This site may contain affiliate or referral links. If you buy through one, we may be compensated. How we make money

Automated penetration testing: what it is, what it costs and when it counts

By The PenTest Index · Offers and prices checked October 9, 2026

Automated penetration testing is software that attacks your systems to prove what can be exploited, without a person doing each step. The label covers three purchases: a scanner, a platform you run, and an AI-led test sold with a report. Astra lists one at $2,999 a year; whether it counts as your pentest depends on who must accept the report.

Our short verdict: it is a good buy for testing often between human-led tests. As the only report you hand to an auditor or customer, ask them first. One vendor, Cobalt, says plainly that its own autonomous test is not for compliance. Several others promise auditor-ready or compliance-ready reports. The prices, the limits and the question to ask are all below.

What is automated penetration testing?

It is security testing where software, not a person, finds weaknesses and then tries to use them. A penetration test (pentest) is an attempt to break in the way a real attacker would. NIST describes it as testing that mimics real attacks and looks for "combinations of vulnerabilities" that give more access than one weakness alone (NIST glossary, SP 800-115, read October 9, 2026).

OWASP now publishes an incubator Autonomous Penetration Testing Standard for platform governance, but it is not a testing methodology and does not make these offers equivalent (OWASP APTS, read October 9, 2026). So sellers still use the same words for three different products. Five questions tell you which one is in front of you.

Table columns: Ask the seller; A scanner you run; A platform you run; An AI-led test sold with a report.
Ask the sellerA scanner you runA platform you runAn AI-led test sold with a report
Does it try to exploit what it finds and link steps together?Sometimes. Active scanners may send attack payloads or validate a finding, but that is narrower than a scoped penetration test.YesYes
Who runs it?YouYouThe provider
What is the price unit?Per month or year, per targetPer year, per assetPer test, or per target per year
Is a person involved, and doing what?Usually no; some plans add expert reviewUsually noIt varies: directing the test, rechecking fixes, or no active supervision stated
What do you get?A list of findingsAttack paths with proofA report written to hand to someone

Think of it this way. A scanner is a smoke detector. A platform is a guard who walks the building every night. A human-led test is a locksmith you hire to actually get in. Each is useful. They are not the same job.

Is it just a vulnerability scan?

Sometimes it is, and one vendor says so itself. Intruder's page on the topic says automated pen-testing tools "are most commonly known as vulnerability scanners" (Intruder, read October 9, 2026).

A vulnerability scan checks for known weaknesses and may actively probe or validate some findings. The first row still matters, but exploitation alone does not make a scan a full penetration test: scope, chaining, judgment and the report also matter. If it only repeats scanner checks and lists findings, you are buying a scan. That can still be the right purchase. Just pay scan prices for it. Our guide to penetration testing vs vulnerability scanning goes deeper.

How much does automated penetration testing cost?

For the named web-app offers compared below, published annual and per-test prices run from $2,999 a year to $4,181 or more per test. Some network platforms are sold in annual asset packages, starting at $25,000 a year on one public listing. Most of the platform vendors in this table publish no price at all.

Every figure below is the provider's own published price, shown with a dollar sign as displayed, read on October 9, 2026. None is a quote for your scope. An unknown charge is not zero.

AI-led tests sold with a report (web apps)

