Penetration testing services: which type you need
By The PenTest Index · Offer terms checked October 8, 2026 · How we check offers
Penetration testing services are authorized attacks on your systems, run to find weaknesses before an attacker does. They are sold by what gets tested: a web app, an API, a mobile app, a network, a cloud account or your people. Start with the system named in the request you received. One warning: a vulnerability scan is a different assessment.
The first table turns the request you got into the service to ask for. Further down, we check five real offers against one example buyer and show which types of test have a published price at all.
Which penetration testing services do you need?
You need the one that covers the system in your request. Find your request in the left column. If the request doesn't name a system, don't ask for quotes yet. Ask the person who sent it.
| The request says | Ask providers for | Settle this first |
|---|---|---|
| "A penetration test of our app, platform or product" | A web application penetration test, with the API named in the scope | Which signed-in user roles get tested, and which API functions |
| "API pentest," or partners call your API directly | An API penetration test, alone or scoped together with the web app | The list of endpoints, including ones your website never calls |
| "Mobile app pentest" | A mobile application test for iOS, Android or both | Whether the server-side API behind the app is included |
| "External and internal penetration test" or "network pentest" | An external network test and an internal network test. These are two starting points, often quoted together | Where testers start from and which address ranges they may touch |
| "Pentest of your cloud environment" | A cloud penetration test or a cloud configuration review | Which of the two the requester means. They are different jobs |
| "Vulnerability scan" or "ASV scan" | A scan, not a penetration test | Who runs it and how often |
| Wireless, physical, phishing, a device, or "red team" | The specialist service for that exact target | Relevant experience, and written permission for that activity |
| Nothing specific, and you mostly use other companies' software | Start with what you control: logins, settings, laptops, your office network | Which of those the requester wants evidence about |
| Just "get a pentest" | Nothing yet | Send the three questions below |
Three questions to send the person who asked:
- "Which systems should the test cover, and is anything excluded?"
- "What must the report show, and by when?"
- "Does the work have to be done by an independent or qualified tester?"
Already have a report, a provider, or a test bundled with another product? Hold it up against the request before you buy anything. Check the systems covered, the roles tested, the report date and any findings still open. Then ask the requester to name what's missing. If nothing is, you're done without a new purchase.
Testing a web app or API? Our index already compares published offers for that work: compare published web app and API offers.
Testing something else? Our index doesn't compare network, cloud or mobile offers yet. The next table shows what to gather so every provider you call is pricing the same job.
What does each type of test cover?
Each type answers a different question about a different system. Most buyers need one or two. Think of home inspections: a roof inspection and a plumbing inspection are both "inspections," but one tells you nothing about the other.
| Type | The question it answers | What a provider needs to price it | Watch for |
|---|---|---|---|
| Web application | Can someone misuse the app or reach another customer's data? | Number of apps, the environment, user roles, the workflows that matter most | A "web app" package that leaves out part of your API |
| API | Can one user, role or customer reach another's data through the endpoints? | Endpoint list or API description file, how clients sign in, permission levels | Only the calls your website makes get tested |
| Mobile app | Does the app on the phone leak data or trust the device too much? | Platforms, test accounts, the API behind the app | The server side left out |
| External network | What can an outsider reach from the internet? | Count of public addresses and services | A scan report with "penetration test" on the cover |
| Internal network | What could an attacker do once inside? | Starting access, address ranges, sites, any on-site work | A scope that skips how accounts and permissions are managed |
| Cloud | Can a stolen login cross a boundary in AWS, Azure or Google Cloud? | Accounts, services and identities in scope | A settings review sold as a penetration test, or the reverse |
| Wireless | Can someone get onto your network over Wi-Fi? | Sites and network names | Travel costs for on-site work |
| Social engineering | Will staff hand over access when asked? | Channels such as email or phone, and how many people | Buying it for a card-payment audit that doesn't call for it (see the card-payment row further down) |
| Physical | Can someone walk in? | Sites, rules, who to call if stopped | Missing written permission on the day |
| Red team | Would you notice and stop a determined attacker? | Goals, rules, duration | Buying this when a penetration test was requested. A red team checks your defenders. A penetration test looks for as many weaknesses as it can in a set scope |
| Device or hardware | Is the product itself attackable? | Product, version, interfaces | A generalist firm with no device work to show |
| AI feature in your product | Can the model or its tools be pushed to leak data or act without permission? | The features, the tools the model can call, user roles | "AI pentest" can mean testing an AI feature or using AI to test any app. Ask which |
For wireless, social engineering and device testing, look for a provider that lists that exact service. Rapid7's catalogue is one example. It lists all three and publishes no prices (read October 8, 2026).
