Cobalt penetration testing: which test, what price, and when retesting ends

By The PenTest Index · Cobalt's published terms checked October 9, 2026

Cobalt penetration testing is sold as annual credit packages priced by quote. The one published price we found is a $3,500 Autonomous Pentest promotion for tests started and finished before December 31, 2026. If a customer or auditor will read the report, ask for a Comprehensive pentest. Cobalt says its Agile and Autonomous reports are meant for internal readers.

Our read, in three lines

  • Worth a quote if: you run several tests a year, or one yearly test and you're fine buying it as an annual credit package.
  • Think twice if: you need a published price for a human-led test, or your contract requires testers employed by the provider. Cobalt's testers are freelancers.
  • Check first: the test type, the last day you can ask for a retest, and what happens to credits you don't use.

We read Cobalt's public pricing, documentation and contract terms. We did not buy or run a test.

Already sure Cobalt is the one? Take the ten questions with you and ask for an itemized quote. This is a plain link (how we make money).

Request a quote from Cobalt

What does Cobalt penetration testing include?

Cobalt sells three kinds of pentest on one platform, and they are not interchangeable. Pick by who will read the report and how much of your system needs testing. Pick the pricing tier second.

A penetration test (pentest) is an authorized attack on your own system to find weaknesses before someone else does. Here is how Cobalt's three versions differ, in Cobalt's own documentation.

ComprehensiveAgileAutonomous
Who does the workCobalt pentestersCobalt pentestersAn AI agent, supervised by a Cobalt pentester
What it coversA broad area of an assetOne specific part, such as a new feature or a code changeWeb only, up to 25 pages and 2 user roles
Standard length14 days7 days at 3 or 4 credits; 14 days from 5 credits1 business day
ReportsWritten by pentesters: Customer Letter, Attestation Letter, Attestation Report, Full Report, Full Report + Finding DetailsAutomated ReportAI-generated versions of the Comprehensive report types
Who the report is for, per CobaltExternal stakeholdersInternal stakeholdersInternal stakeholders
PriceCredits, by quoteCredits, by quote$3,500 per test, limited-time promotion
If an auditor or customer must read the reportSupported. This is the type Cobalt positions for audits and customer requests. Your recipient still decides if it's enough.Mismatch. Internal-use report.Unresolved. See below.

Source: Cobalt documentation, Create a Pentest: Overview, and Cobalt pricing. Provider-published. Checked October 9, 2026.

"Supported," "Mismatch" and "Unresolved" are findings on that one condition. They are not a grade for Cobalt.

Cobalt also sells DAST, an automated scanner for web apps and APIs. A scanner checks for known problems on a schedule. It is a different service from a pentest, so keep the two apart when you compare quotes.

Is an Agile test enough?

Yes, when one change is the whole job. Say you shipped a new permissions screen and want it attacked before launch. That is what Agile is for.

It is the wrong buy if your customer asked for a pentest of the whole app. One word trips people up here: "Automated Report" describes how the report is produced. People still do the testing.

Where does the $3,500 Autonomous Pentest fit?

It fits a quick internal check on a small web app. It does not fit as audit evidence unless Cobalt and your auditor both say so in writing.

The price is a promotion. Cobalt's pricing page lists $3,500 per test as a "limited time offer" for new customers and existing customers on any credit tier. The test must be started and completed before December 31, 2026. Cobalt adds that the credits taken from your account may vary with your contracted rate per credit. We found no price for after the promotion, and no retest allowance for this test.

Now the report distinction. Cobalt's Autonomous Pentest page says the product "does not produce compliance attestation reports" and points buyers who need audit evidence to its human-led testing. Cobalt's setup documentation lists an AI-generated Attestation Letter and Attestation Report for the same product, with internal stakeholders as the audience. A report's name does not make it right for your auditor. Ask for a sample and show it to the person who will read it.

How much does Cobalt cost, and can you buy just one test?

Cobalt does not publish a price for its human-led tests. Standard, Premium and Enterprise each end in a "get a quote" button, and the number of credits your app needs is set during scoping. Even one test is bought as an annual credit package.

What Cobalt does publish, as of October 9, 2026:

  • What a credit is. "The equivalent of 8 hours of offensive security testing—delivered through a combination of AI-powered automation and human expertise." Read that carefully. A credit is not eight hours of a person's time. Think of it as a prepaid block of platform work, part machine and part human.
  • How credits are sold. In annual packages. The count for a given app "will depend on the scope and delivery options of each test."
  • More credits mid-year. Cobalt says you can buy them during your contract.

