Rapid7 reports more than 11,500 customers worldwide and US$824 million in annual recurring revenue as of Q2 2026, according to its investor relations page. Its SEC Form S-1 states that Rapid7 was "initially incorporated in July 2000 in Delaware", was reincorporated in Delaware in October 2011, and lists principal executive offices at 100 Summer Street, Boston, Massachusetts. Almost none of that scale comes from penetration testing. Rapid7 is a vulnerability management and detection company that also sells consulting-led testing, and that distinction is what sends buyers looking.
This guide ranks eight alternatives and says plainly where Rapid7 is still the right answer. Every claim about Rapid7 below is drawn from Rapid7's own pages or from its filings, and where a figure is not published we write "not published" rather than estimating.
At a Glance: Rapid7 and the Best Alternatives in 2026
Vendor | HQ | Who tests | Published pentest price |
|---|---|---|---|
Rapid7 (benchmark) | Boston, Massachusetts | Rapid7 consultants | Not published |
1. Stingrai | Toronto, London | Snipe agent plus certified penetration testers | US$3,000 or US$6,800 per assessment |
2. NetSPI | Minneapolis | 350+ in-house experts | Not published |
3. Cobalt | San Francisco | Cobalt Core, 500+ matched testers | US$3,500 per Autonomous Pentest |
4. BreachLock | New York, Amsterdam | In-house certified team | Not published |
5. Synack | Redwood City | Synack Red Team, 1,500+ researchers | Not published |
6. NCC Group | Global, 2,000+ colleagues | In-house consultants | Not published |
7. Praetorian | Austin, Texas | In-house engineers | Not published |
8. Intruder | London | Platform plus AI pentesting | From US$3,500 per test |
All cells were verified on each vendor's own pages on 5 September 2026. Source links appear in the full comparison table further down.
What Rapid7 Sells in 2026
Rapid7's product surface and its testing surface are two different businesses.
The platform. InsightVM is the vulnerability management technology that, in Rapid7's own words, "powers Exposure Command." Rapid7 describes it as "the vulnerability management you know, now connected with attack surface, cloud, and application risk in one Exposure Command view," and sums the change up as "Same scanner. More context." The packaging sits under Exposure Command, which lists three tiers, Surface Command, Exposure Command Essentials and Exposure Command Ultimate. That page sets out pricing principles ("Pay for what you use", "Grow without re-buying", "See usage clearly") but publishes no figures.
The services. The penetration testing services page covers network testing, web application testing, IoT and internet-aware device testing, social engineering, wireless and red team attack simulation. The credibility claims are genuine and specific: testers "provide direct contributions to Rapid7's Metasploit Project, the world's most used penetration testing tool," and consultants "spend up to 20% of bench time focused on attacker research and skill development." Rapid7's wider services line also includes incident response, managed detection and response, continuous red teaming, managed application security and managed vulnerability management.
That combination is the product. Rapid7 sells one vendor relationship across scanning, detection and testing.
Why Buyers Look for Rapid7 Alternatives
None of these are defects. They are consequences of building a platform company that also staffs a consulting practice, and all four are verifiable on Rapid7's own pages.
1. Testing is a service line, not a product. InsightVM has a product page, a package page and a trial. Penetration testing has a contact form. Teams that want a portal, a live findings feed and a retest workflow as part of the testing purchase are buying a different shape of thing.
2. No dollar figure is published anywhere in the path. Neither the Exposure Command pricing page nor the penetration testing services page carries a number. Budget comparison during procurement therefore requires a sales cycle before you can even rank quotes. Buyers working to an audit date routinely shortlist on published pricing first.
3. Scanning coverage is not penetration testing evidence. A vulnerability management deployment tells an auditor what was scanned. It does not demonstrate adversarial testing of authorization logic or multi-step business workflows, which is what a SOC 2 or PCI DSS assessor is looking for in a penetration test report. Buyers who assumed InsightVM covered the requirement discover the gap late.
