Bug bounty vs penetration testing: which to buy first
Bug bounty vs penetration testing comes down to what you are paying for. A penetration test buys agreed testing on named systems, usually at a fixed price, with a report of what was covered. A bug bounty pays researchers for each eligible finding and promises no coverage. If someone needs proof of a completed test, buy the pentest first.
The table below shows which to buy first in six common situations. After that you will find what three companies that sell both put in writing, including the prices and retest limits they publish.
Which should you buy first?
| Your situation | Buy first | Why | What could change it |
|---|---|---|---|
| A customer, auditor or contract asks for a penetration test report | Penetration test | You get a report of agreed work, on agreed systems, by a date | The recipient tells you in writing that something you already have is enough |
| The system has never been tested by anyone outside your team | Penetration test | One fixed price looks for common problems. On a bounty you would pay a reward for each eligible finding | You have already fixed what scans and code review found |
| The target is internal, pre-release, or needs special access | Penetration test | A small named team works under agreed rules | A private, invite-only bounty with access you control |
| You are tested every year, ship often, and can sort and fix reports weekly | Add a bug bounty | It keeps skilled people looking between tests | Nobody owns the inbox, or there is no reward budget |
| You only want a safe way for outsiders to report problems | Neither. Publish a vulnerability disclosure policy | It is a reporting channel with no rewards | Reports start arriving faster than you can handle them |
| You need a report and you like paying for results | A hybrid test | Some sellers pay testers a base fee plus rewards and still deliver a report | The paperwork. Check which document you get (see below) |
Buy a penetration test first if anyone needs proof that a defined test was done, or if the system has never been tested. A bug bounty comes second. It suits a public product that has already been tested and has someone ready to handle incoming reports.
We read each seller's own pages on October 10, 2026. We did not buy or run these services, and nothing here rates the quality of anyone's testing.
Already sure you need a defined test? Compare published pentest offers, then send every provider the same request.
Bug bounty vs penetration testing: what does each one buy?
A penetration test buys effort against a list. A bug bounty buys results, wherever researchers decide to look. That one difference explains the price, the paperwork and the workload.
A penetration test (pentest) is an authorized attack on systems you name, run for an agreed time, ending in a report. A bug bounty is a standing offer: find a real weakness in the systems we list, report it under our rules, and we pay a reward. Scope means the systems and actions that are allowed. Triage means sorting incoming reports into real, duplicate and invalid.
The sellers describe the split the same way. HackerOne's pentest FAQ says its pentesters "look for coverage of the scope rather than just focusing on impactful vulnerabilities as in a bug bounty program," and that the goal of its pentests "is to help meet regulatory compliance and pass vendor assessments through a structured and checklist-driven process." (HackerOne Pentest FAQs) Bugcrowd puts it this way: "Pen testing is time-boxed, scoped, and led by a defined group of testers. Bug bounty programs are ongoing, open to a broader group, and use a pay-for-results model to find emergent vulnerabilities." (Bugcrowd)
Think of a building inspector and a posted reward. The inspector walks every room on your list and signs a report, even if every room is fine. The reward brings many sharp eyes, but each person chooses where to look. You might get ten reports about the front door and none about the basement. The comparison has a limit: bounty researchers are often highly skilled, and a good reward can pull deep work onto one hard problem.
| Buying question | Penetration test | Bug bounty | What to check |
|---|---|---|---|
| What work is promised? | Agreed tests on agreed systems | None. Rewards are offered for eligible findings | Who commits to test which roles, features and APIs |
| What does "in scope" mean? | What will be tested | What may be tested and what earns a reward | In scope on a bounty does not mean anyone looked |
| How long does it run? | A set window with a report date | Ongoing, or a time-limited challenge | Whether you need a report by a date |
| Who takes part? | A named team | Invited or public researchers | Access, identity checks and data rules |
| What do you get on paper? | A report of the work and findings, often with a short attestation letter | Individual finding reports, plus any program summary or statement | What each document says was done |
| What do you pay for? | The test | The platform, plus each reward, plus fees | The full commitment, not one line |
| What does "no findings" tell you? | Read it against the work recorded in the report | Very little. No reports does not show that testing happened | Coverage records, not the count of findings |
The last row is our reasoning from how the two models work. It is not a seller's claim, and a clean pentest report is not proof that a system is secure.
