Automotive penetration testing: what to buy, what it costs and what the rules say

By The PenTest Index · Offers and rules checked October 10, 2026

Automotive penetration testing is a hands-on attack test of a vehicle, one of its control units (ECUs), or the apps and servers around it. Which one you need depends on who asked for the report. One specialist, Block Harbor, publishes prices: from $30,000 for a remote test. UN R155 requires "appropriate and sufficient testing" but never names penetration testing.

So the first job is to work out which of four tests you are buying. The table below does that. After it come the rules in their own words, the published prices, nine providers side by side, and a scope brief you can copy.

Table columns: What you need to know; The test to buy; Where it happens; What you supply.
What you need to knowThe test to buyWhere it happensWhat you supply
Is this one unit safe? (a telematics box, head unit, gateway, charger)A unit test, often called ECU-levelA workbench or a remote rigSample units or firmware images, wiring details
Can an attacker move between units?A test of several units wired togetherA rigThe units and a wiring harness
Can someone get in from outside the car? (diagnostic port, Bluetooth, cellular, keys, updates)A unit, connected-service or whole-vehicle test, depending on the attack pathThe agreed unit or service setup, rig or real vehicleThe relevant units, vehicle or service access
Is our phone app, fleet portal or update server safe?An app, API or cloud testRemoteTest accounts
Do the tests we already ran cover the request?A review of your existing evidenceRemoteYour test reports

A parts supplier usually needs the first row. A vehicle maker heading for type approval needs testing suited to the vehicle type and its approval requirements. If you only own the app, you may not need a car specialist at all.

Testing only an app or API? Then this is a web, mobile or API test with car-shaped data in it. Our tool walks you through those questions and gives you a checklist to copy or print. It is free, asks for no email, and sends nothing to providers.

Find My PenTest Match

For a unit or a vehicle, keep reading. The tool does not list specialists for vehicles or devices, so this page does that work.

What is automotive penetration testing?

It is people attacking a vehicle or its parts on purpose, with written permission, to find weaknesses before a criminal does. Then they write up what they found and how to fix it.

A modern car is a network of small computers. Each one is an electronic control unit, or ECU, and each runs one or more jobs: brakes, door locks, the screen in the dash. They talk to each other over in-car networks such as CAN, LIN and Ethernet. A penetration tester tries to make one of those computers do something it should not, or to get from a harmless one to an important one.

Three things make it different from testing a website:

  • There is hardware. Testers may open the unit, connect to its ports and read its firmware (the software stored on the chip).
  • There is radio. Bluetooth, Wi-Fi, cellular and key fobs are all ways in.
  • There is safety. A test that crashes a web server is an annoyance. A test that confuses a brake controller in a moving car is not. Limits get agreed in writing first.

One more distinction to keep straight. A vulnerability scan is software checking for known problems. A penetration test is a person trying to break in. They are different purchases, and we explain the difference between a penetration test and a vulnerability scan on its own page.

If you came here to learn car hacking as a skill, this page is about buying a test. Look up the Car Hacking Village community for the hands-on side.

Does UN R155 require penetration testing?

No, not by name. UN Regulation No. 155 requires the vehicle maker to test before type approval, and leaves the method open. The word "penetration" does not appear in the regulation.

We read the regulation as published in the EU's Official Journal in January 2025, and the U.S. guidance from NHTSA. Here is what each one says.

Table columns: Source; What the text says; What that means for you.
SourceWhat the text saysWhat that means for you
UN R155, paragraph 7.3.6The vehicle manufacturer must perform "appropriate and sufficient testing" before type approvalTesting is required. The kind of testing is not fixed
UN R155, paragraph 5.1.3(d)Approval is refused if that testing was not doneThe duty sits with the vehicle maker
UN R155, paragraph 5.1.2The approval authority or its technical service also tests a vehicle, by samplingYour pentest report does not replace their checks
UN R155, paragraphs 7.2.2.5 and 7.3.2The manufacturer must identify and manage supplier-related risksThe supplier-risk duty sits with the vehicle maker. Your customer's contract can set your testing duties
UN R155, paragraph 1.1It applies to vehicle categories L, M, N and O fitted with at least one ECUCars, trucks, buses, trailers, and two- and three-wheelers are in its scope. Which markets apply it is a separate question
NHTSA best practices (September 2022), items G.13 and G.14Manufacturers "should" use penetration tests, with "qualified testers who have not been part of the development team"NHTSA calls this guidance "non-binding and voluntary." Not on the development team does not have to mean an outside company
ISO/SAE 21434NHTSA's guidance says the standard "recommends penetration testing" in item RC-10-12A recommendation, on NHTSA's reading. The standard is paid, and we did not read it ourselves

Two things follow.

