Bishop Fox penetration testing: tiers, retest terms and pricing

By The PenTest Index · Offer terms checked October 10, 2026

Bishop Fox penetration testing is sold by quote, and its packaged web app tests come in three tiers: Baseline with one day of human validation, Standard with one week of human-driven testing, and Advanced with two weeks. We found no published price. A recheck of your fixes is listed for Standard and Advanced but not Baseline, so ask in writing.

Below you'll find the three tiers side by side, the points Bishop Fox's own documents leave open, and a message you can copy to get the missing price, dates and retest terms on paper. We read Bishop Fox's service pages, two datasheets, its package methodology and its CREST listing. We have not bought or run a Bishop Fox test.

Which Bishop Fox tier should you ask about?

Ask about Advanced when specific features must be tested in depth, such as who can see whose data or how money moves through your app. Ask about Standard for a typical business app where the common user flows are the worry. Baseline is the fast, broad check, and it fits only if the person who will read your report accepts AI-led testing backed by one day of human work.

Three things can rule Bishop Fox out before you get that far:

  • You need to see a price before a sales call. There isn't one in public. See the priced alternatives.
  • You were offered Baseline, but your customer or auditor wants a human-led test. Ask them first. Their answer decides the tier.
  • You have a hard date. Bishop Fox publishes how long testing runs, not when it can start or when the final report lands. Get both dates in the agreement.

If what you need tested is not a web app, the three tiers are not your answer. Networks, cloud accounts, devices, AI systems and red team work are separate Bishop Fox services, covered in the second table below.

Already set on Bishop Fox? Take the quote request below with you.

Request a quote from Bishop Fox

What does Bishop Fox penetration testing include?

Bishop Fox sells three packaged web application tiers, custom-scoped application and network tests, a continuous testing service for your internet-facing systems, and specialist work on devices, AI systems and red team exercises. The same company name sits on a Baseline assessment that Bishop Fox says completes within five business days and a multi-week engagement, so the tier decides what you actually get.

The three web application tiers

Everything in this table is what Bishop Fox publishes in its AI-powered application penetration testing datasheet, checked October 10, 2026. It describes Bishop Fox's stated offer, not testing quality, which we have not measured.

BaselineStandardAdvanced
Human work publishedOne day of human validation and exploitation, after AI-powered discovery and testingOne week of human-driven testing, with AI speeding up discoveryTwo weeks of human-driven testing, with AI speeding up discovery
What the testing focuses onCoverage and speed across many appsOWASP Top 10 and common business logicOWASP Top 10, business logic, plus your app's specific features and risk areas
Stated timingFinal results in about 5 business daysOne week of testing. Start and report dates not statedTwo weeks of testing. Start and report dates not stated
Kickoff call and status updatesNot listedListedListed
Recheck of fixes (remediation testing)Not listed for this tier. AskListed. Count and deadline not statedListed. Count and deadline not stated
ReportPDF findings report and a statement of engagement letterSame, plus a report readout on requestSame, plus a report readout on request
Portal access12 months12 months12 months
PriceQuote requiredQuote requiredQuote required

Two terms in plain words. The OWASP Top 10 is a widely used list of the most critical web app security risks. Business logic flaws are mistakes in your app's own rules, like being able to skip a payment step or open another customer's invoice.

Three cautions when you read the table:

  • One day, one week and two weeks are not the same kind of work. Baseline's day is a person checking and exploiting what the AI found. Standard's week and Advanced's two weeks are people doing the testing. None of these figures tells you how many testers or hours you get, so don't divide a quote by them.
  • Twelve months of portal access is not twelve months of free retests. The datasheet lists remediation testing under portal access for Standard and Advanced. It does not say how many rechecks you get or when you must ask.
  • The tiers are web application packages. Whether your API counts as part of the app is not stated. Bishop Fox's custom application service does list APIs.

Bishop Fox's package methodology adds useful detail on depth. Baseline covers login and permission controls, session handling, basic encryption in transit, common injection attacks and header checks. Testing file uploads and trying to get around the app's logic are marked Standard and Advanced only.

