This site may contain affiliate or referral links. If you buy through one, we may be compensated. How we make money
Penetration testing as a service (PTaaS): what you actually buy
By The PenTest Index · Offers and terms checked October 9, 2026
Penetration testing as a service (PTaaS) is a way to buy and run penetration tests through a provider's online platform, as one test, a yearly plan or a pool of credits. The label doesn't tell you how much new testing you get, who does it, or what unused credits and late retests will cost you.
Those details are where the money goes. For one web app, the published first-year prices we found run from $2,999 for an AI-led plan to $152,400 for year-long human testing with a required platform fee. Below are the offers, the terms and the math.
| Your situation | The route that fits | What could rule it out |
|---|---|---|
| You need one report by a date | One scoped test. A platform is a nice extra, not the point | A retest window shorter than the time you need to fix things |
| You need a first test plus checks after big releases | A plan that pays for new testing after each release | A plan that only includes scans and retests after the first test |
| You want testers active all year | A year-long program with stated activity and reporting | A price that covers a testing window but no stated effort |
| You already have a provider or a test included elsewhere | Check its scope, date and report first | A real gap between what you have and what was asked for |
Which penetration testing as a service offer fits your team?
Pick by the work you need done, then by the company. The same provider often sells a human-led test, an AI-led test and a scanner under one PTaaS banner, at very different prices.
Every fact below comes from the provider's own pages, read on October 9, 2026. We have not bought these services or tested their quality. Prices are in US dollars as shown by the provider. Providers are listed A to Z. This is not a ranking.
Offers that include human testers
| Offer | What you pay for up front | Published price | What expires or runs out |
|---|---|---|---|
| Astra Pentest Expert | A yearly plan for one target. One web app and the APIs it calls count as one target | $5,999 per target per year | How many manual tests you get in the year is not stated. Ask |
| BreachLock Standard, Extended, Extensive | A scoped project. Platform access is optional | Quote on the current pricing page. An older official page still shows "starts at $2,500" for a one-time test and "$5K" for annual | Ask which page applies to you |
| Cobalt Standard, Premium, Enterprise | A yearly pack of credits. One credit is "the equivalent of 8 hours" of AI and human work combined | Quote only | Unused credits expire when the contract ends |
| HackerOne H1 Pentest | A platform edition plus testing hours. Each test runs 14 days, with 40 hours per tester | Quote only | Hours are drawn down during the contract period |
| NetSPI PTaaS | One point-in-time test plus a year of platform access | Quote only | Later tests are not part of that description. Ask what is included |
| Synack SynackST | One 5-day test (5–10 days for AWS Large) by an assigned researcher, plus a required platform line | Synack's site: from $10,283 per test, platform separate. Synack's AWS Marketplace list: $10,010 (small app, one role) or $16,720 (large app, 2 to 3 roles), plus $16,000 for the platform, per 12 months | The FAQ says one year after purchase; the product terms limit credits to the subscription period or earlier termination |
| Synack Synack365 | Rotating researchers over a 365-day window | Synack's site: contact sales. AWS Marketplace list: $136,400 plus the $16,000 platform, per 12 months | Ask what activity is promised inside the window |
Offers led by AI
automated penetration testing explained.
| Offer | What it is | Published price | The condition that matters |
|---|---|---|---|
| Astra Pentest Auto | Autonomous testing of one web or SaaS app | $2,999 per target per year | Humans only check your fixes: one manual rescan |
| Cobalt Autonomous Pentest | AI testing directed by Cobalt pentesters, for web apps | $3,500 per test, as a promotion | Must start and finish before December 31, 2026. Cobalt says it "does not produce compliance attestation reports" |
| Synack Sara Pentest | AI-led test of one low-complexity web app or 100 host IPs | From $4,181 per test, platform separate | Reports use AI-generated summaries of findings, per Synack's offering table |
Four things in these tables change a purchase, so we'll say them plainly.