Table columns: Offer; Published price; What it covers; The condition that changes the purchase.
OfferPublished priceWhat it coversThe condition that changes the purchase
Aikido, "Typical Pentest"$4,000 per assessmentOne application and one set of APIsWhite-box by default, which means you share your source code. Black-box and grey-box cost extra; the amount is not stated. Free re-testing of findings from the initial pentest "for up to 6 months." Aikido advertises "No High or Critical Finding = Don't Pay." Prices exclude withholding, import, sales, VAT and other local taxes.
Astra, Pentest Auto$2,999 per year, per targetOne web or SaaS app, including the APIs it uses, is one targetTesting is by autonomous agents. One human re-scan to check fixes. The standard request window is 30 days from reported vulnerabilities; Astra says extensions may be granted case by case, and extra manual re-scans can be purchased.
Cobalt, Autonomous Pentest$3,500 per test, limited-time promotionOne externally facing web app with fewer than 25 pages, up to 2 roles, and a username and password login without MFA or magic linksThe test must start and finish before December 31, 2026. The price after that is not published. For existing credit customers, the exact credits debited may vary with the contracted credit rate. Cobalt says this offer "does not produce compliance attestation reports."
Intruder, AI web app pentest$3,500 per test; $12,000 for four testsWhite-box web app testYou must connect your code repository. Tests must be used within 1 year of purchase. The pricing page advertises "Unlimited retesting," but the AI Pentest Terms say one test and one report are included and a repeat, re-run or extension needs another order. Confirm what fix verification is included. Full payment is due in advance, taxes are extra, and unused tests receive no refund or credit. Refund if your auditor rejects the report.
Synack, Sara PentestFrom $4,181 per testAI-led test, 4 to 5 day assessmentThe Synack Platform is required and is "a separate line item." A Basic Platform is listed at no cost. Which tier you need is not stated, so the total is incomplete.
XBOWPentest On-Demand launched with a provider-published starting price of $4,000; the current pricing page is quote-based. An AWS Marketplace Enterprise listing shows a credit package at $50,000 for 12 months.Web applicationsThe $4,000 figure is a November 2025 launch "starts at" price, not a current fixed quote. The AWS listing sells Attack Credits and lists overage at $0.01 per unit; XBOW's documentation warns that incomplete assessments can waste attack credits. Additional AWS infrastructure costs may apply. How many credits one completed test uses is not published, so the Enterprise package cannot be turned into a per-test price.

Sources: Aikido pricing, Astra pricing and re-scan rules, Cobalt pricing, setup guide and service page, Intruder pricing and AI Pentest Terms, Synack pricing, XBOW Pentest On-Demand announcement, current pricing, assessment guidance and AWS Marketplace listing.

See Aikido's pentest pricing See Astra's plans See Cobalt's Autonomous Pentest offer See Intruder's AI pentest pricing See Synack's packages Ask XBOW for a quote

We also keep longer profiles of Astra, Cobalt, Synack and XBOW.

Platforms you run yourself (mostly networks)

Table columns: Offer; Published price; Unit; What to know.
OfferPublished priceUnitWhat to know
Horizon3.ai, NodeZero Core$25,000 for 12 monthsPackage of 500 assetsFrom Horizon3.ai's AWS Marketplace listing. Its own website shows the packages with no prices. Pro is $32,500 and Elite is $42,500 for the same 500 assets. Web app testing is a separate $10,000 line.
Horizon3.ai, NodeZero Flex$15,000 for 12 months1,000 assets, described as a one-time testSame listing.
Kaseya (Vonahi), vPenTestQuote requiredNot publishedThe vendor sends pricing requests to a quote form.
PenteraQuote requiredNot publishedWe found no public pricing page.
PicusQuote requiredAnnual, per PicusPicus says pricing is "usually quote-based."

Sources: NodeZero on AWS Marketplace, Horizon3.ai packages, Picus on pricing.

See the NodeZero listing on AWS Marketplace

What the price leaves out

We did the arithmetic so you don't have to.

  • NodeZero Core works out to $50 per asset per year ($25,000 ÷ 500). Pro is $65 and Elite is $85. You buy the 500-asset package, not single assets. AWS notes that extra infrastructure costs may apply.
  • Intruder's four-test pack saves $2,000 only if you use all four. Four separate $3,500 tests cost $14,000; the pack is $12,000. Three separate tests cost $10,500, so the pack costs $1,500 more if you use only three. Tests must be used within one year, and unused tests receive no refund or credit.
  • Synack's $4,181 may be the total if the no-cost Basic Platform is enough. The platform is a separate line item, and the page does not state which tier Sara requires. Until Synack confirms that, the total is incomplete.
  • Cobalt's $3,500 has a finish line. The test must be completed before December 31, 2026. Count back from that date.
  • Astra's scanner is cheaper by the year. $199 a month is $2,388 over 12 months. The annual plan is $1,999. That is $389 less. And it is a scanner, not the $2,999 autonomous test.

For human-led prices to set these against, see penetration testing cost.

Will an auditor or customer accept an automated penetration test?

For a customer or auditor request, ask the person who receives the report; for PCI DSS, the standard's requirements apply. The vendors themselves disagree, so ask before you buy.

Here is what we could read on October 9, 2026.

