This site may contain affiliate or referral links. If you buy through one, we may be compensated. How we make money

Mobile application penetration testing services: prices, scope and retest terms compared

By The PenTest Index · Offers checked October 9, 2026

Mobile application penetration testing services test your iOS or Android app and, only if the scope says so, the API behind it. Four of eight providers we checked on October 9, 2026 publish a starting price; the selected pricing cards and listings run from $2,200 per app (Astra, shared codebase) to $6,000 (Blaze). Astra and NowSecure count iOS and Android as two units, so name both builds.

The short version. If a customer or auditor asked for a pentest report, buy a human-led test that names the app builds and API in the requested scope. If your fixes will take more than a month, look first at Blaze and Software Secured, because Astra Pentest Expert's included re-check must be requested within 30 days. If all you want is the Google Play security badge, you need a different review, covered below.

Mobile application penetration testing services compared

Compare the exact offer, not the company. The same provider can sell a yearly plan, a one-off test and a quote-only service, and each has its own price unit and re-check rules.

Companies are listed A to Z within each group. This is not a ranking. Prices are in US dollars. Everything below is provider-published: we read it on the provider's own pages on October 9, 2026. We have not bought these tests.

Offers with a published starting price

Table columns: Provider and offer; Published price and unit; iOS and Android; Backend API; Retest terms; Stated timing.
Provider and offerPublished price and unitiOS and AndroidBackend APIRetest termsStated timing
Astra, Pentest Expert$5,999 per year per target. For apps that share a codebase, its FAQ says "tailored pricing starting from $2200/app depending on the scope". The billing period for that figure is not stated. PricingTwo targets. "Mobile is per platform, so an Android app and an iOS app are two targets."Not stated for a mobile target. Standalone APIs count as one target each.2 manual rescans, within 30 days of the date the vulnerabilities were reported. Fix at least 50% of Critical and High findings first. Extensions case by case. Rescan rulesManual pentest: 10 to 15 working days (pricing FAQ)
Blaze, mobile app pentest"From $5,299" in its cost guide. "Prices starting at $6,000" on its AWS Marketplace listing, followed by a private offer.Tests "each iOS and Android build". Its cost guide associates $5,299–$9,999 with a single platform. Platform coverage at the $6,000 Marketplace starting price is not stated."Can be included." A large or shared API estate "may need a dedicated API pentest". Mobile pageAWS listing: free fix validation within 90 days of the final report. Its own site says retesting is available "when included".Average start about two weeks. Effort 5 to 25 person-days (AWS listing).
Halo Security, mobile app pentest"Starts at $3,950", then a fixed-price quote after a scoping call. Service pageNumber of platforms is a listed price factor. No multiplier published.Backend API complexity is a listed price factor. Backend API testing is listed in its coverage; the full API scope at the starting price is not stated.One round of retesting included. Window not stated.1 to 2 weeks for one platform, 2 to 3 for both, 3 to 4 for complex apps
Software Secured, Mobile App Pentesting"Starts at $5,400 USD." Pricing Its mobile service page also displays $10,800 USD. The pages do not explain the difference; confirm the applicable starting scope.Scoping is "based on platforms, APIs, SDKs". Whether the starting price covers one platform or two is not stated.APIs are named in its coverage line."3 rounds over 12 months." Requests within 12 months of report delivery.Scheduling within 3 to 6 weeks, sometimes sooner; report within 48 to 72 hours of test completion

