This site may contain affiliate or referral links. If you buy through one, we may be compensated. How we make money

Cloud penetration testing services: scope, prices and offers compared

By The PenTest Index · Offers and cloud provider rules checked October 9, 2026

Cloud penetration testing services cover four kinds of work: testing your cloud-hosted app, testing what's exposed to the internet, reviewing account settings, and attacking from inside the account with agreed access. Two offers we checked publish a price: Pentest Express lists $4,995 for one external asset, and Astra lists $5,999 a year per target. The rest need a quote.

Those two prices buy different work. So before you compare anyone, find your row in the first table.

Which cloud penetration testing services do you need?

You need the one that answers the question your report has to answer. "Cloud pentest" is a label. Vendors put it on four different jobs, and a quote for one will not satisfy a request for another.

Table columns: The question you need answered; Work to ask for; Access you hand over; What it will not tell you.
The question you need answeredWork to ask forAccess you hand overWhat it will not tell you
Can someone misuse our product or reach another customer's data?Application and API penetration testTest accounts for each user roleWhether your cloud account's permissions are safe
What can a stranger on the internet reach?External test of named public hosts, IPs or endpointsNoneFull authenticated coverage, including cloud-account permission review
Are our cloud settings and permissions set up safely?Cloud configuration reviewRead-only access to the accountWhether a weak setting can really be exploited
If one cloud login or server were taken over, how far could an attacker get?Cloud penetration test from an agreed starting pointCredentials and console access, sometimes a test machine inside your networkHow your application handles its own users, unless the quote includes it

Two terms, since they come up in every quote. IAM (identity and access management) is the set of permissions that decide who or what can use each cloud resource. A configuration review reads those settings and flags the risky ones. A penetration test tries to use them.

A fair way to picture it: a configuration review reads the building plans and marks the doors with bad locks. A penetration test tries the doors and tells you which rooms it got into. Both are useful. They are different purchases.

What this means for you:

  • An auditor or customer asked for "a pentest" and you run a SaaS product. They most often mean the application. Ask them. If so, start with our SaaS penetration testing comparison.
  • A questionnaire asks about your "cloud infrastructure." Ask whether a configuration review satisfies it or whether they want exploitation shown.
  • You want to know your real exposure if a key leaks. That is the fourth row.
  • You want ongoing checks. That can be a scanning tool you run yourself, covered in the cost section below, or an ongoing testing service. A self-run tool is a separate purchase from a test someone performs for you.

If your need isn't cloud at all, our guide to which type of penetration testing you need covers the other kinds.

Which offers cover which work?

Six offers from five companies, grouped by the work they document and listed A to Z within each group. This is not a ranking. Everything in the table is what the provider publishes on its own pages, checked October 9, 2026. We did not buy or test any of them.

Table columns: Offer; Work it documents; Access it needs; Published price; Fix recheck (retest).
OfferWork it documentsAccess it needsPublished priceFix recheck (retest)
Inside-the-account testing
Astra Pentest ExpertHuman testers plus autonomous agents. "Cloud" is on its list of supported targets.Not stated on the pricing page$5,999 a year per target2 re-scans by experts, available for 30 days
Bishop Fox Cloud Penetration TestingConfiguration review combined with penetration testing, built around a scenario you choose, such as a compromised user or a compromised applicationNot stated on the service pageQuoteOptional remediation review; window and charge not stated
Cobalt Cloud PentestSimulated attacks on AWS, Azure or Google Cloud, including cloud-hosted apps and APIs in its manual phaseCredentials, console access and a small test server inside your cloud networkQuote, in annual credits. Sized by the number of accounts, services and hosts.See the note below
NetSPI Cloud Penetration TestingManual and automated testing from two views: anonymous outsider and authenticated insiderNot spelled out. The insider view is described as authenticated.QuoteNot stated on its cloud pages
Outside-only testing
Pentest Express Cloud ExternalPublic-facing hosts, IPs and cloud endpoints, tested without credentialsNone$4,995 for one asset; $7,995 for two to fourFree in days 1–14 after report delivery; 25% of the original fee in days 15–60
Settings review
Cobalt Cloud Configuration ReviewAutomated assessment plus manual review of misconfigurations, "without engaging in active exploitation"Read-only rolesQuote, in annual creditsSee the note below

Sources: Astra pricing, Bishop Fox cloud service, Cobalt cloud pentest methodology, Cobalt configuration review methodology, NetSPI cloud pentesting, Pentest Express cloud and its terms.

Four conditions sit behind those cells, and each one can change your decision.