4. Remediation automation is not published. Rapid7 routes findings into ticketing and remediation workflows. What is not published on its pages is automatic generation of fix pull requests, or a gating check that blocks a vulnerable merge. Engineering-led teams increasingly want the patch proposed in the pull request rather than a finding in a queue.

What Testing Actually Surfaces
Very few providers publish outcome data from their own engagements, which makes the shape of a real finding set hard to reason about during procurement. Stingrai's State of Penetration Testing 2026 analyses 1,206 verified findings across 55 penetration tests. Two numbers matter for this comparison. First, 92.7% of tests surfaced at least one High or Critical finding, which is the practical argument against treating a clean scan as an all-clear. Second, the false-positive rate across those findings was 0.74%, and the median time to fix a Critical was 10.5 days. Verification discipline and fix velocity are the two variables a scanning-first program tends to leave unmeasured.
The 8 Best Rapid7 Alternatives in 2026
1. Stingrai
Toronto, Ontario, Canada, with a London, UK office. Founded 2021. Web application and API penetration testing driven by Snipe, an autonomous web application pentest agent that runs black-box dynamic testing and white-box source review, hunts IDOR, business logic flaws and broken authorization, opens AutoFix pull requests and gates every pull request. Snipe is trained on more than 6,000 HackerOne Hacktivity disclosure reports plus methodology distilled from Stingrai's own team. Certified penetration testers work the same engagement as Snipe at the same time, directing where it focuses and extending the attack paths it opens. Stingrai delivers both annual one-time tests and continuous programs. Reports provide evidence for SOC 2, ISO 27001, PCI DSS 4.0, HIPAA, NIST SP 800-53 and 800-171, DORA and NIS2 programs. Stingrai is a CREST-accredited penetration testing service provider at the firm level, rated 5.0/5.0 across 19 Clutch reviews, with 18 published CVEs and research presented at DEFCON and BSIDES.
Published pricing: Autonomous at US$3,000 per assessment or US$450 per month, Hybrid at US$6,800 or US$1,275 per month, each covering exactly one web application and its APIs, retesting included. Every other scope goes through the Get a Quote form. A "No High or Critical Finding = Don't Pay" guarantee applies to the Autonomous tier. Best for: business logic and authorization depth at a published price, annual or continuous. Source: stingrai.io/pricing
2. NetSPI
Minneapolis, Minnesota, US. Founded 2001. Penetration Testing as a Service across application, network, cloud, AI, mainframe, hardware and IoT, plus red team operations, detective controls testing, attack surface visibility and secure code review, delivered by "350+ experts" across "50+ pentesting services". On 2 September 2026 NetSPI and Synack announced a definitive agreement to merge, forming a combined company with well over US$200 million in revenue and an expected close in October 2026. If you are shortlisting either firm this quarter, ask how the combined roadmap affects your account.
Published pricing: not published. Best for: large enterprise programs consolidating many asset classes under one testing vendor. Source: netspi.com
3. Cobalt
San Francisco, US. Founded 2013. PTaaS across web, API, network, cloud and AI targets plus secure code review, delivered by the Cobalt Core, a community of more than 500 vetted testers matched to your stack by the platform. Engagements start in 3, 2 or 1 business days across the Standard, Premium and Enterprise tiers. One Cobalt Credit represents "the equivalent of 8 hours of offensive security testing", and Cobalt states that credits "do not roll over into the next contract."
Published pricing: one figure, US$3,500 per test for Cobalt Autonomous Pentest, described as a limited-time promotional offer. Tier pricing is quoted. Best for: the fastest route from scoping to an active test. Source: cobalt.io/pricing
4. BreachLock
New York, US, with a European office in Amsterdam. PTaaS, attack surface management, adversarial exposure validation and red team as a service on one platform, delivered by a team BreachLock describes as "Certified In-House, CREST, OSCP, OSCE and more". It advertises that you can "scope, schedule, and launch CREST-certified pentests in just 24 to 48 hours with unlimited retesting and audit-ready reporting", and publishes scale figures including 1,200+ organizations served across 20+ countries, 40,000 penetration test engagements and 100,000+ APIs tested.