First, be careful with sales pages. PCA Cyber Security's page says R155 and ISO/SAE 21434 "explicitly mandate penetration testing." The regulation we read does not use the word, and NHTSA describes the ISO item as a recommendation. Several other providers say their test "complies with" R155. A test can meet R155's testing requirement even when the rule does not prescribe the test method. What they can truthfully offer is evidence your recipient may accept.

Second, the person who decides what is enough is not the provider and not us. It is the approval authority, the technical service, or your customer. So ask them before you buy. You can copy this:

"Which product and software version must the test cover, what must the report show, who has to do the testing, and who decides whether it is enough?"

Their answer goes straight into your scope brief below.

How much does automotive penetration testing cost?

Of the nine providers we checked, one publishes prices. Block Harbor, a vehicle security firm in Detroit, lists these on its services page (US dollars, checked October 10, 2026):

Table columns: Block Harbor service; Published price; Stated timeline.
Block Harbor servicePublished priceStated timeline
Remote Penetration Assessment$30,000+2+ weeks; "from quotation to testing within 72 hours"
Penetration Assessment$50,000+4+ weeks
Fuzz Testing$20,000+Customer defined
Regression Testing$20,000+Customer defined
Reverse Engineering$50,000+Customer defined

Source: Block Harbor Red Team Services. Every figure has a plus sign. These are starting prices for that firm, not quotes for your project, and not a market average. The page does not say whether the standard assessment covers a single unit or a whole vehicle.

Fuzz testing, for the record, means throwing huge numbers of broken or unexpected messages at a unit to see what fails. It is a separate line here and at PlaxidityX, so do not assume it is inside a pentest price.

The other eight providers ask you to request a quote. We will not guess a "typical range" for them. What moves a quote is fairly plain: how many units and interfaces, whether a real vehicle is involved, how much you share (firmware, source code, diagnostic keys), whether the app and servers are included, and whether checking your fixes costs extra.

That last one is where budgets slip. Block Harbor's page does not say if a re-check of your fixes is part of the base price. It lists Regression Testing separately at $20,000+. If the re-check turns out to be that separate service, the remote test starts at $50,000 ($30,000 + $20,000) and the standard one at $70,000 ($50,000 + $20,000). That is our arithmetic on their published numbers, and it may not apply. Ask.

See Block Harbor's published prices

For prices on other kinds of testing, see our penetration testing cost page. A web-app price tells you nothing about a vehicle price.

Which automotive penetration testing companies fit your scope?

Here is what nine providers publish about their automotive offers. They are in alphabetical order, which is not a ranking. Everything in the table comes from each provider's own page on October 10, 2026. "Not stated" means we did not find it on that page. It does not mean they don't offer it.

Table columns: Provider; What their page says they test; Published price; Stated timing; Re-check of fixes.
ProviderWhat their page says they testPublished priceStated timingRe-check of fixes
AssuredSingle units or the full vehicle, in-car networks, wireless, backend, apps. Testing "in a rig, on a vehicle or via firmware images"Not statedNot stated"Verification testing" is listed under additional services
Block HarborVehicle systems: CAN, Ethernet, USB, Wi-Fi, Bluetooth, web API, mobile, hardware$30,000+ remote; $50,000+ standard2+ weeks remote; 4+ weeks standardNot stated. Regression Testing is a separate $20,000+ line
NetSPIMobile apps, desktop apps, connected environments, internal network, sensor dataNot statedNot statedNot stated
PCA Cyber SecurityWhole vehicle, any ECU, motorcycles, apps, backend systemsNot statedNot stated"Full support with remediation and retesting"; count and price not stated
PlaxidityXSeparate ECU-level and vehicle-level tests; code review and fuzz testing listed apartNot statedNot statedNot stated
PraetorianVehicle systems by goal. Examples include ECUs, CAN networks, key fobs, mobile app accounts. Its datasheet is reported to split work into targeted and broad assessmentsNot statedNot statedNot stated
QualysecUnit, vehicle, backend API, update pipeline. Unit work "without a physical vehicle" on a benchNot stated; fixed-price quote after a call2 to 6 weeks; report within five business days afterSays the re-test is "included in the base cost"
SGSSimulated-attack testing, plus review of test documents you already haveNot statedNot statedNot stated
VicOne (xScope)ECU, infotainment, over-the-air updates, whole vehicle, at three depthsNot statedNot statedNot stated

We have not bought, run or inspected any of these tests. The table shows what each company says about itself.