Quote-only offers

Table columns: Provider and offer; What it publishes about mobile; Price basis; Retest terms.
Provider and offerWhat it publishes about mobilePrice basisRetest terms
Cobalt, pentest under an annual credit packageMethod based on OWASP MASVS and MASTG. Testers "do not need access to the source code", unless you require it. You share the IPA and/or APK files. Backend work follows its API method. Mobile methodAnnual credits. No mobile figure. Credits needed for your scope require a quote. PricingThe help policy states free retesting for 6 months (Standard) or 12 months (Premium, Enterprise), only while the contract is active, and no later than 10 days before it ends. The pricing FAQ instead describes retesting throughout the contract; confirm the applicable end date. Retest policy
DeepStrike, mobile app pentestManual testing with API security testing listed. Service pageQuote. No unit stated."Free Unlimited Re-testing" on the mobile page. Its Basic pricing plan lists 12 months of remediation retesting; confirm that plan applies to the mobile quote and when the period starts.
NetSPI, Mobile App Pentesting"Human-led" testing for iOS and Android, covering "both client-side and backend server functionality". Service pageQuote. No figure on the page.Not stated on the mobile page.
NowSecure, mobile app pen testTesting on real iOS and Android devices, signed in as a user. Sells full-scope and focused tests. Service pageQuote. Its terms (effective August 6, 2026) count the same app on iOS and Android as two Apps."A retest to confirm the fix" is listed. Count and window not stated.

Two things follow from these tables. A provider that can test both platforms has not told you one price covers both. And two platforms does not mean you pay for two full API tests. Ask every provider to split the quote into three lines: iOS work, Android work and shared backend work.

Which mobile pentest offers deserve a closer look?

Start with the condition that would rule an offer out for you. For most teams that is the retest date, then source code access, then how the app is counted.

Table columns: Your situation; Look first; What to confirm.
Your situationLook firstWhat to confirm
One test this year, and fixes will take longer than 30 daysBlaze, Software SecuredThat the retest is written into your offer, and what starts the clock
You can share app files but not source codeBlaze, Cobalt, Software Secured"Can you finish this scope with builds and test accounts only? What would be left out?"
Several tests a year across apps and APIsCobaltCredits needed per test, and your contract end date
You want a yearly plan and can fix inside 30 daysAstra Pentest ExpertTarget count, whether the API is a third target, and which plan the "$2,200/app" figure belongs to
One platform and a low published starting figureHalo SecurityWhat the starting price leaves out, and the retest window
Complex signed-in flows, or you need proof on real devicesNowSecure, NetSPIFull-scope or focused, NowSecure's two-app count, and retest terms
You already have a pentest provider or a recent API reportYour current provider"Which mobile app and app-to-API work does our last report leave open?"

That last row matters. If your API was tested recently and has not changed much, you may only need the two app builds tested. Ask before you buy a whole new assessment.

A worked Purchase Check

A Purchase Check is how we turn published terms into a decision: take one buyer's requirements, apply them to one exact offer and record what the evidence shows. "Supported" means that one condition is backed by what the provider published. It is not a verdict on testing quality, and it does not mean your customer will accept the report.

Here is an example. It is made up, and no provider has quoted for it.

The brief: Say you ship one app on iOS and Android from a shared React Native codebase. It talks to one API and has two user roles. You can hand over app files, test accounts and API docs, but not source code. Your customer wants a report that names both builds and the API. Findings and the final report arrive on the same day, and your fixes will be ready for a manual re-check 45 days later.

