Bug bounty vs penetration testing: which to buy first

Bug bounty vs penetration testing comes down to what you are paying for. A penetration test buys agreed testing on named systems, usually at a fixed price, with a report of what was covered. A bug bounty pays researchers for each eligible finding and promises no coverage. If someone needs proof of a completed test, buy the pentest first.

The table below shows which to buy first in six common situations. After that you will find what three companies that sell both put in writing, including the prices and retest limits they publish.

Which should you buy first?

Table columns: Your situation; Buy first; Why; What could change it.
Your situationBuy firstWhyWhat could change it
A customer, auditor or contract asks for a penetration test reportPenetration testYou get a report of agreed work, on agreed systems, by a dateThe recipient tells you in writing that something you already have is enough
The system has never been tested by anyone outside your teamPenetration testOne fixed price looks for common problems. On a bounty you would pay a reward for each eligible findingYou have already fixed what scans and code review found
The target is internal, pre-release, or needs special accessPenetration testA small named team works under agreed rulesA private, invite-only bounty with access you control
You are tested every year, ship often, and can sort and fix reports weeklyAdd a bug bountyIt keeps skilled people looking between testsNobody owns the inbox, or there is no reward budget
You only want a safe way for outsiders to report problemsNeither. Publish a vulnerability disclosure policyIt is a reporting channel with no rewardsReports start arriving faster than you can handle them
You need a report and you like paying for resultsA hybrid testSome sellers pay testers a base fee plus rewards and still deliver a reportThe paperwork. Check which document you get (see below)

Buy a penetration test first if anyone needs proof that a defined test was done, or if the system has never been tested. A bug bounty comes second. It suits a public product that has already been tested and has someone ready to handle incoming reports.

We read each seller's own pages on October 10, 2026. We did not buy or run these services, and nothing here rates the quality of anyone's testing.

Already sure you need a defined test? Compare published pentest offers, then send every provider the same request.

Bug bounty vs penetration testing: what does each one buy?

A penetration test buys effort against a list. A bug bounty buys results, wherever researchers decide to look. That one difference explains the price, the paperwork and the workload.

A penetration test (pentest) is an authorized attack on systems you name, run for an agreed time, ending in a report. A bug bounty is a standing offer: find a real weakness in the systems we list, report it under our rules, and we pay a reward. Scope means the systems and actions that are allowed. Triage means sorting incoming reports into real, duplicate and invalid.

The sellers describe the split the same way. HackerOne's pentest FAQ says its pentesters "look for coverage of the scope rather than just focusing on impactful vulnerabilities as in a bug bounty program," and that the goal of its pentests "is to help meet regulatory compliance and pass vendor assessments through a structured and checklist-driven process." (HackerOne Pentest FAQs) Bugcrowd puts it this way: "Pen testing is time-boxed, scoped, and led by a defined group of testers. Bug bounty programs are ongoing, open to a broader group, and use a pay-for-results model to find emergent vulnerabilities." (Bugcrowd)

Think of a building inspector and a posted reward. The inspector walks every room on your list and signs a report, even if every room is fine. The reward brings many sharp eyes, but each person chooses where to look. You might get ten reports about the front door and none about the basement. The comparison has a limit: bounty researchers are often highly skilled, and a good reward can pull deep work onto one hard problem.

Table columns: Buying question; Penetration test; Bug bounty; What to check.
Buying questionPenetration testBug bountyWhat to check
What work is promised?Agreed tests on agreed systemsNone. Rewards are offered for eligible findingsWho commits to test which roles, features and APIs
What does "in scope" mean?What will be testedWhat may be tested and what earns a rewardIn scope on a bounty does not mean anyone looked
How long does it run?A set window with a report dateOngoing, or a time-limited challengeWhether you need a report by a date
Who takes part?A named teamInvited or public researchersAccess, identity checks and data rules
What do you get on paper?A report of the work and findings, often with a short attestation letterIndividual finding reports, plus any program summary or statementWhat each document says was done
What do you pay for?The testThe platform, plus each reward, plus feesThe full commitment, not one line
What does "no findings" tell you?Read it against the work recorded in the reportVery little. No reports does not show that testing happenedCoverage records, not the count of findings

The last row is our reasoning from how the two models work. It is not a seller's claim, and a clean pentest report is not proof that a system is secure.

