Astra penetration testing: plans, prices and the 30-day retest limit

By The PenTest Index

Astra penetration testing includes Pentest Auto at $2,999 a year per target, tested by AI agents, and Pentest Expert at $5,999 a year per target, which adds a manual test by human testers. Need human-led testing? Look at Expert. Both give you 30 days after findings are reported to request a manual re-check of fixes.

Prices and terms checked October 9, 2026, on Astra's own pages. We read what Astra publishes. We have not bought or run an Astra test.

Which Astra penetration testing plan should you choose?

Pick by who needs to do the testing. If your customer or auditor wants people testing your app, Pentest Expert is the plan to look at. If they accept AI-led testing and you want a fast, lower-cost result, Pentest Auto can fit. Enterprise is for bigger or unusual setups and a longer window to get fixes re-checked.

Astra planWho does the first testWhat it coversPublished price (US dollars)Manual re-checks of your fixesHow you buy
Pentest AutoAI agents. Astra calls this an autonomous pentest. A person checks your fixes afterward.Web apps and SaaS$2,999 a year, per target1, requested within 30 days of findings being reportedOnline checkout
Pentest ExpertAstra's human testers, plus the AI agents. Includes unlimited web scans for the year.Web, mobile, cloud, network and AI systems$5,999 a year, per target2, requested within 30 days of findings being reportedSales call
EnterpriseHuman testers plus AI agents, with options like private cloud or on-premise setupSame as Expert, tailoredListed "from $9,999 a year." What that amount covers is not stated.4, requested within 90 days of findings being reportedSales call

Source: Astra's pricing page for plans and prices, and Astra's rescan quota article for re-check counts and windows. Both are Astra's own statements, checked October 9, 2026. These are advertised yearly package prices. They are not a quote for your systems.

Three things to know before you go further:

  • The price is per target, per year. Two targets at list price is double. We work through that below.
  • The $3,000 gap buys a human-led test. $5,999 minus $2,999 is $3,000. It is the difference between two packages, not a price for a set number of tester hours. Astra does not publish how many hours or days of human testing Expert includes.
  • Astra's cheaper plans are scanners. The Scanner plans ($69 to $499 a month) run automated checks that you operate. They are a separate product. If someone asked you for a penetration test, a scanner plan alone is not that.

Already know which plan you need? Go straight to Astra, and take the questions below with you.

See Astra's pentest plans on its pricing page

Does Astra fit your purchase? A worked check

For a small SaaS company that needs a human-led test, Pentest Expert fits on testing approach, and the retest finding turns on one thing: how fast you can fix what the test finds.

Here is how we get there. We take a buyer's requirements and hold each one against the exact plan, using Astra's published terms. We call this a Purchase Check. A finding of "Supported" means that one condition is backed by the source. It does not rate Astra's testing quality or promise your report will be accepted.

The example (made up, not a real customer): Say you run a 30-person SaaS company. You have one web app, the API it calls, and two user roles. A customer's security team wants a report from a human-led test. You are fine with a yearly plan. No provider has quoted for this example.

What this buyer needsPentest AutoPentest ExpertWhat would change the finding
A human-led first test (required by the customer)Mismatch. The first test is run by AI agents.Supported. The plan includes a manual pentest by Astra's testers.The customer says in writing that AI-led testing is acceptable.
The app and the API it calls, in one targetSupported for a web app and the APIs it uses.Supported for a web app and the APIs it uses.Astra counts your setup as more than one target. Send your asset list and ask.
Both user roles and the boundaries between customers' data testedUnresolved.Unresolved. Astra asks for role-based access, but the pages do not say which role and tenant checks your fee includes.A written scope that names the roles and workflows.
Fixes re-checked by a person, if fixes are ready on day 21Supported for timing. 21 is inside 30.Supported for timing. 21 is inside 30.You must also have a re-check left and meet Astra's readiness rule (below).
Fixes re-checked by a person, if fixes are ready on day 45Mismatch. 45 is past 30.Mismatch. 45 is past 30. An extension is possible but not guaranteed.Astra agrees to a longer window in writing, and tells you the cost.
A final report by a fixed dateUnresolved.Unresolved. Astra's pages give different lengths for the manual test.A report date in writing.
Full first-year costUnresolved. Published one-target price: $2,999 a year.Unresolved. Published one-target price: $5,999 a year. Extra re-checks and extensions have no published price.An itemized order.