What do the companies that sell both put in writing?
Bugcrowd, HackerOne and Intigriti each sell pentests and bug bounties, and each prices and documents the two differently. Compare the named offer, not the company. Companies are listed A to Z. This is not a ranking.
| Company | Its penetration test | Its bug bounty | Published price (checked Oct 10, 2026) |
|---|---|---|---|
| Bugcrowd | Three tiers. Standard: "Platform-generated report" and "Launch within 3 business days". Plus: "Custom scoping and report". Max: "Methodology-driven pen testing for coverage combined with bug bounty for discovery" | Managed Bug Bounty with managed triage. A program summary PDF is available | Pentest: Standard Small $5,000, Medium $8,000, Large $15,000, each per 12-month contract on its AWS Marketplace listing. Bounty: "Contact us for pricing" |
| HackerOne | Scoped by assets and user roles. Two calendar weeks of testing by one to five pentesters, 40 hours each. Final PDF report plus a Letter of Attestation | You set the reward table and approve each payout. Rewards are separate from the platform subscription | None for either. "A rewards service fee applies to the bounty program and is confirmed in the quote" |
| Intigriti | A hybrid: testers get a base fee per day plus a reward pool. Three types: Focused, Comprehensive, Certified | Three plans, each listing unlimited triage. "Pay only for vulnerabilities validated by our expert triage team" | Pentest base fees listed as proposed: €300, €450 and €600 per day by type, plus a reward pool with no stated amount. Bounty plans: "Request pricing" |
Sources: Bugcrowd's pentest page, bounty page and AWS Marketplace listing; HackerOne's pentest phases, deliverables and pricing page; Intigriti's pentest FAQ, dated December 18, 2025, and pricing page. All provider-published.
Three details in those cells matter before you compare anything else.
Bugcrowd's price is for a size, not for your app. Small covers "1 low-complexity webapp, 50 active IPs, or 45 API endpoints." Medium covers one medium-complexity web app, 100 active IPs, or 75 API endpoints. Large covers one high-complexity web app, 256 active IPs, or 150 API endpoints. Note the word "or." If you need a web app and its API tested, ask whether that is one unit or two. The listing also says fees are "non-cancellable and non-refundable except as required by law."
HackerOne's product name and its help pages describe the testing differently. Its pricing page calls the product "H1 Agentic Pentest" and describes it as "AI-driven pentesting." Its help center describes a human team putting in 40 hours each over 14 days. Ask who and what will do the testing in your quote.
Intigriti's pentest type with the lowest proposed base rate gives you a letter, not a full report. The Focused type comes with a Letter of Attestation. Comprehensive and Certified come with a letter or a full penetration test report. If your customer wants the report, Focused is the wrong type.
The links to providers on this page are plain links. See how we make money.
We cover HackerOne's pentest offer in more depth in our HackerOne profile.
Why can two attestation letters prove different things?
Both products can hand you an official-looking PDF. What matters is what the PDF says was done.
HackerOne offers two. For a bounty or disclosure program, its statement of attestation is "a PDF that proves that your program has either a VDP or BBP on HackerOne." (Proof of Compliance) For a pentest, its Letter of Attestation "confirms the authenticity and scope contained with the pentest report." (Pentest Deliverables)
The first says a program exists. The second says a specific test happened on a specific scope. A customer who asked for a penetration test is asking the second question.
Bugcrowd's bounty programs can produce a Summary Report PDF too. Bugcrowd says it "provides information about the performance of your bug bounty or vulnerability disclosure program." (Bugcrowd docs) That is useful: it can include testing methodologies, tested targets and findings. It does not by itself show that every test your recipient requires was completed.
One more thing to ask HackerOne: its pricing page lists an "attestation letter" as a feature of its Enterprise platform plan without saying which of the two it means.
We read the sellers' descriptions of these documents. We did not inspect a paying customer's copy.