What do the companies that sell both put in writing?

Bugcrowd, HackerOne and Intigriti each sell pentests and bug bounties, and each prices and documents the two differently. Compare the named offer, not the company. Companies are listed A to Z. This is not a ranking.

Table columns: Company; Its penetration test; Its bug bounty; Published price (checked Oct 10, 2026).
CompanyIts penetration testIts bug bountyPublished price (checked Oct 10, 2026)
BugcrowdThree tiers. Standard: "Platform-generated report" and "Launch within 3 business days". Plus: "Custom scoping and report". Max: "Methodology-driven pen testing for coverage combined with bug bounty for discovery"Managed Bug Bounty with managed triage. A program summary PDF is availablePentest: Standard Small $5,000, Medium $8,000, Large $15,000, each per 12-month contract on its AWS Marketplace listing. Bounty: "Contact us for pricing"
HackerOneScoped by assets and user roles. Two calendar weeks of testing by one to five pentesters, 40 hours each. Final PDF report plus a Letter of AttestationYou set the reward table and approve each payout. Rewards are separate from the platform subscriptionNone for either. "A rewards service fee applies to the bounty program and is confirmed in the quote"
IntigritiA hybrid: testers get a base fee per day plus a reward pool. Three types: Focused, Comprehensive, CertifiedThree plans, each listing unlimited triage. "Pay only for vulnerabilities validated by our expert triage team"Pentest base fees listed as proposed: €300, €450 and €600 per day by type, plus a reward pool with no stated amount. Bounty plans: "Request pricing"

Sources: Bugcrowd's pentest page, bounty page and AWS Marketplace listing; HackerOne's pentest phases, deliverables and pricing page; Intigriti's pentest FAQ, dated December 18, 2025, and pricing page. All provider-published.

Three details in those cells matter before you compare anything else.

Bugcrowd's price is for a size, not for your app. Small covers "1 low-complexity webapp, 50 active IPs, or 45 API endpoints." Medium covers one medium-complexity web app, 100 active IPs, or 75 API endpoints. Large covers one high-complexity web app, 256 active IPs, or 150 API endpoints. Note the word "or." If you need a web app and its API tested, ask whether that is one unit or two. The listing also says fees are "non-cancellable and non-refundable except as required by law."

HackerOne's product name and its help pages describe the testing differently. Its pricing page calls the product "H1 Agentic Pentest" and describes it as "AI-driven pentesting." Its help center describes a human team putting in 40 hours each over 14 days. Ask who and what will do the testing in your quote.

Intigriti's pentest type with the lowest proposed base rate gives you a letter, not a full report. The Focused type comes with a Letter of Attestation. Comprehensive and Certified come with a letter or a full penetration test report. If your customer wants the report, Focused is the wrong type.

The links to providers on this page are plain links. See how we make money.

View Bugcrowd pentest tiers

View HackerOne's pentest

View Intigriti's plans

We cover HackerOne's pentest offer in more depth in our HackerOne profile.

Why can two attestation letters prove different things?

Both products can hand you an official-looking PDF. What matters is what the PDF says was done.

HackerOne offers two. For a bounty or disclosure program, its statement of attestation is "a PDF that proves that your program has either a VDP or BBP on HackerOne." (Proof of Compliance) For a pentest, its Letter of Attestation "confirms the authenticity and scope contained with the pentest report." (Pentest Deliverables)

The first says a program exists. The second says a specific test happened on a specific scope. A customer who asked for a penetration test is asking the second question.

Bugcrowd's bounty programs can produce a Summary Report PDF too. Bugcrowd says it "provides information about the performance of your bug bounty or vulnerability disclosure program." (Bugcrowd docs) That is useful: it can include testing methodologies, tested targets and findings. It does not by itself show that every test your recipient requires was completed.

One more thing to ask HackerOne: its pricing page lists an "attestation letter" as a feature of its Enterprise platform plan without saying which of the two it means.

