Automotive penetration testing: what to buy, what it costs and what the rules say
By The PenTest Index · Offers and rules checked October 10, 2026
Automotive penetration testing is a hands-on attack test of a vehicle, one of its control units (ECUs), or the apps and servers around it. Which one you need depends on who asked for the report. One specialist, Block Harbor, publishes prices: from $30,000 for a remote test. UN R155 requires "appropriate and sufficient testing" but never names penetration testing.
So the first job is to work out which of four tests you are buying. The table below does that. After it come the rules in their own words, the published prices, nine providers side by side, and a scope brief you can copy.
| What you need to know | The test to buy | Where it happens | What you supply |
|---|---|---|---|
| Is this one unit safe? (a telematics box, head unit, gateway, charger) | A unit test, often called ECU-level | A workbench or a remote rig | Sample units or firmware images, wiring details |
| Can an attacker move between units? | A test of several units wired together | A rig | The units and a wiring harness |
| Can someone get in from outside the car? (diagnostic port, Bluetooth, cellular, keys, updates) | A unit, connected-service or whole-vehicle test, depending on the attack path | The agreed unit or service setup, rig or real vehicle | The relevant units, vehicle or service access |
| Is our phone app, fleet portal or update server safe? | An app, API or cloud test | Remote | Test accounts |
| Do the tests we already ran cover the request? | A review of your existing evidence | Remote | Your test reports |
A parts supplier usually needs the first row. A vehicle maker heading for type approval needs testing suited to the vehicle type and its approval requirements. If you only own the app, you may not need a car specialist at all.
Testing only an app or API? Then this is a web, mobile or API test with car-shaped data in it. Our tool walks you through those questions and gives you a checklist to copy or print. It is free, asks for no email, and sends nothing to providers.
For a unit or a vehicle, keep reading. The tool does not list specialists for vehicles or devices, so this page does that work.
What is automotive penetration testing?
It is people attacking a vehicle or its parts on purpose, with written permission, to find weaknesses before a criminal does. Then they write up what they found and how to fix it.
A modern car is a network of small computers. Each one is an electronic control unit, or ECU, and each runs one or more jobs: brakes, door locks, the screen in the dash. They talk to each other over in-car networks such as CAN, LIN and Ethernet. A penetration tester tries to make one of those computers do something it should not, or to get from a harmless one to an important one.
Three things make it different from testing a website:
- There is hardware. Testers may open the unit, connect to its ports and read its firmware (the software stored on the chip).
- There is radio. Bluetooth, Wi-Fi, cellular and key fobs are all ways in.
- There is safety. A test that crashes a web server is an annoyance. A test that confuses a brake controller in a moving car is not. Limits get agreed in writing first.
One more distinction to keep straight. A vulnerability scan is software checking for known problems. A penetration test is a person trying to break in. They are different purchases, and we explain the difference between a penetration test and a vulnerability scan on its own page.
If you came here to learn car hacking as a skill, this page is about buying a test. Look up the Car Hacking Village community for the hands-on side.
Does UN R155 require penetration testing?
No, not by name. UN Regulation No. 155 requires the vehicle maker to test before type approval, and leaves the method open. The word "penetration" does not appear in the regulation.
We read the regulation as published in the EU's Official Journal in January 2025, and the U.S. guidance from NHTSA. Here is what each one says.