Only two of the six publish a current price for human testing you could budget from. That's Astra and Synack. Cobalt's only dollar figure is a promotion for its AI-led test. BreachLock's figures sit on an older page that uses different package names from its current one.
Synack's sticker price is not the total. Its pricing page says the platform "is required to purchase any of the testing products and is a separate line item." It also describes a Basic Platform "available at no cost." On its AWS Marketplace listing the platform is $16,000 for 12 months. So the smallest human-led purchase there is $10,010 + $16,000 = $26,010. Ask which platform tier your purchase needs before you compare it with anyone.
A credit is not an hour of a person's time. Cobalt defines a credit as the equivalent of 8 hours "delivered through a combination of AI-powered automation and human expertise." The number of credits a test needs is set after scoping.
NetSPI and Synack are now one company. Synack says the merger closed on October 5, 2026 and that "no combined SKU, pricing or packaging has been announced." We list their offers separately because they are still sold that way.
To see an offer on the provider's own site:
View Astra's pentest plans View BreachLock's packages View Cobalt's tiers and credits View H1 Pentest View NetSPI PTaaS View Synack's packages
We keep a longer profile of each: Astra, BreachLock, Cobalt, HackerOne, NetSPI and Synack. If you'd rather see these beside providers that sell plain one-off projects, use our full comparison of penetration testing companies.
What is PTaaS, and how is it different from a regular pentest or a scan?
PTaaS changes the paperwork and the rhythm. It does not change what a good test is.
A penetration test (pentest) is an authorized attempt to break into a system the way an attacker would, to show what can actually be exploited. A vulnerability scan is software checking for known weaknesses. With a traditional pentest you agree a scope by email, wait for a slot, and get a PDF at the end. With PTaaS you do the same job inside a portal: you set the scope there, watch findings arrive during the test, and ask for a retest with a click. A retest is a check that a fix worked.
| What PTaaS changes | What it does not change |
|---|---|
| How you order and schedule a test | The scope still has to be agreed in writing |
| Findings show up live, not only in a final report | The skill of whoever does the testing |
| Retests are requested in the platform | Whether your auditor or customer accepts the report |
| History stays in one place across tests | The need for written permission to test your systems |
| Billing is often yearly or by credit | How deep the testing goes for the price |
The platform and the test are separate things. BreachLock makes that visible: its packages list platform access as "optional," and you can run the whole test through a project manager.
So is PTaaS just scanning with a nicer name? Sometimes part of it is. Astra sells Pentest Auto (AI-led, $2,999) and Pentest Expert (with a manual pentest, $5,999) on the same pricing page under the same PTaaS label. Read the line that says who does the first round of testing. If your requester asked for a pentest and you're not sure a scan would do, our guide to penetration testing vs vulnerability scanning sorts that out.
How much new testing do you get in a year?
Count it yourself, because "a year of PTaaS" doesn't say. A plan can hold five different things, and only the first two are new testing.
| What a plan can include | What it does | What to pin down |
|---|---|---|
| A full test | Examines the agreed app, API and roles in a new testing period | Scope, who tests, dates, report |
| A change test | Examines one release or one feature and what it touches | Which change, which roles, when a full test is needed instead |
| Scanning | Runs automated checks at the frequency the plan allows | Targets, logged-in or not, how often |
| Retesting | Checks that an earlier finding was fixed | How many, requested by when, who checks |
| Platform access | Lets you see findings and manage the work | For how long, and what you can export after |
Unlimited scans and unlimited retests can sit in a plan that includes exactly one new test.
A worked year for a made-up company
Say you run a 30-person SaaS company. You have one web app with its API, two user roles, and customers kept apart from each other in the same system. A large customer wants a pentest report and an attestation letter, which is a short letter confirming the test happened. You plan three big releases this year. Your team usually needs about six weeks to fix findings.
