This site may contain affiliate or referral links. If you buy through one, we may be compensated. How we make money
Cloud penetration testing services: scope, prices and offers compared
By The PenTest Index · Offers and cloud provider rules checked October 9, 2026
Cloud penetration testing services cover four kinds of work: testing your cloud-hosted app, testing what's exposed to the internet, reviewing account settings, and attacking from inside the account with agreed access. Two offers we checked publish a price: Pentest Express lists $4,995 for one external asset, and Astra lists $5,999 a year per target. The rest need a quote.
Those two prices buy different work. So before you compare anyone, find your row in the first table.
Which cloud penetration testing services do you need?
You need the one that answers the question your report has to answer. "Cloud pentest" is a label. Vendors put it on four different jobs, and a quote for one will not satisfy a request for another.
| The question you need answered | Work to ask for | Access you hand over | What it will not tell you |
|---|---|---|---|
| Can someone misuse our product or reach another customer's data? | Application and API penetration test | Test accounts for each user role | Whether your cloud account's permissions are safe |
| What can a stranger on the internet reach? | External test of named public hosts, IPs or endpoints | None | Full authenticated coverage, including cloud-account permission review |
| Are our cloud settings and permissions set up safely? | Cloud configuration review | Read-only access to the account | Whether a weak setting can really be exploited |
| If one cloud login or server were taken over, how far could an attacker get? | Cloud penetration test from an agreed starting point | Credentials and console access, sometimes a test machine inside your network | How your application handles its own users, unless the quote includes it |
Two terms, since they come up in every quote. IAM (identity and access management) is the set of permissions that decide who or what can use each cloud resource. A configuration review reads those settings and flags the risky ones. A penetration test tries to use them.
A fair way to picture it: a configuration review reads the building plans and marks the doors with bad locks. A penetration test tries the doors and tells you which rooms it got into. Both are useful. They are different purchases.
What this means for you:
- An auditor or customer asked for "a pentest" and you run a SaaS product. They most often mean the application. Ask them. If so, start with our SaaS penetration testing comparison.
- A questionnaire asks about your "cloud infrastructure." Ask whether a configuration review satisfies it or whether they want exploitation shown.
- You want to know your real exposure if a key leaks. That is the fourth row.
- You want ongoing checks. That can be a scanning tool you run yourself, covered in the cost section below, or an ongoing testing service. A self-run tool is a separate purchase from a test someone performs for you.
If your need isn't cloud at all, our guide to which type of penetration testing you need covers the other kinds.
Which offers cover which work?
Six offers from five companies, grouped by the work they document and listed A to Z within each group. This is not a ranking. Everything in the table is what the provider publishes on its own pages, checked October 9, 2026. We did not buy or test any of them.
| Offer | Work it documents | Access it needs | Published price | Fix recheck (retest) |
|---|---|---|---|---|
| Inside-the-account testing | ||||
| Astra Pentest Expert | Human testers plus autonomous agents. "Cloud" is on its list of supported targets. | Not stated on the pricing page | $5,999 a year per target | 2 re-scans by experts, available for 30 days |
| Bishop Fox Cloud Penetration Testing | Configuration review combined with penetration testing, built around a scenario you choose, such as a compromised user or a compromised application | Not stated on the service page | Quote | Optional remediation review; window and charge not stated |
| Cobalt Cloud Pentest | Simulated attacks on AWS, Azure or Google Cloud, including cloud-hosted apps and APIs in its manual phase | Credentials, console access and a small test server inside your cloud network | Quote, in annual credits. Sized by the number of accounts, services and hosts. | See the note below |
| NetSPI Cloud Penetration Testing | Manual and automated testing from two views: anonymous outsider and authenticated insider | Not spelled out. The insider view is described as authenticated. | Quote | Not stated on its cloud pages |
| Outside-only testing | ||||
| Pentest Express Cloud External | Public-facing hosts, IPs and cloud endpoints, tested without credentials | None | $4,995 for one asset; $7,995 for two to four | Free in days 1–14 after report delivery; 25% of the original fee in days 15–60 |
| Settings review | ||||
| Cobalt Cloud Configuration Review | Automated assessment plus manual review of misconfigurations, "without engaging in active exploitation" | Read-only roles | Quote, in annual credits | See the note below |
Sources: Astra pricing, Bishop Fox cloud service, Cobalt cloud pentest methodology, Cobalt configuration review methodology, NetSPI cloud pentesting, Pentest Express cloud and its terms.
Four conditions sit behind those cells, and each one can change your decision.
