This site may contain affiliate or referral links. If you buy through one, we may be compensated. How we make money

Penetration testing as a service (PTaaS): what you actually buy

By The PenTest Index · Offers and terms checked October 9, 2026

Penetration testing as a service (PTaaS) is a way to buy and run penetration tests through a provider's online platform, as one test, a yearly plan or a pool of credits. The label doesn't tell you how much new testing you get, who does it, or what unused credits and late retests will cost you.

Those details are where the money goes. For one web app, the published first-year prices we found run from $2,999 for an AI-led plan to $152,400 for year-long human testing with a required platform fee. Below are the offers, the terms and the math.

Your situationThe route that fitsWhat could rule it out
You need one report by a dateOne scoped test. A platform is a nice extra, not the pointA retest window shorter than the time you need to fix things
You need a first test plus checks after big releasesA plan that pays for new testing after each releaseA plan that only includes scans and retests after the first test
You want testers active all yearA year-long program with stated activity and reportingA price that covers a testing window but no stated effort
You already have a provider or a test included elsewhereCheck its scope, date and report firstA real gap between what you have and what was asked for

Which penetration testing as a service offer fits your team?

Pick by the work you need done, then by the company. The same provider often sells a human-led test, an AI-led test and a scanner under one PTaaS banner, at very different prices.

Every fact below comes from the provider's own pages, read on October 9, 2026. We have not bought these services or tested their quality. Prices are in US dollars as shown by the provider. Providers are listed A to Z. This is not a ranking.

Offers that include human testers

OfferWhat you pay for up frontPublished priceWhat expires or runs out
Astra Pentest ExpertA yearly plan for one target. One web app and the APIs it calls count as one target$5,999 per target per yearHow many manual tests you get in the year is not stated. Ask
BreachLock Standard, Extended, ExtensiveA scoped project. Platform access is optionalQuote on the current pricing page. An older official page still shows "starts at $2,500" for a one-time test and "$5K" for annualAsk which page applies to you
Cobalt Standard, Premium, EnterpriseA yearly pack of credits. One credit is "the equivalent of 8 hours" of AI and human work combinedQuote onlyUnused credits expire when the contract ends
HackerOne H1 PentestA platform edition plus testing hours. Each test runs 14 days, with 40 hours per testerQuote onlyHours are drawn down during the contract period
NetSPI PTaaSOne point-in-time test plus a year of platform accessQuote onlyLater tests are not part of that description. Ask what is included
Synack SynackSTOne 5-day test (5–10 days for AWS Large) by an assigned researcher, plus a required platform lineSynack's site: from $10,283 per test, platform separate. Synack's AWS Marketplace list: $10,010 (small app, one role) or $16,720 (large app, 2 to 3 roles), plus $16,000 for the platform, per 12 monthsThe FAQ says one year after purchase; the product terms limit credits to the subscription period or earlier termination
Synack Synack365Rotating researchers over a 365-day windowSynack's site: contact sales. AWS Marketplace list: $136,400 plus the $16,000 platform, per 12 monthsAsk what activity is promised inside the window

Offers led by AI

automated penetration testing explained.

OfferWhat it isPublished priceThe condition that matters
Astra Pentest AutoAutonomous testing of one web or SaaS app$2,999 per target per yearHumans only check your fixes: one manual rescan
Cobalt Autonomous PentestAI testing directed by Cobalt pentesters, for web apps$3,500 per test, as a promotionMust start and finish before December 31, 2026. Cobalt says it "does not produce compliance attestation reports"
Synack Sara PentestAI-led test of one low-complexity web app or 100 host IPsFrom $4,181 per test, platform separateReports use AI-generated summaries of findings, per Synack's offering table

Four things in these tables change a purchase, so we'll say them plainly.

Only two of the six publish a current price for human testing you could budget from. That's Astra and Synack. Cobalt's only dollar figure is a promotion for its AI-led test. BreachLock's figures sit on an older page that uses different package names from its current one.

Synack's sticker price is not the total. Its pricing page says the platform "is required to purchase any of the testing products and is a separate line item." It also describes a Basic Platform "available at no cost." On its AWS Marketplace listing the platform is $16,000 for 12 months. So the smallest human-led purchase there is $10,010 + $16,000 = $26,010. Ask which platform tier your purchase needs before you compare it with anyone.

A credit is not an hour of a person's time. Cobalt defines a credit as the equivalent of 8 hours "delivered through a combination of AI-powered automation and human expertise." The number of credits a test needs is set after scoping.