| Source | What the text says | What that means for you |
|---|---|---|
| UN R155, paragraph 7.3.6 | The vehicle manufacturer must perform "appropriate and sufficient testing" before type approval | Testing is required. The kind of testing is not fixed |
| UN R155, paragraph 5.1.3(d) | Approval is refused if that testing was not done | The duty sits with the vehicle maker |
| UN R155, paragraph 5.1.2 | The approval authority or its technical service also tests a vehicle, by sampling | Your pentest report does not replace their checks |
| UN R155, paragraphs 7.2.2.5 and 7.3.2 | The manufacturer must identify and manage supplier-related risks | The supplier-risk duty sits with the vehicle maker. Your customer's contract can set your testing duties |
| UN R155, paragraph 1.1 | It applies to vehicle categories L, M, N and O fitted with at least one ECU | Cars, trucks, buses, trailers, and two- and three-wheelers are in its scope. Which markets apply it is a separate question |
| NHTSA best practices (September 2022), items G.13 and G.14 | Manufacturers "should" use penetration tests, with "qualified testers who have not been part of the development team" | NHTSA calls this guidance "non-binding and voluntary." Not on the development team does not have to mean an outside company |
| ISO/SAE 21434 | NHTSA's guidance says the standard "recommends penetration testing" in item RC-10-12 | A recommendation, on NHTSA's reading. The standard is paid, and we did not read it ourselves |
Two things follow.
First, be careful with sales pages. PCA Cyber Security's page says R155 and ISO/SAE 21434 "explicitly mandate penetration testing." The regulation we read does not use the word, and NHTSA describes the ISO item as a recommendation. Several other providers say their test "complies with" R155. A test can meet R155's testing requirement even when the rule does not prescribe the test method. What they can truthfully offer is evidence your recipient may accept.
Second, the person who decides what is enough is not the provider and not us. It is the approval authority, the technical service, or your customer. So ask them before you buy. You can copy this:
"Which product and software version must the test cover, what must the report show, who has to do the testing, and who decides whether it is enough?"
Their answer goes straight into your scope brief below.
How much does automotive penetration testing cost?
Of the nine providers we checked, one publishes prices. Block Harbor, a vehicle security firm in Detroit, lists these on its services page (US dollars, checked October 10, 2026):
| Block Harbor service | Published price | Stated timeline |
|---|---|---|
| Remote Penetration Assessment | $30,000+ | 2+ weeks; "from quotation to testing within 72 hours" |
| Penetration Assessment | $50,000+ | 4+ weeks |
| Fuzz Testing | $20,000+ | Customer defined |
| Regression Testing | $20,000+ | Customer defined |
| Reverse Engineering | $50,000+ | Customer defined |
Source: Block Harbor Red Team Services. Every figure has a plus sign. These are starting prices for that firm, not quotes for your project, and not a market average. The page does not say whether the standard assessment covers a single unit or a whole vehicle.
Fuzz testing, for the record, means throwing huge numbers of broken or unexpected messages at a unit to see what fails. It is a separate line here and at PlaxidityX, so do not assume it is inside a pentest price.
The other eight providers ask you to request a quote. We will not guess a "typical range" for them. What moves a quote is fairly plain: how many units and interfaces, whether a real vehicle is involved, how much you share (firmware, source code, diagnostic keys), whether the app and servers are included, and whether checking your fixes costs extra.
That last one is where budgets slip. Block Harbor's page does not say if a re-check of your fixes is part of the base price. It lists Regression Testing separately at $20,000+. If the re-check turns out to be that separate service, the remote test starts at $50,000 ($30,000 + $20,000) and the standard one at $70,000 ($50,000 + $20,000). That is our arithmetic on their published numbers, and it may not apply. Ask.
See Block Harbor's published prices
For prices on other kinds of testing, see our penetration testing cost page. A web-app price tells you nothing about a vehicle price.
Which automotive penetration testing companies fit your scope?
Here is what nine providers publish about their automotive offers. They are in alphabetical order, which is not a ranking. Everything in the table comes from each provider's own page on October 10, 2026. "Not stated" means we did not find it on that page. It does not mean they don't offer it.