Astra's target count is unclear for cloud. Its plan description says "Networks, cloud, IPs and standalone APIs are 1 target each." Its pricing FAQ says a SaaS app "with all its APIs and underlying cloud is 1 target," and that multiple clouds "can be clubbed into one target" on a sales call. Both statements are on the same page. Ask how many targets your accounts count as, and get the total in writing.
Cobalt's retest rules don't name cloud tests. Its retest documentation gives 6 months on the Standard tier and 12 months on Premium and Enterprise for its "Agile and Comprehensive" pentests. Free retesting needs an active contract, and requests close 10 days before the contract ends. The page does not say whether a Cloud Pentest or a Configuration Review falls under those rules. Ask.
Pentest Express stops at the edge of your account. Its page says: "We don't log into your cloud console or review IAM/identity configuration directly." It calls a credentialed review "a separate, credentialed engagement we don't offer today." Its price is per external asset, not per cloud account, and the price is in USD.
Pentest Express limits who can see the report. Its terms say you may not share reports with third parties without written consent, except where law requires it or with your legal counsel, auditors or insurance carriers under confidentiality. Customers and prospects are not on that list. If the whole point is to send the report to a customer, get consent in writing before you buy.
Which ones deserve a closer look?
If you need to know how far an attacker gets from inside the account, request quotes from Bishop Fox, Cobalt (the Cloud Pentest, not the review) and NetSPI. Their published methods describe that work. None publishes a price, so the quote is where you learn the rest. If you are on Azure, NetSPI's Azure page names managed identities, service principals and Entra ID permissions specifically.
View Bishop Fox's cloud penetration testing
View Cobalt's cloud pentest service
View NetSPI's cloud pentesting
If you want a published price and a subscription suits you, Astra Pentest Expert is the one to ask, with two questions first: how many targets, and what access its testers use inside the account. Rule it out if your fixes will take longer than 30 days and you need them rechecked, unless Astra extends the window in writing.
View Astra's plans and pricing
If your whole requirement is "what can the internet reach," Pentest Express is a fixed-price fit. Rule it out if anyone needs account permissions examined.
View Pentest Express's external cloud test
If the request is about settings, Cobalt's Configuration Review is built for that. Rule it out if the recipient wants exploitation demonstrated.
View Cobalt's configuration review scope
How do the offers hold up against one real-looking purchase?
For the made-up buyer below, three offers stay in and three drop out. Nobody's published terms settle the price.
Say you run a 30-person SaaS company with two AWS accounts, production and staging. Your app was tested last quarter. Now a customer wants to know whether one stolen low-privilege cloud login could reach the production database. You expect fixes to take about 45 days.
Your requirements: the tester must try to exploit permissions from an agreed starting login (mandatory), both accounts must be named in scope (mandatory), a recheck must be possible on day 45 at a known cost (mandatory), and the customer must be allowed to see the report (mandatory).
| Offer | Finding | Why |
|---|---|---|
| Bishop Fox | Method supported. Scope, price and day-45 recheck unresolved. | Its service is built around a scenario such as a compromised user. No price, retest window or retest charge is published. |
| Cobalt Cloud Pentest | Method supported. Price and day-45 recheck unresolved. | Its method exploits weaknesses with credentials. Two accounts set the size; credits need a quote. Its retest periods are long enough, subject to the contract cutoff, but the page doesn't say they cover cloud tests. |
| NetSPI | Method supported. Scope, price and day-45 recheck unresolved. | Authenticated insider testing is documented. No price or retest terms on its cloud pages. |
| Astra Pentest Expert | Mismatch on the recheck. Target count and price unresolved. | Re-scans are available for 30 days; you need day 45. Two accounts could be two targets ($11,998 a year at list, 2 × $5,999) or be bundled into one at a tailored price. |
| Pentest Express | Mismatch. | No console or IAM work. Report sharing with a customer needs written consent. |
| Cobalt Configuration Review | Mismatch. | No active exploitation. |
"Supported" here means one named condition is backed by what the provider publishes. It is not a quality rating. A mandatory mismatch takes an offer off this buyer's list; a different buyer would get different results. This is our Purchase Check applied to a fictional brief. No provider quoted for it.
The question to send the three that remain:
Can you test the path from one agreed low-privilege login in our first AWS account to a named database in the second? Please list what is excluded, the access you need, the report date, the complete price, and the cost and last request date for a recheck we expect to ask for 45 days after findings are delivered. May we share the report with our customer?
How much does a cloud penetration test cost?