What this means for the example buyer: Auto is out, because the customer asked for human-led testing and one required mismatch is enough to rule a plan out. Expert is the Astra plan to pursue. If your team can ship fixes within about three weeks, the published request window works. If fixes will take six weeks, get the extension and its cost in writing before you pay, or look at a provider with a longer retest window.

If you already have a test: check it first. If your compliance platform or current provider already includes a pentest, ask your customer or auditor whether that report meets the request. If it does, you may not need to buy anything.

What counts as one target, and what will you pay?

Astra charges per target, so your real price depends on how Astra counts your systems. For one web app and the APIs it calls, that is one target on either plan.

Astra's plan cards define a target this way, as of October 9, 2026:

  • One web or SaaS app is one target, including the APIs it uses.
  • A mobile app is one target per platform. An Android app and an iOS app are two targets.
  • Networks, cloud accounts, IP addresses and standalone APIs are one target each.

Here is the list-price math. It is our arithmetic from Astra's published per-target prices, not a quote.

Your setupTargets by Astra's cardPentest Auto at list pricePentest Expert at list price
One web app and its API1$2,999 a year$5,999 a year
Two separate web apps2$5,998 a year$11,998 a year
A web app plus iOS and Android apps3Not offered. Auto lists web apps and SaaS only.$17,997 a year

Real quotes may come in lower. Astra's pricing FAQ says it offers "favorable pricing" on multi-year and bundled deals, without stating an amount. It also says mobile apps that share a codebase get tailored pricing "starting from $2200/app," and that several clouds, IPs or APIs "can be clubbed into one target" on a sales call.

Two things about scope that the price does not settle:

  • APIs are tested when they are in scope. Astra's web app pentesting page says APIs are tested "when they are included in the scope of the engagement." Name your APIs in writing.
  • An admin panel may or may not be a second target. Astra's scanner documentation says a separate subdomain with its own login needs its own scanner target. That article covers the scanner only. Ask whether the same rule applies to your pentest.

How do Astra's retests work, and what if fixes take longer than 30 days?

You get a fixed number of manual re-checks, and you must ask for them within 30 days of the date your findings were reported (90 days on Enterprise). After that, Astra says an extra purchase may be needed.

Astra calls a re-check a "rescan." There are two kinds, and the difference matters:

  • Manual rescan. One of Astra's security engineers checks whether your fix worked. This is the limited one: 1 on Auto, 2 on Expert, 4 on Enterprise.
  • Automated rescan. The scanner re-runs its own check. These are unlimited, but they only work on findings the scanner itself reported. Findings from human testers need a manual rescan. So do findings from the AI-led pentest: Astra's rescan instructions say automated rescans are "currently unavailable for Autonomous Pentest."

Turning 30 days into a date. Say your findings are reported on Tuesday, November 3, 2026.

When your fixes are readyDatePentest Auto or Expert (30 days: by December 3, 2026)Enterprise (90 days: by February 1, 2027)
Day 21November 24, 2026Inside the windowInside the window
Day 45December 18, 2026Outside the windowInside the window

Astra's policy says "days," not working days. It does not say whether day 30 itself counts. Astra says the exact date shows in your dashboard when you click the Re-Scan button, so treat that date as the one that binds.

Rules that catch people out. All of these come from Astra's help center, checked October 9, 2026:

  • You must have fixed at least 50% of your Critical and High severity findings before you can request a manual rescan.
  • Only findings you mark "Under Review" are included in the rescan.
  • A manual rescan is "typically completed within 3–9 business days." Add that to your timeline.
  • To get more time, raise a support ticket before the window closes. Astra reviews extension requests case by case. After the window closes, "an additional purchase may be required."
  • Extra manual rescans are sold as an add-on. Astra does not publish the price. An unknown charge is not a zero charge.

