,000 per test as a one-off. Platform plan prices are configured rather than listed

1 web application test

Fixed price per test, sitting beside a per-asset platform subscription

intruder.io/pentest-pricing and intruder.io/pricing

NetSPI

Not published

Not published

Quote only

netspi.com

OnSecurity

Not published. The page advertises transparent pricing and an instant quote flow rather than a figure

Not published

Quote only, through a scoping questionnaire

onsecurity.io/pricing

Stingrai

US$3,000 one-time (Autonomous), US$6,800 one-time (Hybrid), US$450 and US$1,275 per month on a 12-month engagement

One web application and its APIs

Fixed package price, one-time or monthly

stingrai.io/pricing

Synack

From US$4,181 (Sara Pentest), from US$10,283 (SynackST), from US$27,120 (Synack14/365), Enterprise quote-only

1 pentest against a stated scope and assessment window. The Synack Platform is a separate line item and its price is not published

Per-assessment package on top of a required platform subscription

synack.com/pricing

Five of ten vendors publish nothing. That is the single most important row in the table, because it means that for half the category the only honest answer to "what does it cost" is "ask them", and any number you find attached to those names on a third-party site is somebody's estimate rather than the vendor's price.

Which pricing facts each PTaaS vendor publishes on its own site in 2026

Key takeaways

  • The published entry point for one web application clusters tightly, and the ceiling does not. Five of the six lowest published figures sit between US$2,999 and US$4,181. Above that the published numbers jump to US$5,999, US$6,800, US$9,999, US$10,283 and US$27,120. The cluster is the automated or AI-led tier of each vendor's line; the jump is where a team of people is attached to the scope.

  • A credit is a unit of time, not a unit of price. Cobalt publishes that one credit is the equivalent of eight hours of offensive security testing and that credits are sold in annual packages, and it publishes that the number of credits an asset needs is set by engagement complexity. It does not publish what a credit costs. Two of the three inputs to your invoice are public and the third is not, which means a credit contract cannot be priced from the website.

  • A per-asset subscription is priced by a definition, and the definition is on the page. Astra publishes that one web or SaaS app counts as one target including all APIs it consumes, that mobile is per platform so an Android and an iOS app are two targets, and that networks, cloud accounts, IPs and standalone APIs are one target each. Read that paragraph before you read the price, because it is the paragraph that decides how many prices you pay.

  • A required platform line item can be larger than the test. Synack's pricing page states that the Synack Platform is required to purchase any of the testing products and is a separate line item. The three published package prices are therefore floors, not totals, and the page does not publish the platform figure that turns a floor into a total.

  • Retest terms move the real cost more than the headline does. Cobalt publishes unlimited on-demand retesting throughout the contract term. Intruder publishes unlimited retesting on its per-test price. Astra publishes one human re-scan on Pentest Auto and two on Pentest Expert. Stingrai includes retesting in the published package. A vendor that meters retests can turn a cheaper headline into a more expensive year.

Methodology

The verification pass for this page closed on 5 September 2026. A figure appears here only if it was read directly from the vendor's own website on that date, in the currency the vendor used, attached to the unit the vendor attached it to.

What counted as a published price. A number displayed on a page the vendor controls, on a public URL, with no login. Prices behind a "talk to sales" click, prices that only appear inside a configurator after you enter asset counts, and prices quoted by analyst marketplaces, procurement-intelligence sites or review sites were all excluded. That exclusion is why several vendors with widely circulated "typical cost" figures appear here as "not published": those figures are third-party estimates of what buyers paid, not prices the vendor stands behind.

How ambiguous figures were handled. Astra's pricing page carries a monthly and annual toggle advertising a 15% annual saving, and the rendered page repeats a monthly token across several cards. Only the annual figures, which are unambiguous per plan, are cited here. Intruder's platform tiers price through an asset-count configurator rather than a list, so no platform figure is printed on this page; only the two per-test prices, which are printed as flat figures, are cited.

Promotional and floor pricing is labelled. Cobalt's US$3,500 per test is described on the page as a limited time offer, and the page's own fine print states that an Autonomous Pentest must be initiated and completed before 31 December 2026 to qualify, and that the exact number of credits debited may vary based on the contracted rate per credit. Synack's three package figures are published as "pricing starts at". Astra's Enterprise plan is published as "onwards". Every one of those qualifiers is carried through into the tables rather than dropped.