Only two of the six offers publish a number, and they price different things. Both were read on the providers' own pages on October 9, 2026.
| Offer | Published price | What the unit is | What it leaves open |
|---|---|---|---|
| Pentest Express Cloud External | $4,995 for one asset; $7,995 for two to four. Larger brackets are on its page. | One public-facing host, IP or cloud endpoint | Taxes are extra. Fees are due in full at purchase unless a signed statement of work says otherwise. |
| Astra Pentest Expert | $5,999 a year | One "target" | How many targets your cloud accounts count as. Astra also lists an Enterprise plan from $9,999 a year with 4 re-scans available for 90 days. |
Everyone else prices by quote. What moves a cloud quote is mostly counting: how many accounts, subscriptions or projects, how many distinct services, whether the application is included, and whether containers or Kubernetes are in. Cobalt's scoping guide sizes cloud work exactly this way.
We don't repeat the "typical range" figures that vendor blogs publish. None we saw ties the range to a defined scope, so they can't tell you what your test should cost.
What does a late recheck add?
With Pentest Express, about a quarter more. Its terms make the retest free in days 1–14 after report delivery and charge 25% of the original fee in days 15–60. For a one-asset test rechecked on day 30:
$4,995 × 25% = $1,248.75. Test plus recheck: $6,243.75, before tax.
After day 60 it recommends a full new engagement at list price. The terms count days from report delivery but do not say whether the retest must be requested or finished inside the window. Ask which.
Are scanners and self-run tools the same thing?
No. They are software you operate, and they answer a narrower question.
Astra's Cloud Starter plan is $999 a year for automated configuration scans of one cloud account, up to 250 resources. Amazon's AWS Continuum for penetration testing lists $50 per task-hour, and it tests applications, not account settings. A task-hour is machine work running in parallel, not a person's hour. Both can be worth having. Check with your report recipient before you offer either as "the pentest."
For budgeting across every kind of test, see our penetration testing cost page. If you already hold a quote, our quote checklist shows the lines to check.
Do you need permission from AWS, Azure or Google Cloud?
Not for ordinary testing of your own resources. All three publish rules instead, and a few activities are banned or need approval. A vendor who says a standard test must wait for cloud provider sign-off is either adding time or planning something on the restricted list.
| Policy | AWS | Microsoft Azure | Google Cloud |
|---|---|---|---|
| Approval for a standard test of your own resources | Not needed for its list of permitted services, which includes EC2, RDS, Lambda, API Gateway, ECS and Fargate. Other services: contact AWS first. | Not needed. Microsoft dropped pre-approval on June 15, 2017, and notification is not required. | Not needed. Google says you are not required to contact it. |
| Rules you must follow | AWS penetration testing policy | Microsoft's Rules of Engagement, summarized on Microsoft Learn | Acceptable Use Policy and Terms of Service, per the Cloud Security FAQ |
| Off limits | Denial-of-service attacks; simulations except as permitted under AWS's DDoS Simulation Testing policy; request flooding, S3 bucket takeover, subdomain takeover, DNS attacks through Route 53, and testing AWS's own infrastructure | Denial-of-service testing, touching tenants or data you neither own nor have explicit permission to access, using credentials that aren't yours | Anything that affects other customers' projects |
| Needs approval first | Covert adversarial simulations and all security testing with command-and-control, simulated phishing and malware testing, through a Simulated Events form at least two weeks ahead | A third-party tester needs written authorization from you, the resource owner. Microsoft does not grant it for you. | Not stated on the page we read |
The list of permitted AWS services changes, so check the live page for the services you run.
One thing these policies do not do: give a testing company permission to touch your systems. That comes from you, in writing, naming the actual accounts and activities. Nothing on this page authorizes testing either.
Will testing disrupt production? It can. Agree on the environment, the hours, the rate limits, the conditions for stopping and an emergency contact before work starts. No provider page we read promises zero impact, and you shouldn't expect one to.
What should you send providers?
Send every provider the same scope request, so their answers line up. Here is one you can copy. Fill in what you know and leave the rest marked unknown. An honest "unknown" gets you a better quote than a guess.
Cloud testing scope request
Why and for whom. We need this test to answer: [question]. The report will go to [auditor / customer / internal team], who asked for [their exact wording].
Cloud and size. [AWS / Azure / Google Cloud]. About [number] accounts, subscriptions or projects. Exact targets will be shared privately once we choose a provider.
Work requested. Mark each as included, excluded or optional: application and API testing; external testing of public endpoints; configuration review; attack testing from inside the account; containers or Kubernetes; serverless functions; build and deploy pipelines.