This site may contain affiliate or referral links. If you buy through one, we may be compensated. How we make money
See Rapid7's listed testing services
Three terms you'll see on every quote. Black box means the tester starts with no inside information. Gray box means partial information, usually test accounts. White box means full information, sometimes including source code. Those definitions come from the card industry's testing guidance (PCI Security Standards Council, 2017, section 1.3). Providers use the labels loosely, so ask what access each offer assumes.
Can one test cover your app, API and cloud?
For a product-specific comparison, see penetration testing for a SaaS product.
Yes, when the written scope names all three. The risk runs both ways: paying for a second test you didn't need, or assuming something is covered when it isn't.
Does a web application test include the API?
Often part of it. Rarely all of it, unless you ask.
Cobalt's scoping guide says its web tests also cover "the backend API endpoints frequently used to populate content on those pages," and adds that if your only APIs feed web pages, "you may not need to set up a separate API asset" (Cobalt, read October 8, 2026). NetSPI draws the same line from the other side: in a web app test, API coverage is "limited to specific API calls used by the workflows of that application," while a dedicated API test should cover every documented call (NetSPI, read October 8, 2026).
So the question to ask is simple: "Which API functions are included, including ones the website never uses?" If partners or a mobile app call endpoints your site doesn't, those are the ones that fall through.
Does hosting in the cloud mean you need a cloud pentest?
No. Where your app runs doesn't decide which test you need. What you want to know does.
A cloud configuration review reads your settings. Cobalt describes its review as "without engaging in active exploitation" (Cobalt, read October 8, 2026). A cloud penetration test tries to use a weakness to get somewhere it shouldn't. An application test looks at the app, whatever it sits on. Ask the requester which of those three questions they want answered.
Some bundles blur this. Astra's pricing page says "the entire app with all its APIs and underlying cloud is 1 target" (Astra, read October 8, 2026). That tells you how Astra counts for billing. It doesn't tell you what cloud testing is done, so ask.
Do you need external testing, internal testing or both?
That depends on where the requester wants the attack to start. External testing starts from outside your network, usually the internet. Internal testing starts from inside, as an employee or as an attacker who already got in (NIST SP 800-115, section 2.4.1).
Neither word tells you whether a tester will sign in to your app. "External" is a starting point. Whether the tester gets accounts is a separate choice.
A worked example: one portal, one API, five real offers
For this buyer, one published offer is ruled out, two are worth a closer look, and one question decides the price. Here is how we got there.
Say you run a 30-person software company. You have one customer portal and one API. Part of that API is used only by partner integrations, not by the portal. A customer's security questionnaire asks for a third-party penetration test that covers signed-in users. You can give testers a customer account and an admin account. You would rather not hand over source code.
This buyer is made up. Nobody quoted for it. The requirements below are this buyer's own, not anything a standard demands.
- Must have: the portal and the API, including the partner-only functions.
- Must have: testing as two signed-in roles, customer and admin.
- Would prefer: no source code access, and one engagement instead of two.
- Still open: the report date and how long fixes will take.
We read each provider's public page on October 8, 2026 and checked it against those lines. "Supported" means the page supports that one condition. It is not a verdict on the provider. We did not buy or run any of these tests.
| Offer | Published price (US dollars) | What we found | Ask the provider |
|---|---|---|---|
| Pentest-Tools.com, black box web app test | $3,400, fixed, one test | Mismatch. The page describes an "anonymous attacker." This buyer needs signed-in testing | Skip it, or ask for the grey box version |
| Pentest-Tools.com, grey box web app test | "Starting from" $3,400 plus $900 per user role. For two roles: $3,400 + (2 × $900) = $5,200 starting amount | Supported for signed-in testing. Unresolved for the API and for rechecking fixes: the page mentions neither | "Does this price cover our API, including the partner-only functions? What does a retest cost, and until when can we ask for one?" |
| Astra, Pentest Expert | $5,999 per year for one target. A yearly plan, not a single test | Supported for a manual test of the app and the APIs it uses. Unresolved for the partner-only API: Astra counts "all APIs consumed" by the app as one target, and the app doesn't use those functions | "Is our partner-only API part of the same target, or a second one?" One target is $5,999 a year. At the same per-target rate, two would be 2 × $5,999 = $11,998 a year |
| Cobalt, Standard, Premium or Enterprise | Quote required. Sold as yearly credit packages | Supported for a combined web and API scope with user roles. Unresolved for the total: Cobalt supports a combined Web + API asset, but the required API scope and credit amount still need confirmation | "How many credits does a web plus API test with two roles need, and what happens to credits we don't use?" |
| Aikido, Typical Pentest | $4,000 per assessment, before taxes | Supported for "a single application and its primary APIs." The default is white box, which uses your code. Black and grey box cost extra, and the extra isn't published, so the total is Unresolved for a buyer who won't share code. It is AI-led | "What is the price without code access? Are partner-only functions 'primary APIs'?" And ask your customer whether they accept AI-led testing |
Sources: Pentest-Tools.com service page, Astra pricing, Cobalt pricing and Cobalt scoping guide, Aikido pricing. All read October 8, 2026. Each price is what the provider publishes, not a quote for this scope.