| Provider | What their page says they test | Published price | Stated timing | Re-check of fixes |
|---|---|---|---|---|
| Assured | Single units or the full vehicle, in-car networks, wireless, backend, apps. Testing "in a rig, on a vehicle or via firmware images" | Not stated | Not stated | "Verification testing" is listed under additional services |
| Block Harbor | Vehicle systems: CAN, Ethernet, USB, Wi-Fi, Bluetooth, web API, mobile, hardware | $30,000+ remote; $50,000+ standard | 2+ weeks remote; 4+ weeks standard | Not stated. Regression Testing is a separate $20,000+ line |
| NetSPI | Mobile apps, desktop apps, connected environments, internal network, sensor data | Not stated | Not stated | Not stated |
| PCA Cyber Security | Whole vehicle, any ECU, motorcycles, apps, backend systems | Not stated | Not stated | "Full support with remediation and retesting"; count and price not stated |
| PlaxidityX | Separate ECU-level and vehicle-level tests; code review and fuzz testing listed apart | Not stated | Not stated | Not stated |
| Praetorian | Vehicle systems by goal. Examples include ECUs, CAN networks, key fobs, mobile app accounts. Its datasheet is reported to split work into targeted and broad assessments | Not stated | Not stated | Not stated |
| Qualysec | Unit, vehicle, backend API, update pipeline. Unit work "without a physical vehicle" on a bench | Not stated; fixed-price quote after a call | 2 to 6 weeks; report within five business days after | Says the re-test is "included in the base cost" |
| SGS | Simulated-attack testing, plus review of test documents you already have | Not stated | Not stated | Not stated |
| VicOne (xScope) | ECU, infotainment, over-the-air updates, whole vehicle, at three depths | Not stated | Not stated | Not stated |
We have not bought, run or inspected any of these tests. The table shows what each company says about itself.
Where to start, by situation
- You need a number for a budget this week. Block Harbor is the only one with a price. Ask what the base price covers and whether the re-check is in it.
- You are a supplier with one unit and no vehicle. Assured and Qualysec both say unit work can be done on a bench. Qualysec states the re-test is included, with no price published.
- You are heading for type approval. Assured lists witnessed audits for type approval under R155. PlaxidityX sells a separate vehicle-level test. Neither can promise approval; the authority decides.
- Your unit talks to a server and both must be covered. Assured, Block Harbor, PCA and Qualysec name backend or API work on their automotive pages. For the others it is not ruled out, only not written down. Ask.
- You build motorcycles or scooters. PCA names motorcycles as a target.
- You already have test results. Ask SGS, or your report recipient, whether a review of that evidence could meet the request before you pay for a new test.
- You already use NetSPI. Its automotive page links a brief that names control units and other hardware attack surfaces. Ask which are covered in your quote. See our NetSPI profile.
Assured's automotive testing page Block Harbor's red team services NetSPI's automotive testing page PCA's automotive testing page PlaxidityX's automotive testing page Praetorian's automotive testing page Qualysec's automotive testing page SGS's automotive penetration tests page VicOne's xScope page
A worked example: one telematics unit, six weeks
Say you make one telematics unit, the box that connects a car to the cellular network. Your carmaker customer wants an independent test report in six weeks. The unit talks to a test server you run. You have two bench units and no vehicle. Nothing may be done that destroys a unit. And you want your fixes checked again when they are ready.
This is a made-up brief. No provider has seen it or quoted for it.
What it calls for: a unit test on a bench plus a test of the server's API. It does not call for a whole-vehicle test, and a web-only quote would miss the unit.
We checked each condition against what providers publish. This is our Purchase Check: one requirement, one offer, one finding.
| Your condition | Offer | Finding | Why |
|---|---|---|---|
| Works on a bench, no vehicle | Assured | Supported | Page says testing can be done "in a rig, on a vehicle or via firmware images" |
| Works on a bench, no vehicle | Qualysec | Supported | Page says unit work can be done "without a physical vehicle" |
| Server API included | Block Harbor | Supported as a listed activity | "Web API" is in its test list. Your quote must still name your API |
| Complete price with re-check | Block Harbor, remote | Unresolved | $30,000+ to start. $50,000+ if the re-check is the separate $20,000+ service |
| Re-check included | Qualysec | Supported, price unresolved | Page says included. No price, count or deadline given |
| Report within six weeks | Block Harbor, remote | Unresolved | "2+ weeks" is a floor, not a delivery date |
| Report within six weeks | Qualysec | Unresolved | The longest stated case is 6 weeks of testing plus five business days, about 7 weeks |
| No destructive work | Every offer | Unresolved | None of the pages addresses it. It has to be written into the agreement |
| Customer accepts the report | Every offer | Unresolved | Only your customer can say |
"Supported" means that one condition is backed by the provider's own page. It is not a verdict on the provider.