Table columns: Who says it; What they say; What kind of evidence it is.
Who says itWhat they sayWhat kind of evidence it is
PCI Security Standards Council, Penetration Testing Guidance v1.1 (September 2017)A penetration test is "a manual process that may include the use of vulnerability scanning or other automated tools." It is due "at least annually and upon significant changes."The Council's own guidance document. It predates the current PCI DSS version. Source
PCI DSS v4.0.1, Requirement 11.4 (June 2024)Its guidance says, "Penetration testing is a highly manual process." Some automated tools may be used, but the tester uses system knowledge and often chains exploits. Requirements 11.4.2 and 11.4.3 require internal and external testing at least once every 12 months and after significant changes, by a qualified internal resource or qualified external third party with organizational independence; a QSA or ASV is not required.The current standard's own requirement and guidance. Source
Cobalt, about its own Autonomous PentestIt is "not a replacement for compliance-bound pentesting" and "does not produce compliance attestation reports." Cobalt adds that most major frameworks, including PCI DSS, SOC 2, ISO 27001 and HIPAA, "require human-led pentesting with formal attestation."A vendor's statement. The first part describes its own product. The framework claim is Cobalt's view; we have not confirmed it for each framework. Source
Intruder and Aikido, about their own AI testsIntruder says its reports "can be used as evidence for ISO 27001 and SOC2" and offers a refund if your auditor rejects one. Aikido advertises "auditor-accepted reports."Vendor statements. A refund gets your money back. It does not get your audit done on time. Intruder, Aikido

What we take from this:

  • Card data in scope (PCI DSS): plan on testing led by a qualified, organizationally independent person for the required pentest. That can be a qualified internal resource or a qualified external third party; it need not be a QSA or ASV. Human testers can and do use automated tools. An automated-only report is a risk you don't need. The standard's requirements control; confirm your validation path with the organization that manages your PCI DSS compliance program and, if you use one, your assessor.
  • SOC 2, ISO 27001 or a customer questionnaire: the sellers don't agree with each other, so the label on the product tells you nothing. Your auditor or customer decides. Our page on SOC 2 penetration testing covers that case.
  • Your own security team: there is no outside recipient's acceptance rule to meet. Buy on what gets tested.

Send this before you spend anything:

"Will you accept a penetration test report where the testing was done by automated or AI tooling? If yes, what human involvement and tester qualifications must the report show?"

  • "Yes, no conditions." The AI-led offers above are worth a close look.
  • "Yes, if a qualified person directs or reviews it." Keep only offers that state that human role, and get it in writing for your order.
  • "No." Use a human-led test. Use automated testing in between if you want more frequent checks.

If the answer is no, or you now need to compare several offers fairly, write your scope down once and send every provider the same thing. That way the answers line up. Our free scope checklist walks you through it for a web app or API. You can copy or print it, and it asks for no contact details.

Find My PenTest Match

Does it cover your API and every user role?

Not always, and the limits are in the fine print. Check three things: how many roles, what kind of login, and whether your API counts as its own target.

  • Cobalt's Autonomous Pentest takes up to 2 roles, fewer than 25 pages, and a username and password login without MFA or magic links. Its setup guide says only web assets are supported, not APIs as their own asset. A third role, an MFA-only login or a magic-link login rules it out.
  • Astra counts one web or SaaS app, including the APIs it uses, as one target. A customer dashboard and an admin dashboard with different login pages are two targets, so two prices.
  • Aikido's $4,000 price is for one application and one set of APIs.

A "role" is a type of user, such as customer or admin. Testing with roles matters because many serious flaws are one user reaching another user's data. Ask each seller which roles the test logs in as, and whether it tries to cross from one to another. More on writing this down in our scope guide.

Can it replace manual testing?

For repeat checks of known weakness types, largely yes. For flaws in how your product is meant to work, and for reports someone else must accept, not on what we can verify today.

Table columns: Automation is strong at; A person still matters for.
Automation is strong atA person still matters for
Running the same checks every week or after every releaseBusiness-logic flaws, such as a refund flow that can be abused
Covering many apps or hundreds of hosts at onceJudging what an odd result means for your business
Rechecking a fix within minutesBeing the named, qualified tester a recipient asks for
Price per runScope that doesn't fit a setup form

Even sellers draw this line. Picus, which sells a platform, says automated testing does not replace red teams, and names "business-logic abuse" as work that stays with people (Picus, read October 9, 2026). Cobalt says its autonomous test is for "breadth across the portfolio" and human-led testing is for "targeted depth on critical assets."

We have not run these products, so we make no claim about which one finds more.

Which automated option fits you?

Start with who reads the report and what is being tested. Then rule offers out by their stated limits. Here is how that works for one made-up buyer.

Say you run a 30-person SaaS company. You have one web app with two user roles and the API it uses. A SOC 2 audit is coming in March. You won't share source code. Your team needs about 45 days to fix what a test finds.