Does "retesting included" cover your fix schedule?
A retest only helps if its window is longer than the time you need to fix things. Check the window, when it starts, and what happens after.
Say you expect to ask for a fix check 45 days after the findings arrive.
| Offer | Published retest term | Day-45 request | Finding |
|---|---|---|---|
| HackerOne pentest, Essential tier | Unlimited retests during a 30-calendar-day remediation period after testing | Outside the window. Later retests, while your HackerOne platform service stays active, carry a fee you set, minimum $50 | Mismatch on timing |
| HackerOne pentest, Premium tier | Unlimited retests during a 90-calendar-day remediation period after testing | Inside the window | Supported on timing only |
| Bugcrowd Standard pentest | "12 months of retesting (with 1 report update)" for web apps, networks and APIs | Inside the window on the product page | Unresolved (see below) |
| HackerOne bounty report | Each retest carries its own reward, minimum $50, paid from your bounty pool | Available at a cost | Paid each time |
| Bugcrowd bounty submission | Retesting is a "Paid Add-On", up to five per submission | Available for accepted, Bugcrowd-triaged submissions if you bought the add-on | Paid add-on |
Sources: HackerOne on retest windows by tier, managing pentest retests and bounty retests; Bugcrowd's pentest page and bounty retest docs. Checked October 10, 2026.
Two things are unsettled in the sellers' own pages.
HackerOne's help center gives two different answers. Two newer articles, dated June 13, 2025 and March 24, 2026, describe unlimited retests within 30 or 90 days. Its older Pentest FAQ, dated July 17, 2024, says "there is a 60-day window to initiate two retests per report at no additional cost." HackerOne also says customers on its new platform plans use the Premium tier. Get the retest terms that apply to you in the order.
Bugcrowd's product page lists 12 months of retesting inside the Standard tier. Its self-service buying guide describes retesting as one of the "add-ons." (Bugcrowd docs) These may describe different ways of buying. Ask which applies to yours.
A question you can send either provider:
"Which retest terms apply to our order: how many retests, how many days, and what date does the window start? What must be finished before it closes, and what does a retest cost after that?"
On the bounty side, retests are small but they add up. HackerOne suggests a retest reward of $50 plus 5% of the bounty. For a $2,000 bounty that is $50 + $100 = $150, and HackerOne says you pay it "even if the issue remains unresolved." Both companies also say a retest checks the original issue only. A new way around your fix counts as a new report.
Is a bug bounty cheaper than a penetration test?
Nobody can tell you before you sign, because a bounty's total depends on how many eligible reports arrive. A fixed-price pentest has one price for a stated scope. So compare the whole bill, not a reward against a quote.
Here is what the sellers publish. Bugcrowd lists a fixed pentest price, from $5,000 for the Small size, and sends bounty buyers to sales. HackerOne publishes no price for either and says "your team gets a clear, itemized quote before any commitment." Intigriti lists proposed day rates for pentests and "Request pricing" for its plans. On the pages we read, only pentest prices are public. No bounty program price is.
| Line on the bill | Penetration test | Bug bounty |
|---|---|---|
| What you pay the seller | One price for the scope, or a package | A platform subscription |
| What you pay per finding | Nothing for a fixed-price test; hybrid tests can add finding rewards | A reward for each eligible report |
| Fees on top of rewards | Not applicable without finding rewards; otherwise check the terms | At HackerOne, a rewards service fee "confirmed in the quote" |
| Sorting reports | Done by the test team | Included, an optional extra, or your staff. HackerOne says managed triage is "confirmed in the quote rather than bundled in by default" |
| Checking your fixes | Included if your order covers retesting, and only inside its window | Paid per retest, or a paid add-on |
| Your team's time | A burst: scoping, then fixing | Every week, for as long as the program runs |
| Total known before signing? | Yes for a fixed-price test, once the scope is agreed | No. You know your cap, if you set one |
Two rules keep the comparison fair.
An unknown required charge is not zero. If a platform fee, rewards fee or triage service is unpriced, the bounty total is incomplete. It is not cheap.