If your team usually needs more than a month to ship security fixes, settle this before you buy. Here is the question to send:

Our fixes may be ready 45 days after the findings are reported. Will this order include a manual rescan then? What will it cost, and when will we receive the updated report?

A rescan checks the fixes for the original findings. It is not a fresh test of features you added since.

How long does an Astra pentest take?

Plan on two to four working weeks for the manual test, plus time for your fixes and the re-check. Astra's own pages give three different figures, so get your report date in writing.

Where Astra says itStated timeWhat it measures
Pricing page FAQ10–15 working daysThe manual pentest
Help article on pentest length10–15 working daysCounted from when Astra's engineers have all the information they need from you, not from sign-up
Help article on maximum duration10–20 working days"The entire exercise," depending on scope and how busy Astra's team is
Web app pentesting page10–14 business daysTesting, reporting and re-scan verification together

All checked October 9, 2026. These are estimates, not booked dates.

A made-up timeline. Say Astra has everything it needs and starts on Monday, November 2, 2026. Ten working days ends Friday, November 13. Twenty working days ends Friday, November 27. If findings are reported on November 27, your 30-day rescan window closes on December 27, and the rescan itself can take 3 to 9 more business days. Public holidays and Astra's queue are not counted here.

Three more points for a buyer on a deadline:

  • You control part of the clock. The count starts when Astra has your scope, test accounts and access. Have them ready.
  • Astra mentions an express option. The help article says you can ask your account contact about an "express Pentest option." No price or timing is published.
  • Pentest Auto is faster, with a limit. Astra advertises "first report on the same day." That is an advertised speed for the AI-led test, not a contract date, and it does not help if your recipient wants human-led testing.

If you need to show progress before the report is done, Astra offers an engagement letter: a one-page PDF saying a pentest is under way. Astra says it is only available on manual pentest plans. It is not a report. Your auditor or customer decides whether it helps.

Will your customer or auditor accept an Astra report?

Your customer or auditor decides that. Astra does not, and neither do we. Ask them what they need before you pick a plan.

Astra's pricing FAQ says its "pentest reports are recognized by all auditors." That is Astra's claim. Astra's own Terms of Service also say it does not warrant that "the results of using the service will meet Your requirements." Both statements are Astra's. Read them together.

Three questions to send the person who asked for the test:

  1. Is AI-led testing alone acceptable, or must people do the testing?
  2. Does the testing company need a named accreditation?
  3. Do you need proof that the fixes were re-checked?

Their answers pick your plan. If they say people must test, that is Expert. If they need proof of re-checked fixes, the 30-day window above matters a lot. Our free checklist has a fuller list of questions for your report recipient.

Ask for a sample. Astra has published a sample report from a manual test. It is dated June 2024, so ask Astra for a current sample from the exact plan you are buying. Check that it names what was tested and what was left out, the test dates, the methods, evidence for each finding, and whether each fix was re-checked.

Is Astra CREST accredited?

Yes, for the company named Astra IT Inc. CREST's own directory, the CREST Marketplace, lists Astra IT Inc. with Penetration Testing under its CREST accreditations. We read that entry on October 9, 2026.

Keep that finding narrow. It covers that company and that service. It does not tell you which testers will work on your app or what they hold. And on Astra's pricing page, "CREST, PCI-ASV, CERT-IN compliant reports" appear on the Expert plan, not on Auto.

Astra also says it is a PCI Approved Scanning Vendor (ASV) and is listed by India's CERT-In. CERT-In's current list names Astra Security (Czar Securities Pvt. Ltd.); we have not confirmed Astra's ASV status with PCI SSC. One thing worth knowing: the PCI Security Standards Council describes an ASV as an organization that performs external vulnerability scanning. That is a scanning role. It is a different thing from a penetration test. If you are buying for PCI, ask your assessor what they need.

