BreachLock penetration testing: prices and retest terms
By The PenTest Index · Checked October 9, 2026 · We read BreachLock's published pages. We did not buy or run a test.
BreachLock penetration testing is human-led testing by what BreachLock says is an in-house team, sold in three packages. Its main pricing page shows no prices. A second official page lists "Starts at $2,500" for a one-time test and "$5K" for annual coverage, under different package names. Free manual retests are one, two or custom, with no published deadline.
Is it worth a call? Yes, if you want people doing the testing, a company on CREST's accredited list and a quick start, and you are fine getting your real price by quote. If you need a fixed price before you talk to sales, start with the offers that publish one. Already have a provider? Put the eight questions below to them first. You may not need to switch.
This site may contain affiliate or referral links. Our links to BreachLock are plain links. How we make money.
Tell BreachLock your test requirements
How much does BreachLock cost?
BreachLock publishes two price tables that do not match. The main one, linked from its menu, is quote-only. An older one shows starting prices. Neither tells you what your project will cost.
The main pricing page names three packages, Standard, Extended and Extensive. Each one has a "Get a Quote" button and no dollar figure. (BreachLock pricing page, checked October 9, 2026.)
The second pricing page is still live and uses different names:
| Package on that page | Published price | Free manual retests | Platform access |
|---|---|---|---|
| 1-Time Security Validation | "Starts at $2,500" | 1 | 6 months |
| Annual Security Validation | "Starts at $5K" | 2 | 12 months |
| Continuous Security Validation | Custom pricing | Custom | Custom |
Source: BreachLock's second pricing page, provider-published, checked October 9, 2026. The page shows a dollar sign and no currency code. BreachLock's Terms of Use (section 5) say direct purchases are billed in US dollars.
Three things to know before you rely on those numbers:
- "Starts at" is a floor, not a quote. The page does not say how many apps, hosts or user roles $2,500 covers.
- BreachLock does not say how the two sets of packages relate. The retest counts line up (1, 2, custom) and so do several feature rows, so they look like the same three tiers under old and new names. That is our reading, not BreachLock's statement.
- The older-looking page may be out of date. Its page data shows a last change in January 2024. The main pricing page shows December 2025.
BreachLock's own FAQ says price depends on the size and complexity of what you test and how often you test it. Its article on reading a quote adds that extra fees can apply for specialized tools, onsite travel or dedicated resources outside the base scope. When you buy direct, the Terms of Use say fees are due when you receive the invoice.
So treat $2,500 as the published starting figure for the 1-Time package, and nothing more. Ask them to confirm in writing whether that starting price still applies and what it buys. For help setting a budget across providers, see penetration testing cost.
What does BreachLock penetration testing include?
Every package includes testing by BreachLock's own staff, a report and a free manual retest allowance. BreachLock advertises unlimited automated retests through its platform, which the pricing grid lists as optional. What changes by package is how much support and tailoring you get.
| Standard | Extended | Extensive | |
|---|---|---|---|
| BreachLock says it suits | Small to mid-size web apps, basic internal and external networks | Mid-size apps, complex networks, APIs | Large enterprise apps, layered networks |
| Published price | None | None | None |
| Free manual retests | 1 | 2 | Custom |
| Dedicated project manager | No | Yes | Yes |
| Pentest checklist in the report | No | Yes | Yes |
| Report review sessions with an expert | No | Yes | Yes |
| Requests for tester location or time zone | No | Yes | Yes |
| Customized reports | No | No | Yes |
| Red teaming / source code review | No | No | Yes |
| Platform access | Optional | Optional | Optional |
Source: BreachLock pricing page, provider-published, checked October 9, 2026. BreachLock describes all testers as in-house and certified, and says it does not outsource or crowdsource. That is the company's statement. We have not verified who would be assigned to you.
Who each package does not fit:
- Standard is thin if your fixes will land in two waves, because you get one manual retest. It also lists no dedicated project manager.
- Extended does not include source code review. If you need your code read, that is Extensive only.
- Extensive is built for large environments. A single small app is unlikely to need it.
The "suits" row is BreachLock's description. It does not promise that a package covers every API, user role or environment you have. Your quote has to name them.
Is BreachLock retesting really unlimited?
Only the automated kind. A retest is a check that your fix worked. BreachLock offers two different checks, and they are not equal.
- Automated retest: you click a button in the platform and software rechecks one finding. BreachLock says these are unlimited and free.
- Manual retest: your assigned tester goes back in and verifies the fixes, and you get an updated report. This is the one most customers and auditors care about. It is capped at one, two or a custom number, depending on package.
BreachLock's services page says "unlimited re-testing" near the top and explains the split further down. So the page is accurate if you read all of it. The risk is stopping at the headline.
What we could not find anywhere is a deadline. None of the pages we read says how long after the report you can ask for your manual retest, or what an extra one costs. The Terms of Use have no retest clause at all. They do give a 90-day warranty on professional services (section 16), but that covers poor work, not a retest window. The six or twelve months of platform access on the second pricing page is not a retest window either.