A cap controls spending, not coverage. HackerOne says you set reward budgets and approve every payout, which keeps the bill in your hands. Ask what happens to researcher interest when the reward pool runs low.
A hybrid test shows why one number is never the whole price. Say an Intigriti Comprehensive test needs ten researcher-days. That number is made up for the example. The base is 10 × €450 = €4,500. The reward pool and the platform plan are not priced on the pages we read, so the total is still incomplete.
"Pay only for results" is true of the reward line. It leaves out the lines above and below it.
For pentest numbers, see what a penetration test costs. If you already hold a quote, check that it prices everything in your request.
Can a bug bounty replace a penetration test for an audit or a customer?
For the document and evidence, see penetration testing report.
Only if the work and the paperwork match what the recipient asked for, and only they can tell you that. A program badge, a statement that a program exists, or a list of findings is not a completed test.
Ask the recipient before you spend anything. You can copy this:
"You asked for [the test or evidence]. We run a bug bounty program covering [systems]. Would [the documents we can provide] meet your request, including the testing dates and proof that fixes were checked? If not, what exactly is missing?"
Three answers are possible. If they accept it, keep what you have and buy nothing. If they name a gap, buy only the missing work. If the answer is vague, ask again before you book. Our questions for your report recipient can help.
What changes when PCI DSS applies?
PCI DSS has its own penetration testing requirements, and a list of bounty findings does not show they were met.
We read Requirement 11.4 in PCI DSS v4.0.1, published June 2024. In short:
- 11.4.1 requires a penetration testing methodology that is "defined, documented, and implemented," with "coverage for the entire CDE perimeter and critical systems" and testing "from both inside and outside the network." The CDE is the cardholder data environment.
- 11.4.2 and 11.4.3 require internal and external penetration testing "at least once every 12 months" and after any significant infrastructure or application upgrade or change, by a "qualified internal resource or qualified external third party," with "organizational independence of the tester."
- 11.4.4 requires that exploitable weaknesses are corrected and that "penetration testing is repeated to verify the corrections."
The standard uses the words "bug bounty" once. It is in the guidance for Requirement 6.3.1, as one way to hear about weaknesses in your own software. It does not appear in Requirement 11.4.
An assessor has looked at this question for one seller. In a September 2022 paper prepared for Bugcrowd, the assessment firm Schellman wrote that Bugcrowd's Managed Bug Bounty "can partially support organizations in achieving compliance with" the PCI penetration testing requirement "if the customer adequately defines the scope of the testing engagement, including ensuring adequate test coverage." (Schellman paper, hosted by Bugcrowd) Read that with care. Bugcrowd commissioned it, it covers one company's service, and it was written before v4.0.1.
Your assessor decides what meets the requirement. The current standard is in the PCI SSC document library.
What if the request just says "SOC 2" or "ISO 27001"?
For SOC 2, see the related comparison.
Ask for the actual control, contract clause or evidence request. A framework's name does not tell you what this auditor or customer expects, and neither does a seller's compliance logo. We are not going to tell you every audit needs a pentest or that every auditor will turn down a bounty. Neither is true as a rule. Get the request in writing and answer that.
Which should a small SaaS company buy first?
In the example below, buy the scoped penetration test first. The customer is asking about testing that was completed, not about whether a discovery program is running.
Say you run a 30-person SaaS company. You have one web app, its API, two user roles and two test tenants. A customer asks for a third-party penetration test covering logged-in access and tenant isolation, with a final PDF in six weeks. You expect to ask for a fix check 45 days after the findings arrive. This company and its customer are made up.
