Fintech penetration testing: rules, scope and published prices
By The PenTest Index · Rules and offer terms checked October 10, 2026
Fintech penetration testing is a pentest scoped around how money moves: your web app, its APIs and the rules behind payments, transfers and identity checks. What you must buy depends on who asked. The FTC Safeguards Rule, New York's Part 500, PCI DSS and DORA set different terms, and a bank or customer can ask for more.
Find who asked in the first table. Then see what that scope costs from the providers that publish a price.
Our short answer for a product that moves money: buy a test where people sign in as each kind of user and try to break your payment and permission rules, on the web app and the API together. Get the requester's needs in writing first. Add mobile, cloud or network testing only when your rule or your setup calls for it. If your current provider's written scope already covers this, you may not need a new one.
Which rule applies to your fintech?
It depends on who will read the report. Six requesters cover most fintechs, and they do not ask for the same thing. We read the rule text for the first three rows on October 10, 2026.
| Who asked | What the text says | Who may test | What it does not say |
|---|---|---|---|
| FTC Safeguards Rule (US non-bank financial institutions the FTC oversees) | Testing must include "continuous monitoring or periodic penetration testing and vulnerability assessments." Without effective continuous monitoring or other systems that detect, on an ongoing basis, changes that may create vulnerabilities, you need penetration testing every year, scoped from your risk assessment, plus vulnerability assessments at least every six months, whenever operations or business arrangements materially change, and whenever circumstances you know or have reason to know may materially affect your information security program. 16 CFR 314.4(d)(2) | Not stated in this paragraph | This testing paragraph does not apply if you hold customer information on fewer than 5,000 consumers. 16 CFR 314.6. It does not say penetration testing must be entirely manual or entirely automated. |
| New York DFS, 23 NYCRR Part 500 (companies licensed or registered under New York banking, insurance or financial services law) | Penetration testing "from both inside and outside the information systems' boundaries by a qualified internal or external party at least annually." Section 500.5(a)(1) | A qualified internal or external party | It does not require an outside firm. Small covered entities are exempt from 500.5 (see the next section). Having New York customers does not by itself make you a covered entity. |
| DORA (EU financial entities in the regulation's scope) | At least yearly, "appropriate tests" on the systems and applications that support critical or important functions. Penetration testing is one test type on a list of about a dozen. Threat-led penetration testing at least every 3 years (unless the authority adjusts the frequency) applies only to firms their authority has identified. Articles 24 to 26 | "Independent parties, whether internal or external" | It does not say every firm must buy a penetration test each year. The yearly-testing and independence paragraphs do not apply to microenterprises. |
| PCI DSS (you store, process or send card data, or can affect its security) | PCI DSS is a contract standard from the PCI Security Standards Council, enforced through your acquirer or processor. Version 4.0.1 holds its penetration testing requirements under Requirement 11. We could not open the Council's copy of the standard on October 10, 2026, so we do not restate its terms here. | Read Requirement 11 in the PCI SSC document library, or ask your assessor | Whether it reaches you at all. If a processor handles all card data, ask your acquirer which parts apply to you. |
| An audit such as SOC 2 or ISO 27001 | Your auditor decides what evidence is enough. We did not rely on a public clause for this row. | Ask your auditor | A provider's "SOC 2 ready" label is not your auditor's approval. |
| A sponsor bank, partner or customer | Whatever the contract, program agreement or security questionnaire says. This is a private requirement, not a public rule. | Whatever they wrote | Anything, until you get it in writing. |
Three things in those texts surprise people. The FTC rule has a size cutoff and a monitoring alternative. New York and DORA both allow a qualified or independent internal tester. And DORA's yearly duty is "appropriate tests," with a penetration test as one option.
None of this is legal advice. Your regulator, assessor, bank or customer decides what they accept.
Not sure what your requester wants? Send them the eight questions for your report recipient before you compare a single quote.
Is fintech penetration testing required by law?
Sometimes. In the US it turns on which regulator covers you and how big you are. Here is how to check the two rules that name penetration testing.
The FTC Safeguards Rule, in three questions.
- Does the rule cover you? It applies to "financial institutions" under FTC jurisdiction. The rule's own examples include "a business that regularly wires money to and from consumers" and a mortgage broker. A "consumer" in this rule is a person who gets a financial product for personal, family or household use. Ask counsel if you are unsure. 16 CFR 314.2
- Do you hold customer information on fewer than 5,000 consumers? Then the testing paragraph does not apply to you. Other parts of the rule still do.
- Do you have effective continuous monitoring or other ongoing detection systems that catch changes which may create vulnerabilities? If yes, this rule's yearly penetration test is not triggered. Be ready to show why your monitoring is effective. If no, you need the yearly test and the six-monthly and change-triggered vulnerability assessments.