We read the sellers' descriptions of these documents. We did not inspect a paying customer's copy.

Does "retesting included" cover your fix schedule?

A retest only helps if its window is longer than the time you need to fix things. Check the window, when it starts, and what happens after.

Say you expect to ask for a fix check 45 days after the findings arrive.

Table columns: Offer; Published retest term; Day-45 request; Finding.
OfferPublished retest termDay-45 requestFinding
HackerOne pentest, Essential tierUnlimited retests during a 30-calendar-day remediation period after testingOutside the window. Later retests, while your HackerOne platform service stays active, carry a fee you set, minimum $50Mismatch on timing
HackerOne pentest, Premium tierUnlimited retests during a 90-calendar-day remediation period after testingInside the windowSupported on timing only
Bugcrowd Standard pentest"12 months of retesting (with 1 report update)" for web apps, networks and APIsInside the window on the product pageUnresolved (see below)
HackerOne bounty reportEach retest carries its own reward, minimum $50, paid from your bounty poolAvailable at a costPaid each time
Bugcrowd bounty submissionRetesting is a "Paid Add-On", up to five per submissionAvailable for accepted, Bugcrowd-triaged submissions if you bought the add-onPaid add-on

Sources: HackerOne on retest windows by tier, managing pentest retests and bounty retests; Bugcrowd's pentest page and bounty retest docs. Checked October 10, 2026.

Two things are unsettled in the sellers' own pages.

HackerOne's help center gives two different answers. Two newer articles, dated June 13, 2025 and March 24, 2026, describe unlimited retests within 30 or 90 days. Its older Pentest FAQ, dated July 17, 2024, says "there is a 60-day window to initiate two retests per report at no additional cost." HackerOne also says customers on its new platform plans use the Premium tier. Get the retest terms that apply to you in the order.

Bugcrowd's product page lists 12 months of retesting inside the Standard tier. Its self-service buying guide describes retesting as one of the "add-ons." (Bugcrowd docs) These may describe different ways of buying. Ask which applies to yours.

A question you can send either provider:

"Which retest terms apply to our order: how many retests, how many days, and what date does the window start? What must be finished before it closes, and what does a retest cost after that?"

On the bounty side, retests are small but they add up. HackerOne suggests a retest reward of $50 plus 5% of the bounty. For a $2,000 bounty that is $50 + $100 = $150, and HackerOne says you pay it "even if the issue remains unresolved." Both companies also say a retest checks the original issue only. A new way around your fix counts as a new report.

Is a bug bounty cheaper than a penetration test?

Nobody can tell you before you sign, because a bounty's total depends on how many eligible reports arrive. A fixed-price pentest has one price for a stated scope. So compare the whole bill, not a reward against a quote.

Here is what the sellers publish. Bugcrowd lists a fixed pentest price, from $5,000 for the Small size, and sends bounty buyers to sales. HackerOne publishes no price for either and says "your team gets a clear, itemized quote before any commitment." Intigriti lists proposed day rates for pentests and "Request pricing" for its plans. On the pages we read, only pentest prices are public. No bounty program price is.

Table columns: Line on the bill; Penetration test; Bug bounty.
Line on the billPenetration testBug bounty
What you pay the sellerOne price for the scope, or a packageA platform subscription
What you pay per findingNothing for a fixed-price test; hybrid tests can add finding rewardsA reward for each eligible report
Fees on top of rewardsNot applicable without finding rewards; otherwise check the termsAt HackerOne, a rewards service fee "confirmed in the quote"
Sorting reportsDone by the test teamIncluded, an optional extra, or your staff. HackerOne says managed triage is "confirmed in the quote rather than bundled in by default"
Checking your fixesIncluded if your order covers retesting, and only inside its windowPaid per retest, or a paid add-on
Your team's timeA burst: scoping, then fixingEvery week, for as long as the program runs
Total known before signing?Yes for a fixed-price test, once the scope is agreedNo. You know your cap, if you set one

Two rules keep the comparison fair.

An unknown required charge is not zero. If a platform fee, rewards fee or triage service is unpriced, the bounty total is incomplete. It is not cheap.