That adds up to four pieces of new testing: one full test now and three change tests later. Checking your fixes at around day 45 is a fifth job, and a different one.
This company is invented. Nobody has quoted for it. Here is what each provider's published terms say when you hold them up to that plan.
| What the plan needs | Astra Pentest Expert | Cobalt (credits) | HackerOne H1 Pentest | Synack (ST plus platform) |
|---|---|---|---|---|
| First test covers the app, its API and both roles | Supported for the app and the APIs it calls, which Astra counts as one target. Confirm both roles | Unresolved until Cobalt scopes it in credits | Unresolved until HackerOne sizes it | Unresolved. The AWS list puts "2 to 3 roles, multi-tenant" in the large package. An API is a separate asset type |
| Three releases each get new testing | Unresolved. The number of manual tests per year is not stated | Supported as a route. Cobalt's Agile Pentest is built for "recent code changes." Credits per test unknown | Supported as a route. Hours are bought as a pool. Four separate tests at the smallest size is 4 × 40 = 160 hours | Supported at a price. Each further test is another package |
| Report plus attestation letter | Unresolved. A pentest report is listed. A letter is not named | Supported for a Comprehensive Pentest. Mismatch for Agile, whose report is "intended for internal use" | Supported in HackerOne's help center. Its pricing page also lists the letter under the Enterprise edition, so confirm yours | Unresolved. A "compliance ready report" is listed. A letter is not named |
| Fix check requested at day 45 | Mismatch. Manual rescans must be requested within 30 days of findings being reported | Supported on Standard (6 months) if the contract is still active and more than 10 days from its end | Supported on Premium (90 days). Mismatch on Essential (30 days) | Unresolved. No count or window is published |
| First-year cost you can work out today | $5,999 for the plan. Extra tests and an extension: unknown | None. Quote only | None. Quote only | $16,720 + $16,000 = $32,720 on the AWS list for the first test. Three more tests are extra |
"Supported" here means that one condition is backed by what the provider publishes. It is not a quality score and not a promise your customer will accept the report.
What we'd do with this. Send the same four-test plan to Cobalt and HackerOne first. Both sell testing in a way that fits a first test plus release checks. Both document an attestation letter. Both have a retest window that can reach day 45. Their quotes decide the rest.
Keep Astra Pentest Expert on the list if price matters most. At $5,999 it is the lowest published human-led plan here. It needs three answers in writing: how many manual tests the year includes, whether you get a letter, and whether the rescan window can stretch to day 45. Astra's help center says extensions "may be granted on a case-by-case basis" and extra manual rescans are sold as an add-on.
Look at Synack if you want researchers active all year or you buy through AWS, and budget for the platform line.
And if you dropped the three releases? Then you need one test, not a plan. A single project works. One published example is Pentest-Tools.com's managed gray-box test, which starts at $3,400 + (2 roles × $900) = $5,200. It doesn't price the API or state a retest.
Whichever way you lean, every provider should be pricing the same job. Our free scope checklist walks you through the app, roles, exclusions and deadline, then gives you a list to copy or print. It doesn't ask for contact details and it doesn't pick a provider for you.
What does PTaaS cost, and what are you locked into?
The published prices use four different units, so they can't be lined up without doing the work above.
- Per target per year. Astra: $2,999 (AI-led) or $5,999 (with a manual pentest).
- Per test. Synack: from $4,181 (AI-led) or $10,283 (one researcher) on its site, plus a platform line. Cobalt's AI-led promotion: $3,500 for tests started and completed before December 31, 2026.
- Per credit or per hour, bought as a yearly pool. Cobalt and HackerOne. No public price for either.
- Per project. BreachLock and NetSPI. Quote only on their current pages.
For a wider look at what a single test costs outside of plans, see our page on penetration testing cost.
The price is half of it. Here is what the contracts take back.
Unused credits expire. Cobalt's contract page says that when the contract ends, "your remaining credits expire." Synack's pricing page says credits "expire one year from purchase date." Its product terms instead tie expiry to the subscription period in the purchase work order or earlier termination.