Table columns: Requirement; Offer; What the published terms show; Finding; Question to send.
RequirementOfferWhat the published terms showFindingQuestion to send
Manual retest requested on day 45Astra Pentest ExpertRescans must be requested within 30 days of findings being reportedMismatch"Will you include a manual rescan requested on day 45, and at what price?"
Manual retest requested on day 45Blaze, AWS Marketplace listingFix validation within 90 days of the final reportUnresolved on the request deadline; day 45 falls within the published validation period"Confirm the day-45 retest is in our offer, and whether 90 days is the date to request or to finish."
Manual retest requested on day 45Software Secured3 rounds; requests within 12 months of report deliverySupported for the timing condition"Confirm our report-delivery date and available retest rounds."
Manual retest requested on day 45Cobalt6 or 12 months by tier, capped at 10 days before the contract endsUnresolved until Cobalt confirms the applicable retest end date"What is our last retest submission date?"
Manual retest requested on day 45Halo, NetSPI, NowSecureA retest is listed, but no windowUnresolved"Until what date can we request the included retest?"
Manual retest requested on day 45DeepStrikeBasic lists 12 months; mobile-plan applicability and the clock start are not establishedUnresolved"Does Basic apply to our mobile quote, and what is our last retest request date?"
No source codeBlaze, Cobalt, Software SecuredAll three say they can test app files without sourceSupported"List anything you could not test without source."
Both platforms pricedAstra Pentest ExpertTwo targets at $5,999 eachSupported: $11,998 per year at list. The API may be a further target."Is our API a third target? Does shared-codebase pricing apply instead?"
Both platforms pricedNowSecureTwo Apps under its termsSupported as a count. Price is unresolved."Itemize both apps and the shared API work."
Complete price for both builds plus the APIEvery offerNo provider publishes this totalUnresolved"What is the complete price for iOS, Android and the API with two roles, including the day-45 retest?"

What this means for that buyer. Astra Pentest Expert is out on its included terms, because day 45 is past the 30-day window. It comes back in only if Astra extends the window in writing. Blaze and Cobalt pass the no-source-code condition; Blaze's day-45 request deadline and Cobalt's applicable retest end date still need confirmation. Software Secured passes the published retest and no-source conditions. Between them, the choice is about how you buy. Blaze and Software Secured publish a starting dollar figure for a single test. Cobalt sells a year of credits, which makes more sense if you will run several tests.

One answer that still decides it is the complete price. Nobody publishes it for two builds plus an API, so send the same brief to each and compare the itemized replies.

Compare the offers that may fit:

View Blaze mobile testing

View Software Secured pricing

View Cobalt plans

If your fixes will land inside 30 days, or you want scanning included in a yearly plan:

View Astra plans

For a single platform, or for testing on real devices:

View Halo mobile testing

View NowSecure mobile testing

View NetSPI mobile testing

These links open the provider's own page. They do not send your details to anyone.

How much does a mobile app penetration test cost?

The selected pricing cards and listings show starting figures from $2,200 to $6,000, but none of them is a full price for two app builds plus an API. Here is what each number actually is, as checked on October 9, 2026:

  • $2,200 per app. Astra's starting point for "tailored pricing" when iOS and Android share a codebase. The billing period is not stated.
  • $3,950. Halo Security's starting price before a scoping call.
  • $5,299 and $6,000. Blaze's starting prices in its own cost guide and on AWS Marketplace. They differ by channel, and the Marketplace price leads to a private offer.
  • $5,400. Software Secured's mobile pricing-card figure. Its mobile service page also displays $10,800 USD; confirm the applicable starting scope.
  • $5,999 per year per target. Astra's Pentest Expert plan. An iOS app and an Android app are two targets, so the list arithmetic for both is 2 × $5,999 = $11,998 a year. That is our sum from Astra's published rule, not a quote.

A starting price is the floor for the smallest job the provider will take. These are the things that move it:

  1. Platforms. One build or two.
  2. The API. In, out or already tested.
  3. User roles. Each extra role is more permission checking.
  4. Source code. Testing with it can go deeper and may be scoped differently.
  5. Retest terms. A second re-check, or a later one, can cost extra.
  6. Commitment. One test, or a yearly plan or credit package.

You will also see wide ranges quoted around the web. Blaze's cost guide, for example, lists $5,000 to $30,000 as the "average 2026 cost" of a mobile app pentest. That is Blaze's estimate. We do not have a measured market average, and we will not invent one.

For prices across every kind of test, see penetration testing cost.

Do iOS and Android need separate penetration tests?

If you ship both, both need to be in the scope, and most pricing treats them as two units. Astra counts two targets. NowSecure's terms count two Apps. Blaze says it tests "each iOS and Android build" with platform-specific techniques, "even when both apps share a backend". Halo lists the number of platforms as a price factor.