Starting point and goal. Start from [no credentials / an application user / a low-privilege cloud login / a named server]. Show whether that starting point can reach [the thing we care about].
Access. Tell us exactly what access you need for each phase, how we hand it over safely, and when it gets revoked.
Ground rules. Environment, testing hours, systems that are off limits, conditions for stopping, emergency contacts.
Report. We need the tested scope, what was excluded, evidence for each finding and fix guidance. First report by [date]. Confirm who we may share it with.
Price. The complete commitment: currency, taxes, any required subscription or platform fee, payment dates, renewal terms, and the charge for added scope.
Rechecks. How many are included, what gets rechecked, when the window starts, whether the deadline is for asking or for finishing, and the cost if our fixes take longer. We expect fixes in about [number] days.
Open items. Tell us anything you cannot confirm before contract.
This request does not authorize testing. Written authorization covering the actual targets and activities comes before any work starts.
Still not sure what the report has to cover? That is the one thing to settle first, and it is what our tool is for. Find My PenTest Match walks you through what needs testing and what to ask the person who wants the report, then gives you a free checklist to copy or print. No contact details. Use it for the questions and this page for the offers.
Will your auditor or customer accept the report?
Only they can say, so ask before you buy. No provider, and no comparison site, can promise acceptance.
Four questions settle most of it:
- Do you need exploitation demonstrated, or is a configuration review enough?
- Must the cloud account and the application be in one report, or can they be separate?
- Does automated testing alone count, or must people do the testing?
- How recent must the test be, and do you need proof that fixes were rechecked?
If a framework such as SOC 2 or PCI DSS is behind the request, ask the auditor or assessor to point to the exact wording they are applying. We have not quoted either standard here because the answer that matters is theirs.
When the report arrives, check that it names the accounts tested, the access the testers had, the dates, what was left out, evidence for each finding, and the recheck status. A report that doesn't say which accounts it covered will be hard to hand to anyone.
How long does a cloud penetration test take?
It depends on the work, and published figures are thin. Pentest Express says a single-asset external test can be delivered "in as little as 3 business days" from checkout. Astra's pricing page gives 10–15 working days for its manual pentest. The other providers here publish no fixed completion time for these cloud offers.
Those are the providers' own statements about testing time. They are not a booking date. If you have a deadline, ask for the final report date in writing, and leave room for fixes and a recheck.
What if you only use SaaS tools, or already have a test?
Then you may not need to buy anything new.
You use Microsoft 365, Salesforce or Okta but run no cloud infrastructure. There is no cloud account of yours to attack. What you control is tenant settings, user identities and integrations. Tell the requester that, and ask what evidence they want. Subscribing to a product does not give you the right to test that vendor's platform.
You already have a pentest report, or a test bundled with a compliance platform. Read its scope page. If it covered the application and the request was about the application, you may be done. If the request names cloud infrastructure and your report doesn't, the gap might be a configuration review, not a whole new engagement. Ask the requester one thing: "Which part of our existing scope or evidence doesn't meet your request?"
You already run a cloud scanner. It shows that you watch for bad settings. Whether it counts as the test is the recipient's call, not the vendor's.
How we checked this
We read each provider's own service, pricing, terms and documentation pages on October 9, 2026, and each cloud provider's testing policy the same day. We did not buy these services, see a real report, or test anyone's quality. Where a page was silent, the table says "not stated." Provider links here are plain links with no referral codes; see how we make money.
Sources
| Source | Used for | Checked |
|---|---|---|
| Astra plans and pricing | Prices, target definitions, re-scan counts and windows, timing | October 9, 2026 |
| Bishop Fox cloud penetration testing and methodology overview | Method, scenarios, reporting | October 9, 2026 |
| Cobalt cloud pentest methodology and service page | Method and access | October 9, 2026 |
| Cobalt configuration review methodology | Scope, exclusion of exploitation, access | October 9, 2026 |
| Cobalt scoping guide and retest rules | Sizing and retest periods | October 9, 2026 |
| NetSPI cloud pentesting and Azure page | Method and Azure coverage | October 9, 2026 |
| Pentest Express cloud and terms (last updated July 28, 2026) | Scope, prices, retest, payment, report sharing | October 9, 2026 |
| AWS penetration testing policy | Permitted services, prohibited activities, approvals | October 9, 2026 |
| Microsoft Learn: Azure penetration testing and Rules of Engagement | Azure rules | October 9, 2026 |
| Google Cloud Security FAQ | Google Cloud rules | October 9, 2026 |
| AWS Continuum for penetration testing pricing | Self-run tool rate | October 9, 2026 |