Where to start, by situation

  • You need a number for a budget this week. Block Harbor is the only one with a price. Ask what the base price covers and whether the re-check is in it.
  • You are a supplier with one unit and no vehicle. Assured and Qualysec both say unit work can be done on a bench. Qualysec states the re-test is included, with no price published.
  • You are heading for type approval. Assured lists witnessed audits for type approval under R155. PlaxidityX sells a separate vehicle-level test. Neither can promise approval; the authority decides.
  • Your unit talks to a server and both must be covered. Assured, Block Harbor, PCA and Qualysec name backend or API work on their automotive pages. For the others it is not ruled out, only not written down. Ask.
  • You build motorcycles or scooters. PCA names motorcycles as a target.
  • You already have test results. Ask SGS, or your report recipient, whether a review of that evidence could meet the request before you pay for a new test.
  • You already use NetSPI. Its automotive page links a brief that names control units and other hardware attack surfaces. Ask which are covered in your quote. See our NetSPI profile.

Assured's automotive testing page Block Harbor's red team services NetSPI's automotive testing page PCA's automotive testing page PlaxidityX's automotive testing page Praetorian's automotive testing page Qualysec's automotive testing page SGS's automotive penetration tests page VicOne's xScope page

A worked example: one telematics unit, six weeks

Say you make one telematics unit, the box that connects a car to the cellular network. Your carmaker customer wants an independent test report in six weeks. The unit talks to a test server you run. You have two bench units and no vehicle. Nothing may be done that destroys a unit. And you want your fixes checked again when they are ready.

This is a made-up brief. No provider has seen it or quoted for it.

What it calls for: a unit test on a bench plus a test of the server's API. It does not call for a whole-vehicle test, and a web-only quote would miss the unit.

We checked each condition against what providers publish. This is our Purchase Check: one requirement, one offer, one finding.

Table columns: Your condition; Offer; Finding; Why.
Your conditionOfferFindingWhy
Works on a bench, no vehicleAssuredSupportedPage says testing can be done "in a rig, on a vehicle or via firmware images"
Works on a bench, no vehicleQualysecSupportedPage says unit work can be done "without a physical vehicle"
Server API includedBlock HarborSupported as a listed activity"Web API" is in its test list. Your quote must still name your API
Complete price with re-checkBlock Harbor, remoteUnresolved$30,000+ to start. $50,000+ if the re-check is the separate $20,000+ service
Re-check includedQualysecSupported, price unresolvedPage says included. No price, count or deadline given
Report within six weeksBlock Harbor, remoteUnresolved"2+ weeks" is a floor, not a delivery date
Report within six weeksQualysecUnresolvedThe longest stated case is 6 weeks of testing plus five business days, about 7 weeks
No destructive workEvery offerUnresolvedNone of the pages addresses it. It has to be written into the agreement
Customer accepts the reportEvery offerUnresolvedOnly your customer can say

"Supported" means that one condition is backed by the provider's own page. It is not a verdict on the provider.

Where that leaves this buyer. Send the same brief to Block Harbor's remote offer and to Qualysec, and add Assured or PCA as a third. Block Harbor is the only one that gives you a price and a short timeline today. Qualysec is the only one that says in writing the re-check is included. One question settles most of it:

"For this unit and this API, on a bench, with no destructive work: what is the complete price including a re-check of our fixes, and on what date do we get the final report?"

If Block Harbor says the re-check is included, compare its scoped price and report date with Qualysec's fixed quote. If it is extra, compare its total with Qualysec's fixed quote. If anyone cannot commit to your date, they are out for this job, however good they are.

What should your automotive scope brief include?

A scope brief is one page that asks every provider the same question, so the answers line up. Without it you get three quotes for three different jobs. Copy the left column, replace the example with your own details, and send the same version to each provider.

Automotive scope brief: field and example for the made-up telematics unit.
FieldExample (the made-up telematics unit)
Why you need the test and who gets the reportCarmaker customer handoff. Customer to confirm what the report must show before work starts
What is being tested, with versionsOne telematics unit design, hardware revision A, firmware 2.3
Test setupBench, wiring harness, simulated signals from the rest of the car. Two units available. No vehicle
Interfaces in scopeCAN, diagnostic port, cellular, Bluetooth, USB
Apps and servers in scopeOne staging API, one test tenant, two user roles. No real customer data
Questions the test must answerCan someone send commands they shouldn't? Read data they shouldn't? Load a tampered update?
What you will shareArchitecture and interface documents, firmware, test accounts. Source code: undecided
What is out of scopeOther units and whole-vehicle behavior. The report must not claim anything about them
Limits and safetyNo destructive work. Opening a unit or changing its firmware needs written approval first. Named contact who can stop the test
Who owns whatList the owner of the unit, the server and any third-party service, such as the cellular carrier. Confirm who can authorize each target and follow each third party's testing rules
What the report must containSee the report list below
DatesReport due in six weeks. Fixes ready about day 45. Re-check needed after that
Price to be itemizedSetup, testing, reporting, shipping or travel, re-check, any required platform fee, taxes, optional extras. Currency and payment dates

This brief is a buying document. It is not permission to test.