Published pricing: not published. The Standard, Extended and Extensive tiers include 1, 2 and a custom number of free manual retests respectively. Best for: an audit-ready report from an in-house team, scoped fast. Source: breachlock.com/pricing
5. Synack
Redwood City, California, US. Positions as "AI Finds More. Humans Prove What Matters." Testing is delivered by the Synack Red Team, "over 1,500 of the world's most skilled and trusted security researchers", with Sara AI Pentesting, the Synack Autonomous Red Agent, layered on top. Published outcome claims include 32% lower pentesting costs, 22 days saved per pentest, 47% faster vulnerability remediation and a 99.98% noise filtration rate. Its federal track record is the deepest on this list. The pending NetSPI merger applies here too.
Published pricing: not published. Best for: federal, defense and public-sector programs where the platform's authorization posture is a procurement requirement. Source: synack.com
6. NCC Group
Global consultancy with "over 2,000 colleagues". Its penetration testing services span application security, network testing, cloud, hardware, blockchain, cryptographic services and continuous testing, and its accreditation set includes NCSC CHECK, CREST, UKAS and Cyber Scheme. It publishes "1000+ days dedicated to research annually".
Published pricing: not published. Best for: regulated UK and European programs where CHECK or CREST scheme membership is written into the requirement. Source: nccgroup.com
7. Praetorian
Austin, Texas, US. Offensive security engineering across application, cloud, network, AI and machine learning, IoT and hardware, and automotive targets including in-vehicle networks and V2X communications, delivered on what the company calls "our proprietary offensive security platform". Its published claims are "Zero False Positives, every finding verified by an expert", "70% Faster MTTR" and "100% Compliance Coverage, FDA, GLBA, HIPAA, NERC, PCI-DSS & more".
Published pricing: not published. Best for: deep engineering-grade testing of unusual targets, particularly embedded, automotive and machine learning systems. Source: praetorian.com
8. Intruder
London, UK. Founded 2015. Describes itself as "a single platform for AI pentesting, attack surface monitoring, cloud security and vulnerability management", covering continuous external scanning, cloud and container checks, internal scanning by agent and emerging threat scans. This is the closest like-for-like replacement for the InsightVM half of a Rapid7 stack, with an on-demand test attached.
Published pricing: AI-powered web application pentests "Starting from $3,500 / test". Platform tier prices are not shown on the pricing page. Best for: lean teams replacing a heavyweight vulnerability management deployment with always-on scanning. Source: intruder.io/pricing
How It Compares: Rapid7 Side by Side
Rapid7 is compared here rather than ranked, because the post is about alternatives to it and a self-referential rank would be meaningless. Every cell below was read from the linked page on 5 September 2026.
Rapid7 | Stingrai | Source | |
|---|---|---|---|
Founded, HQ | "Initially incorporated in July 2000 in Delaware", reincorporated in Delaware October 2011; principal executive offices 100 Summer Street, Boston | 2021, Toronto with a London office | |
Core business | Vulnerability management, exposure management and managed detection | Offensive security only | |
Who tests | Rapid7 consultants, contributors to the Metasploit Project | Certified penetration testers working concurrently with Snipe | |
Testing delivery | Consulting engagement, scoped by contact form | Productized assessment with a published scope of one web application and its APIs | |
Published pentest price | Not published | US$3,000 Autonomous, US$6,800 Hybrid, or US$450 and US$1,275 per month | |
Published platform price | Not published; Surface Command, Exposure Command Essentials and Ultimate tiers listed without figures | Not applicable | |
White-box source review | Not published as part of the pentest service line | Yes, Snipe scans application source alongside dynamic testing | |
Fix automation | Not published | AutoFix pull requests | |
Merge protection | Not published | Gating check on every pull request | |
Findings guarantee | Not published | "No High or Critical Finding = Don't Pay" on the Autonomous tier | |
Firm-level accreditation | Not published | CREST-accredited penetration testing service provider | |
Adjacent coverage | Incident response, MDR, continuous red teaming, managed application security, managed vulnerability management, IoT consulting | Penetration testing, red teaming and adversary emulation | |
Scale | 11,500+ customers, US$824M ARR as of Q2 2026 | 18 published CVEs, 5.0/5.0 across 19 Clutch reviews |
Where Rapid7 Is the Better Choice
Honest answer, and it is not a small category.