Say your developers need 45 days to fix what the test finds. Whether your free manual retest is still available on day 45 is something only BreachLock can tell you. Get the answer in writing before you sign.
Is BreachLock manual or automated?
BreachLock sells both, as separate things. Make sure your quote says which one you are buying.
| What you can buy | What BreachLock says it is | Consider it when | Confirm before buying |
|---|---|---|---|
| Penetration testing services (also sold as PTaaS, meaning delivered through an online platform) | Staff testers do the work. AI handles early steps like host discovery and scanning. BreachLock says a tester validates every finding. | A customer, auditor or your own team wants people testing a defined app, API or network | What the testers will do, which assets are in scope, how many tester days |
| Breach360 | An autonomous testing product, announced August 26, 2026, sold by subscription on contracted assets. A human reviewer is an optional add-on. | You want frequent automated testing between human tests | Whether whoever reads your report accepts an AI-led test |
| Attack surface management | Discovery and vulnerability scanning | You need to find exposed assets or meet a scanning requirement | Whether you also need a separate pentest |
Sources: services page and Breach360 page, provider-published, checked October 9, 2026.
A vulnerability scan looks for known weaknesses. A penetration test has someone try to break in and prove what is exploitable. If you are not sure which one you were asked for, read penetration testing vs vulnerability scanning before you request a quote.
Where BreachLock's own pages disagree
We read BreachLock's pages side by side on October 9, 2026. In six places they say different things. None of these is a scandal. Each one is a question to settle in your quote.
| Topic | One page says | Another page says | Ask BreachLock |
|---|---|---|---|
| Price | Main pricing page: quote only | Second pricing page: "Starts at $2,500" and "$5K" | Which package list applies to my quote, and does the starting price still stand? |
| Project manager | Main pricing page lists a dedicated project manager among its general benefits | Grid on the same page: not in Standard | Will I have a named contact? |
| Checklist and report walkthrough | Same benefits list includes both | Same grid: not in Standard | Are they in my package? |
| Timing | Services page: a few days to a couple of weeks | Older FAQ: in most cases, at most five to seven business days, report a day later | What date will I have the final report? |
| Automation | Older FAQ: "We have no offering that is fully automated" | Breach360 is an autonomous product | Is my quote for human-led testing, Breach360, or both? |
| Platform | Main pricing page: optional | Second pricing page: 6 or 12 months of access | How long do I keep access, and can I export reports after? |
A worked example: one app, one API, fixes ready on day 45
Here is how we would check BreachLock for one made-up buyer. This is our Purchase Check: take each thing the buyer needs, hold it against what the provider has published, and record what is settled and what is not.
Say you run a 30-person software company. You have one web app and its API, two user roles, and you will not share source code. A customer has asked for a test done by people. Your developers will need about 45 days to fix what turns up, and then you want a tester to confirm the fixes. Nobody at BreachLock has quoted for this. It is an example.
Our conclusion: worth a call. Ask for a quote on the entry package (Standard, or "1-Time" if they use the old names), and ask what the middle package costs, because one manual retest is tight if fixes come in two rounds. Nothing published rules BreachLock out. Four must-haves stay open until the quote answers them.
| What you need | Finding | Why | What would settle it |
|---|---|---|---|
| People do the testing (must-have) | Supported, on BreachLock's word | Services page describes staff testers validating every finding | The quote states tester days and tasks |
| App, API and both roles covered, no source code (must-have) | Unresolved | API testing is offered, but no package states what it covers | The quote lists each API and role, plus exclusions |
| Manual retest on day 45 (must-have) | Unresolved | One manual retest is included. No deadline is published | Written confirmation of the last request date |
| A second manual retest (nice to have) | Not in the entry package | Extended lists two | Price for Extended, or for one extra retest |
| Total price (must-have) | Unresolved | "Starts at $2,500" does not price this scope | An itemized quote, including any extras |
| Report date (must-have) | Unresolved | Published timing is an estimate, and two pages differ | A report date in the quote |
"Supported" here means that one condition is backed by what BreachLock has published. It is not a verdict on the quality of BreachLock's testing.
If the answer on day 45 comes back "no, the retest must be requested within 30 days," then the entry package fails this buyer unless BreachLock adds an extension in writing. That single answer decides it.
Eight questions to send BreachLock before you sign
Send these with your scope. Send the same scope and questions to any other provider you are considering. That is what makes the answers comparable.
- Which package is this quote for, and which of your two published package lists applies?
- Exactly what is in scope? Please list each app, API, user role and environment, and anything excluded.
- Is this human-led testing, Breach360, or both? How many tester days are included?
- How many manual retests are included, and what is the last date we can request one?
- What does an extra manual retest cost?
- What is the total price in US dollars, including platform access and any extras? When is each payment due?
- What date will we have the final report, and the updated report after the retest?
- Which BreachLock company signs the order, and is that the company on CREST's accredited list?
