NetSPI penetration testing: pricing, retests and the Synack merger

By The PenTest Index

NetSPI penetration testing is quote-based testing that NetSPI says is led by its own employed testers. NetSPI publishes no price for a test, and its own materials describe retesting two different ways, so get the total and the retest terms in writing. NetSPI says its merger with Synack closed in October 2026; Synack's priced packages are a separate offer.

Sources checked October 9, 2026. We read NetSPI's published pages, its AWS Marketplace listing and part of its public sample report. We did not buy or run a NetSPI test. How we check offers · How we make money

Worth a scoped quote if you want testers employed by the provider, you have many systems to cover, or you need specialist work. NetSPI lists mainframe, hardware, medical device, cloud and AI testing alongside web apps and networks.

Probably not your first call if you need a price before you talk to sales, or you have one small web app and a tight budget. Start with an offer that publishes its price.

What decides it: four things NetSPI does not publish. The total, exactly what is in scope, the retest terms and the report date.

Already know what needs testing and who needs the report? Ask NetSPI to quote the named service, the delivery date and the retest terms.

Request a scoped NetSPI proposal

Need a price today instead? See offers with published prices.

Which NetSPI penetration testing service fits your project?

Ask for a scoped test when you have one defined system. Ask about H-DAP when you want lighter coverage across many web apps. Ask about continuous testing when your systems change often. They are three different purchases, and a quote that just says "PTaaS" does not tell you which one you are getting.

A penetration test is an authorized attempt to find and prove weaknesses an attacker could use. PTaaS means "penetration testing as a service". At NetSPI, that means the test is delivered through an online platform where you see findings and track fixes. It does not mean unlimited tests.

NetSPI serviceWhat NetSPI says it isWho it suitsPublished priceWhat your quote must confirm
Scoped web application or API testManual testing with commercial, open source and in-house tools. Covers anonymous and signed-in users and access checks across user roles.A team that needs one defined app or API tested, often for a customer or auditor.None. Quote required.Which apps, APIs, user roles and environments are covered, the total, the retest terms and the report date.
H-DAP (Human-Driven Automated Pentesting)Scanning tools plus targeted manual testing. NetSPI calls it "a lighter touch manual assessment" with "limited exploitation".A team that wants more of its web app portfolio looked at, not just the high-risk apps.None. Quote required.Whether whoever needs your report accepts a lighter test. Which manual checks are included.
Continuous penetration testingOngoing testing through the platform, "tailored to your risk profile and operational cadence". Listed for external, internal, cloud, web app and AI systems.A team whose systems change often and that wants recurring testing.None. Cadence and contract term are not stated.How often people test, on which systems, what triggers a new test, the term, the renewal and what report you get.

Service descriptions are from NetSPI's web application, H-DAP and continuous testing pages, checked October 9, 2026. The "who it suits" and "must confirm" columns are our reading.

A few practical rules follow from that table.

  • One product, one customer asking for a report. Start with the scoped test. Take the customer's written requirements to the first call.
  • Dozens of apps. Decide which ones need a deep test and which can take the lighter H-DAP pass. Do not assume H-DAP depth matches a full manual test. NetSPI's own page says it does not.
  • Cloud, network, mainframe, hardware or AI systems. Name the specialist service in your request. NetSPI lists these in its service catalog, but listing a service is not the same as including it in your order.

On who does the work: NetSPI's pages state "350+ pentesters" who are "Employed, not outsourced". That is NetSPI's claim about its staff. Your quote should still say who will be assigned and what experience they have with systems like yours.

How much does NetSPI cost?

NetSPI publishes no price for a penetration test. We found none on its service pages, its data sheet or its AWS Marketplace listing, so the only real number is the one in your written quote.

Three things you may see that look like a price are not one.

The $1.00 AWS Marketplace line. NetSPI's AWS listing shows one item: "NetSPI Platform", described as "Access to NetSPI Platform - PenTest hours not included", at $1.00 for a 12-month contract. The listing also says "No refunds available" and sends buyers to a private offer for custom pricing. So the listed dollar buys platform access, not testing. If your company wants to pay through AWS, ask NetSPI for the private offer and its full total.

Synack's package prices. Synack is now part of the same company and does publish starting prices. Those packages are a different delivery model. More on that in the merger section below.