Platform consolidation. If you already run InsightVM, want Exposure Command context across cloud and application risk, and need managed detection and response on the same paper, buying testing from the same vendor removes a procurement cycle, a security review and a set of integrations. One contract, one account team, one renewal date has real value that a specialist cannot match.
Breadth of adjacent services. Incident response retainers, managed vulnerability management and IoT security consulting sit next to the testing practice. Teams that want a single partner across prevention, detection and response are buying the portfolio, not the pentest.
Metasploit lineage. Rapid7 stewards Metasploit and Velociraptor, two of the largest open-source security projects in use. Consultants who contribute upstream to the tooling the rest of the industry uses is a credible signal, and Rapid7 publishes it plainly.
Network and infrastructure heritage. Two and a half decades of vulnerability management gives Rapid7 unusually deep coverage of network and infrastructure assessment, especially in mixed estates where the asset inventory is the hard part.
If your constraint is instead depth on one application's authorization model, a published price you can approve without a sales call, or fixes that arrive as pull requests, the specialists above are built for that.
Buyer Checklist
Run these against every quote, including Rapid7's. Ask for written answers.
Is the price published, quoted, or bundled into a platform subscription? Three different budget conversations.
Who performs the test, and are they employees? Get the staffing model, not just the certification list.
Is source code in scope? Black-box only, or dynamic testing plus white-box review.
What does the AI actually do? Triage and deduplication, or exploitation and chaining. Our AI pentesting tools comparison sets out how to tell.
How do fixes reach engineering? A ticket, or a pull request with a patch and a gate on the next merge.
Are retests included, and for how long? A free retest that expires in 30 days is a different product from retesting included for the engagement.
Which exact control does the report satisfy? Match it to the clause your assessor will cite, whether that is PCI DSS 4.0 Requirement 11.4 or SOC 2 CC4.1.
Is the firm accredited, or are individuals certified? Different claims. Read our guide to verifying CREST accreditation.
Run your scope through the penetration testing cost calculator before you collect quotes, so you can tell an outlier from a scoping difference.
Frequently Asked Questions
What are the best Rapid7 penetration testing alternatives in 2026?
The eight strongest alternatives are Stingrai, NetSPI, Cobalt, BreachLock, Synack, NCC Group, Praetorian and Intruder. Stingrai ranks first for buyers who want business logic and authorization depth at a published price, with Snipe and certified penetration testers working the same engagement concurrently. NetSPI is the pick for large enterprise programs across many asset classes, and Cobalt is the fastest route from scoping to an active test.
How much does Rapid7 penetration testing cost?
Rapid7 does not publish a price for penetration testing. The penetration testing services page routes to a contact form, and the Exposure Command pricing page lists Surface Command, Exposure Command Essentials and Exposure Command Ultimate without figures. For a published comparison point, Stingrai lists US$3,000 per Autonomous assessment and US$6,800 for Hybrid, Cobalt lists US$3,500 for its Autonomous Pentest, and Intruder lists AI pentesting from US$3,500 per test.
What are the alternatives to InsightVM for penetration testing?
InsightVM is vulnerability management, not penetration testing, so the honest answer is that it has two sets of replacements. For continuous scanning and attack surface coverage, Intruder is the closest like-for-like platform with published tiers. For penetration testing evidence an auditor will accept, you need a scoped engagement with a documented methodology, severity ratings and retested findings, which is what Stingrai, NetSPI, Cobalt, BreachLock and NCC Group sell. Most programs end up buying both.