The contract matters as much as the pricing page. Cobalt's Platform Services Agreement, dated August 1, 2026, says:

TermWhat the agreement saysWhy you care
What you're buyingThe Sales Order names the tier, the number of credits, the fees and the Service Period (section 2.1)Your order, not the website, is the deal.
When you payWithin 15 days of the invoice date, unless the Sales Order says otherwise (section 2.2)Ask how much is invoiced at signing. An annual commitment and the amount due now can be different numbers.
RenewalRenews for one more year if the Sales Order contains auto-renewal language (section 2.5)Look for that sentence in your order before you sign.
Unused creditsMust be used by the end of the Service Period, or the annual term within a multi-year Service Period, unless the Sales Order says otherwise (section 3.1)Any rollover has to be written into your order.

Provider-published. Checked October 9, 2026.

So can you buy one test? Cobalt describes Standard as for "teams in need of a speedy, annual pentest to meet a compliance need or client request." That is a one-test buyer. You still get there through a quote and an annual package. Ask this:

"Can you quote only this one Comprehensive pentest? What is the smallest package that covers it, what is the total I'm committing to, and does the order renew automatically?"

You may see dollar figures for Cobalt on other sites. Software-buying marketplaces and rival vendors publish their own estimates of Cobalt contract sizes and per-credit rates. Those are other people's numbers, not Cobalt's prices, and we have not verified them. Use your own quote.

Is Cobalt worth the extra cost?

You can only tell after both quotes cover the same job. A cheaper quote for fewer user roles, no API, or an automated test is not a saving. It is a smaller purchase.

Line the two quotes up on five things: what is tested, who tests it, which report you get, when retesting ends, and the full commitment. If you need a baseline for a scoped test, see what a penetration test costs. If you already hold two proposals, see how to compare pentest quotes.

Standard, Premium or Enterprise: what changes?

The tiers mostly change how fast a test starts, how long free retesting lasts, and how much support you get. A higher tier does not make the test itself broader. Scope is set per test.

StandardPremiumEnterprise
Who Cobalt says it's forA speedy annual pentest for a compliance need or client requestBuilding a structured pentest programScaling pentest programs and testing more often
Start pentest within3 business days2 business days1 business day
Free retesting (Agile and Comprehensive)6 months12 months12 months
Customer successPoolNamed managerNamed manager
OnboardingEmailLiveLive
Program planningNot includedAnnualQuarterly
Requests for testers in a region or time zoneNot offered in the agreementNot offered in the agreementYes, with limits
PriceQuoteQuoteQuote

Sources: Cobalt pricing tier table; Platform Services Agreement section 3.5.3 for tester requests. Provider-published. Checked October 9, 2026.

Three conditions sit under that table:

  • Start time has a footnote. Cobalt says start times "may vary depending on type of testing engagement." The clock runs from when your test is set to Planned and a start date is selected, with an 11 a.m. Pacific Standard Time (19:00 UTC) cutoff for the first day to count.
  • Retest months can be cut short. Requests close 10 days before your contract ends. The retest section shows how that plays out.
  • Enterprise tester requests are limited. The agreement says Cobalt "may not be able to accommodate more than one" special request per engagement, and all of them are "subject to Cobalt's availability and capacity."

The pricing table also has rows for single sign-on, integrations with tools like Jira and GitHub, and customizable reports. If one of those is a must-have, ask Cobalt which tier includes it and get the answer in the quote.

How to choose. Start with Standard as your baseline if its report and dates meet your need. Look at Premium if your fixes will take longer than six months or you want a named contact. Look at Enterprise only for something it alone offers, such as a tester in a set region. Don't buy up because a bigger name sounds more thorough.

Where do Cobalt's own pages disagree?

These four comparisons include different public descriptions and an Autonomous report distinction. None is a scandal. Each is a term you should get in writing, because your Sales Order is what counts.

TopicOne Cobalt source saysAnother Cobalt source saysWhat to do
Unused creditsPricing FAQ: "Credits do not roll over into the next contract."Pricing tier table: Enterprise credit rollover "Up to 10%"Ask which applies to you. The agreement lets a Sales Order change the default, so have it written there.
How long retesting lastsPricing FAQ: "unlimited on-demand retesting throughout your contract term"Tier table and documentation: 6 or 12 months by tier, with requests closing 10 days before the contract endsPlan on the narrower rule. Ask for your retest end date.
How fast a test startsPricing page description: "start a pentest in 24 hours"Tier table: 3, 2 or 1 business days by tier, and start times may varyAsk for your start date in writing.
Autonomous and audit evidenceProduct page: "does not produce compliance attestation reports"Documentation: AI-generated Attestation Letter and Attestation Report are available for internal stakeholdersDon't plan audit evidence around Autonomous without written confirmation from Cobalt and your auditor.