Astra's target count is unclear for cloud. Its plan description says "Networks, cloud, IPs and standalone APIs are 1 target each." Its pricing FAQ says a SaaS app "with all its APIs and underlying cloud is 1 target," and that multiple clouds "can be clubbed into one target" on a sales call. Both statements are on the same page. Ask how many targets your accounts count as, and get the total in writing.

Cobalt's retest rules don't name cloud tests. Its retest documentation gives 6 months on the Standard tier and 12 months on Premium and Enterprise for its "Agile and Comprehensive" pentests. Free retesting needs an active contract, and requests close 10 days before the contract ends. The page does not say whether a Cloud Pentest or a Configuration Review falls under those rules. Ask.

Pentest Express stops at the edge of your account. Its page says: "We don't log into your cloud console or review IAM/identity configuration directly." It calls a credentialed review "a separate, credentialed engagement we don't offer today." Its price is per external asset, not per cloud account, and the price is in USD.

Pentest Express limits who can see the report. Its terms say you may not share reports with third parties without written consent, except where law requires it or with your legal counsel, auditors or insurance carriers under confidentiality. Customers and prospects are not on that list. If the whole point is to send the report to a customer, get consent in writing before you buy.

Which ones deserve a closer look?

If you need to know how far an attacker gets from inside the account, request quotes from Bishop Fox, Cobalt (the Cloud Pentest, not the review) and NetSPI. Their published methods describe that work. None publishes a price, so the quote is where you learn the rest. If you are on Azure, NetSPI's Azure page names managed identities, service principals and Entra ID permissions specifically.

View Bishop Fox's cloud penetration testing

View Cobalt's cloud pentest service

View NetSPI's cloud pentesting

If you want a published price and a subscription suits you, Astra Pentest Expert is the one to ask, with two questions first: how many targets, and what access its testers use inside the account. Rule it out if your fixes will take longer than 30 days and you need them rechecked, unless Astra extends the window in writing.

View Astra's plans and pricing

If your whole requirement is "what can the internet reach," Pentest Express is a fixed-price fit. Rule it out if anyone needs account permissions examined.

View Pentest Express's external cloud test

If the request is about settings, Cobalt's Configuration Review is built for that. Rule it out if the recipient wants exploitation demonstrated.

View Cobalt's configuration review scope

How do the offers hold up against one real-looking purchase?

For the made-up buyer below, three offers stay in and three drop out. Nobody's published terms settle the price.

Say you run a 30-person SaaS company with two AWS accounts, production and staging. Your app was tested last quarter. Now a customer wants to know whether one stolen low-privilege cloud login could reach the production database. You expect fixes to take about 45 days.

Your requirements: the tester must try to exploit permissions from an agreed starting login (mandatory), both accounts must be named in scope (mandatory), a recheck must be possible on day 45 at a known cost (mandatory), and the customer must be allowed to see the report (mandatory).

Table columns: Offer; Finding; Why.
OfferFindingWhy
Bishop FoxMethod supported. Scope, price and day-45 recheck unresolved.Its service is built around a scenario such as a compromised user. No price, retest window or retest charge is published.
Cobalt Cloud PentestMethod supported. Price and day-45 recheck unresolved.Its method exploits weaknesses with credentials. Two accounts set the size; credits need a quote. Its retest periods are long enough, subject to the contract cutoff, but the page doesn't say they cover cloud tests.
NetSPIMethod supported. Scope, price and day-45 recheck unresolved.Authenticated insider testing is documented. No price or retest terms on its cloud pages.
Astra Pentest ExpertMismatch on the recheck. Target count and price unresolved.Re-scans are available for 30 days; you need day 45. Two accounts could be two targets ($11,998 a year at list, 2 × $5,999) or be bundled into one at a tailored price.
Pentest ExpressMismatch.No console or IAM work. Report sharing with a customer needs written consent.
Cobalt Configuration ReviewMismatch.No active exploitation.

"Supported" here means one named condition is backed by what the provider publishes. It is not a quality rating. A mandatory mismatch takes an offer off this buyer's list; a different buyer would get different results. This is our Purchase Check applied to a fictional brief. No provider quoted for it.

The question to send the three that remain:

Can you test the path from one agreed low-privilege login in our first AWS account to a named database in the second? Please list what is excluded, the access you need, the report date, the complete price, and the cost and last request date for a recheck we expect to ask for 45 days after findings are delivered. May we share the report with our customer?

How much does a cloud penetration test cost?

Only two of the six offers publish a number, and they price different things. Both were read on the providers' own pages on October 9, 2026.