Currency. Every figure in this comparison is published in US dollars by its source, so no conversion was performed and no exchange rate is applied anywhere on this page.

What was dropped. NetSPI publishes no pricing page; a netspi.com/pricing URL returned HTTP 404 during the pass, and the widely repeated per-engagement bands attached to the name in search results trace to review and procurement sites rather than to NetSPI, so none of them are printed here. Bugcrowd's pricing URL resolved to a portal page with no figures. OnSecurity's pricing page loaded and returned HTTP 200, and advertises transparent pricing and an instant quote generated from scoping questions, but carries no currency figure, so it is recorded here as not published rather than excluded. A number of aggregator pages publishing "average PTaaS cost" bands were read and excluded for the same reason: no primary publisher, no methodology, no unit.

The four pricing models, and the arithmetic each one hides

Credit models

Cobalt is the reference implementation. Its pricing page defines a Cobalt Credit as the equivalent of eight hours of offensive security testing delivered through a combination of automation and human expertise, states that credits are sold in annual packages that include asset scoping, testing, retesting and platform access, and states that the credit cost of a specific asset depends on the scope and delivery options of the test. Three tiers, Standard, Premium and Enterprise, are named and differentiated by start time, onboarding, support model and features, and all three carry a "get a quote" button rather than a number.

What the buyer can compute from the published page: nothing. What the buyer can compute after one sales call, given a rate per credit and a credit count for the asset, is everything.

The buyer question that unlocks a credit model is not "what does a credit cost". It is "how many credits does an asset like mine consume, and what happens if the scope turns out to be deeper than the estimate". Credit counts set by engagement complexity are, by construction, an estimate made before the test. Ask for the estimate in writing, ask what happens when it is wrong, and ask whether unused credits survive the contract year. Cobalt publishes that credits are specific to each contract year, and that additional credits can be purchased mid-year if the attack surface grows.

Per-asset models

Astra and Intruder both sell against a count. Astra's unit is a target, defined on the pricing page as one web or SaaS app including all the APIs it consumes, with mobile counted per platform and networks, cloud accounts, IPs and standalone APIs counted as one target each. Intruder's platform is priced through a configurator against infrastructure and web app counts, with the numbers appearing only after you set those counts, which is why no platform figure appears in the table above.

The arithmetic a per-asset model hides is the growth curve. One application at US$2,999 a year is a clean number. The same number applied to a product that ships a second customer-facing app, an admin console on a separate host, an Android build and an iOS build is five targets, and the honest way to read the price is to count your targets first and multiply second.

Per-assessment packages on a required platform

Synack publishes three package floors and, on the same page, publishes that the platform is required and separately priced. That structure is common in the enterprise tier of this category and it is the most frequent source of a surprised buyer, because the number that reaches a budget approval is usually the package floor.

Synack also publishes what each package buys in scope and time, which is unusually specific and worth reading next to the price:

Package

Published starting price

Published scope

Published assessment window

Source

Sara Pentest

From US$4,181

1 low complexity web app, or 100 host IPs, external web or host

4 to 5 days

synack.com/pricing

SynackST

From US$10,283

Up to 25 unauthenticated web apps, 1 low complexity authenticated web app, or 100 host IPs, internal and external

5 days

synack.com/pricing

Synack14/365

From US$27,120

Up to 50 unauthenticated web apps, 1 authenticated web app, or 250 host IPs, internal and external web, host, API and mobile

14 or 365 days

synack.com/pricing

Enterprise

Not published

Custom scoping based on your attack surface

Custom

synack.com/pricing

Synack Platform

Not published, stated to be required and a separate line item

Not published

Not applicable

synack.com/pricing

The line worth noticing is the authenticated-application count. Sara covers one low complexity web app. SynackST covers up to 25 unauthenticated web apps but one low complexity authenticated one. Synack14/365 covers one authenticated web app. Authenticated testing is where the findings live, and in all three published packages the authenticated count is one.