These questions are for buying. They do not give anyone permission to test your systems. Written authorization has to name the actual targets and activities, and it comes later, with the provider you hire. Do not put passwords or keys in an email like this.
If you cannot yet answer question 2 for yourself, start there. Find My PenTest Match walks you through what needs testing and gives you a scope checklist to copy or print. It is free and asks for no contact details. Today it covers web apps and APIs, so a network-only buyer will get less from it.
Is BreachLock CREST accredited?
A BreachLock company is. CREST's directory lists Breachlock Ltd, based in the United Kingdom, as accredited for penetration testing. We read that listing on October 9, 2026.
Two cautions. First, BreachLock's public terms send legal notices to BreachLock Inc. in Delaware, which is a different company name. If CREST accreditation matters to your customer, ask which company signs your order. Second, BreachLock calls its reports "CREST-certified." We found no CREST page that defines a certified report. CREST's listing accredits the company. It does not vouch for an individual tester or a specific report. We have no connection to CREST.
Will an auditor accept a BreachLock report?
That is your auditor's call, not BreachLock's and not ours. BreachLock says its reports are "audit-ready" and mapped to SOC 2, PCI DSS, ISO 27001 and HIPAA. Those are the company's claims.
Before you request a quote, ask whoever will read the report what it has to show: which systems, what kind of testing, how recent, and whether they want proof that fixes were retested. We keep a short list of questions for your report recipient. Then ask BreachLock for a full sample report for your type of test. Its website shows a few sample pages as images, which is not enough to judge a whole report.
How long does a BreachLock pentest take?
BreachLock says testing can start within 24 to 48 hours and usually runs from a few days to a couple of weeks, depending on scope. Both figures come from its services page, checked October 9, 2026.
A fast start is not a fast report. The clock that matters to you runs through setup, testing, the first report, your fixes, the retest and the updated report. Ask for the report date in writing. If you are buying an internal network test, also ask who sets up access on your side and who fixes it if the setup stalls.
What do buyers say about BreachLock?
Not enough to lean on. Public accounts are few and mixed. One 2022 thread on Reddit's r/msp forum includes a poster who described struggling to get an internal test off the ground, and another who said BreachLock did a good job against a deadline across eight locations and that a lot depends on your project manager. These are unverified personal accounts from years ago. Use them as prompts for questions 3 and 7, not as a rating.
BreachLock alternatives with a published price
If the open questions above are a dealbreaker, two providers publish a firm price for a web app test. Order is A to Z.
| Offer | Published price | What it covers | The catch |
|---|---|---|---|
| Astra Pentest Expert | $5,999 per year, per target | One web or SaaS app and the APIs it uses count as one target. Testing by people plus automated agents | An annual package, not a one-time fee |
| Pentest-Tools.com managed web app test | $3,400 fixed (black box). Grey box from $3,400 + $900 per user role | Black box tests as an anonymous attacker. Grey box adds logged-in roles | For two roles the starting price is $5,200 ($3,400 + 2 × $900). API coverage and retesting are not priced on the page |
Sources: Astra pricing and Pentest-Tools.com service page, provider-published, checked October 9, 2026. Prices in US dollars.
A lower headline price is not a like-for-like saving. Send each provider the same scope and the same eight questions. Our full comparison covers more providers, including those that sell by quote.
Fine print worth knowing
These points come from BreachLock's public Terms of Use, checked October 9, 2026. A signed order or service agreement can change them, so read yours. This is not legal advice.
- Liability cap (section 18): subject to stated exceptions, limited to fees payable for the relevant SaaS product, hardware or service in the 12 months before the event giving rise to liability.
- Publicity (section 19): BreachLock may name you publicly as a customer. Ask to strike this if it matters.
- Non-payment (section 5): BreachLock may end your access and delete your data, and may not restore it.
- Governing law (section 19): U.S. federal and Delaware state law.
Other questions
Does BreachLock fix the problems it finds?
No. Its FAQ says BreachLock gives guidance and answers questions, and your own team or IT provider makes the changes.
Will testing disrupt our live systems?
BreachLock's FAQ recommends testing a staging environment and says it can test outside business hours at no extra charge. Agree the environment and hours in writing before work starts.
Can we buy a single test, or is it a subscription?
BreachLock's pages describe one-time, periodic and continuous testing. The second pricing page lists a "1-Time" package. Confirm in your quote that you are not signing up for a renewing term.
Sources
All checked October 9, 2026.
- BreachLock penetration testing pricing: packages, feature grid, manual retest counts
- BreachLock pricing, second page: starting prices, platform access periods
- BreachLock penetration testing services: who tests, retesting, start and duration
- BreachLock Breach360: autonomous product
- BreachLock FAQ: older timing and automation statements, remediation, off-hours testing
- BreachLock, Understanding Your Penetration Testing Quote: possible extra fees
- BreachLock Terms of Use: payment, warranty, liability, publicity, governing law
- CREST marketplace, Breachlock Ltd: accreditation listing
- Astra pricing and Pentest-Tools.com web app testing: alternative prices