New York Part 500. If you are a covered entity, the answer is yes, every year, from inside and outside your systems. The limited exemption in section 500.19(a) removes section 500.5 for a covered entity with any one of these: fewer than 20 employees and independent contractors (counting affiliates), less than $7.5 million in gross annual revenue in each of the last three fiscal years, or less than $15 million in year-end total assets. The revenue and asset tests have their own counting rules, so read the section before you rely on it.
In the EU, DORA requires a testing program and yearly "appropriate tests" for firms that are not microenterprises. If your authority has identified you for threat-led penetration testing, that is a separate, larger exercise run on live production systems. The ordinary application offers on this page are not a stand-in for it.
Everywhere else, the requirement is usually a contract: PCI DSS through your acquirer, or a clause from a bank or customer.
What should a fintech pentest cover?
The parts where money or identity can be changed. A scanner can tell you a software library is old. It cannot tell you that two transfers sent in the same instant both go through. That second kind of flaw is a business logic flaw: the app works as built, but its rules can be bent.
Use this table to write your scope. Each row is something to name in the quote.
| Part of your product | What to put in the scope | The offer falls short if |
|---|---|---|
| Sign-in, recovery and account changes | Login methods, password reset, session rules, changes to email, phone or payout details | It tests only the public sign-in page and you need signed-in testing |
| Roles and customers | Every user role, and proof that one customer cannot see or act on another's data. In a shared product, each customer organization is a tenant | Required roles or tenant checks are left out |
| Transfers, payouts and refunds | The named steps, approvals, limits and balance effects, using test money | It promises "OWASP testing" but will not confirm these workflows |
| Repeated or overlapping requests | Duplicate, replayed and same-instant transactions. When overlapping requests beat a rule, that is a race condition | These cases are excluded or can't be run in the agreed environment |
| Onboarding and identity checks | Whether a user can act as verified before passing your checks | Verification status is not tested |
| Web, mobile and partner APIs | Each API and version, who calls it, and its documentation | A web-only package is assumed to cover a mobile app or a partner API |
| Payment, bank and identity partners | Your side of each integration. List the partner's systems as out of scope unless the partner agrees in writing | The quote assumes permission to attack your processor or bank |
| Admin and support tools | Internal screens that can move money, change limits or view customer data | Staff tools are skipped |
The rows draw on OWASP's API guidance on object-level authorization and sensitive business flows, and its business logic testing section. The fintech examples are ours. This is a buying checklist, not an official standard or a full test plan.
Does your product move money or only show it?
A read-only dashboard and a payments platform need different checks. If you only display balances pulled from other institutions, the weight sits on the roles row and the partner row. If you start transfers or payouts, add every money-movement row. Don't buy every service with a fintech label on it.
Are mobile apps, cloud and networks included?
Only if the scope names them. Testing the API that a mobile app calls is not the same as testing the app on the phone. Cloud and network testing are separate lines too. New York's "inside and outside" wording points to internal and external testing, not an app test alone.
Counting rules change the price here. Astra's pricing page counts one web app and the APIs it uses as one target, and each mobile platform as its own target. So a web app plus an iOS app plus an Android app is three targets. If each were priced at the listed one-target rate of $5,999 a year, that is $17,997 a year. Astra does not publish a multi-target rate for this plan, so ask. Astra pricing, checked October 10, 2026.
For other kinds of testing, see which penetration testing service fits.
What does a fintech pentest cost?
For one web app, its API and three user roles, the lowest published starting figure we found for testing done by people is $6,100. It comes from Pentest-Tools.com's public formula, before any retest or extra API work. Astra publishes $5,999 a year for one target. The other offers we checked need a quote, so nobody can give you an honest "typical fintech price."
We worked the numbers against one made-up buyer. No provider has quoted for it.
The example. Say you run a 40-person payments platform for businesses. You have one web app and its API, three user roles, two test customers in a sandbox, and a payment partner's sandbox. A bank prospect wants a technical report in eight weeks. You won't share source code. Your engineers expect to need 45 days to fix what is found, and you want the fixes checked by a person.
Each row below applies one requirement from that example to one published offer. Supported means the published terms meet that one condition. Mismatch means they don't. Unresolved means the page doesn't say, so you have to ask. None of these is a verdict on a provider's quality. All terms are provider-published and were checked October 10, 2026.