Table columns: Offer; Published price; What the unit is; What it leaves open.
OfferPublished priceWhat the unit isWhat it leaves open
Pentest Express Cloud External$4,995 for one asset; $7,995 for two to four. Larger brackets are on its page.One public-facing host, IP or cloud endpointTaxes are extra. Fees are due in full at purchase unless a signed statement of work says otherwise.
Astra Pentest Expert$5,999 a yearOne "target"How many targets your cloud accounts count as. Astra also lists an Enterprise plan from $9,999 a year with 4 re-scans available for 90 days.

Everyone else prices by quote. What moves a cloud quote is mostly counting: how many accounts, subscriptions or projects, how many distinct services, whether the application is included, and whether containers or Kubernetes are in. Cobalt's scoping guide sizes cloud work exactly this way.

We don't repeat the "typical range" figures that vendor blogs publish. None we saw ties the range to a defined scope, so they can't tell you what your test should cost.

What does a late recheck add?

With Pentest Express, about a quarter more. Its terms make the retest free in days 1–14 after report delivery and charge 25% of the original fee in days 15–60. For a one-asset test rechecked on day 30:

$4,995 × 25% = $1,248.75. Test plus recheck: $6,243.75, before tax.

After day 60 it recommends a full new engagement at list price. The terms count days from report delivery but do not say whether the retest must be requested or finished inside the window. Ask which.

Are scanners and self-run tools the same thing?

No. They are software you operate, and they answer a narrower question.

Astra's Cloud Starter plan is $999 a year for automated configuration scans of one cloud account, up to 250 resources. Amazon's AWS Continuum for penetration testing lists $50 per task-hour, and it tests applications, not account settings. A task-hour is machine work running in parallel, not a person's hour. Both can be worth having. Check with your report recipient before you offer either as "the pentest."

For budgeting across every kind of test, see our penetration testing cost page. If you already hold a quote, our quote checklist shows the lines to check.

Do you need permission from AWS, Azure or Google Cloud?

Not for ordinary testing of your own resources. All three publish rules instead, and a few activities are banned or need approval. A vendor who says a standard test must wait for cloud provider sign-off is either adding time or planning something on the restricted list.

Table columns: Policy; AWS; Microsoft Azure; Google Cloud.
PolicyAWSMicrosoft AzureGoogle Cloud
Approval for a standard test of your own resourcesNot needed for its list of permitted services, which includes EC2, RDS, Lambda, API Gateway, ECS and Fargate. Other services: contact AWS first.Not needed. Microsoft dropped pre-approval on June 15, 2017, and notification is not required.Not needed. Google says you are not required to contact it.
Rules you must followAWS penetration testing policyMicrosoft's Rules of Engagement, summarized on Microsoft LearnAcceptable Use Policy and Terms of Service, per the Cloud Security FAQ
Off limitsDenial-of-service attacks; simulations except as permitted under AWS's DDoS Simulation Testing policy; request flooding, S3 bucket takeover, subdomain takeover, DNS attacks through Route 53, and testing AWS's own infrastructureDenial-of-service testing, touching tenants or data you neither own nor have explicit permission to access, using credentials that aren't yoursAnything that affects other customers' projects
Needs approval firstCovert adversarial simulations and all security testing with command-and-control, simulated phishing and malware testing, through a Simulated Events form at least two weeks aheadA third-party tester needs written authorization from you, the resource owner. Microsoft does not grant it for you.Not stated on the page we read

The list of permitted AWS services changes, so check the live page for the services you run.

One thing these policies do not do: give a testing company permission to touch your systems. That comes from you, in writing, naming the actual accounts and activities. Nothing on this page authorizes testing either.

Will testing disrupt production? It can. Agree on the environment, the hours, the rate limits, the conditions for stopping and an emergency contact before work starts. No provider page we read promises zero impact, and you shouldn't expect one to.

What should you send providers?

Send every provider the same scope request, so their answers line up. Here is one you can copy. Fill in what you know and leave the rest marked unknown. An honest "unknown" gets you a better quote than a guess.

Cloud testing scope request

Why and for whom. We need this test to answer: [question]. The report will go to [auditor / customer / internal team], who asked for [their exact wording].

Cloud and size. [AWS / Azure / Google Cloud]. About [number] accounts, subscriptions or projects. Exact targets will be shared privately once we choose a provider.

Work requested. Mark each as included, excluded or optional: application and API testing; external testing of public endpoints; configuration review; attack testing from inside the account; containers or Kubernetes; serverless functions; build and deploy pipelines.