Table columns: What this buyer needs; Offer; Finding; Why; Ask this.
What this buyer needsOfferFindingWhyAsk this
A report for the auditorCobalt AutonomousMismatchCobalt says it does not produce compliance attestation reportsAsk Cobalt about its human-led test instead
No source code sharedIntruderMismatchYou must connect a code repository"Do you offer a test without repository access?"
No source code sharedAikidoUnresolvedWhite-box is the $4,000 default; other modes cost extra, amount not stated"What is the price for a grey-box test of one app and its API?"
A fix check on day 45Astra Pentest AutoUnresolvedThe standard re-scan window is 30 days, but Astra says extensions may be granted case by case"Can you extend to 45 days, and what does it cost?"
A fix check on day 45AikidoSupportedRe-testing of findings from the initial pentest for up to 6 monthsNothing more on this point
A complete priceSynack SaraUnresolvedThe applicable platform tier is not stated; Basic Platform is listed at no cost"Please itemize the test and the platform charge."
The auditor accepts AI-led testingAll of themUnresolvedOnly the auditor can saySend the question above

For this buyer: ask the auditor first. That answer decides everything. If the answer is yes, Aikido and Synack Sara deserve the closer look, each with one question to settle. Astra also remains possible if it confirms a 45-day re-scan extension. If the buyer were willing to share code, Intruder would come back in only after it confirms the day-45 fix check and resolves the conflict between its pricing page and AI Pentest Terms. If the test were only for the buyer's own developers, with no auditor, Cobalt's $3,500 offer could fit if the app is externally facing, has fewer than 25 pages, uses username and password without MFA or magic links, and finishes by December 31, 2026.

"Supported" here means that one condition is met by the provider's published terms. It is not a verdict on the whole offer or on testing quality.

Now find your own row:

  • You handle card data. Use a qualified, organizationally independent internal resource or a qualified external third party for the PCI requirement. Add automation between tests if you want.
  • One web app, and your recipient says yes. Compare the AI-led offers on three things: the access they need, the retest window, and the complete price.
  • A network of hundreds of machines you want checked all year. Look at a platform. Expect an annual, per-asset price and a quote. NodeZero's public listing gives you a number to budget against.
  • You already have a scanner, or a test came bundled with your compliance tool. Put it through the five questions near the top of this page before you buy anything. You may already be covered, or you may find it is a scan.
  • You don't know who will read the report. Find that out first. It is the one fact that changes the answer.

What should you confirm before you order?

Six things, in writing, on one order. These work for a new provider or for checking a deal you already have.

  1. Scope. "Which apps, APIs, user roles and environments are included? How will the report show what was not reached?"
  2. Access. "What accounts, source code access and test data do you need from us?"
  3. Who does the work. "What is done by software, what is done by a person, and who reviews the findings?"
  4. Dates. "When does testing start and when is the report delivered?"
  5. Retest. "What fix checks are included, for how long, and what needs a new paid order?"
  6. Full cost. "What is the total, including platform fees, taxes, minimum term and renewal?"

These questions help you buy. They do not give anyone permission to test. Automated tools run real attacks, so agree the targets, the timing and a stop contact in writing with whoever owns the systems before anything runs.

Comparing written offers? Our quote guide shows how to line them up.

How we checked

We read each provider's own pricing and product pages on October 9, 2026, and applied their published terms to one made-up buyer. Every provider price and offer term here is provider-published. We did not buy or run any of these products, and we do not rate testing quality. Where a fact was missing we wrote "not stated" instead of guessing. Offers are listed A to Z, not ranked. Payment plays no part in which offers appear. More in our methodology and how we make money.

A few more questions

Is AI pentesting the same as automated penetration testing?

Mostly, in how the words are sold. "AI pentest" usually means the third kind: a test run by AI agents and sold with a report. Use the same five questions to see what you are getting.

How is it different from breach and attack simulation?

They answer different questions. Picus puts it this way: automated pentesting proves whether a weakness can be exploited, while breach and attack simulation checks whether your defenses catch known attack behavior.

Are there free automated penetration testing tools?

Yes. OWASP Nettacker, for example, describes itself as an open-source automated penetration testing framework and vulnerability scanner. OWASP Nettacker is a tool you run yourself. Its output is not an independent third-party report for someone else. If you want to learn the process, see how to do a penetration test.

Sources

All read October 9, 2026 unless noted.