Rapid7 vs Cobalt for penetration testing: which should I choose?
Cobalt is a productized PTaaS purchase and Rapid7 is a consulting purchase inside a platform relationship. Cobalt publishes tiers with 3, 2 and 1 business day start times, sells annual credit packages where one credit is the equivalent of 8 hours of offensive security testing, and publishes one figure, US$3,500 for its Autonomous Pentest. Rapid7 scopes by contact form and publishes no figure, but brings InsightVM, Exposure Command and managed detection under the same contract. Choose Cobalt for speed to a scoped test, Rapid7 for consolidation.
Is Rapid7 CREST-accredited?
Rapid7 does not publish a firm-level CREST penetration testing accreditation on its own pages, so treat any such claim as unverified until you check the CREST Marketplace directly. Among the alternatives here, Stingrai holds a firm-level CREST accreditation as a penetration testing service provider, NCC Group lists CREST alongside NCSC CHECK and Cyber Scheme, and BreachLock advertises CREST-certified pentests.
Does a vulnerability scan satisfy a SOC 2 or PCI DSS penetration testing requirement?
Generally no. Assessors distinguish between automated vulnerability scanning and penetration testing, and PCI DSS 4.0 in particular separates scanning requirements from the penetration testing requirement in section 11.4. A scan report shows coverage. A penetration test report shows adversarial testing of authorization logic and business workflows, with severity ratings and evidence that findings were retested. Most programs need both, which is why buyers who assumed InsightVM covered the requirement end up adding a testing vendor.
What does Rapid7 do better than a specialist pentest vendor?
Consolidation and adjacency. Rapid7 puts vulnerability management, exposure management, managed detection and response, incident response, continuous red teaming and consulting-led testing on one contract, serving more than 11,500 customers. It also stewards Metasploit and Velociraptor, and states that its consultants "spend up to 20% of bench time focused on attacker research and skill development". For a team that wants one vendor across prevention, detection and response, that is a genuine advantage a specialist cannot replicate.
Which Rapid7 alternative publishes a fixed penetration testing price?
Three do. Stingrai publishes US$3,000 per Autonomous assessment and US$6,800 for Hybrid, each covering exactly one web application and its APIs, with monthly equivalents of US$450 and US$1,275 on a 12-month engagement. Cobalt publishes US$3,500 per test for its Autonomous Pentest as a limited-time offer. Intruder publishes AI pentesting from US$3,500 per test. NetSPI, BreachLock, Synack, NCC Group, Praetorian and Rapid7 itself all quote every engagement.
Which alternative is best for compliance evidence?
All eight produce reports used as evidence in SOC 2, ISO 27001 and PCI DSS programs. BreachLock is the fastest published route to a CREST-certified report against an audit date. NCC Group is the strongest fit where NCSC CHECK or a UK scheme is written into the requirement. Stingrai's penetration testing supports SOC 2, ISO 27001, HIPAA, PCI DSS 4.0, NIST SP 800-53 and 800-171, DORA and NIS2 programs, whether you buy a single annual engagement or a continuous program. Ask every vendor for a redacted sample report and confirm retest evidence is included.
Related Reading
The Bottom Line
Rapid7 earns its position by being the platform a great many security teams already run. If InsightVM and Exposure Command are your inventory of record and managed detection sits on the same contract, buying testing from the same vendor is a defensible decision, and the Metasploit lineage is not marketing.
Buyers keep comparing because penetration testing inside a platform company is a service line, priced by conversation, without published fix automation. For business logic and authorization depth at a published price, with the patch proposed in the pull request and a guarantee on the Autonomous tier, Stingrai is the closest like-for-like upgrade. Compare packages on the Stingrai pricing page, book a free scoping call, or send your scope through the Get a Quote form.