This is how we apply the PenTest Index Purchase Check: take each thing the buyer must have, hold it against the seller's published terms, and record what those terms do and do not settle.
| What this buyer must have | What published terms show | Finding | Question to send |
|---|---|---|---|
| A report of a completed, scoped test | HackerOne's pentest delivers a final PDF with scope, checklists and method, plus a Letter of Attestation. Bugcrowd Plus lists "Custom scoping and report." A bounty program statement proves a program exists | Supported for both pentests. Mismatch for a bounty statement alone | "Please send a sample report showing how completed work and limits are recorded." |
| Both roles and tenant isolation tested | Sellers list the asset types they support, not your workflows | Unresolved for every offer | "Which roles and tenant checks will you cover, and where will you sample?" |
| Final report in six weeks | HackerOne states 48 hours to 7 business days to scope, up to 3 days to staff, 2 weeks of testing, and a report 3 to 5 business days later. Bugcrowd Standard states launch within 3 business days | Unresolved. Stated times are not a booked date | "What final report date will our order commit to?" |
| Fix check on day 45 | HackerOne: remediation period after testing, 30 days on Essential, 90 on Premium. Bugcrowd: 12 months listed | HackerOne Essential Mismatch, Premium Supported on timing. Bugcrowd Unresolved | The retest question above |
| A complete price | HackerOne: quote only. Bugcrowd: $5,000 to $15,000 by size for Standard; Plus is quoted | Unresolved | "Please itemize the test, any platform charge, retests and the contract term." |
On paper the deadline is tight but possible. Adding HackerOne's stated steps gives roughly three to five weeks from the start of scoping to final report, if setup and scheduling add no delay. Six weeks would leave about one to three weeks to spare, without reserving extra time for fixes or retests. A stated process time is not a promise.
Our conclusion for this buyer: send the same written request to HackerOne for its pentest and to Bugcrowd for Plus. Consider Bugcrowd Standard only if they confirm in writing that it covers both roles and tenant isolation. Compare the answers with the other published pentest offers. These are offers worth a closer look for this request. They are not approved providers, and no offer is cleared while a must-have is still unresolved.
When this company should buy nothing. If it already runs a bounty, and the records show the needed scope, dates and work, and the customer accepts them, use that. If only the tenant isolation testing is missing, ask for that one piece.
A request you can send any provider:
"Will you commit to testing [our app, API, both user roles and tenant isolation] and report the completed work and anything left out by [date], even if you find nothing? Please confirm the access you need, the full price and the retest terms in writing."
Your decision worksheet. Fill this in before you ask for quotes. Leave out passwords, keys and details of known weaknesses.
Who needs the evidence, and their exact request:
Systems, user roles and features that must be tested:
Work the provider must complete:
What we must receive even if nothing is found, and by what date:
Evidence we already have, and what is missing:
Who handles incoming reports and who fixes them:
Full price and retest terms (write "Unresolved" if any required charge is unpriced):
Route (pentest, bug bounty, both, or existing evidence) and what still needs confirming:
Writing the request is the slow part. Find My PenTest Match turns what needs testing into a scope checklist you can copy or print, so every provider answers the same request. It is free, needs no email or sign-up, and sends nothing to providers. It does not recommend a provider, and it compares web app and API offers only.
When does a bug bounty make sense, and when do you need both?
A bug bounty makes sense when the product is public, has already been tested, and you have a person and a budget for the reports. Use both when you need a defined test and want people looking the rest of the year. One does not make the other necessary.
Check yourself against five questions. A "no" on any of them is something to settle first.
- Has the product been pentested, and were the findings fixed? If not, you may pay rewards for common issues a pentest could have found.
- Can researchers reach it? Internal or pre-release systems need controlled access. Ask about private, invite-only programs.
- Does one named person own incoming reports? Someone has to answer, sort and route every one.
- Is there a reward budget with a cap? Decide it before launch.
- Are the rules written down? What may be tested, what is off limits, and that good-faith research under the rules is authorized.
Then ask any platform these six things:
- What is the subscription price and term?
- What fee is charged on top of rewards?
- Is triage included, or priced separately?
- What does a retest cost?
- Can we cap spending, and what happens when the pool runs low?
- What document do we receive, and what does it say was done?
View Bugcrowd Managed Bug Bounty
If you do both, keep them from overlapping by accident. Give the bounty the public product. Give the pentest the parts a crowd cannot reach or will not choose, such as internal systems, admin roles and new features before release. Share past pentest findings with the bounty platform so you do not pay rewards for issues you already know.
Stopping at the pentest is fine. The sellers have a reason to recommend both: they sell both.