| Requirement | Offer | Finding | Ask this |
|---|---|---|---|
| Three signed-in roles | Pentest-Tools.com grey box | Supported, starting amount only. $3,400 + (3 × $900) = $6,100. Stated time: 4 or more working days, best effort. Source | "For this app, its API and three roles, what is the complete price, including a retest?" |
| Web app and API as one purchase | Astra Pentest Expert | Supported. One web or SaaS app and the APIs it uses count as one target at $5,999 a year. Astra describes the work as done by certified pentesters and autonomous agents. Source | "Is our API one target with the app, or a standalone API?" |
| Named money-movement workflows | Software Secured fintech testing | Supported as a published scope. Its page says it tests transfers, payouts and refunds with dummy accounts in a sandbox, and checks tenant isolation. Source | "Will the statement of work list each of our workflows and roles?" |
| Named money-movement workflows | Bishop Fox application testing | Supported as a scoping option. Its page says a test can be focused on payment and transaction workflows. Source | "Which workflows and tenant checks does your proposal include?" |
| Named money-movement workflows | Astra, Cobalt, Pentest-Tools.com | Unresolved. Their pages describe manual or expert testing but don't name transfers, refunds or duplicate requests. | "Which of these workflows will a person attempt, and for how long?" |
| A person rechecks fixes, requested on day 45 | Astra Pentest Expert | Mismatch. Two manual rescans, requested within 30 days of the date vulnerabilities were reported. 45 is past 30. Extensions are case by case. Source | "Will you extend the window to day 45 in writing, and at what price?" |
| Same | Software Secured | Supported for timing. Retest requests within 12 months of report delivery. Number of rounds and any fee are not stated. | "How many retest rounds are included?" |
| Same | Cobalt Agile or Comprehensive Pentests | Supported for timing, with a cutoff. Free retesting for 6 months on Standard and 12 months on Premium and Enterprise, ending no later than 10 days before your contract ends. Source | "What is our retest end date under this contract?" |
| Same | Bishop Fox, Pentest-Tools.com | Unresolved. Bishop Fox lists retesting without a count or window. We found no retest term on the Pentest-Tools.com service page. | "Is a retest included, and until when?" |
| Report in eight weeks | All five | Unresolved. Stated timings are not bookings. Software Secured says scheduling is within 3 to 6 weeks, sometimes sooner, then a report 48 to 72 hours after testing ends. Bishop Fox describes 1 to 2 weeks of scoping, 1 to 3 of fieldwork and 1 to 2 of reporting. Astra says its manual test takes 10 to 15 working days. | "What final report date will you put in the contract?" |
| The bank accepts the report | All five | Unresolved. Only the bank can say. | Ask the bank first (see below). |
Which offers deserve a closer look?
For the buyer in the example, ask Software Secured and Bishop Fox for a scoped quote first. Their published pages are the two that name money-movement testing. Use Pentest-Tools.com's $6,100 as a floor to judge those quotes against, and ask it the workflow question too. Astra Pentest Expert is out for this buyer unless Astra extends the rescan window in writing. Software Secured's 3 to 6 week scheduling may be tight against an eight-week deadline, so get the date before anything else.
If you want a published price and can fix fast, Astra Pentest Expert at $5,999 a year and Pentest-Tools.com's formula are the two places to start. Both are annual or project prices for a defined target, not quotes for your scope.
If you plan several tests a year, look at Cobalt's credit packages. One credit is "the equivalent of 8 hours" of testing delivered by automation and people together, so it is not eight hours of a person's time. Cobalt's pricing page also disagrees with itself in two places. Its Enterprise column lists credit rollover of up to 10% while its FAQ says credits do not roll over, and the FAQ promises unlimited retesting for the contract term while the tier table lists 6 or 12 months. Get both terms in writing. Cobalt pricing
If you already have a provider, send it the same scope and questions. A new purchase is unnecessary if its written scope meets the need.
View Astra's plans and target rules
View Bishop Fox application testing
View the Pentest-Tools.com price formula
View Software Secured fintech testing
We also keep fuller profiles of Astra, Cobalt and Pentest-Tools.com, and a wider table of published penetration testing prices.
Your scope won't match our example. Answer a few questions about why you need the test and what needs testing, and Find My PenTest Match shows which of our compared web app and API offers fit, with a scope checklist to copy or print. It's free, there is no email or sign-up, and nothing is sent to providers.
Will an AI or automated pentest be accepted?
Only your requester can say, so ask in writing before you buy. None of the three rule texts we read says penetration testing must be entirely manual or entirely automated. The FTC rule defines penetration testing as a method in which "assessors attempt to circumvent or defeat the security features of an information system." Whether a given automated product meets that is not ours to decide.
Two published details are worth knowing. Cobalt lists an Autonomous Pentest for web applications at $3,500 per test as a limited-time offer. The test must start and finish before December 31, 2026, and Cobalt says its pentesters direct each engagement. Intruder's AI pentest page lists "Connect your codebase" as its first step, which rules it out for the buyer in our example, and advertises a refund if your auditor rejects the report. A refund promise is not acceptance.
If your requester says automated testing is fine, put these offers through the same scope table. If the answer is unclear, read penetration testing versus vulnerability scanning so you know what you are being sold.
What does a bank or customer want from the report?
Whatever their request says, so get it in writing before you compare offers. A provider's list of compliance logos tells you nothing about what your bank will accept.