Bishop Fox's other testing services

All provider-published, read on Bishop Fox's site October 10, 2026. "Not stated" means we did not find it on the page named.

ServiceWhat it coversStated timingRecheck of fixesPrice
Application penetration testing (custom scope)Web, thick-client and single-page apps, APIs. Testers picked for your app type and programming language3 to 7 weeks end to end. That is our sum of Bishop Fox's stated ranges: 1 to 2 weeks scoping, 1 to 3 weeks testing, 1 to 2 weeks reportingRetesting is listed as a deliverable. Count and deadline not statedQuote required
External penetration testingYour internet-facing network. Can extend to public cloud storage and outer web apps. Going further after a break-in is optionalNot statedNot statedQuote required
Attack Surface TestingOngoing managed testing of your internet-facing systems. Bishop Fox says its team confirms each finding before you see itContinuousOn-demand retesting listed. Limits not statedDemo and quote. AWS Marketplace lists private offers for the broader Cosmos service, not a separate Attack Surface Testing price
Internal network, cloud, mobile, secure code review, hardware, AI and LLM systems, red teamListed in Bishop Fox's services menu. We did not review these pages in detailNot reviewedNot reviewedQuote required

Three points Bishop Fox's documents leave open

Two current Bishop Fox documents describe the packages in slightly different ways. They may describe different versions of the offer. Either way, a buyer can't tell from public pages which one applies to a quote. Each point below is unresolved until Bishop Fox answers in writing.

  1. How much of Baseline is human. The AI-powered datasheet says AI-powered testing plus one day of human validation. The package methodology describes every package as a human-driven crawl, scan and manual test. Ask which document describes the Baseline you're being quoted.
  2. Whether Baseline includes a recheck of your fixes. The datasheet lists remediation testing for Standard and Advanced only. The methodology says remediation testing can be requested for each finding during the subscription period, with no tier left out. "Not listed" is not the same as "not included," so ask.
  3. How fast is fast. The AI-powered service page says most tests finish in two to five business days. The datasheet ties the five-day figure to Baseline and lists one and two weeks of testing for the other tiers. Plan on the tier's own number.

A worked example: one SaaS app, an API and two tenant roles

For this made-up buyer, Advanced is the tier to ask about first, and one written answer could move them down to Standard.

Say you run a 40-person software company. You have one web app and its API, with two user roles spread across separate customer accounts (tenants). Your biggest worry is one customer seeing another's invoices or exports. A large customer wants a detailed test report within six weeks. Your team will need about 45 days to fix what's found, and you want those fixes rechecked by a person.

We checked each requirement against what Bishop Fox publishes for each tier. "Supported" means that one condition is backed by the document. It is not a rating of Bishop Fox, and it doesn't mean your customer will accept the report. No provider has quoted for this example.

What this buyer needsBaselineStandardAdvanced
Deep testing of tenant separation, invoices and exports (must-have)Mismatch. Getting around app logic is marked Standard and Advanced onlyUnresolved. Covers common business logic. Your named flows need confirmingUnresolved. Built for specific features and risk areas, but your named flows need confirming
The API in scope (must-have)UnresolvedUnresolvedUnresolved
Fixes rechecked around day 45 (must-have)Unresolved. Not listed in the datasheetListed. Count and deadline unresolvedListed. Count and deadline unresolved
Final report within six weeks (must-have)Unresolved. Start date not statedUnresolved. Start and report dates not statedUnresolved. Start and report dates not stated
PDF report and a letter for the customer (must-have)SupportedSupportedSupported
Full price known before the call (nice to have)MismatchMismatchMismatch

What we'd do in this buyer's seat. Ask for an Advanced quote first. Its published description is the strongest fit for the must-have in row one, but your named flows still need confirming. Baseline is out, because a must-have mismatch can't be traded away for speed. Don't sign until the API, the retest terms, the report date and the full price are in writing.

The one answer that changes the choice. Ask: "Will Standard test separation between tenants and our invoice and export flows, by hand, with the same report evidence?" If yes, get Standard and Advanced quotes for the same scope and compare price and dates. If no, it's Advanced or a custom-scoped test.