NetSPI and Synack are now one company. Synack says the merger closed on October 5, 2026 and that "no combined SKU, pricing or packaging has been announced." We list their offers separately because they are still sold that way.

To see an offer on the provider's own site:

View Astra's pentest plans View BreachLock's packages View Cobalt's tiers and credits View H1 Pentest View NetSPI PTaaS View Synack's packages

We keep a longer profile of each: Astra, BreachLock, Cobalt, HackerOne, NetSPI and Synack. If you'd rather see these beside providers that sell plain one-off projects, use our full comparison of penetration testing companies.

What is PTaaS, and how is it different from a regular pentest or a scan?

PTaaS changes the paperwork and the rhythm. It does not change what a good test is.

A penetration test (pentest) is an authorized attempt to break into a system the way an attacker would, to show what can actually be exploited. A vulnerability scan is software checking for known weaknesses. With a traditional pentest you agree a scope by email, wait for a slot, and get a PDF at the end. With PTaaS you do the same job inside a portal: you set the scope there, watch findings arrive during the test, and ask for a retest with a click. A retest is a check that a fix worked.

What PTaaS changesWhat it does not change
How you order and schedule a testThe scope still has to be agreed in writing
Findings show up live, not only in a final reportThe skill of whoever does the testing
Retests are requested in the platformWhether your auditor or customer accepts the report
History stays in one place across testsThe need for written permission to test your systems
Billing is often yearly or by creditHow deep the testing goes for the price

The platform and the test are separate things. BreachLock makes that visible: its packages list platform access as "optional," and you can run the whole test through a project manager.

So is PTaaS just scanning with a nicer name? Sometimes part of it is. Astra sells Pentest Auto (AI-led, $2,999) and Pentest Expert (with a manual pentest, $5,999) on the same pricing page under the same PTaaS label. Read the line that says who does the first round of testing. If your requester asked for a pentest and you're not sure a scan would do, our guide to penetration testing vs vulnerability scanning sorts that out.

How much new testing do you get in a year?

Count it yourself, because "a year of PTaaS" doesn't say. A plan can hold five different things, and only the first two are new testing.

What a plan can includeWhat it doesWhat to pin down
A full testExamines the agreed app, API and roles in a new testing periodScope, who tests, dates, report
A change testExamines one release or one feature and what it touchesWhich change, which roles, when a full test is needed instead
ScanningRuns automated checks at the frequency the plan allowsTargets, logged-in or not, how often
RetestingChecks that an earlier finding was fixedHow many, requested by when, who checks
Platform accessLets you see findings and manage the workFor how long, and what you can export after

Unlimited scans and unlimited retests can sit in a plan that includes exactly one new test.

A worked year for a made-up company

Say you run a 30-person SaaS company. You have one web app with its API, two user roles, and customers kept apart from each other in the same system. A large customer wants a pentest report and an attestation letter, which is a short letter confirming the test happened. You plan three big releases this year. Your team usually needs about six weeks to fix findings.

That adds up to four pieces of new testing: one full test now and three change tests later. Checking your fixes at around day 45 is a fifth job, and a different one.

This company is invented. Nobody has quoted for it. Here is what each provider's published terms say when you hold them up to that plan.

What the plan needsAstra Pentest ExpertCobalt (credits)HackerOne H1 PentestSynack (ST plus platform)
First test covers the app, its API and both rolesSupported for the app and the APIs it calls, which Astra counts as one target. Confirm both rolesUnresolved until Cobalt scopes it in creditsUnresolved until HackerOne sizes itUnresolved. The AWS list puts "2 to 3 roles, multi-tenant" in the large package. An API is a separate asset type
Three releases each get new testingUnresolved. The number of manual tests per year is not statedSupported as a route. Cobalt's Agile Pentest is built for "recent code changes." Credits per test unknownSupported as a route. Hours are bought as a pool. Four separate tests at the smallest size is 4 × 40 = 160 hoursSupported at a price. Each further test is another package
Report plus attestation letterUnresolved. A pentest report is listed. A letter is not namedSupported for a Comprehensive Pentest. Mismatch for Agile, whose report is "intended for internal use"Supported in HackerOne's help center. Its pricing page also lists the letter under the Enterprise edition, so confirm yoursUnresolved. A "compliance ready report" is listed. A letter is not named
Fix check requested at day 45Mismatch. Manual rescans must be requested within 30 days of findings being reportedSupported on Standard (6 months) if the contract is still active and more than 10 days from its endSupported on Premium (90 days). Mismatch on Essential (30 days)Unresolved. No count or window is published
First-year cost you can work out today$5,999 for the plan. Extra tests and an extension: unknownNone. Quote onlyNone. Quote only$16,720 + $16,000 = $32,720 on the AWS list for the first test. Three more tests are extra

"Supported" here means that one condition is backed by what the provider publishes. It is not a quality score and not a promise your customer will accept the report.