Fixed-price models

A fixed package price publishes the invoice. There is no unit to convert, no configurator to run and no line item held back. Stingrai's pricing page publishes an Autonomous Pentest from US$3,000 one-time and a Hybrid Pentest at US$6,800 one-time, each covering one web application and its APIs, with retesting included, and the same two tiers at US$450 and US$1,275 per month on a 12-month engagement for buyers who want the testing running all year rather than once. Scopes beyond one application are quoted through Get a Quote.

The trade-off is real and worth stating plainly: a fixed price is only fixed for the scope it names. Every fixed-price vendor in this category, including this one, moves to a quote when the scope stops being one application.

Total cost of ownership: one web application, twelve months

This is the comparison most buyers actually want, and it is the one the pricing pages do not do for you. The scope is held constant: one production web application and the APIs behind it, tested once in the year, with the findings retested after remediation.

Every line below is either a published figure or a published figure multiplied by twelve. Nothing is estimated. Where a published figure is a floor or a promotion, the row says so.

Vendor and plan

Published figure

Arithmetic for 12 months, one web application

12-month published cost

Model

Source

Astra Pentest Auto

US$2,999 a year, 1 target

The published annual price covers the year

US$2,999

Per-asset annual subscription

getastra.com/pricing

Stingrai Autonomous, one-time

US$3,000 one-time

One annual engagement at the published one-time price

US$3,000

Fixed package price

stingrai.io/pricing

Cobalt Autonomous Pentest

US$3,500 per test, promotional

One test in the year at the promotional rate, which must be initiated and completed before 31 December 2026

US$3,500 plus the credit contract it debits against

Fixed per-test price inside a credit contract

cobalt.io/platform/pricing

Intruder AI Pentesting, subscriber rate

US$3,500 per test

One test in the year, plus a platform subscription whose price is configured rather than published

US$3,500 plus an unpublished platform subscription

Fixed per-test price beside a per-asset subscription

intruder.io/pentest-pricing

Intruder AI Pentesting, one-off

US$4,000 per test

One test in the year, no subscription required

US$4,000

Fixed price per test

intruder.io/pentest-pricing

Synack Sara Pentest

From US$4,181, 4 to 5 day window

One assessment in the year, plus the required platform line item

From US$4,181 plus an unpublished platform fee

Per-assessment package on a required platform

synack.com/pricing

Stingrai Autonomous, continuous

US$450 a month on a 12-month engagement

450 multiplied by 12

US$5,400

Monthly subscription

stingrai.io/pricing

Astra Pentest Expert

US$5,999 a year, 1 target

The published annual price covers the year

US$5,999

Per-asset annual subscription

getastra.com/pricing

Stingrai Hybrid, one-time

US$6,800 one-time

One annual engagement at the published one-time price

US$6,800

Fixed package price

stingrai.io/pricing

Astra Enterprise

From US$9,999 a year

The published annual floor covers the year

From US$9,999

Per-asset annual subscription

getastra.com/pricing

Synack SynackST

From US$10,283, 5 day window

One assessment in the year, plus the required platform line item

From US$10,283 plus an unpublished platform fee

Per-assessment package on a required platform

synack.com/pricing

Stingrai Hybrid, continuous

US$1,275 a month on a 12-month engagement

1,275 multiplied by 12

US$15,300

Monthly subscription

stingrai.io/pricing

Synack14/365

From US$27,120, 14 or 365 day window

One assessment in the year, plus the required platform line item

From US$27,120 plus an unpublished platform fee

Per-assessment package on a required platform

synack.com/pricing

BreachLock, Bugcrowd, HackerOne, NetSPI, OnSecurity

Not published

Cannot be computed

Not published

Quote only

See the published price table above

Cobalt credit contract

Credit defined as 8 hours of testing; credit price not published

Cannot be computed without a rate per credit and a credit count

Not published

Credit consumption

cobalt.io/platform/pricing

Two readings of that table are worth spelling out.

The one-time and the continuous number are answering different questions. US$3,000 buys a point-in-time test of an application as it stands. US$5,400 buys twelve months of testing against an application that ships every week. Comparing them directly is the most common mistake in this budget line, and it usually happens because a spreadsheet sorted a "price" column. Sort by what the money buys instead: a compliance deadline, a customer security review and a board report are point-in-time purchases; a continuous delivery pipeline is not.