Cobalt contradicts itself on rollover. Its tier table lists credit rollover of "up to 10%" for Enterprise. The FAQ on the same page says "Credits do not roll over into the next contract." Ask which one your contract will say.
The last month of a contract is mostly gone. Cobalt's own documentation tells customers to start tests "at least 30 days before your contract expires" and to submit retests "at least 10 days before." The help center gives a 15-day grace period to download your data, but Cobalt's current Platform Services Agreement gives 14 days. For a contract ending December 31 without renewal, that means the last sensible test starts around December 1, the last retest request is December 21, and the published export periods end January 14 or 15. Confirm the export deadline in your agreement.
A platform can be its own bill. Synack's is the clear example above. HackerOne prices a platform edition first, then the pentest on top of it.
A promotion is not a price. Cobalt's $3,500 figure covers one kind of test for a limited time. Its human-led tiers have no public price.
Before you sign, get five answers in writing. How many new human-led tests does the term include? What happens to unused credits or hours? Is there a platform fee on top? What is the full amount, and when is it billed? What can you still open and download after the contract ends? Our page on comparing a penetration testing quote gives you the line-by-line version.
Who checks your fixes, and how long do you have?
A retest only helps if your fixes are ready before the window closes. The windows below range from 30 days to 12 months, and they don't all start counting from the same event.
| Provider | Retests included | The clock |
|---|---|---|
| Astra | 1 manual rescan on Auto, 2 on Expert, 4 on Enterprise | Request within 30 days (90 on Enterprise) "from the date the vulnerabilities were reported." Astra also requires fixing at least half of the critical and high findings first |
| BreachLock | 1, 2 or a custom number of free manual retests by package | No window is published. Ask |
| Cobalt Agile / Comprehensive | Free retesting for 6 months on Standard, 12 on Premium and Enterprise | Only while the contract is active, and no later than 10 days before it ends unless a renewal has been executed. The help center says within 7 days; the service terms leave retest timing to Cobalt |
| HackerOne | Unlimited retests during the remediation period | 30 calendar days on Essential, 90 on Premium. After that you set a fee per retest, minimum $50, while your service is active |
| NetSPI | Remediation testing can be scheduled | No count or window is published. Ask |
| Synack | "Patch verification" is listed | No count or window is published. Ask |
Two cautions. First, Cobalt's pricing FAQ promises "unlimited on-demand retesting throughout your contract term," while its tier table and help center give Standard customers 6 months and cut off retest requests 10 days before the contract ends unless a renewal has been executed. The help center has the detailed rule, and Cobalt's documentation doesn't plainly say which date the 6 months count from. Ask for your retest end date in writing.
Second, Astra uses the word "rescan" for two different things. A manual rescan is a person checking your fix, and it uses up your allowance. An automated rescan is unlimited but only works on findings the scanner itself reported. Findings from Astra's engineers or its autonomous tester need the manual kind.
Remember that a retest looks at an old finding. It is not a test of your new release.
Will your auditor or customer accept a PTaaS report?
That is their call, not the provider's and not ours. The PTaaS label proves nothing either way. What matters is whether the scope, the method, the dates and the documents match what the person asking actually needs.
So ask them before you buy. Does the work have to be human-led? Does the tester need to be independent of you? Do they want the full report or a letter? How recent must it be? The questions for your report recipient in our checklist cover this in a few minutes.
Then check that the offer you're eyeing produces that document. The differences are real:
- Cobalt's Comprehensive Pentest comes with reports "intended for external stakeholders," including an attestation letter. Its Agile Pentest comes with an automated report "intended for internal use."
- Cobalt says its Autonomous Pentest is built for coverage, "not as a replacement for compliance-bound pentesting."
- HackerOne's help center lists a final PDF report and a Letter of Attestation for each pentest.