Is Pentest Auto a penetration test or a scan?

It is neither a plain scan nor a human-led test. Astra sells three different things, and the names are easy to mix up.

  • A vulnerability scan is software that checks your app for known weaknesses. You run it. Astra's Scanner plans do this.
  • An autonomous pentest is Astra's term for AI agents that try to attack your app the way a tester would, including chaining steps together. Pentest Auto is this. People do not run the first test.
  • A human-led pentest is people testing your app by hand, with tools helping. Pentest Expert includes this.

Astra's autonomous pentesting page is candid about where Auto sits. Asked whether it replaces human testers, Astra answers "No. It complements them." It also says autonomous testing currently covers web apps and APIs. Astra's pricing page describes Auto as having "depth equal of a 2-week human pentest." That is Astra's claim, and we have no way to check it.

So judge Auto by what your recipient will accept, not by its name. If nobody has told you people must test, Auto may be enough. If they have, it is not.

Is this a one-time purchase? Renewal, cancelling and refunds

No. Astra's pentest plans are yearly subscriptions that renew on their own unless you stop them.

These points come from Astra's Terms of Service, last updated September 8, 2025, read on October 9, 2026. This is our plain reading, not legal advice. A signed service agreement can change any of it, so ask for yours.

  • It renews automatically. The plan renews for the same length of time at Astra's "then current rates," which the terms say "may be higher or lower" than what you first paid.
  • You must act before renewal. The terms say you may cancel one day before the renewal date.
  • Refunds are narrow. If you cancel, Astra "may refund" the unused part of the term, but only if a manual pentest has not been used during that subscription period. Once the manual test is done, expect no refund.
  • Liability is capped at the fees you paid.
  • Indian law applies. Disputes go to arbitration in New Delhi. The terms name two companies: Astra IT Inc., a Delaware corporation, and Czar Securities Private Limited in Chandigarh, India.

One practical warning. Astra's dashboard has both a Pause and a Cancel button, and they are not the same. Astra's help article says Pause stops renewals but keeps your plan on the account. Cancel is "permanent and irreversible," stops scanning immediately, and means setting up your targets again if you come back. If you only want to stop the next renewal, ask Astra which button does that without cutting off access you have paid for.

Is the $7 trial a penetration test?

No. Astra's trial terms describe a 7-day trial of its vulnerability scanning for $7. If you do nothing, the plan you chose starts and bills the full amount when the trial ends. No trial of the pentest plans is stated.

Where Astra's pages give different answers

We found four places where Astra's own pages do not agree. None of them is a reason to walk away. Each one is a question to get answered in writing.

TopicOne Astra page saysAnother Astra page saysAsk Astra
Length of the manual test10–15 working days (pricing FAQ)10–20 working days (help center); 10–14 business days including reporting and re-checks (web app page)"What is my report date?"
Number of manual rescansA pentest plan "comes with 2 rescans" (pricing FAQ)Auto has 1, Expert 2, Enterprise 4 (plan cards and help center)If buying Auto: "Do I get 1 or 2?"
Whether your cloud account is its own target"Networks, cloud, IPs and standalone APIs are 1 target each" (plan card)A SaaS app "with all its APIs and underlying cloud is 1 target" (pricing FAQ)"Is our cloud account inside the app target, or separate?"
Stopping your planCancel a day before renewal; a part refund is possible if no manual pentest was used (Terms of Service)Cancel is permanent and stops scanning immediately; refunds are not mentioned (help center)"How do I stop renewal and keep access until the term ends?"

All checked October 9, 2026.

What do Astra reviews tell you?

Reviews can tell you what to ask about. They cannot tell you what your order will include.

Astra has a page of customer reviews on G2. Individual reviewers there describe helpful support, and some describe friction with setup for apps that serve several customers and with exporting reports. Many G2 reviews are written at the seller's invitation, and G2 labels them. Treat them as leads. If report export or multi-customer setup matters to you, ask Astra to show you both before you pay.