Sources: Cobalt pricing, Remediate Findings, Autonomous Pentest, Create a Pentest: Overview. Checked October 9, 2026.

When does Cobalt's free retesting actually end?

It ends on the earlier of two dates: the end of your tier's retest period, or 10 days before your contract ends. A test you run late in your contract year can have a much shorter retest window than "6 months" suggests.

A retest is a tester going back to confirm that a fix worked. Cobalt's documentation sets these rules for Agile and Comprehensive tests:

  • Free retesting lasts 6 months on Standard and 12 months on Premium and Enterprise, "provided your contract is active."
  • Your retest end date is "either the duration of your purchased tier or 10 days before your contract end date (until 23:59 UTC)."
  • If you start a test right before your contract expires, Cobalt says "you may not qualify for retesting."

Cobalt's platform shows a "Retest end date" for each test, which Cobalt says is based on your tier and your contract end date. Use that date. We don't work out the start of the 6 or 12 months ourselves, because Cobalt's own worked example doesn't make clear which day it counts from.

Here is the rule applied to two made-up buyers. Both expect their fixes to be ready for a retest request on April 5, 2027.

Buyer ABuyer B
Tier retest period ends (assumed for this example)June 15, 2027August 15, 2027
Contract ends, no renewalDecember 31, 2027March 31, 2027
Contract end minus 10 daysDecember 21, 2027March 21, 2027
Last day to request a retest (the earlier date)June 15, 2027March 21, 2027
Request on April 5, 2027Supported. Inside the window.Mismatch. 15 days too late.

Every date in this table is invented, and the arithmetic is ours. It is not a quote or a promise from Cobalt.

Buyer B has the later retest end date on paper and still misses. The contract end date did that. Buyer B's choices are to renew or get a written extension (Cobalt says to contact your customer success manager or support), fix faster, or pick a provider whose terms cover the date.

Three more things from Cobalt's Running a Security Program terms, dated August 1, 2026:

  • A retest covers findings from the original report that you have taken steps to fix. It is not a fresh test of new features.
  • Cobalt's help documentation says testers finish a retest within seven days of your request. The terms say retest timing "is at Cobalt's sole discretion." If a retest has to be done by a certain day, get that day in writing.
  • The terms tell customers to request services at least 30 days before the end of the annual Service Period. Leftover credits in the final month may not leave room for a test and its retests.

Copy this and send it:

"What is the Retest end date for this pentest, which day does the retest period count from, and will a request on [your date] be covered under our order?"

Does a Cobalt web test cover your API, user roles and tenants?

Partly, and only what is written into the scope. Cobalt's web methodology says a standard web pentest includes "testing of APIs that serve application content." For deeper API work, Cobalt points to a separate API pentest or a combined Web + API pentest.

That gap matters. An API used only by partners or by your mobile app does not serve your web pages, so a web-only test may never touch it.

Cobalt sizes a test, and so prices it, by counting things. Its scoping guide counts:

  • User roles that need testing, such as admin, manager and standard user.
  • Dynamic pages or routes in a web app. Read-only static pages don't count.
  • API endpoints, or queries and mutations for GraphQL. GET and POST on the same URL count as one.

Write down four things before you ask anyone for a price:

  1. Each app and API, and which environment will be tested.
  2. Every user role, including admin.
  3. The workflows that would hurt most if broken, such as payments or data export.
  4. Whether you need testing between tenants. A tenant is one customer's private space inside a shared app. A tenant test asks whether customer A can reach customer B's data.

A scope written this way does one more job. It asks every provider the same question, so their answers line up.

If your scope isn't written down yet, do that before you request quotes. Find My PenTest Match walks you through what needs testing and gives you a scope checklist to copy or print. It is free and asks for no contact details. It prepares your brief. It does not pick a provider for you.

Find My PenTest Match

A scope checklist is a buying aid. It does not authorize anyone to test anything. Testing needs written permission that covers the exact systems and activities. For more on writing the brief, see how to scope a penetration test.