This brief is a buying document. It is not permission to test. Written permission has to name the actual units, vehicles, servers and activities, and come from a party authorized to permit the testing. If a cellular carrier or cloud host sits in the path, their rules apply too. Liability for damaged hardware belongs in the contract, and that part is worth a lawyer's read. Our rules of engagement page covers the document that sets those limits, and our penetration testing scope page has a filled-in example for software.

Before you send the brief, it helps to settle who reads the report and how you will compare the answers. Find My PenTest Match has those questions in a general checklist you can copy or print. It will not list automotive specialists; use the table above for that.

Build your scope checklist

What do you have to hand over?

For a unit test: the units or firmware images required for the agreed scope, and the documents that explain how the unit is wired and what it talks to. For a vehicle test, a vehicle or a full test rig.

Assured's page describes arranging "documentation, architecture/network maps, service descriptions and test access" at the scoping stage, and handing over "access credentials or diagnostic keys" at kickoff. Qualysec's page says unit-level work can be done from bench units and firmware images, while tests across the whole car need "a physical vehicle" or a full test rig.

Three practical points:

  1. Ask how many units they need and whether any work could damage them. If so, plan spares and say in the brief what is allowed.
  2. Decide how much to share. Testers given firmware and documents start further ahead than testers given a sealed box. Ask each provider what changes in coverage if you hold something back.
  3. Name one engineer who can answer questions the same day. Slow answers eat test time you paid for.

How long does automotive penetration testing take?

Two providers publish numbers. Block Harbor says 2+ weeks for a remote assessment and 4+ weeks for a standard one. Qualysec says two to six weeks, with the report within five business days after testing ends.

Those are testing times, not your full calendar. Add time to sign the contract, ship units, fix what is found, and re-check the fixes. Ask every provider for six dates in writing: units received, test start, test end, final report, the last day you can ask for a re-check, and re-check report.

What should the report show?

Enough for your customer or the approval authority to see what was tested, on which version, how, what was found, and what was left out. Ask for these before you sign:

  • The exact hardware and firmware versions tested, and the test setup
  • What was in scope, what was out, and what was simulated
  • The methods used and the time spent
  • Each finding with proof someone else can repeat, and what an attacker would need to pull it off
  • The effect of each finding and how to fix it
  • What was not tested and why
  • For a re-check: which version was re-tested and the status of each finding

Then ask each provider: "Can you share a sample report with the details removed for this type of test, and tell us which of these parts ours will include?" Assured says its re-check results come as "a concise report suitable for sharing with regulators, partners or internal stakeholders." Praetorian lists an executive summary, a presentation and a technical findings report. Block Harbor links a report example from its services page; we have not reviewed it.

A report that finds nothing is not proof that nothing is there. It means these testers, in this time, with this access, did not get in. Our penetration testing report page goes deeper on what to check.

Common questions

Does automotive penetration testing require a physical vehicle?

Not always. A single unit can be tested on a bench with firmware and a wiring setup. Attacks that cross several systems need a setup covering those systems. An entry point outside the car may be tested on a relevant unit, rig or connected service. Qualysec and Assured both describe it this way on their pages.

Can a general penetration testing firm do it?

For the app, API and cloud parts, often yes. For the unit itself, ask who will do the work and which vehicle units they have tested before. Hardware and in-car networks are a separate skill from web testing, and a company name does not tell you who is assigned to your job.

We are a supplier. Does R155 apply to us directly?

The supplier-risk duties are written for the vehicle manufacturer. It must manage supplier risks, and your customer's contract may pass testing requirements to you. R155 also requires the manufacturer or its suppliers to make sufficient information available for approval checks where it is protected intellectual property or specific know-how. Read your customer's requirement, not just the regulation.

Is a bench test enough?

It can be, for a question about one unit. The report should say what was simulated and what was not tested. Whether your customer also wants testing in a vehicle is their call, so ask them first.

Already have a quote?

Check it against the brief line by line. Anything your brief lists that the quote does not mention is a question, not a yes. Our penetration testing quote page shows how to compare proposals.

How we checked

We read each provider's public automotive page, UN Regulation No. 155 as published in the Official Journal of the European Union (2025/5), and NHTSA's September 2022 guidance, all on October 10, 2026. We did not buy a test, speak to a provider, or read ISO/SAE 21434 itself. Prices and terms change, and a public page is not a contract, so get the terms in writing.

The PenTest Index is the independent buyer's index for penetration testing. We compare specific offers against stated buying requirements, show our sources and check dates, and keep compensation out of eligibility, fit and order. We have no commercial relationship with any provider on this page. See our method and how we make money.

Sources

All checked October 10, 2026.