What about a VDP, crowdsourced pentests and PTaaS?
These three terms sit between the two products, and each is easy to mistake for one of them.
A vulnerability disclosure policy (VDP) tells outsiders how to report a problem and what research is allowed. It pays nothing. The US cybersecurity agency CISA puts it this way: "A VDP is similar to, but distinct from, a 'bug bounty.' In bug bounty programs, organizations pay for valid and impactful findings of certain types of vulnerabilities in their systems or products." (CISA BOD 20-01) That directive binds US federal civilian executive-branch agencies, not private companies. We use it here for the definition.
A crowdsourced pentest uses testers drawn from a researcher community, but it is still a scoped test with a report. HackerOne's pentests work this way: "Pentesters are not HackerOne employees. Tests are conducted by our community." Synack sells fixed-window tests on a similar model. Who employs the tester does not decide which product you bought. The contract does.
PTaaS, or penetration testing as a service, describes delivery through a platform with a dashboard. It does not tell you who tests or how deeply. Bugcrowd's Max tier and Intigriti's hybrid model both mix pentest structure with bounty-style rewards, so read the deliverable line before you compare prices.
If a scanner is also on your list, see penetration testing vs vulnerability scanning. To choose a type of pentest, see penetration testing services.
What has to be agreed before anyone tests?
Written permission that covers the real systems, people and actions. Nothing on this page, and no scope checklist, gives that permission.
For a pentest, the permission is in the signed engagement documents. For a bounty or VDP, it is in the published program rules. Either way, settle these first: which systems and methods are allowed, what is off limits, which test accounts and data to use, who to call if something breaks, when testing must stop, and how findings may be shared. If a cloud host or another company runs part of the system, check whether you need their permission too. A lawyer should review the terms where liability or third-party rights are involved. Our guide to penetration testing scope covers the scope side.
This page is for companies buying testing. It does not cover careers in bug bounty hunting or penetration testing.
Sources and check dates
Everything about a provider below is provider-published and was read on October 10, 2026. We did not purchase these services or assess testing quality. Found something out of date? Send a correction.
| Source | What we used it for |
|---|---|
| Bugcrowd: Penetration Testing as a Service | Tier inclusions, retest term, definition of pentest vs bounty |
| Bugcrowd on AWS Marketplace | Standard Pen Test prices and sizes, refund term, bounty "contact us" |
| Bugcrowd: Managed Bug Bounty | Managed triage, quote-only |
| Bugcrowd docs: self-service Standard Pen Test | Retesting described as an add-on |
| Bugcrowd docs: Retesting | Bounty retest is a paid add-on, five per submission |
| Bugcrowd docs: Summary Report | What a bounty program PDF contains |
| HackerOne: pricing | No public prices, rewards fee, triage, product naming |
| HackerOne docs: Pentest FAQs | Coverage vs impact, fixed cost, older retest term, community testers |
| HackerOne docs: Pentest Phases and Terminology | Team size, hours, timeline, tiers |
| HackerOne docs: Pentest Deliverables | Report contents, Letter of Attestation |
| HackerOne docs: Retesting Pentests and Manage Pentest Retesting | 30 and 90 day windows, fee after the window |
| HackerOne docs: Request a Retest | Bounty retest reward formula |
| HackerOne docs: Proof of Compliance | Program statement of attestation |
| Intigriti: PTaaS FAQ (dated December 18, 2025) | Hybrid model, proposed day rates, deliverables by type |
| Intigriti: pricing | Plans, triage, "Request pricing" |
| PCI DSS v4.0.1, June 2024, Requirements 6.3.1 and 11.4.1 to 11.4.4 (PCI SSC document library) | What the standard says about penetration testing and bug bounty |
| Schellman review for Bugcrowd, September 2022 | One assessor's view of a bounty service against PCI DSS; commissioned by Bugcrowd |
| CISA Binding Operational Directive 20-01 | Definition of a VDP vs a bug bounty |
The PenTest Index does not perform, authorize or certify penetration testing, and is not affiliated with PCI SSC, CISA or any provider named here. Read how we check offers.