Send the person who asked these questions:
- Which systems must the test cover, and is anything excluded?
- Is automated testing alone acceptable, or must people test it?
- Must the tester be outside our company, or hold a particular qualification?
- What must the report contain? Is a summary letter enough?
- How recent must the test be when we hand it over?
- Do you need proof that findings were fixed and rechecked?
- When do you need it?
Their answers become part of your scope. A requester can tell you what it will accept. It cannot remove a legal duty you already have.
A fintech scope brief you can copy
Send every provider the same brief. That way each one answers the same question and you can line the answers up. Replace the bracketed parts with your own details and leave unknowns visible.
PENETRATION TEST SCOPE BRIEF 1. Why and for whom [Why we need the test. Who receives the report. The exact clause or request, if we have it.] 2. What to test [Web app, API names and versions, mobile apps, cloud or network, hostnames, test environment.] 3. Roles and customers [Each user role. Test accounts we will supply. How customers are separated from each other.] 4. Money and identity workflows [Transfers, payouts, refunds, approvals, limits, onboarding and verification steps that matter.] 5. Cases we want attempted [Acting across customers or roles. Duplicate, replayed and same-instant requests. Skipping a step.] 6. Access we will give [Accounts and API documentation. Source code: yes or no.] 7. Third parties and limits [Partner systems that are out of scope. Sandbox money and data. Request limits. Who to call to stop.] 8. Report and dates [What the report must contain. Final report deadline. Who will read it.] 9. Retest [When our fixes will be ready. How long we need to request a retest. Who must do it.] 10. What we need back [Itemized scope and effort, who tests, currency, full price, required fees, contract length, retest count and window, final report date in writing.] This brief is a buying aid. It does not authorize testing. Written authorization must cover the actual targets and activities. Do not include passwords, keys or customer data.
For a filled-in general example, see a worked penetration testing scope. To check a proposal you already hold, use Quote Check.
Can the test run in production?
Use the environment and the activities that the system owners approve in writing. A sandbox is the usual place for money-movement cases, and Software Secured says it prefers staging or user-testing environments. Write down how your sandbox differs from production, because a tester can only vouch for what was tested.
Agree these before work starts: which targets, which activities, request and transaction limits, how test data is handled, and who can stop the test. Your payment processor, bank partner and cloud host each have their own rules about being tested. Have a lawyer look at the authorization and the liability terms. NIST's testing guide, SP 800-115, treats these rules of engagement as part of planning.
How often does a fintech need testing?
Start from the floor your rule sets, then add tests when the product changes in ways that matter. The FTC and New York texts say yearly. DORA says yearly "appropriate tests." A report from last spring says nothing about the payout feature you shipped in the fall.
If budget is tight, a common pattern is one full test a year plus smaller tests of changed money-movement workflows. Rotating scope is fine for the extra tests. It does not replace a full scope that a rule requires.
Other questions before you book
Is a fintech pentest a different product from a normal pentest?
No. The method is the same. The scope is different, because the tester needs to understand your payment and permission rules. A provider with a fintech page has not proved it will test them. The written scope does that.
Do we need a pentest or a red team?
A pentest looks for weaknesses in an agreed set of systems. A red team exercise tests whether your people and tools notice and respond to an attack. If the request is about detection and response, ask the requester which one they mean before you buy.
How we checked this
The PenTest Index is an independent buying resource. We do not perform, authorize or certify penetration testing. For this page we read rule text and provider pages on October 10, 2026, applied them to one fictional buyer, and did the arithmetic shown. We did not buy a test, collect quotes or see a provider's report. Read how we check offers and how we make money.
Sources
All read October 10, 2026 unless noted.
Rules
- 16 CFR 314.2, definitions, 314.4, elements and 314.6, exceptions. eCFR, shown as current to October 7, 2026.
- 23 NYCRR Part 500, text as amended November 1, 2023. Sections 500.1, 500.5 and 500.19. Hosted by the New York Department of Financial Services.
- Regulation (EU) 2022/2554 (DORA). Articles 24, 25 and 26. EUR-Lex.
- PCI SSC document library. We could not open the Council's copy on this date and quote no terms from it.
Provider pages (provider-published terms)
- Astra pricing and Astra rescan quota and validity
- Bishop Fox application penetration testing
- Cobalt pricing and Cobalt retesting
- Intruder AI pentest page
- Pentest-Tools.com web application penetration testing
- Software Secured fintech penetration testing
Guidance
- OWASP API Security Top 10 2023: API1, Broken Object Level Authorization and API6, Unrestricted Access to Sensitive Business Flows
- OWASP Web Security Testing Guide v4.2, Business Logic Testing
- NIST SP 800-115, Technical Guide to Information Security Testing and Assessment
None of these organizations endorses this site or any provider.