What we'd do with this. Send the same four-test plan to Cobalt and HackerOne first. Both sell testing in a way that fits a first test plus release checks. Both document an attestation letter. Both have a retest window that can reach day 45. Their quotes decide the rest.

Keep Astra Pentest Expert on the list if price matters most. At $5,999 it is the lowest published human-led plan here. It needs three answers in writing: how many manual tests the year includes, whether you get a letter, and whether the rescan window can stretch to day 45. Astra's help center says extensions "may be granted on a case-by-case basis" and extra manual rescans are sold as an add-on.

Look at Synack if you want researchers active all year or you buy through AWS, and budget for the platform line.

And if you dropped the three releases? Then you need one test, not a plan. A single project works. One published example is Pentest-Tools.com's managed gray-box test, which starts at $3,400 + (2 roles × $900) = $5,200. It doesn't price the API or state a retest.

Whichever way you lean, every provider should be pricing the same job. Our free scope checklist walks you through the app, roles, exclusions and deadline, then gives you a list to copy or print. It doesn't ask for contact details and it doesn't pick a provider for you.

Find My PenTest Match

What does PTaaS cost, and what are you locked into?

The published prices use four different units, so they can't be lined up without doing the work above.

  • Per target per year. Astra: $2,999 (AI-led) or $5,999 (with a manual pentest).
  • Per test. Synack: from $4,181 (AI-led) or $10,283 (one researcher) on its site, plus a platform line. Cobalt's AI-led promotion: $3,500 for tests started and completed before December 31, 2026.
  • Per credit or per hour, bought as a yearly pool. Cobalt and HackerOne. No public price for either.
  • Per project. BreachLock and NetSPI. Quote only on their current pages.

For a wider look at what a single test costs outside of plans, see our page on penetration testing cost.

The price is half of it. Here is what the contracts take back.

Unused credits expire. Cobalt's contract page says that when the contract ends, "your remaining credits expire." Synack's pricing page says credits "expire one year from purchase date." Its product terms instead tie expiry to the subscription period in the purchase work order or earlier termination.

Cobalt contradicts itself on rollover. Its tier table lists credit rollover of "up to 10%" for Enterprise. The FAQ on the same page says "Credits do not roll over into the next contract." Ask which one your contract will say.

The last month of a contract is mostly gone. Cobalt's own documentation tells customers to start tests "at least 30 days before your contract expires" and to submit retests "at least 10 days before." The help center gives a 15-day grace period to download your data, but Cobalt's current Platform Services Agreement gives 14 days. For a contract ending December 31 without renewal, that means the last sensible test starts around December 1, the last retest request is December 21, and the published export periods end January 14 or 15. Confirm the export deadline in your agreement.

A platform can be its own bill. Synack's is the clear example above. HackerOne prices a platform edition first, then the pentest on top of it.

A promotion is not a price. Cobalt's $3,500 figure covers one kind of test for a limited time. Its human-led tiers have no public price.

Before you sign, get five answers in writing. How many new human-led tests does the term include? What happens to unused credits or hours? Is there a platform fee on top? What is the full amount, and when is it billed? What can you still open and download after the contract ends? Our page on comparing a penetration testing quote gives you the line-by-line version.

Who checks your fixes, and how long do you have?

A retest only helps if your fixes are ready before the window closes. The windows below range from 30 days to 12 months, and they don't all start counting from the same event.

ProviderRetests includedThe clock
Astra1 manual rescan on Auto, 2 on Expert, 4 on EnterpriseRequest within 30 days (90 on Enterprise) "from the date the vulnerabilities were reported." Astra also requires fixing at least half of the critical and high findings first
BreachLock1, 2 or a custom number of free manual retests by packageNo window is published. Ask
Cobalt Agile / ComprehensiveFree retesting for 6 months on Standard, 12 on Premium and EnterpriseOnly while the contract is active, and no later than 10 days before it ends unless a renewal has been executed. The help center says within 7 days; the service terms leave retest timing to Cobalt
HackerOneUnlimited retests during the remediation period30 calendar days on Essential, 90 on Premium. After that you set a fee per retest, minimum $50, while your service is active
NetSPIRemediation testing can be scheduledNo count or window is published. Ask
Synack"Patch verification" is listedNo count or window is published. Ask

Two cautions. First, Cobalt's pricing FAQ promises "unlimited on-demand retesting throughout your contract term," while its tier table and help center give Standard customers 6 months and cut off retest requests 10 days before the contract ends unless a renewal has been executed. The help center has the detailed rule, and Cobalt's documentation doesn't plainly say which date the 6 months count from. Ask for your retest end date in writing.