Why can't one test cover both? Think of the same recipe cooked in two different kitchens. The logic is shared. But where the app keeps data on the phone, how it talks to other apps and how it resists tampering are built differently on each system. A flaw on Android may not exist on iOS, and the reverse.

A shared codebase, such as React Native or Flutter, is still worth mentioning to providers. Astra says in writing that it changes the price. Ask the others to show which work is shared and which is per platform.

If you only ship on one platform, say so and skip the second. Don't pay for an Android test of an app that doesn't exist.

Does a mobile app pentest include the backend API?

Not automatically. An API is the server-side interface your app sends data to and gets data from. OWASP, the nonprofit behind the main mobile security standard, is blunt about the gap: its Mobile Application Security Verification Standard (MASVS) "only covers the security of the mobile app (client-side)", and the remote endpoints "should be verified against appropriate standards" of their own. OWASP source

This matters because the app is the remote control and the API is the TV. Most of what an attacker wants, such as other customers' data, lives behind the API.

What the providers publish:

  • Blaze: APIs "can be included". A large or shared API estate "may need a dedicated API pentest".
  • Cobalt: backend testing follows its separate API method.
  • NetSPI: tests "both client-side and backend server functionality".
  • Software Secured: names APIs in its mobile coverage line.
  • Astra: mobile API testing is listed, but the included scope is not defined. Standalone APIs count as one target each.
  • Halo Security: API complexity changes the price.

So write the API into your request by name: which services, which environment, which roles. Then ask whether it is included, excluded or priced separately.

What if the API was already tested?

Then you may not need to pay for it twice. Give the provider the earlier report's scope and date, and tell them what has changed since. Ask them to price only what is still open: the two app builds and the way they talk to the API. Check with whoever asked for the report that the earlier API test still counts for them.

If you also have a web app on the same API, see web application penetration testing services.

Will the retest window last until your fixes are ready?

"Retest included" tells you almost nothing until you know the count, the deadline and what starts the clock. A retest is the provider checking that your fixes worked. If you miss the window, you either pay again or hand your customer a report with open findings.

The clocks we could read on October 9, 2026 start from different events:

Table columns: Offer; Included re-checks; Deadline; Clock starts.
OfferIncluded re-checksDeadlineClock starts
Astra Pentest Expert2 manual rescans30 daysThe date the vulnerabilities were reported
Astra Enterprise (from $9,999 per year)4 rescans90 daysThe date the vulnerabilities were reported
Blaze, AWS Marketplace listingFix validation, count not stated90 daysThe final report
CobaltFree retesting6 months (Standard) or 12 months (Premium, Enterprise)Not stated in the policy we read. Capped at 10 days before your contract does.
Software Secured3 rounds12 months for requestsReport delivery
Halo Security1 roundNot statedNot stated
DeepStrike"Unlimited" on the mobile pageBasic plan: 12 months; applicability to mobile quote requires confirmationNot stated

Two details are easy to miss. Astra asks you to fix at least 50% of Critical and High findings before you request a manual rescan. And Cobalt's deadline is tied to your contract, not only your tier. Say your Cobalt contract ends December 20. Under the documented ten-day rule, the contract-based submission cutoff is December 10, even if your tier's 12 months would run longer.

Check your own date:

Retest date check

This assumes your findings and final report arrive on the same day. If your report arrives later, the Blaze and Software Secured clocks start later.

Enter a whole number from 0 to 365, or select “Not sure”.

Enter a whole number, or leave “Not sure” selected.

Worked example, without entering anything: D = 45, C = Not sure; Astra Pentest Expert: Mismatch; Astra Enterprise: Supported for timing; Blaze: Unresolved on request deadline; Software Secured: Supported for timing; Cobalt: Unresolved; Halo Security, DeepStrike, NetSPI and NowSecure: Unresolved.