Starting point and goal. Start from [no credentials / an application user / a low-privilege cloud login / a named server]. Show whether that starting point can reach [the thing we care about].

Access. Tell us exactly what access you need for each phase, how we hand it over safely, and when it gets revoked.

Ground rules. Environment, testing hours, systems that are off limits, conditions for stopping, emergency contacts.

Report. We need the tested scope, what was excluded, evidence for each finding and fix guidance. First report by [date]. Confirm who we may share it with.

Price. The complete commitment: currency, taxes, any required subscription or platform fee, payment dates, renewal terms, and the charge for added scope.

Rechecks. How many are included, what gets rechecked, when the window starts, whether the deadline is for asking or for finishing, and the cost if our fixes take longer. We expect fixes in about [number] days.

Open items. Tell us anything you cannot confirm before contract.

This request does not authorize testing. Written authorization covering the actual targets and activities comes before any work starts.

Still not sure what the report has to cover? That is the one thing to settle first, and it is what our tool is for. Find My PenTest Match walks you through what needs testing and what to ask the person who wants the report, then gives you a free checklist to copy or print. No contact details. Use it for the questions and this page for the offers.

Find My PenTest Match

Will your auditor or customer accept the report?

Only they can say, so ask before you buy. No provider, and no comparison site, can promise acceptance.

Four questions settle most of it:

  1. Do you need exploitation demonstrated, or is a configuration review enough?
  2. Must the cloud account and the application be in one report, or can they be separate?
  3. Does automated testing alone count, or must people do the testing?
  4. How recent must the test be, and do you need proof that fixes were rechecked?

If a framework such as SOC 2 or PCI DSS is behind the request, ask the auditor or assessor to point to the exact wording they are applying. We have not quoted either standard here because the answer that matters is theirs.

When the report arrives, check that it names the accounts tested, the access the testers had, the dates, what was left out, evidence for each finding, and the recheck status. A report that doesn't say which accounts it covered will be hard to hand to anyone.

How long does a cloud penetration test take?

It depends on the work, and published figures are thin. Pentest Express says a single-asset external test can be delivered "in as little as 3 business days" from checkout. Astra's pricing page gives 10–15 working days for its manual pentest. The other providers here publish no fixed completion time for these cloud offers.

Those are the providers' own statements about testing time. They are not a booking date. If you have a deadline, ask for the final report date in writing, and leave room for fixes and a recheck.

What if you only use SaaS tools, or already have a test?

Then you may not need to buy anything new.

You use Microsoft 365, Salesforce or Okta but run no cloud infrastructure. There is no cloud account of yours to attack. What you control is tenant settings, user identities and integrations. Tell the requester that, and ask what evidence they want. Subscribing to a product does not give you the right to test that vendor's platform.

You already have a pentest report, or a test bundled with a compliance platform. Read its scope page. If it covered the application and the request was about the application, you may be done. If the request names cloud infrastructure and your report doesn't, the gap might be a configuration review, not a whole new engagement. Ask the requester one thing: "Which part of our existing scope or evidence doesn't meet your request?"

You already run a cloud scanner. It shows that you watch for bad settings. Whether it counts as the test is the recipient's call, not the vendor's.

How we checked this

We read each provider's own service, pricing, terms and documentation pages on October 9, 2026, and each cloud provider's testing policy the same day. We did not buy these services, see a real report, or test anyone's quality. Where a page was silent, the table says "not stated." Provider links here are plain links with no referral codes; see how we make money.

Sources

Table columns: Source; Used for; Checked.
SourceUsed forChecked
Astra plans and pricingPrices, target definitions, re-scan counts and windows, timingOctober 9, 2026
Bishop Fox cloud penetration testing and methodology overviewMethod, scenarios, reportingOctober 9, 2026
Cobalt cloud pentest methodology and service pageMethod and accessOctober 9, 2026
Cobalt configuration review methodologyScope, exclusion of exploitation, accessOctober 9, 2026
Cobalt scoping guide and retest rulesSizing and retest periodsOctober 9, 2026
NetSPI cloud pentesting and Azure pageMethod and Azure coverageOctober 9, 2026
Pentest Express cloud and terms (last updated July 28, 2026)Scope, prices, retest, payment, report sharingOctober 9, 2026
AWS penetration testing policyPermitted services, prohibited activities, approvalsOctober 9, 2026
Microsoft Learn: Azure penetration testing and Rules of EngagementAzure rulesOctober 9, 2026
Google Cloud Security FAQGoogle Cloud rulesOctober 9, 2026
AWS Continuum for penetration testing pricingSelf-run tool rateOctober 9, 2026