A floor plus an unpublished line item is not a price. Three rows in the table end with "plus an unpublished platform fee" or "plus the credit contract it debits against". Those rows are honest floors and dishonest comparisons. If you put them in a spreadsheet next to a complete number, ask the vendor for the missing line item first and only then compare.

What a subscription actually buys

Headline prices are the easy part. The four things that decide whether a cheaper headline stays cheaper are retesting, the report, the portal and the integrations. All four are published by most vendors that publish anything, and they are the rows buyers skip.

Vendor

Retest terms as published

Report as published

Portal and integrations as published

Source

Astra

1 human re-scan on Pentest Auto, 2 human re-scans on Pentest Expert

SOC 2, ISO 27001, HIPAA reports on Pentest Auto; CREST, PCI-ASV and CERT-IN compliant reports on Pentest Expert

Vulnerability management console; 1 integration on Pentest Auto, unlimited on Pentest Expert

getastra.com/pricing

Cobalt

Free retesting on all tiers, described as unlimited on-demand retesting throughout the contract term

Structured report generated automatically at engagement close; customizable reports listed at higher tiers

Results delivered in the Cobalt platform; integrations with Jira, GitHub, Slack and 50+ tools

cobalt.io/platform/pricing

Intruder

Unlimited retesting included in the per-test price

Same-day audit-ready reports for ISO 27001 and SOC 2, with a published refund if an auditor rejects the report

GitHub, GitLab and Bitbucket integration

intruder.io/pentest-pricing

Stingrai

Retesting included in the published package, automated retests on both tiers

Penetration testing report on both tiers, quarterly executive status reports on Hybrid

PTaaS portal with Jira and Slack integration on Hybrid

stingrai.io/pricing

Synack

Patch verification on all published packages

Compliance ready report on all published packages

The Synack Platform, required and separately priced

synack.com/pricing

BreachLock

1 free manual re-test on Standard, 2 free re-tests on Extended and Extensive

CREST-certified, audit-ready reports

Not published on the pricing page

breachlock.com pentest pricing

Bugcrowd, HackerOne, NetSPI, OnSecurity

Not published

Not published

Not published

See the published price table above

Retesting is the row that most often changes the ranking of two quotes. A vendor publishing one re-scan against a vendor publishing unlimited retesting for the contract term are selling different products at superficially similar prices, and the difference shows up in the second month, when the first round of fixes lands and somebody has to prove they worked.

What the price does not tell you about the test

Stingrai's State of Penetration Testing 2026 analysed 1,206 verified findings from 55 penetration tests. 92.7% of those tests surfaced at least one High or Critical finding, and the dataset carried a 0.74% false-positive rate. Those two numbers are the output side of the price you are comparing: a test that surfaces nothing tells you nothing, and a test that surfaces noise costs your engineers more than the invoice did.

The other half of the budget is remediation. In the same dataset the median Critical finding took 10.5 days to fix and the median High took 38.0 days. A twelve-month plan that funds the test and not the fix window has bought a report rather than a security outcome, and the retest terms in the table above are exactly what determine whether the fix ever gets verified.

For a scope-by-scope walk through what moves a quote, see the 2026 penetration testing cost guide and the cost per hour and day rate analysis. For a number against your own asset count rather than a market band, the pentest cost calculator shows its assumptions alongside its output.

How Stingrai prices, and why

Stingrai publishes fixed package prices rather than a credit rate or an asset-count configurator. The pricing page carries an Autonomous Pentest from US$3,000 one-time and a Hybrid Pentest at US$6,800 one-time, each covering one web application and its APIs, and the same two tiers at US$450 and US$1,275 per month on a 12-month engagement. Retesting is included. The Autonomous tier carries a published No High or Critical Finding, Don't Pay guarantee. Anything beyond one application, including networks, cloud, mobile and social engineering scope, is quoted through Get a Quote.

Both delivery models are available at both tiers, which is the point of publishing four numbers rather than two: an annual point-in-time engagement and year-round continuous coverage are different purchases, and a buyer should be able to see both prices before talking to anyone.