- Astra's pricing FAQ says its reports "are recognized by all auditors." That is Astra's claim. No provider can promise what your auditor will do.
We are not saying what any standard requires here. If you answer to PCI DSS, SOC 2 or another framework, your assessor or auditor is the one to tell you what they will accept.
Send every provider the same request
Quotes only compare when they answer the same question. Copy this, fill in the brackets, and send it to each provider on your list.
We need testing for [app, API and environment], including [user roles, tenant separation and key workflows]. The report is for [who and why], and we need [full report, attestation letter or both] by [date].
Please price the first test and these planned changes separately: [release 1], [release 2], [release 3]. For each one, say whether it is included, uses credits or hours, or needs a new purchase. Tell us who does the testing and what automation does.
List any scanning or AI-led testing that runs between those tests, and what report it produces.
Our fixes will likely be ready on [date]. Confirm how many retests are included, who performs them, the last date we can request one, and the cost after that.
Itemize the full cost: test charges, any required platform fee, the minimum commitment, when we are billed, and renewal and cancellation terms. Say what happens to unused credits or hours, and what we can access after the contract ends.
Please send a sample report. This is a request for a quote. Testing needs separate written authorization for the agreed targets and activities.
The request is a buying tool. It is not permission to test. If you want help filling in the scope lines, our guide to penetration testing scope has a worked example.
Common questions
Does PTaaS mean continuous testing?
No. A PTaaS platform can deliver one test, a few tests a year, or year-long testing. "Continuous" is set by the contract. Synack365 is a 365-day window with rotating researchers. Astra's Expert plan lists unlimited scanning all year alongside manual pentesting. Those are very different things under the same word, so ask what runs, who runs it and what you receive.
Is PTaaS cheaper than a traditional pentest?
It depends on how many new tests you need. If you need one, a single project or a per-target plan is usually the smaller bill: $5,200 to start for the Pentest-Tools.com example above, or $5,999 for Astra's yearly plan. If you need several, a pool of credits or hours can make sense, but only two of the six providers here publish enough to check that without a quote.
Is PTaaS worth it for a small company?
It can be, if you ship often or get asked for evidence several times a year. For one stable app and one yearly request, a platform adds convenience and not much else. Check the retest window and what you keep after the contract ends before paying for a year.
Do I need a new provider to get PTaaS?
Not always. Ask your current provider whether they offer a portal, live findings and a retest window that fits how long your fixes take. If they do, you may already have what the label describes. Our overview of penetration testing services can help you confirm you're buying the right kind of test in the first place.
Sources and how we checked
We read each provider's public pricing, service and help-center pages on October 9, 2026 and recorded what they say. Totals and the worked year are our own arithmetic from those figures. Findings marked Supported, Mismatch or Unresolved apply one made-up buyer's needs to those published terms. We did not buy a test, inspect a delivered report or contact a provider, and nothing here rates testing quality. More on how we work is on our methodology page, and how the site earns money is on how we make money.
| Provider | Pages read | Checked |
|---|---|---|
| Astra | Pricing · Rescan rules · Rescan prerequisites · Scan quotas | October 9, 2026 |
| BreachLock | Penetration testing pricing · Older pricing page | October 9, 2026 |
| Cobalt | Pricing and FAQ · Retesting rules · Contract terms · Platform Services Agreement · Running a Security Program · Glossary · Report contents · Autonomous Pentest | October 9, 2026 |
| HackerOne | Pricing · H1 Pentest · Phases and sizing · Retest periods · Managing retests · Deliverables | October 9, 2026 |
| NetSPI | PTaaS data sheet | October 9, 2026 |
| Synack | Pricing · Offering table · Product Specific Terms · AWS Marketplace listing · Merger notice | October 9, 2026 |
| Pentest-Tools.com | Managed web app testing | October 9, 2026 |
Provider terms change. If you spot something out of date, the check date above tells you how old our reading is.