One practical detail from the methodology: Bishop Fox says it may need two sets of login details for each role, plus accounts in different tenants. For two roles, plan for at least four sets of credentials if requested, with the final account setup confirmed during scoping.

The same scope sent to every provider is what makes quotes comparable. It's like asking three builders to price the same floor plan instead of three different houses. Find My PenTest Match walks you through what needs testing and who reads the report, then gives you a brief you can send to Bishop Fox and to anyone else you're weighing. It's free, needs no email or sign-up, and sends nothing to providers.

Find My PenTest Match

How much does a Bishop Fox penetration test cost?

Bishop Fox does not publish a price for any tier or service we read, and its Cosmos listing on AWS Marketplace offers custom pricing by private offer only (both checked October 10, 2026). You need a written quote for your scope. Dollar figures for Bishop Fox on other sites did not trace back to a Bishop Fox source, so we don't repeat them.

Bishop Fox does say its packages are meant to give predictable scope and pricing. That does not establish a fixed total price or billing model. It doesn't tell you the number.

A quote you can compare should state all of this:

  • The currency and whether the price is one-time or a subscription, and for how long
  • How many apps, APIs, environments, roles and tenants it covers
  • The human testing time included
  • Any charge for the portal, retests, readouts or added roles
  • Renewal and cancellation terms

If any required charge is missing, the total is unknown. It is not zero.

For a sense of what a published price looks like elsewhere, Pentest-Tools.com lists a manual web app test starting from $3,400 plus $900 per user role with logged-in testing (checked October 10, 2026). For two roles, that formula gives a starting amount of $3,400 + 2 × $900 = $5,200. That is a different provider, a shorter test of four or more working days, and a starting figure that doesn't price an API or a retest. It is not a Bishop Fox price and not a like-for-like comparison.

When a Bishop Fox proposal arrives, run a Quote Check on it. For published prices across providers, see penetration testing cost.

Is retesting included with Bishop Fox?

Remediation testing is listed for the Standard and Advanced packages, for custom application tests and for the continuous Attack Surface Testing service. For Baseline it is not listed in the current datasheet. Nowhere did we find how many rechecks you get, the last day you can ask, or whether you receive an updated report.

The deadline matters more than most buyers expect. Here is a made-up calendar to show why. Say your final findings arrive March 1 and your team can't finish fixes until April 15. A 30-day retest window counted from the report would have closed on March 31. A 60-day window would still be open. Bishop Fox's public pages state no window, so we are not saying either applies. The point is that the clock's start and length decide whether "retest included" is worth anything to you.

The methodology says rechecks can be requested "throughout the service subscription period." The datasheet lists 12 months of portal access. If those are the same period, your last day to ask is 12 months after portal access starts. We could not confirm they are the same, which is why it's in the quote request below. For more on planning fixes around a retest, see penetration testing remediation.

Does Bishop Fox use AI instead of human penetration testers?

No. Bishop Fox describes its AI engine, Cosmos AI, as a tool its own testers use, and says it is "not a product you can buy", not software you operate, and not a replacement for human testers (checked October 10, 2026). The mix changes by tier, though, and that is what you're buying.

In Baseline, the AI does the discovery and testing and a person spends one day confirming and exploiting what it found. In Standard and Advanced, the AI speeds up discovery and people do the testing for one or two weeks. Bishop Fox says no finding reaches you without a human check in any tier. That is Bishop Fox's claim about its service. We have not tested its output.

Why it matters to you: some customers and auditors ask for a human-led test. If yours does, ask them one question before you pick a tier: "Is AI-led testing with one day of human validation acceptable, or must people do the testing?" If people must do the testing, look at Standard, Advanced or a custom scope.

How long does a Bishop Fox penetration test take?

On Bishop Fox's stated figures: about 5 business days for Baseline, one week of testing for Standard, two weeks for Advanced, and 3 to 7 weeks end to end for a custom application test. None of these is a booked date.