Where that leaves this buyer. Start with the Pentest-Tools.com grey box test if you want one project and one invoice. Look at Astra Pentest Expert if a yearly plan with ongoing scanning suits you. Bring in Cobalt if you expect several tests a year. Aikido only fits if you're willing to share code or pay the unpublished extra, and your customer accepts AI-led testing.
Don't pick on price yet. One fact is still missing from every row: the partner-only API. Until each provider says in writing whether it's in, the cheapest number here is the price of a smaller job.
One more date to check. Astra's two expert re-scans must be requested within 30 days of the day findings are reported (Astra help center, read October 8, 2026). If your fixes take 45 days, ask for an extension in writing before you sign.
Already settled on one of these? Go straight to the provider and send the question from its row.
View the grey box web app test
Your own version of this takes about ten minutes. Write down your systems, roles, API functions, deadline and open questions once, then send the same list to every provider. That way their answers line up. Find My PenTest Match walks you through it and gives you a free scope checklist to copy or print. It doesn't ask for contact details, and it doesn't pick a provider for you.
Who does the testing: people, platforms, crowds or AI?
The same type of test can be delivered four ways, and the label won't tell you how much of the work a person does. Ask every provider: "How much of this is human testing, how much is automated, and who reviews the findings?"
| How it's delivered | In plain words | Examples from published pages, A to Z | Confirm |
|---|---|---|---|
| A project with a testing firm | One scoped test, one report | Bishop Fox (quote required); Pentest-Tools.com managed web app test | Scope, days of effort, retest terms |
| A subscription or platform, often called PTaaS (penetration testing as a service) | Testing bought as a yearly package or as credits you spend | BreachLock; Cobalt; NetSPI; Raxis | How many tests the package buys, and what happens to what you don't use |
| A vetted pool of outside testers | The provider assigns researchers from its network | Synack | Who is assigned, and the full price including required platform access |
| AI-led | Software does much of the testing. People may direct it or check results | Aikido; Astra Pentest Auto; Cobalt Autonomous Pentest; Intruder; Synack Sara | The human role, the access it needs, and whether your report reader accepts it |
These overlap. A subscription can buy human testing, AI testing or both. One company can sell all four.
Two details from the pages we read, both worth a question:
- Cobalt's pricing table shows credit rollover of "Up to 10%" in the Enterprise column. The FAQ on the same page says "Credits do not roll over into the next contract." Ask which applies to you (Cobalt, read October 8, 2026).
- Intruder's listed AI test is white box, and its first step is "Connect your codebase" (Intruder, read October 8, 2026). If you won't share code, ask whether another option exists.
Each offer's terms and sources are on the index: see the full comparison.
Is a vulnerability scan a penetration test?
No. A scan uses software to look for known weaknesses. A penetration test tries to use weaknesses to get past your defenses. Scanning can be included in a penetration test.
The card industry's guidance puts it plainly. A scan is mostly automated tools and takes seconds to minutes per machine. A penetration test is "a manual process that may include the use of vulnerability scanning or other automated tools," and can run for days or weeks (section 2.1). It also says that "simply running an automated tool does not satisfy the penetration testing requirement" (section 4.2.2). That guidance is from September 2017 and says it does not replace the card standard itself.
NIST adds the practical reason. Scanners report false alarms at a high rate, and they can't see a danger that only appears when two small weaknesses are combined. Finding those combinations is what a penetration test is for (NIST SP 800-115, sections 4.3 and 5.2).