Where that leaves this buyer. Send the same brief to Block Harbor's remote offer and to Qualysec, and add Assured or PCA as a third. Block Harbor is the only one that gives you a price and a short timeline today. Qualysec is the only one that says in writing the re-check is included. One question settles most of it:
"For this unit and this API, on a bench, with no destructive work: what is the complete price including a re-check of our fixes, and on what date do we get the final report?"
If Block Harbor says the re-check is included, compare its scoped price and report date with Qualysec's fixed quote. If it is extra, compare its total with Qualysec's fixed quote. If anyone cannot commit to your date, they are out for this job, however good they are.
What should your automotive scope brief include?
A scope brief is one page that asks every provider the same question, so the answers line up. Without it you get three quotes for three different jobs. Copy the left column, replace the example with your own details, and send the same version to each provider.
| Field | Example (the made-up telematics unit) |
|---|---|
| Why you need the test and who gets the report | Carmaker customer handoff. Customer to confirm what the report must show before work starts |
| What is being tested, with versions | One telematics unit design, hardware revision A, firmware 2.3 |
| Test setup | Bench, wiring harness, simulated signals from the rest of the car. Two units available. No vehicle |
| Interfaces in scope | CAN, diagnostic port, cellular, Bluetooth, USB |
| Apps and servers in scope | One staging API, one test tenant, two user roles. No real customer data |
| Questions the test must answer | Can someone send commands they shouldn't? Read data they shouldn't? Load a tampered update? |
| What you will share | Architecture and interface documents, firmware, test accounts. Source code: undecided |
| What is out of scope | Other units and whole-vehicle behavior. The report must not claim anything about them |
| Limits and safety | No destructive work. Opening a unit or changing its firmware needs written approval first. Named contact who can stop the test |
| Who owns what | List the owner of the unit, the server and any third-party service, such as the cellular carrier. Confirm who can authorize each target and follow each third party's testing rules |
| What the report must contain | See the report list below |
| Dates | Report due in six weeks. Fixes ready about day 45. Re-check needed after that |
| Price to be itemized | Setup, testing, reporting, shipping or travel, re-check, any required platform fee, taxes, optional extras. Currency and payment dates |
This brief is a buying document. It is not permission to test.
This brief is a buying document. It is not permission to test. Written permission has to name the actual units, vehicles, servers and activities, and come from a party authorized to permit the testing. If a cellular carrier or cloud host sits in the path, their rules apply too. Liability for damaged hardware belongs in the contract, and that part is worth a lawyer's read. Our rules of engagement page covers the document that sets those limits, and our penetration testing scope page has a filled-in example for software.
Before you send the brief, it helps to settle who reads the report and how you will compare the answers. Find My PenTest Match has those questions in a general checklist you can copy or print. It will not list automotive specialists; use the table above for that.
What do you have to hand over?
For a unit test: the units or firmware images required for the agreed scope, and the documents that explain how the unit is wired and what it talks to. For a vehicle test, a vehicle or a full test rig.
Assured's page describes arranging "documentation, architecture/network maps, service descriptions and test access" at the scoping stage, and handing over "access credentials or diagnostic keys" at kickoff. Qualysec's page says unit-level work can be done from bench units and firmware images, while tests across the whole car need "a physical vehicle" or a full test rig.
Three practical points:
- Ask how many units they need and whether any work could damage them. If so, plan spares and say in the brief what is allowed.
- Decide how much to share. Testers given firmware and documents start further ahead than testers given a sealed box. Ask each provider what changes in coverage if you hold something back.
- Name one engineer who can answer questions the same day. Slow answers eat test time you paid for.
How long does automotive penetration testing take?