Your results

  1. Astra Pentest Expert

    Finding: Unresolved

    Ask your team when fixes will be ready, then check again. 2 manual rescans. Fix at least 50% of Critical and High findings first. Extensions case by case.

    Source checked October 9, 2026: Astra Pentest Expert source

  2. Astra Enterprise

    Finding: Unresolved

    Ask your team when fixes will be ready, then check again. 4 manual rescans, subject to remaining quota. Fix at least 50% of Critical and High findings first. Extensions case by case. Plan is $9,999 per year onwards.

    Source checked October 9, 2026: Astra Enterprise source; Astra pricing

  3. Blaze (AWS Marketplace listing)

    Finding: Unresolved

    Ask your team when fixes will be ready, then check again. Fix validation is published within 90 days of the final report; the last request date and completion schedule need confirmation.

    Source checked October 9, 2026: Blaze (AWS Marketplace listing) source

  4. Software Secured

    Finding: Unresolved

    Ask your team when fixes will be ready, then check again. 3 rounds; requests are within 12 months of report delivery.

    Source checked October 9, 2026: Software Secured source; Software Secured mobile service

  5. Cobalt

    Finding: Unresolved

    Ask your team when fixes will be ready, then check again. The contract cutoff is a cap, and the tier period can expire earlier; confirm the applicable tier end date.

    Source checked October 9, 2026: Cobalt source; Cobalt pricing

  6. DeepStrike

    Finding: Unresolved

    Ask your team when fixes will be ready, then check again. Basic lists 12 months; confirm the mobile quote's plan, clock start and last request date.

    Source checked October 9, 2026: DeepStrike source

  7. Halo Security

    Finding: Unresolved

    Ask your team when fixes will be ready, then check again. A retest is listed but no window is published. Ask for the last request date in writing.

    Source checked October 9, 2026: Halo Security source

  8. NetSPI

    Finding: Unresolved

    Ask your team when fixes will be ready, then check again. A retest is listed but no window is published. Ask for the last request date in writing.

    Source checked October 9, 2026: NetSPI source

  9. NowSecure

    Finding: Unresolved

    Ask your team when fixes will be ready, then check again. A retest is listed but no window is published. Ask for the last request date in writing.

    Source checked October 9, 2026: NowSecure source

Nothing is saved or sent. No credentials, vulnerability details or app names are collected.

What does a mobile app penetration test cover?

A penetration test, or pentest, is people trying to break into your app the way an attacker would, with your written permission. For a mobile app that means the app file itself, what it stores on the phone, what it sends over the network, how it deals with other apps and how hard it is to tamper with.

OWASP sorts this into eight groups in its MASVS standard: storage, cryptography, authentication and authorization, network communication, platform interaction, code quality, resilience against reverse engineering and tampering, and privacy. OWASP source Most providers on this page say their method follows it. That is a useful shared checklist, but OWASP "does not certify any vendors, verifiers or software", so "MASVS certified" on a sales page is the provider's own claim.

Two things to settle before you compare offers:

Is it a pentest or a scan? A scan is software checking for known problems. It is quick and cheap, and it misses flaws in how your app's own features can be misused. If the request says "penetration test", an automated scan alone may not meet it. See penetration testing vs vulnerability scanning.

Which build gets tested? Some providers ask for a build with protections switched off so they can see inside it. Astra, for example, asks for an app file "with SSL pinning and Root/Jailbreak Detection disabled". Astra setup guide That is a normal way to test what is underneath. But if those protections matter to your customer, ask: "Will you also test the protections in the build we actually ship, and will the report say which build each finding came from?"

If you are still deciding what kind of test you need at all, start with penetration testing services.

What will testers need from you, and how long does it take?