The custom figure is our sum of the ranges in Bishop Fox's application testing FAQ: 1 to 2 weeks of scoping and preparation, 1 to 3 weeks of testing, and 1 to 2 weeks of reporting and remediation support. Bishop Fox says "most engagements" follow that pattern. It applies to custom work, not to the three packaged tiers.

What the public pages don't say is how far out Bishop Fox is booked. So count your timeline in steps: first contact, scoping, test accounts ready, test start, testing, final report, your fixes, the recheck. A week of testing that starts in five weeks is a six-week wait. Ask for the start date and the final report date in the agreement.

What should you send Bishop Fox to get a useful quote?

Send one message that fixes your scope and asks eight things in writing. It closes every open point on this page. Copy it, replace the brackets with your details, and send the same scope to any other provider you're comparing.

Subject: Quote request: web application penetration test

Hello,

We'd like a quote for a penetration test. Please quote the tier you
recommend and the next tier up or down for the same scope, and tell us
if a tier can't cover it.

Scope: [app name and URL], [API name and version], [number] user roles
across [number] tenants. Environment: [staging or production].
Workflows that matter most: [for example: sign-in, invoices, data
export, role changes].
The report goes to: [customer, auditor or internal team].
We need the final report by: [date].

Please confirm in writing:

1. Which document describes the tier you are quoting, and how many
   days of human testing it includes.
2. Exactly what is in scope (domains, APIs, roles, tenants) and what
   is excluded.
3. Which of our named workflows a person will test.
4. The test start date and the final report date.
5. Remediation testing: whether it is included, how many rechecks,
   who does them, the last day we can ask, what starts that clock,
   and whether we get an updated report.
6. The complete price: one-time or subscription, the subscription
   period, portal access, readouts, renewal, and anything extra.
7. Who will test, and their experience with apps like ours.
8. A sample report, a sample statement of engagement letter, and how
   you handle written authorization to test.

Thank you,
[Name]

What the answers tell you:

If Bishop Fox saysThen
The quoted Baseline follows the AI-powered datasheetYou're buying AI-led testing with one day of human validation. Check that your report reader accepts that
Your named workflows are covered in StandardStandard is a real option. Compare its price and dates with Advanced
Your API is priced separatelyAdd it to the total before comparing with any other quote
Retest requests close before your fixes will be readyAsk for a longer window in writing, or plan for a paid recheck
The final report date is after your deadlineAsk about Baseline for speed, if it fits, or look at another provider

A caution on what this message is not. A quote request or scope brief does not give anyone permission to test. Testing needs written authorization that covers the actual targets. Bishop Fox's methodology also says that if part of your product runs on someone else's system, you need that company's written consent before testing starts, though it notes this is generally not required for most cloud hosting providers. And keep passwords and keys out of email. Agree on how to share access after you've signed.

For a filled-in scope example, see penetration testing scope.

Is Bishop Fox accredited, and what do reviews show?

CREST, an international accreditation body for security testing firms, lists Bishop Fox as accredited for penetration testing. Public review evidence is thin.

  • CREST. The CREST Marketplace listing shows a Penetration Testing accreditation, regions of Europe and North America, four years of membership, and ISO 27001 as a company certification (checked October 10, 2026). This is about the company. It doesn't tell you which exams the people on your job have passed. If your customer requires a particular accreditation, confirm it is this one.
  • Reviews. Gartner Peer Insights showed a 4.8 score from 2 ratings for Bishop Fox Penetration Testing Services on October 10, 2026. Two ratings can't predict how your project will go.
  • Bishop Fox's own claims. Bishop Fox says it was founded in 2005 and has carried out more than 10,000 application security assessments. We have not verified either figure.

A better test than any badge: ask for a sample report and the background of the testers who would work on your app. That's item 7 and item 8 in the quote request. Our guide to the penetration testing report shows what to look for in a sample.

Bishop Fox alternatives when it is not the fit

If Bishop Fox doesn't match a must-have, pick the alternative by the gap you need to close. Providers are listed A to Z within each row. This is not a ranking, and no provider pays to appear here. The other providers' terms come from our homepage comparison, checked October 7, 2026, except Pentest-Tools.com, checked October 10, 2026.