We do not publish a star rating or a score for Astra. We have not bought its service.

When should you compare an alternative?

Compare another provider when a specific term rules Astra out for you. "A competitor says it is better" is not a reason.

If this rules Astra outWhere to lookWhat to confirm
You need longer than 30 days to get fixes re-checkedCobalt documents six- and twelve-month retest periods on its packages.Price needs a quote. Retest requests close at the earlier of the period's end or 10 days before the contract ends (23:59 UTC).
You want a one-time, human-led test with a published pricePentest-Tools.com lists a managed web app test at $3,400 for black-box testing, and from $3,400 plus $900 per user role for gray-box.No retest count or window is published. API coverage is not priced by the formula.
You want an AI-led test priced per test, not per yearCobalt lists an Autonomous Pentest at $3,500 as a promotion that must start and finish before December 31, 2026. Intruder lists $4,000 per test, or $3,500 for platform subscribers, on its pricing page.Cobalt's price after the promotion is not published. Intruder's listed test requires connecting your code repository.

These facts come from each provider's own pages as recorded in our comparison of penetration testing offers, checked October 7 and 8, 2026. Where a row names two providers, they are in alphabetical order. Nobody paid to be listed. How we make money explains our policy.

Whichever providers you contact, send each one the same scope. Then their answers line up and you can compare them fairly.

What should you ask Astra before you buy?

Send one short message that names what you need tested, who needs the report and when. Then ask Astra to confirm each point below in the order you sign.

Fill in the brackets and copy it.

Astra scope and order questions

We need testing for [app name and environment], including [APIs] and [user roles]. The report is for [customer or auditor], who needs [human-led / AI-led accepted] testing, by [date]. We expect fixes to take about [number] days.

  1. Which plan is this, and what will human testers, AI agents and scanners each do in the first test?
  2. How many full manual tests are included in the year?
  3. Here is our list of apps, APIs and hostnames. How many targets is it? Is our cloud account inside the app target? Does our admin panel count as a second target?
  4. Which user roles and workflows will be tested? What accounts and test data do you need from us?
  5. What is the full first-year price, including anything extra our scope needs? What is due now?
  6. What are the start date and the report date? Which dates depend on us?
  7. On what date does our manual rescan window start and end? Can it be extended to [number] days, and at what cost? What does an extra manual rescan cost?
  8. Please send a current sample report for this plan.
  9. If we need a named accreditation, which company signs our order and which testers hold it?
  10. What will renewal cost, and how do we stop renewal without losing access we have paid for?

Please list anything that is assumed or left out.

A note on what this message is not. It is a buying brief. It does not give anyone permission to test. Before work starts, you and the provider need written authorization that names the real systems, the activities and the testing window. Never put passwords or keys in a message like this. Share access only through the provider's secure process.

If you have your details ready, contact Astra directly. Our page does not send anything for you.

Contact Astra about your scope

If you could not fill in the brackets yet, start there. Find My PenTest Match is our free scope checklist. It walks you through what needs testing, the questions for your report recipient and the details providers will ask for. You can copy or print it, and it asks for no contact details. It does not pick a provider for you.

Find My PenTest Match

How we checked this page

We read Astra's pricing page, nine help-center articles, its Terms of Service and two service pages on October 9, 2026. We read CREST's directory entry for Astra IT Inc. and the PCI Security Standards Council's description of its scanning vendor program the same day. Then we applied those terms to a made-up buyer and did the date and price arithmetic shown above.

Everything about Astra's offers on this page is provider-published: Astra's own pages say it. We have not confirmed any of it in writing with Astra, inspected a report from a real engagement, or bought a test. The alternatives table uses records from our comparison, with their own check dates. How our Purchase Check works explains the method.

The PenTest Index is an independent publication. We do not perform, authorize or certify penetration tests, and we are not affiliated with Astra, CREST or the PCI Security Standards Council.

Looking for the Astra WordPress theme? That is a different company.

Sources

All read on October 9, 2026, unless noted.