A cap controls spending, not coverage. HackerOne says you set reward budgets and approve every payout, which keeps the bill in your hands. Ask what happens to researcher interest when the reward pool runs low.

A hybrid test shows why one number is never the whole price. Say an Intigriti Comprehensive test needs ten researcher-days. That number is made up for the example. The base is 10 × €450 = €4,500. The reward pool and the platform plan are not priced on the pages we read, so the total is still incomplete.

"Pay only for results" is true of the reward line. It leaves out the lines above and below it.

For pentest numbers, see what a penetration test costs. If you already hold a quote, check that it prices everything in your request.

Can a bug bounty replace a penetration test for an audit or a customer?

For the document and evidence, see penetration testing report.

Only if the work and the paperwork match what the recipient asked for, and only they can tell you that. A program badge, a statement that a program exists, or a list of findings is not a completed test.

Ask the recipient before you spend anything. You can copy this:

"You asked for [the test or evidence]. We run a bug bounty program covering [systems]. Would [the documents we can provide] meet your request, including the testing dates and proof that fixes were checked? If not, what exactly is missing?"

Three answers are possible. If they accept it, keep what you have and buy nothing. If they name a gap, buy only the missing work. If the answer is vague, ask again before you book. Our questions for your report recipient can help.

What changes when PCI DSS applies?

PCI DSS has its own penetration testing requirements, and a list of bounty findings does not show they were met.

We read Requirement 11.4 in PCI DSS v4.0.1, published June 2024. In short:

  • 11.4.1 requires a penetration testing methodology that is "defined, documented, and implemented," with "coverage for the entire CDE perimeter and critical systems" and testing "from both inside and outside the network." The CDE is the cardholder data environment.
  • 11.4.2 and 11.4.3 require internal and external penetration testing "at least once every 12 months" and after any significant infrastructure or application upgrade or change, by a "qualified internal resource or qualified external third party," with "organizational independence of the tester."
  • 11.4.4 requires that exploitable weaknesses are corrected and that "penetration testing is repeated to verify the corrections."

The standard uses the words "bug bounty" once. It is in the guidance for Requirement 6.3.1, as one way to hear about weaknesses in your own software. It does not appear in Requirement 11.4.

An assessor has looked at this question for one seller. In a September 2022 paper prepared for Bugcrowd, the assessment firm Schellman wrote that Bugcrowd's Managed Bug Bounty "can partially support organizations in achieving compliance with" the PCI penetration testing requirement "if the customer adequately defines the scope of the testing engagement, including ensuring adequate test coverage." (Schellman paper, hosted by Bugcrowd) Read that with care. Bugcrowd commissioned it, it covers one company's service, and it was written before v4.0.1.

Your assessor decides what meets the requirement. The current standard is in the PCI SSC document library.

What if the request just says "SOC 2" or "ISO 27001"?

For SOC 2, see the related comparison.

Ask for the actual control, contract clause or evidence request. A framework's name does not tell you what this auditor or customer expects, and neither does a seller's compliance logo. We are not going to tell you every audit needs a pentest or that every auditor will turn down a bounty. Neither is true as a rule. Get the request in writing and answer that.

Which should a small SaaS company buy first?

In the example below, buy the scoped penetration test first. The customer is asking about testing that was completed, not about whether a discovery program is running.

Say you run a 30-person SaaS company. You have one web app, its API, two user roles and two test tenants. A customer asks for a third-party penetration test covering logged-in access and tenant isolation, with a final PDF in six weeks. You expect to ask for a fix check 45 days after the findings arrive. This company and its customer are made up.

This is how we apply the PenTest Index Purchase Check: take each thing the buyer must have, hold it against the seller's published terms, and record what those terms do and do not settle.