You can see the gap in one company's price list. Astra sells a scanner at $199 a month or $1,999 a year for one target, and its Pentest Expert plan at $5,999 a year for one target (Astra, read October 8, 2026). Same company, two different products.
AI-led testing is a third thing. Judge it by what it covered and the evidence it hands back, not by its name.
If your request might only need a scan, read penetration testing vs vulnerability scanning before you buy.
Which services publish a price?
Web app tests, a few fixed packages counted in web apps or network addresses, and one all-in yearly subscription. Astra also publishes tailored mobile pricing from $2,200 per app when Android and iOS apps share a codebase, with the final price depending on scope. For cloud, wireless, social engineering, physical, red team and device testing bought alone, we found no published price in the sources for the 11 providers we reviewed. That is a statement about those 11, not about the whole market.
Prices are in US dollars, as published. All read October 8, 2026.
| What it covers | Offer | Published price | The condition that changes it |
|---|---|---|---|
| One web app, no sign-in, people | Pentest-Tools.com black box | $3,400 per test, fixed | Three working days, "best effort" |
| One web app, signed-in, people | Pentest-Tools.com grey box | From $3,400 plus $900 per user role, per test | API and retest not mentioned |
| One web app and the APIs it uses, people | Astra Pentest Expert | $5,999 per year, one target | Yearly plan. Two re-scans, requested within 30 days of reported findings |
| One web app, AI-led | Astra Pentest Auto | $2,999 per year, one target | One human re-scan, same 30-day window |
| One web app, AI-led with tester direction | Cobalt Autonomous Pentest | $3,500 per test, promotional | Must start and finish before December 31, 2026. No later price is published |
| One app and its primary APIs, AI-led | Aikido Typical Pentest | $4,000 per assessment, before taxes | White box by default. Other access costs extra |
| One web app, AI-led | Intruder AI web app pentest | $4,000 per test, or $3,500 for platform subscribers, on its pricing page. Its cost article says "$4,000, or $3,500 for existing customers" | White box. Ask which price applies to you |
| One simple web app or 100 addresses, external only, AI-led | Synack Sara Pentest | From $4,181 per test | Required platform access is a separate line item |
| Up to 25 web apps without sign-in, or one simple signed-in app, or 100 addresses, internal and external, one human tester | SynackST | From $10,283 per test | Same platform line item. Credits expire one year after purchase |
| Up to 50 web apps without sign-in, or one signed-in app, or 250 addresses; also lists API and mobile; a team | Synack14 | From $27,120 per test | Same |
| Networks, cloud, web apps, APIs, wireless and social engineering under one subscription, people | Raxis Attack | From $25,000 for one year | A yearly commitment, not one test. The same scope can't be tested twice at once |
Sources: Pentest-Tools.com, Astra, Cobalt, Aikido, Intruder pricing and Intruder cost article, Synack, Raxis.
Three things to take from the table.
These are not the same purchase. A $3,400 three-day test of one app and a yearly subscription starting at $25,000 for an agreed scope can't be ranked by price. Compare what each one covers first.
"From" is not a total. Synack says its platform "is required to purchase any of the testing products and is a separate line item," and also describes a Basic platform "available at no cost." Which one your purchase needs isn't stated, so the total is unknown, not zero. Ask for it itemized.
No published price doesn't mean expensive. Bishop Fox, BreachLock, NetSPI and Rapid7 publish none. It means you need a written scope before anyone can give you a number, which is the reason to write yours down first.
For budgeting, ranges and what moves a quote up or down, see penetration testing cost. To line up proposals you already have, see how to compare penetration testing quotes.
What does the person asking actually require?
Ask them, in writing. What a rulebook says and what your auditor, customer or insurer will accept are not always the same thing, and they are the ones who decide.
| Who is asking | What we could confirm from the source | Ask them |
|---|---|---|
| A card-payment assessor | The card industry's 2017 guidance describes testing from outside and inside, at both the application and network layers, plus checks of any network separation you rely on (sections 2.2 to 2.4). It says social engineering testing is not required (section 2.5). It was written for an earlier version of the card standard | "Which systems are in scope for this year's test under the current version of the standard?" |
| A SOC 2 auditor | Drata, a compliance software company, wrote in February 2026 that "penetration tests are technically not a requirement for SOC 2 compliance." That is Drata's reading. We have not read the auditing criteria ourselves | "Do you expect a penetration test for this audit period, and of what?" |
| A customer | Their questionnaire or contract wording is the requirement | The three questions near the top of this page |
| A health-data (HIPAA) reviewer | The U.S. health department has proposed requiring a penetration test at least once every 12 months. Its fact sheet says "the current Security Rule remains in effect" while that proposal is considered. It was still a proposal when we read the fact sheet on October 8, 2026 | Your compliance lead, about what applies to you today |
| An insurer | We did not research insurer wording | "Please send the exact wording of the testing requirement" |
Sources: PCI SSC guidance; Drata; HHS fact sheet.