Will a Cobalt report satisfy your auditor or customer?

Only your auditor or customer can answer that, so ask them before you buy. What Cobalt can tell you is which reports each test produces, and a Comprehensive pentest is the one built for outside readers.

A Comprehensive test offers five formats, from a one-page Attestation Letter to a Full Report + Finding Details. An attestation letter is a short statement that a test took place. A full report shows what was tested and what was found. Some recipients accept a letter. Others want the findings. Don't guess.

Send your recipient this:

"For this system, which assets must the test cover, what testing approach do you need, and what must the report show? By what date? Do you need proof that findings were fixed and retested?"

One scoping detail can change your purchase. Cobalt's report documentation says it does not create multiple reports for one large asset. If you need a separate report for each API, Cobalt recommends setting up a separate pentest for each one. Settle that before the quote, because it changes the credit count.

A real Cobalt report you can look at

One Cobalt customer, Authentik, published a full report from a Cobalt test run September 2 to 16, 2024. It is two years old and it is one engagement, so read it as an example of the format and nothing more.

What a buyer wants to seeWhat this sample showsWhat to still ask Cobalt
Who tested what, and whenThree named testers, the target addresses and the test datesWho will be on your test
What was in scopeWeb app and API targets, methods usedYour roles, tenant checks and exclusions
Whether fixes were trackedA remediation section showing each finding's statusHow your report is updated after retests
Full detail on every findingNot included. This is a Full Report without the finding-details appendixA current sample of Full Report + Finding Details, if your recipient wants one

Sample inspected October 9, 2026. For what to look for in any provider's deliverable, see what a penetration testing report should contain.

How fast can Cobalt start, and when do you get the report?

Cobalt publishes a start time and a testing length. It does not publish a report delivery date, so ask for one.

Here is what the published figures add up to for a Comprehensive test on Standard:

  1. You submit the test, it is set to Planned, and a start date is selected. Cobalt's start commitment begins here; Planned status must be reached before 11 a.m. Pacific Standard Time (19:00 UTC) for that day to count.
  2. Testing starts within 3 business days.
  3. Testing runs 14 days. That is Cobalt's standard period for non-autonomous tests. Yours can differ.
  4. You can download the report once the test moves to Remediation.
  5. You fix findings and request retests before your retest end date.

That schedule combines the advertised start notice of 3 business days with a standard 14-day test, before any fixing or retesting. It is a sum of Cobalt's published numbers, not a delivery promise. Scoping, the sales process and getting test accounts ready all come before step 1.

If you have an audit date or a deal waiting, ask:

"What calendar date will testing start, what date will we have the final report, and what could move either one?"

Who does the testing at Cobalt?

Freelance pentesters do. Cobalt calls its testers the Cobalt Core and describes them on its own recruiting page as an "elite community of freelance pentesters." They are not Cobalt employees.

What Cobalt says about them, in its own words and not checked by us:

  • More than 500 Core pentesters, with an average of 11 years of experience.
  • A five-stage screening: application review, a skills assessment, an interview, third-party verification, and ongoing peer review of their work.
  • A Lead runs each Comprehensive test. A Coordinator runs each Agile test.

Freelance is neither good nor bad on its own. It matters if your customer contract or policy says testers must be employees of the vendor, or must sit in a certain country. If so, ask who will be assigned and where they are based. Requests for a region or time zone are an Enterprise feature with the limits described above.

CREST. The CREST Marketplace lists "Cobalt Labs" with Penetration Testing under CREST accreditations, in its Germany region listing. We checked it on October 9, 2026. The listing shows no award or expiry date, and it speaks for that company entry, not for each tester. If CREST accreditation is a requirement for you, ask which Cobalt entity will sign your order and confirm it with CREST.

Customer reviews. On G2, reviewers often praise working directly with testers and getting findings they can act on. Some raise concerns about coordination and flexibility in scoping. Some G2 reviews are marked as invited or incentivized. These are individual buyers' accounts. They can tell you what to ask. They can't tell you what your contract says.

A worked Purchase Check: is Cobalt right for this buyer?

For this example buyer, Cobalt's Comprehensive pentest is the right route to quote, and a few terms are still open. Here is how we got there.

The buyer is made up. Say you run a 30-person software company with one web app, a partner API, three user roles and customers in separate tenants. A large customer has asked for a broad, human-led pentest and a report with finding details. Your fixes will be ready for retest on April 5, 2027. You need to know the full cost and what happens to unused credits before you sign.