On every engagement, certified penetration testers work concurrently with Snipe, Stingrai's autonomous AI agent for web application penetration testing. Snipe is custom-trained on thousands of disclosed vulnerability reports and on Stingrai's own testing methodology, and it is built to hunt the classes that matter most in an application scope: broken authorization, IDOR, business logic flaws and access-control failures. It performs black-box dynamic testing and white-box source review, opens AutoFix pull requests for what it finds, and can run as a gating check on every pull request. The Autonomous tier returns same-day results. Stingrai is a Toronto-headquartered, CREST-accredited penetration testing service provider founded in 2021, and its penetration testing supports SOC 2, ISO 27001, PCI DSS and HIPAA programmes by producing the scope statement, technical report, remediation record and retest evidence those programmes consume.

What this means for buyers

  • Ask for the unit before you ask for the price. A credit, a target, a test and a package are four different things. Two quotes are only comparable once both have been converted into the same unit, which is almost always cost per application per year.

  • Get every line item on the quote, including the ones the pricing page separates out. A published package floor plus a required platform subscription is a two-line invoice, and only one of the two lines is on the website.

  • Count your targets before you read a per-asset price. Under Astra's published definition, a product with a customer app, an admin console on its own host, an Android build and an iOS build is four targets, not one. That arithmetic happens before the discount conversation, not after it.

  • Put retest terms in the comparison spreadsheet as a column, not a footnote. One re-scan against unlimited retesting for the contract term is a larger difference than most of the price gaps on this page.

  • Ask what the authenticated scope is. In every Synack package that publishes a price, the authenticated web application count is one. Authenticated, role-aware testing is where authorization and business logic findings come from, and it is routinely the smallest number in a published scope.

  • Treat promotional pricing as a date, not a rate. Cobalt's US$3,500 per test carries a published deadline of 31 December 2026. Anything you plan for 2027 needs the standing rate, which is not published.

  • Do not import third-party "average cost" figures into a vendor comparison. For five of the ten vendors here, every number circulating online is somebody's estimate. Ask the vendor and put their answer in the sheet with a date next to it.

Frequently Asked Questions

How much does PTaaS cost in 2026?

The published range for covering one web application for twelve months runs from US$2,999 to US$27,120, based on prices read from vendor pricing pages on 5 September 2026. The floor is Astra's Pentest Auto plan at US$2,999 a year for one target. The ceiling is a Synack14/365 pentest from US$27,120, before the required Synack Platform line item, which is not priced publicly. Stingrai publishes US$3,000 one-time for an Autonomous Pentest of one web application and its APIs and US$6,800 one-time for a Hybrid Pentest, or US$450 and US$1,275 per month on a 12-month engagement. Five of the ten vendors checked publish no figure at all.

Which PTaaS vendors publish their prices?

Five of ten. Astra, Cobalt for its Autonomous Pentest, Intruder, Stingrai and Synack all publish at least one figure on their own site. BreachLock, Bugcrowd, HackerOne, NetSPI and OnSecurity publish none, and NetSPI has no pricing page at all. Numbers attached to those five names on review and procurement sites are third-party estimates of what buyers paid, not vendor list prices.

How does Cobalt pricing compare to Synack pricing?

They are priced in different units, so the comparison needs a conversion. Cobalt sells credits, publishing that one credit is the equivalent of eight hours of offensive security testing, that credits are sold in annual packages, and that the credit count for an asset depends on scope and delivery options; it does not publish the price of a credit. Its one published figure is a promotional US$3,500 per test for an Autonomous Pentest, which must be initiated and completed before 31 December 2026. Synack sells per-assessment packages starting at US$4,181 for a Sara Pentest, US$10,283 for SynackST and US$27,120 for Synack14/365, and states on the same page that the Synack Platform is required and is a separate line item whose price is not published. Neither vendor can be priced end to end from its website: Cobalt withholds the unit price, Synack withholds the platform price.

What is a pentest credit and how many do I need?

A credit is a prepaid unit of testing time. Cobalt defines one credit as the equivalent of eight hours of offensive security testing delivered through a combination of automation and human expertise, sold in annual packages that include asset scoping, testing, retesting and platform access. The number of credits an asset consumes is set by the scope and delivery options of the test, which means it is estimated before the engagement rather than published. Ask for the credit estimate for your specific application in writing, ask what happens if the scope proves deeper, and ask whether unused credits carry into the next contract year.