Plan on one to four weeks of testing once access is ready, plus the wait for a start date. The providers that publish timing say:

  • Halo Security: 1 to 2 weeks for one platform, 2 to 3 for both, 3 to 4 for complex apps.
  • Blaze: an average start time of "about two weeks" after scoping, and 5 to 25 person-days of effort. A person-day is one tester for one day, so it measures effort, not calendar time.
  • Astra: 10 to 15 working days for the manual pentest, per its pricing FAQ. Its help documentation gives a wider 10 to 20, so ask for your schedule in writing.
  • Cobalt: once you submit a fix, the tester rechecks it "within seven days".

None of these is a promised report date. If you have a deadline, ask for four dates in the proposal: when access must be ready, when testing starts, when the report arrives and the last day to request a retest.

What to have ready, based on the intake lists Halo, Cobalt and Astra publish:

  • The app files: an IPA for iOS and an APK for Android
  • One test account for each user role
  • A staging or test backend the provider is allowed to test
  • API documentation, if you have it
  • Source code only if you want that deeper review

Missing test accounts and late builds are things you control, so sort them out before the start date.

What should a mobile pentest report show?

It should let your customer and your engineers see exactly what was tested, what was left out and how each finding was proven. OWASP's guidance for organizations certifying against MASVS says a report must include "the scope of the verification (particularly if a key component is out of scope)" and a summary of findings with clear indications of how to resolve them.

We read one public example, labeled here as a sample we inspected, not a test we bought. NetSPI publishes a five-page preview of a mobile report with a 2024 cover date. In its scope section it shows:

Table columns: What the preview shows; Why it helps you; What it does not prove.
What the preview showsWhy it helps youWhat it does not prove
Separate tables for the Android and iOS builds, each with version and a file fingerprint (SHA256)You can match the report to the exact build you shippedThat your quote covers both builds
The test accounts and their rolesYou can see whose permissions were testedThat every role you have was included
A line that everything else was out of scopeNo arguing later about what was coveredAnything about the full findings, which are not in the preview

Ask any provider for a recent redacted mobile report and check it against these three things. Then check with the person who asked for the report. See the penetration testing report checklist. They decide whether it is acceptable. The provider doesn't, and neither do we.

Is Google Play's independent security review the same as a pentest?

No. If the request is for the "Independent Security Review" badge on Google Play, a general pentest will not get you there.

Google describes the review as "optional" and "undertaken and paid for by developers". It runs through a program called Mobile Application Security Assessment (MASA), where a Google Authorized Lab checks your Android app against OWASP's MASVS. Once the lab has verified the app, you can show the badge in your Data safety section. Google Play guidance

It is also a narrower check. The App Defense Alliance, which runs MASA, directs apps to its current MASA specification, built on MASVS, and says that "the limited nature of testing does not guarantee complete safety of the application". MASA overview NowSecure, which says its accredited scope covers MASA, states on its own page that this scope is narrower than its pen test.

So match the purchase to the request:

  • A customer wants a pentest report: buy the pentest.
  • You want the Play badge: contact a lab from the official list on the MASA site.
  • You want both: the scopes can be quoted together, and they need not come from the same company.

Mobile scope brief to send every provider

Send every provider the same brief so their answers line up. If each one prices a different job, the cheapest quote is often just the smallest job.

Copy this, fill it in privately and send it to the providers you picked.

Mobile pentest scope brief

Why we need it and who reads the report: [customer request, audit, launch] / [who receives it and what they asked for, in their words]

Platforms: [iOS / Android / both] Framework: [native / React Native / Flutter / other / not sure]

Builds: [app name and version for each platform, shared privately]

Backend API: [which services, which environment]. Please state whether API testing is included, excluded or priced separately.

Earlier testing: [date and scope of any earlier API or mobile test, and what has changed since]. Please price only the work that is still open.

User roles: [list each role]. Sensitive flows: [payments, account recovery, exports, health data and so on]

What we can give you: [app files, test accounts, API docs, staging backend, source code yes or no]. Tell us which build you need and whether any protections must be switched off.