Second, Astra uses the word "rescan" for two different things. A manual rescan is a person checking your fix, and it uses up your allowance. An automated rescan is unlimited but only works on findings the scanner itself reported. Findings from Astra's engineers or its autonomous tester need the manual kind.

Remember that a retest looks at an old finding. It is not a test of your new release.

Will your auditor or customer accept a PTaaS report?

That is their call, not the provider's and not ours. The PTaaS label proves nothing either way. What matters is whether the scope, the method, the dates and the documents match what the person asking actually needs.

So ask them before you buy. Does the work have to be human-led? Does the tester need to be independent of you? Do they want the full report or a letter? How recent must it be? The questions for your report recipient in our checklist cover this in a few minutes.

Then check that the offer you're eyeing produces that document. The differences are real:

  • Cobalt's Comprehensive Pentest comes with reports "intended for external stakeholders," including an attestation letter. Its Agile Pentest comes with an automated report "intended for internal use."
  • Cobalt says its Autonomous Pentest is built for coverage, "not as a replacement for compliance-bound pentesting."
  • HackerOne's help center lists a final PDF report and a Letter of Attestation for each pentest.
  • Astra's pricing FAQ says its reports "are recognized by all auditors." That is Astra's claim. No provider can promise what your auditor will do.

We are not saying what any standard requires here. If you answer to PCI DSS, SOC 2 or another framework, your assessor or auditor is the one to tell you what they will accept.

Send every provider the same request

Quotes only compare when they answer the same question. Copy this, fill in the brackets, and send it to each provider on your list.

We need testing for [app, API and environment], including [user roles, tenant separation and key workflows]. The report is for [who and why], and we need [full report, attestation letter or both] by [date].

Please price the first test and these planned changes separately: [release 1], [release 2], [release 3]. For each one, say whether it is included, uses credits or hours, or needs a new purchase. Tell us who does the testing and what automation does.

List any scanning or AI-led testing that runs between those tests, and what report it produces.

Our fixes will likely be ready on [date]. Confirm how many retests are included, who performs them, the last date we can request one, and the cost after that.

Itemize the full cost: test charges, any required platform fee, the minimum commitment, when we are billed, and renewal and cancellation terms. Say what happens to unused credits or hours, and what we can access after the contract ends.

Please send a sample report. This is a request for a quote. Testing needs separate written authorization for the agreed targets and activities.

The request is a buying tool. It is not permission to test. If you want help filling in the scope lines, our guide to penetration testing scope has a worked example.

Common questions

Does PTaaS mean continuous testing?

No. A PTaaS platform can deliver one test, a few tests a year, or year-long testing. "Continuous" is set by the contract. Synack365 is a 365-day window with rotating researchers. Astra's Expert plan lists unlimited scanning all year alongside manual pentesting. Those are very different things under the same word, so ask what runs, who runs it and what you receive.

Is PTaaS cheaper than a traditional pentest?

It depends on how many new tests you need. If you need one, a single project or a per-target plan is usually the smaller bill: $5,200 to start for the Pentest-Tools.com example above, or $5,999 for Astra's yearly plan. If you need several, a pool of credits or hours can make sense, but only two of the six providers here publish enough to check that without a quote.

Is PTaaS worth it for a small company?

It can be, if you ship often or get asked for evidence several times a year. For one stable app and one yearly request, a platform adds convenience and not much else. Check the retest window and what you keep after the contract ends before paying for a year.

Do I need a new provider to get PTaaS?

Not always. Ask your current provider whether they offer a portal, live findings and a retest window that fits how long your fixes take. If they do, you may already have what the label describes. Our overview of penetration testing services can help you confirm you're buying the right kind of test in the first place.

Sources and how we checked

We read each provider's public pricing, service and help-center pages on October 9, 2026 and recorded what they say. Totals and the worked year are our own arithmetic from those figures. Findings marked Supported, Mismatch or Unresolved apply one made-up buyer's needs to those published terms. We did not buy a test, inspect a delivered report or contact a provider, and nothing here rates testing quality. More on how we work is on our methodology page, and how the site earns money is on how we make money.

Provider terms change. If you spot something out of date, the check date above tells you how old our reading is.