Your gap with Bishop FoxLook atWhat to confirm
You need a published price for human testingAstra, which publishes an annual per-target price, and Pentest-Tools.com, from $3,400 plus $900 per role for logged-in testingThat your API and roles are covered, and what a retest costs
You want a provider-employed testing team and can wait for a quoteBreachLock and NetSPI, which both describe in-house testersWho will test your systems, plus price and retest terms
You want several tests across a yearCobalt, which sells annual credit packages by quoteCredits needed per test and what happens to unused credits
You already have a tester, or a test bundled with a compliance toolYour current provider firstPut its report and terms through the same eight questions. You may not need to buy again
You're not sure a web app test is the right kind of testPenetration testing servicesWhat your customer or auditor actually asked for

More questions buyers ask

Will Bishop Fox test my API and tenant boundaries?

Bishop Fox's custom application service lists APIs, and its methodology asks for accounts in different tenants. Neither binds a specific quote. Your API versions, roles and tenant checks need to be named in the written scope.

Will my auditor or customer accept a Bishop Fox report?

That's their call, not Bishop Fox's and not ours. Bishop Fox says its testing supports compliance work. Before you buy, ask the person who needs the report what systems it must cover, how recent it must be, whether a human-led test is required, and whether they need proof that fixes were rechecked. Then show them a sample report.

Is Bishop Fox Cosmos a penetration test?

Cosmos is the platform Bishop Fox runs behind its services. Bishop Fox says customers don't install or operate it. The continuous service built on it, Attack Surface Testing, checks your internet-facing systems on an ongoing basis. If your customer wants a dated report on one app, ask them whether a continuous service meets that need or whether they want a one-time test.

Does Bishop Fox work with small companies?

We found no stated minimum size or spend. Bishop Fox's package material is written for companies with dozens or hundreds of apps. If you have one app, ask for a single-app Standard or Advanced quote and compare it with a priced provider.

Looking for Bishop Fox penetration tester jobs?

This page is for buyers. Bishop Fox lists open roles on its careers page.

Sources and check dates

We compare specific offers against stated buying requirements, show our sources and check dates, and keep compensation out of fit and order. We have no affiliate or referral agreement with Bishop Fox, and the links to its site are plain links. More on how we check offers and how we make money.

Every Bishop Fox detail on this page is provider-published unless we say otherwise. We did not buy a test, receive a quote, speak with Bishop Fox or inspect a Bishop Fox report.

SourceWhat we used it forChecked
Bishop Fox: AI-powered application penetration testing datasheet (PDF)Tier contents, human testing time, timing, remediation testing, report, portal accessOctober 10, 2026
Bishop Fox: application penetration testing packages methodology (PDF)Depth by tier, test accounts, third-party consent, on-demand remediation testingOctober 10, 2026
Bishop Fox: application penetration testing packages datasheet (PDF)What each package testsOctober 10, 2026
Bishop Fox: application penetration testingCustom scope, timeline FAQ, deliverablesOctober 10, 2026
Bishop Fox: AI-powered application penetration testingStated delivery speed, human roleOctober 10, 2026
Bishop Fox: Cosmos AI and Cosmos platformWhat Cosmos is and who operates itOctober 10, 2026
Bishop Fox: external penetration testingNetwork perimeter serviceOctober 10, 2026
Bishop Fox: Attack Surface TestingContinuous service, on-demand retestingOctober 10, 2026
Bishop Fox: penetration testing servicesService list, no published priceOctober 10, 2026
AWS Marketplace: Bishop Fox CosmosPrivate offer pricing onlyOctober 10, 2026
CREST Marketplace: Bishop FoxAccreditation listingOctober 10, 2026
Gartner Peer Insights: Bishop Fox Penetration Testing ServicesRating countOctober 10, 2026
Pentest-Tools.com: web application penetration testingPublished price formula used in the cost exampleOctober 10, 2026
The PenTest Index: homepage comparisonOther providers' terms in the alternatives tableOctober 7, 2026

Spotted a term that has changed? Send us the source and we'll recheck it.