What does continuous penetration testing cost per month?

The published monthly figures in this pass are Stingrai's, at US$450 per month for an Autonomous Pentest and US$1,275 per month for a Hybrid Pentest on a 12-month engagement covering one web application and its APIs (stingrai.io/pricing), which work out to US$5,400 and US$15,300 across the year. Synack publishes a 365-day assessment window on its Synack14/365 package from US$27,120, but as an annual package price rather than a monthly rate, and the required platform line item is not published. Astra publishes annual subscriptions rather than monthly ones for its penetration testing plans. No other vendor in this pass publishes a monthly continuous testing price.

Is a PTaaS subscription cheaper than a one-off penetration test?

Not usually, and that is the wrong question. A subscription buys testing across the year against an application that keeps changing; a one-off buys a point-in-time assessment of the application as it stands. On the published Stingrai numbers, twelve months of Autonomous coverage is US$5,400 against US$3,000 for a single annual engagement, so the subscription costs 80% more and delivers testing on every release rather than once. Buy the one-off when the driver is an audit date, a customer security review or a board report. Buy the subscription when the driver is release frequency.

Does PTaaS pricing include retesting?

It depends on the vendor and it is published often enough to compare. Cobalt publishes free retesting on all tiers, described as unlimited on-demand retesting throughout the contract term. Intruder publishes unlimited retesting inside its per-test price. Astra publishes one human re-scan on Pentest Auto and two on Pentest Expert. BreachLock publishes one free manual re-test on Standard and two on Extended and Extensive. Stingrai includes retesting in the published package price. Synack publishes patch verification on all three priced packages.

Why does HackerOne not publish pricing?

HackerOne's pricing page carries no figures and no tier prices; it routes to a contact form and a "speak with a security expert" flow. That is the standard pattern for platforms whose commercial model spans bug bounty programmes, vulnerability disclosure programmes and pentest engagements, because the variables (asset count, reward pool, engagement type, programme management level) are set per customer. The practical consequence for a buyer is that there is no published anchor to negotiate against, which makes the published prices in the table above useful even when you are not buying from those vendors. A side-by-side of the two models sits in HackerOne pentest versus Stingrai.

What is the cheapest way to get an audit-ready penetration test report?

On published prices, the lowest figures attached to a compliance-ready deliverable for one web application are Astra's Pentest Auto at US$2,999 a year, which publishes SOC 2, ISO 27001 and HIPAA reports, and Stingrai's Autonomous Pentest from US$3,000 one-time, which includes retesting and carries a No High or Critical Finding, Don't Pay guarantee. Intruder publishes US$4,000 for a one-off test with same-day ISO 27001 and SOC 2 reporting and a refund if an auditor rejects the report. Before optimising for the lowest figure, confirm the authenticated scope, the retest terms and whether your auditor has accepted that vendor's report format before.

How should I compare two PTaaS quotes?

Convert both to cost per application per year, then add four columns: the number of authenticated applications in scope, the retest terms, whether a platform or subscription line item sits outside the quoted figure, and what happens to the price when the scope grows by one application. Those four columns move the twelve-month total more than the headline does. The penetration testing cost guide walks through the scope variables behind each of them, and the pentest cost calculator turns an asset count into a range with its assumptions shown.

References

  1. Astra Security. Pricing. Read 5 September 2026. https://www.getastra.com/pricing. Publishes Pentest Auto at US$2,999 a year, Pentest Expert at US$5,999 a year and Enterprise from US$9,999 a year, all for one target, together with the definition of a target and the re-scan and reporting entitlements of each plan.

  2. BreachLock. Penetration Testing Pricing. Read 5 September 2026. https://www.breachlock.com/pricing/penetration-testing-pricing/. Names Standard, Extended and Extensive packages with re-test and reporting entitlements, and carries no dollar figures.

  3. Bugcrowd. Pricing. Read 5 September 2026. https://www.bugcrowd.com/pricing/. No published figures.

  4. Cobalt. Pricing. Read 5 September 2026. https://www.cobalt.io/platform/pricing. Publishes the Autonomous Pentest promotional rate of US$3,500 per test with its 31 December 2026 deadline, the definition of a Cobalt Credit as the equivalent of eight hours of offensive security testing, the Standard, Premium and Enterprise tier comparison, and the free retesting and integrations entitlements.