What this buyer must haveWhat Cobalt's published terms showFindingAsk Cobalt
A broad, human-led testComprehensive is broad and done by Cobalt pentesters. Agile is narrow. Autonomous is AI-run.Supported for Comprehensive"Is this quote for a Comprehensive pentest?"
Web app, partner API, three roles, tenant checksA web test covers APIs that serve the app. Autonomous is capped at two roles.Unresolved for Comprehensive scope. Mismatch for Autonomous."Are the partner API, all three roles and cross-tenant tests in scope?"
A report with finding details for the customerFull Report + Finding Details is a Comprehensive format.Supported as a format. The customer's acceptance is Unresolved."Please send a current sample of that report."
Retest request on April 5, 2027Depends on the retest end date and contract end.Unresolved until Cobalt confirms the date"Will a request on April 5, 2027 be covered?"
Full cost known before signingNo public credit price or credit count.Unresolved"How many credits, at what price, and what is due at signing?"
Clear terms for unused creditsFAQ and tier table disagree.Conflicting"Which unused-credit rule is in our Sales Order?"

Our findings apply Cobalt's published terms to this invented brief. No provider quoted for it.

A mismatch on a must-have rules that option out for this buyer. That is why Autonomous drops out here, even at $3,500. An unresolved must-have keeps the recommendation conditional until the answer is in writing. If the open items come back in writing and they fit, this buyer has a sound reason to sign. If the April 5 date can't be covered, that alone is a reason to look elsewhere. Read more on how the Purchase Check works.

Ten questions to send Cobalt before you sign

Send these with your scope. The answers turn a credit count into something you can compare with any other quote.

  1. Is this an Agile, Comprehensive or Autonomous pentest, and on which tier?
  2. Which apps, APIs, user roles, tenant checks and environments are in scope, and what is excluded?
  3. How many credits does this take, what is my price per credit, and what is the total I'm committing to?
  4. How much is invoiced at signing, and does the order renew automatically?
  5. How much of the credited work is human testing and how much is automation? Who will test, and where are they based?
  6. Which report format will we get? Please send a current sample.
  7. What date does testing start, and what date will we have the final report?
  8. What is the Retest end date for this pentest, and what happens if our fixes take longer?
  9. What happens to credits we haven't used when the contract ends? Your pricing table and FAQ say different things.
  10. Are our must-haves included on this tier: tester location, integrations, report changes, and report access if we don't renew?

Once you have the answers and they fit, go ahead.

Request a quote from Cobalt

When is Cobalt not the right fit?

Cobalt is the wrong starting point in three cases. In each, take the same must-have to the next provider you look at.

  • You need a published price for a human-led test. Cobalt's are quote-only. Astra and Pentest-Tools.com both publish prices for tests that include human testing.
  • You need testers employed by the provider. BreachLock and NetSPI both describe in-house testing teams.
  • Your retest date falls after Cobalt's cutoff and you can't get an extension. Compare retest windows before anything else.

We list these A to Z within each need, not as a ranking. See them side by side, with prices, retest terms and check dates, in our comparison of penetration testing companies.

And if you already have a provider or a test included with another service, check it against the same ten questions first. Keeping what you have can be the right answer.

Quick answers

Is Cobalt the same as Cobalt Strike?

No. Cobalt (cobalt.io) sells penetration testing as a service. Cobalt Strike is a separate red-team software tool from a different company.

Does Cobalt test networks, cloud and AI apps too?

Cobalt lists external and internal network, cloud, and AI and LLM pentests among its services, along with code review and red teaming. This page and our comparison cover web app and API offers.

Can you buy more Cobalt credits mid-year?

Cobalt's pricing FAQ says yes: "credits are available throughout your contract." Ask whether the price per credit is the same as in your original order.

How we checked this page

We read Cobalt's public pricing page, product pages, help documentation and current contract terms on October 9, 2026, and applied them to stated buying requirements. Everything about Cobalt's offers here is provider-published unless we say otherwise. The Authentik report is a sample we inspected. The review themes are buyer-reported. The dated examples use our own arithmetic; the timeline combines Cobalt's published scheduling figures.

We did not buy a Cobalt test, get a quote, or assess the quality of Cobalt's testing. The PenTest Index does not perform, authorize or certify penetration testing, and payment never decides which providers we include or how we describe them. Terms change. If you spot something out of date, the check date at the top tells you how old our reading is.

Sources

All checked October 9, 2026.