Table columns: What this buyer must have; What published terms show; Finding; Question to send.
What this buyer must haveWhat published terms showFindingQuestion to send
A report of a completed, scoped testHackerOne's pentest delivers a final PDF with scope, checklists and method, plus a Letter of Attestation. Bugcrowd Plus lists "Custom scoping and report." A bounty program statement proves a program existsSupported for both pentests. Mismatch for a bounty statement alone"Please send a sample report showing how completed work and limits are recorded."
Both roles and tenant isolation testedSellers list the asset types they support, not your workflowsUnresolved for every offer"Which roles and tenant checks will you cover, and where will you sample?"
Final report in six weeksHackerOne states 48 hours to 7 business days to scope, up to 3 days to staff, 2 weeks of testing, and a report 3 to 5 business days later. Bugcrowd Standard states launch within 3 business daysUnresolved. Stated times are not a booked date"What final report date will our order commit to?"
Fix check on day 45HackerOne: remediation period after testing, 30 days on Essential, 90 on Premium. Bugcrowd: 12 months listedHackerOne Essential Mismatch, Premium Supported on timing. Bugcrowd UnresolvedThe retest question above
A complete priceHackerOne: quote only. Bugcrowd: $5,000 to $15,000 by size for Standard; Plus is quotedUnresolved"Please itemize the test, any platform charge, retests and the contract term."

On paper the deadline is tight but possible. Adding HackerOne's stated steps gives roughly three to five weeks from the start of scoping to final report, if setup and scheduling add no delay. Six weeks would leave about one to three weeks to spare, without reserving extra time for fixes or retests. A stated process time is not a promise.

Our conclusion for this buyer: send the same written request to HackerOne for its pentest and to Bugcrowd for Plus. Consider Bugcrowd Standard only if they confirm in writing that it covers both roles and tenant isolation. Compare the answers with the other published pentest offers. These are offers worth a closer look for this request. They are not approved providers, and no offer is cleared while a must-have is still unresolved.

When this company should buy nothing. If it already runs a bounty, and the records show the needed scope, dates and work, and the customer accepts them, use that. If only the tenant isolation testing is missing, ask for that one piece.

A request you can send any provider:

"Will you commit to testing [our app, API, both user roles and tenant isolation] and report the completed work and anything left out by [date], even if you find nothing? Please confirm the access you need, the full price and the retest terms in writing."

Your decision worksheet. Fill this in before you ask for quotes. Leave out passwords, keys and details of known weaknesses.

Who needs the evidence, and their exact request:

Systems, user roles and features that must be tested:

Work the provider must complete:

What we must receive even if nothing is found, and by what date:

Evidence we already have, and what is missing:

Who handles incoming reports and who fixes them:

Full price and retest terms (write "Unresolved" if any required charge is unpriced):

Route (pentest, bug bounty, both, or existing evidence) and what still needs confirming:

Writing the request is the slow part. Find My PenTest Match turns what needs testing into a scope checklist you can copy or print, so every provider answers the same request. It is free, needs no email or sign-up, and sends nothing to providers. It does not recommend a provider, and it compares web app and API offers only.

Find My PenTest Match

When does a bug bounty make sense, and when do you need both?

A bug bounty makes sense when the product is public, has already been tested, and you have a person and a budget for the reports. Use both when you need a defined test and want people looking the rest of the year. One does not make the other necessary.

Check yourself against five questions. A "no" on any of them is something to settle first.

  1. Has the product been pentested, and were the findings fixed? If not, you may pay rewards for common issues a pentest could have found.
  2. Can researchers reach it? Internal or pre-release systems need controlled access. Ask about private, invite-only programs.
  3. Does one named person own incoming reports? Someone has to answer, sort and route every one.
  4. Is there a reward budget with a cap? Decide it before launch.
  5. Are the rules written down? What may be tested, what is off limits, and that good-faith research under the rules is authorized.

Then ask any platform these six things:

  1. What is the subscription price and term?
  2. What fee is charged on top of rewards?
  3. Is triage included, or priced separately?
  4. What does a retest cost?
  5. Can we cap spending, and what happens when the pool runs low?
  6. What document do we receive, and what does it say was done?

View Bugcrowd Managed Bug Bounty

View HackerOne's bug bounty

If you do both, keep them from overlapping by accident. Give the bounty the public product. Give the pentest the parts a crowd cannot reach or will not choose, such as internal systems, admin roles and new features before release. Share past pentest findings with the bounty platform so you do not pay rewards for issues you already know.