Two providers publish numbers. Block Harbor says 2+ weeks for a remote assessment and 4+ weeks for a standard one. Qualysec says two to six weeks, with the report within five business days after testing ends.
Those are testing times, not your full calendar. Add time to sign the contract, ship units, fix what is found, and re-check the fixes. Ask every provider for six dates in writing: units received, test start, test end, final report, the last day you can ask for a re-check, and re-check report.
What should the report show?
Enough for your customer or the approval authority to see what was tested, on which version, how, what was found, and what was left out. Ask for these before you sign:
- The exact hardware and firmware versions tested, and the test setup
- What was in scope, what was out, and what was simulated
- The methods used and the time spent
- Each finding with proof someone else can repeat, and what an attacker would need to pull it off
- The effect of each finding and how to fix it
- What was not tested and why
- For a re-check: which version was re-tested and the status of each finding
Then ask each provider: "Can you share a sample report with the details removed for this type of test, and tell us which of these parts ours will include?" Assured says its re-check results come as "a concise report suitable for sharing with regulators, partners or internal stakeholders." Praetorian lists an executive summary, a presentation and a technical findings report. Block Harbor links a report example from its services page; we have not reviewed it.
A report that finds nothing is not proof that nothing is there. It means these testers, in this time, with this access, did not get in. Our penetration testing report page goes deeper on what to check.
Common questions
Does automotive penetration testing require a physical vehicle?
Not always. A single unit can be tested on a bench with firmware and a wiring setup. Attacks that cross several systems need a setup covering those systems. An entry point outside the car may be tested on a relevant unit, rig or connected service. Qualysec and Assured both describe it this way on their pages.
Can a general penetration testing firm do it?
For the app, API and cloud parts, often yes. For the unit itself, ask who will do the work and which vehicle units they have tested before. Hardware and in-car networks are a separate skill from web testing, and a company name does not tell you who is assigned to your job.
We are a supplier. Does R155 apply to us directly?
The supplier-risk duties are written for the vehicle manufacturer. It must manage supplier risks, and your customer's contract may pass testing requirements to you. R155 also requires the manufacturer or its suppliers to make sufficient information available for approval checks where it is protected intellectual property or specific know-how. Read your customer's requirement, not just the regulation.
Is a bench test enough?
It can be, for a question about one unit. The report should say what was simulated and what was not tested. Whether your customer also wants testing in a vehicle is their call, so ask them first.
Already have a quote?
Check it against the brief line by line. Anything your brief lists that the quote does not mention is a question, not a yes. Our penetration testing quote page shows how to compare proposals.
How we checked
We read each provider's public automotive page, UN Regulation No. 155 as published in the Official Journal of the European Union (2025/5), and NHTSA's September 2022 guidance, all on October 10, 2026. We did not buy a test, speak to a provider, or read ISO/SAE 21434 itself. Prices and terms change, and a public page is not a contract, so get the terms in writing.
The PenTest Index is the independent buyer's index for penetration testing. We compare specific offers against stated buying requirements, show our sources and check dates, and keep compensation out of eligibility, fit and order. We have no commercial relationship with any provider on this page. See our method and how we make money.
Sources
All checked October 10, 2026.
- UN Regulation No. 155, OJ L 2025/5: paragraphs 1.1, 3.2.2, 5.1.2, 5.1.3(d), 7.2.2.5, 7.3.2, 7.3.6 and Annex 1 item 9.7
- NHTSA, Cybersecurity Best Practices for the Safety of Modern Vehicles, September 2022: section 1, section 4.2.7 items G.13 to G.15, footnote 26
- Assured, Automotive Penetration Testing
- Block Harbor, Red Team Services
- NetSPI, Automotive Penetration Testing
- PCA Cyber Security, Automotive Penetration Testing
- PlaxidityX, Automotive Penetration Testing
- Praetorian, Automotive Penetration Testing
- Qualysec, Automotive Device Penetration Testing
- SGS, Automotive Penetration Tests
- VicOne, xScope