Report: Please confirm the report will name each build tested, the API scope, exclusions and how each finding was proven. Please send a recent redacted mobile sample.

Dates: access ready on [date]; report needed by [date]; fixes ready for retest around [date].

Retest: How many manual retests are included? What starts the clock? What is the last day we can request one? What does an extra round cost?

Price: Please itemize iOS work, Android work and shared backend work. Include any platform or subscription fee, the full commitment, the billing schedule and renewal terms.

A filled-in example (fictional): Lumen Ledger is a made-up expense app. Why: a customer's security questionnaire asks for a pentest report within 90 days. Platforms: both, React Native. API: one REST API on staging, in scope. Earlier testing: none. Roles: employee and finance admin. What we can give: IPA, APK, two accounts per role, API docs, no source code. Dates: access ready November 3, report by December 5, fixes ready about 45 days after findings. Retest: one manual round needed around day 45.

This brief is a buying aid. It does not give anyone permission to test. Before work starts, you and the provider need written authorization that names the real targets and activities. Keep passwords, keys and details of known weaknesses out of the brief, and agree with your chosen provider how to share access safely.

Buying more than a mobile test? Find My PenTest Match gives you a general scope checklist for web apps, APIs and other systems, plus the questions to ask whoever will read the report. It is free to copy or print and asks for no contact details. It does not list mobile providers yet, so use the tables on this page for those.

Find My PenTest Match

How we checked these offers

We read each provider's public pricing, mobile service, retest and setup pages on October 9, 2026, plus one public sample report preview. We quote their words where the exact wording matters, and we mark anything they do not state as "not stated" instead of guessing.

We did not buy these tests, we have not judged anyone's testing quality, and no provider has quoted for the example brief. The Purchase Check findings apply to the single condition named in each row. Our methodology explains the labels, and how we make money explains our links. Providers appear here because they rank for this search, publish terms we could compare or both. None paid to be included.

Sources and check dates

All checked October 9, 2026 unless noted.

Table columns: Source; What we used it for.
SourceWhat we used it for
Astra pricingPlan prices, target rule, shared-codebase FAQ, rescan counts, timing
Astra rescan rulesRescan window, start of the clock, 50% rule, extensions
Astra iOS or Android target setupBuild and account requirements
Astra mobile application security servicesPublished mobile API testing capability
Blaze mobile service pagePlatforms, source code, API, start time, retesting "when included"
Blaze on AWS MarketplaceStarting price, person-days, 90-day fix validation
Blaze cost guide"From $5,299", duration, Blaze's stated average range
Cobalt mobile methodologiesSource code, app files, backend method
Cobalt retest policyRetest periods, contract cutoff, seven-day recheck
Cobalt pricingAnnual credit packages (checked October 7 and 8, 2026)
DeepStrike mobile service pageScope, retesting statement
DeepStrike pricingBasic-plan retest period; mobile applicability and clock remain unresolved
Halo Security mobile service pageStarting price, retest round, timing, intake list
NetSPI mobile service pageScope description
NetSPI mobile sample report previewSample inspected: build tables, roles, out-of-scope line
NowSecure mobile service pageReal-device testing, test types, retest, MASA scope comparison
NowSecure terms and conditionsDefinition of an App, effective August 6, 2026
Software Secured pricingStarting price, scoping basis, retest rounds
Software Secured mobile serviceDifferent displayed starting figure, report-delivery retest clock, source-free testing and stated timing
OWASP MASVS: Assessment and CertificationClient-side boundary, no OWASP certification, report contents
OWASP: Using the MASVSThe eight control groups
Google Play: Data safety guidanceIndependent security review
App Defense Alliance: MASATransition notice and stated limits
App Defense Alliance: current MASA specificationCurrent requirements replacing the legacy Level 1 description
NowSecure PTaaSOptional standards validation alongside expert testing

Offer terms change. Each figure on this page is what the provider published on the date shown, not a quote for your project.