Stopping at the pentest is fine. The sellers have a reason to recommend both: they sell both.

What about a VDP, crowdsourced pentests and PTaaS?

These three terms sit between the two products, and each is easy to mistake for one of them.

A vulnerability disclosure policy (VDP) tells outsiders how to report a problem and what research is allowed. It pays nothing. The US cybersecurity agency CISA puts it this way: "A VDP is similar to, but distinct from, a 'bug bounty.' In bug bounty programs, organizations pay for valid and impactful findings of certain types of vulnerabilities in their systems or products." (CISA BOD 20-01) That directive binds US federal civilian executive-branch agencies, not private companies. We use it here for the definition.

A crowdsourced pentest uses testers drawn from a researcher community, but it is still a scoped test with a report. HackerOne's pentests work this way: "Pentesters are not HackerOne employees. Tests are conducted by our community." Synack sells fixed-window tests on a similar model. Who employs the tester does not decide which product you bought. The contract does.

PTaaS, or penetration testing as a service, describes delivery through a platform with a dashboard. It does not tell you who tests or how deeply. Bugcrowd's Max tier and Intigriti's hybrid model both mix pentest structure with bounty-style rewards, so read the deliverable line before you compare prices.

If a scanner is also on your list, see penetration testing vs vulnerability scanning. To choose a type of pentest, see penetration testing services.

What has to be agreed before anyone tests?

Written permission that covers the real systems, people and actions. Nothing on this page, and no scope checklist, gives that permission.

For a pentest, the permission is in the signed engagement documents. For a bounty or VDP, it is in the published program rules. Either way, settle these first: which systems and methods are allowed, what is off limits, which test accounts and data to use, who to call if something breaks, when testing must stop, and how findings may be shared. If a cloud host or another company runs part of the system, check whether you need their permission too. A lawyer should review the terms where liability or third-party rights are involved. Our guide to penetration testing scope covers the scope side.

This page is for companies buying testing. It does not cover careers in bug bounty hunting or penetration testing.

Sources and check dates

Everything about a provider below is provider-published and was read on October 10, 2026. We did not purchase these services or assess testing quality. Found something out of date? Send a correction.

Table columns: Source; What we used it for.
SourceWhat we used it for
Bugcrowd: Penetration Testing as a ServiceTier inclusions, retest term, definition of pentest vs bounty
Bugcrowd on AWS MarketplaceStandard Pen Test prices and sizes, refund term, bounty "contact us"
Bugcrowd: Managed Bug BountyManaged triage, quote-only
Bugcrowd docs: self-service Standard Pen TestRetesting described as an add-on
Bugcrowd docs: RetestingBounty retest is a paid add-on, five per submission
Bugcrowd docs: Summary ReportWhat a bounty program PDF contains
HackerOne: pricingNo public prices, rewards fee, triage, product naming
HackerOne docs: Pentest FAQsCoverage vs impact, fixed cost, older retest term, community testers
HackerOne docs: Pentest Phases and TerminologyTeam size, hours, timeline, tiers
HackerOne docs: Pentest DeliverablesReport contents, Letter of Attestation
HackerOne docs: Retesting Pentests and Manage Pentest Retesting30 and 90 day windows, fee after the window
HackerOne docs: Request a RetestBounty retest reward formula
HackerOne docs: Proof of ComplianceProgram statement of attestation
Intigriti: PTaaS FAQ (dated December 18, 2025)Hybrid model, proposed day rates, deliverables by type
Intigriti: pricingPlans, triage, "Request pricing"
PCI DSS v4.0.1, June 2024, Requirements 6.3.1 and 11.4.1 to 11.4.4 (PCI SSC document library)What the standard says about penetration testing and bug bounty
Schellman review for Bugcrowd, September 2022One assessor's view of a bounty service against PCI DSS; commissioned by Bugcrowd
CISA Binding Operational Directive 20-01Definition of a VDP vs a bug bounty

The PenTest Index does not perform, authorize or certify penetration testing, and is not affiliated with PCI SSC, CISA or any provider named here. Read how we check offers.