A provider saying its report is "audit-ready" is the provider talking. Intruder goes further and offers a refund "if your auditor rejects the report." That is a refund promise. It is not your auditor saying yes.
The recipient questions are ready to copy here: questions for your report recipient.
What should you agree before testing starts?
Four things, in writing, whatever type you buy.
- The scope. Systems, roles, functions, and what is excluded. A report with no findings from a narrow scope says nothing about what was left out.
- The report. Ask for a sample. Check that it states scope, dates, methods, evidence for each finding and how to fix it. More on this in what a penetration testing report should contain.
- The recheck. How many retests, when the window opens and when it closes. Real windows differ a lot. Astra's Expert and Auto windows are 30 days from reported findings. Cobalt's help page gives Agile and Comprehensive tests 6 or 12 months by tier while the contract is active, with requests closing at the earlier of that period's end or 10 days before your contract ends (Cobalt, read October 8, 2026). The card industry's guidance notes that if fixes drag on, a fresh test may be needed (section 4.3.2).
- The report date. A start date is not a delivery date. If a customer or audit is waiting, get the final report date in the agreement.
One thing no checklist can do: give permission. A scope checklist or brief helps you buy. It does not authorize anyone to test. Before work starts, you and the provider need signed rules covering the exact systems, the allowed activities, the hours, and who to call if something breaks. If a system belongs to someone else, such as a hosting company, you need their permission too.
When you're ready to turn this into a full brief, see how to write a penetration testing scope.
Common questions
Do I need all of these services?
No. Buy for the system in your request. Add a type when a new system or a new requester gives you a reason. A 30-person software company answering a customer questionnaire usually starts with one web app and API test. See SaaS penetration testing for that case.
Can our own team do the test?
It depends on who reads the report. The card industry's guidance allows a qualified internal tester who is "organizationally independent," meaning separate from the people who run the systems being tested (section 3). A customer may still want an outside firm. Ask before you plan around an internal test.
How long does a penetration test take?
Published times we read run from three working days for a small web app test (Pentest-Tools.com black box, report on the fourth day) to assessment windows of 5 or 14 days (Synack). AI-led offers advertise same-day results. These are providers' stated times, not booked dates. Add time for scoping, access and fixes.
Do I need a penetration testing company near me?
Usually not for app, API and cloud work, which is done remotely. Wireless, physical and some internal network tests may need someone on site. If your contract limits where testers can be or where data can go, put that in your scope.
Looking for a career in penetration testing? This page is for buyers.
How we checked this
We read pricing or service pages for eight providers on October 8, 2026 and recorded what they say, with the limits they state. We did not buy any of these services or judge the quality of anyone's testing. For Bishop Fox, BreachLock and NetSPI we relied on our index record from October 7, 2026.
The worked example uses our Purchase Check: take one requirement, find the published evidence, record what it supports, and write down the question still open. Missing information stays unresolved. It is never treated as a yes or as zero. More on the method: how our Purchase Check works.
The PenTest Index doesn't sell testing. See how we make money.
Sources
Provider pages read October 8, 2026, plus the index records noted below:
- Aikido: pricing
- Astra: pricing; rescan rules
- Cobalt: pricing; scope and test period; retesting; cloud configuration review
- Intruder: pentest pricing; cost article
- NetSPI: API vs web app testing checklist
- Pentest-Tools.com: web app penetration testing service
- Rapid7: penetration testing services
- Raxis: Raxis Attack
- Synack: pricing
- Bishop Fox, BreachLock and NetSPI offer terms: our index sources, checked October 7, 2026
Guidance and official pages, read October 8, 2026. None of these bodies endorses this site.
- PCI Security Standards Council: Information Supplement: Penetration Testing Guidance, version 1.1, September 2017
- NIST: SP 800-115, Technical Guide to Information Security Testing and Assessment, September 2008
- U.S. Department of Health and Human Services: HIPAA Security Rule proposed-rule fact sheet
- Drata: Penetration Tests and SOC 2, February 28, 2026 (a company's article, not an official source)