  5. HackerOne. Pricing. Read 5 September 2026. https://www.hackerone.com/pricing. No published figures; routes to a contact form.

  6. Intruder. Pentest pricing. Read 5 September 2026. https://www.intruder.io/pentest-pricing. Publishes US$3,500 per test for platform subscribers and US$4,000 per test one-off, with unlimited retesting, same-day ISO 27001 and SOC 2 reporting and a published refund if an auditor rejects the report.

  7. Intruder. Pricing. Read 5 September 2026. https://www.intruder.io/pricing. Free, Cloud, Pro and Enterprise platform tiers, priced through an asset-count configurator rather than published as figures, with the pentest per-test price shown alongside.

  8. NetSPI. Company website. Read 5 September 2026. https://www.netspi.com/. No pricing page; a netspi.com/pricing URL returned HTTP 404 during the pass.

  9. OnSecurity. Pricing. Read 5 September 2026. https://www.onsecurity.io/pricing/. Describes transparent pricing and an instant quote produced from scoping questions, and publishes no currency figure, plan price or unit price.

  10. Synack. Pricing. Read 5 September 2026. https://www.synack.com/pricing/. Publishes Sara Pentest from US$4,181, SynackST from US$10,283 and Synack14/365 from US$27,120, with per-package scope and assessment windows, and states that the Synack Platform is required and is a separate line item.

  11. Stingrai. Pricing. Read 5 September 2026. https://www.stingrai.io/pricing. Published one-time and monthly package prices for one web application and its APIs, retest inclusion, and the Autonomous tier guarantee.

  12. Stingrai. The State of Penetration Testing 2026. https://www.stingrai.io/blog/state-of-penetration-testing-2026. 1,206 verified findings across 55 penetration tests, the share of tests surfacing a High or Critical, the false-positive rate and remediation timing.

  13. Stingrai. Penetration Testing Cost 2026. https://www.stingrai.io/blog/penetration-testing-cost-2026. Scope variables behind a quote, by engagement type.

  14. Stingrai. Penetration Testing Cost Per Hour and Day Rates 2026. https://www.stingrai.io/blog/penetration-testing-cost-per-hour-2026. Published day rates and the arithmetic that turns a day rate into a project price.


Ready to compare a published price against your own scope?

Published prices are only useful next to a scope. Stingrai publishes both: an Autonomous Pentest from US$3,000 one-time and a Hybrid Pentest at US$6,800 one-time for one web application and its APIs, the same tiers at US$450 and US$1,275 per month on a 12-month engagement, and retesting included in every one of them. Certified penetration testers work alongside Snipe, our autonomous AI agent for web application penetration testing, throughout the engagement, hunting the broken authorization and business logic flaws that scanners walk past. Book a free scoping call, get a quote for a multi-application, network or cloud scope, or read the numbers yourself on the pricing page.

0 views

0

X

Related reading

Best Healthcare Penetration Testing Companies (2026): HIPAA, HITRUST and Medical Device Testing Compared
Web App SecurityNetwork Security

Best Healthcare Penetration Testing Companies (2026): HIPAA, HITRUST and Medical Device Testing Compared

Best healthcare penetration testing companies in 2026, ranked, with what HIPAA, HITRUST and FDA 524B really require of a pentest.

20 min read

Best BreachLock Alternatives (2026): PTaaS Platforms Compared on Testers, Evidence and Pricing
Web App SecurityNetwork Security

Best BreachLock Alternatives (2026): PTaaS Platforms Compared on Testers, Evidence and Pricing

Compare 8 BreachLock alternatives for 2026 on who tests, what the AI does, retest terms and published pricing, plus BreachLock vs Cobalt and Astra.

13 min read

Best Bugcrowd Alternatives for Penetration Testing (2026): Pentest as a Service vs Crowdsourced
Web App SecurityNetwork Security

Best Bugcrowd Alternatives for Penetration Testing (2026): Pentest as a Service vs Crowdsourced

Compare 8 Bugcrowd alternatives for penetration testing in 2026 on delivery model, compliance fit and published pricing, plus where Bugcrowd still wins.

14 min read

Contents

X