Third-party contract averages. Vendr, a software-buying service, reports a median NetSPI contract of $37,688 a year across 47 purchases, with a low of $13,200 and a high of $156,443, on a page marked "Last updated: February 2026". Those are whole contracts across NetSPI's products with no scope shown. Treat that as what Vendr reports about deals on its platform, not as the cost of a test. Vendr's NetSPI page

One clue about how NetSPI prices comes from a customer story on NetSPI's own site. NetSPI's write-up says a credit union's security manager liked that the pricing "focused on functional elements instead of hours". That is one customer's account, published by NetSPI. It suggests the size and complexity of what you test drives the quote more than a day rate does. It does not tell you your number. Mission Fed customer story

Ask for the quote to be itemized: the test, any platform charge, retesting, anything optional, the contract term, renewal and the payment schedule. A total with one required line missing is not a total yet.

Can you buy one NetSPI test, or is a subscription required?

NetSPI's material describes a one-time test as a normal purchase. Its PTaaS data sheet says that when you choose NetSPI "you get a point-in-time test, along with access to The NetSPI Platform for a year". Continuous testing is listed as a separate service.

Read that sentence carefully. A year of platform access means a year of seeing your findings and tracking fixes. It does not say you get a year of testing. Ask what happens during that year, what would need a new order, and how you export your reports when access ends.

Does NetSPI include retesting?

NetSPI offers retesting, which it calls remediation testing. Whether it is included in your price is not settled by anything public. NetSPI's own site describes it two different ways.

A retest means the testers check specific findings again after you fix them. New features or a wider scope are a separate job.

NetSPI sourceWhat it saysWhat you can take from it
PTaaS data sheet"You can also schedule remediation testing to validate your efforts."Retesting is available. No count, deadline or price is given.
Cost article, dated September 7, 2022NetSPI describes an "a la carte approach": "You only pay for the number of vulnerabilities you need retested."In 2022, NetSPI described retesting as paid per finding.
Mission Fed customer storyThe customer says "remediation testing is included in NetSPI's pricing".For that customer, it was part of the price.

All three checked October 9, 2026. These are different documents about different situations, so we are not calling it a contradiction. We are calling it open. Your proposal has to close it.

Send this question as written:

Which findings and how many retest rounds are included? What starts the retest window, and does the deadline apply to asking for the retest or to finishing it? What costs extra? What updated report do we get afterward?

Here is why the window matters. Say your team needs 45 days after the report to ship fixes. If the answer is "one retest, requested within 30 days of the report", ask whether you can request it before fixes are ready. If not, you need an extension in writing before you sign. If the answer is "paid per finding, no deadline", the timing works but the retest belongs in your total.

Is NetSPI a fit? A worked example

For a company that needs one web app and its API tested by people, NetSPI's published service matches the method. It leaves four conditions open that decide the purchase. So the honest answer is "yes, ask for the quote, and hold the decision until four answers come back."

We reach that by running what we call a Purchase Check. We take one buyer's requirements, check each one against what the provider has published, and mark it Supported, Mismatch or Unresolved. "Supported" means that one condition is backed by the source shown. It is not a grade for the company.

The example buyer is made up. Say you run a 60-person software company. You need one web app and its API tested. The app has three user roles and you want two customer accounts (tenants) tested against each other, in a staging environment. Your customer's questionnaire asks for manual testing. You need the final report in four weeks. Your developers will need about 45 days to fix what is found, and then you want a manual retest. Finance wants the full commitment before approving. A year of access to the findings would be nice to have.

Your requirementFindingWhat NetSPI's published material showsQuestion to send
People do the testing (must have)SupportedThe web app page describes experts "manually testing your web applications". The API page describes manual work combined with automated tools."Confirm the manual testing and the team included in our statement of work."
Signed-in user roles are tested (must have)Supported at service levelThe web app page lists authenticated user testing and "access control verification across user roles"."Does the quoted effort cover all three of our roles?"
This app, this API, three roles, two tenants, in staging (must have)UnresolvedNetSPI lists API security inside its web app test and also sells a separate API test. Neither page says what your order would cover."List the APIs, roles, tenant-to-tenant tests and environment covered, and what is excluded."
Manual retest about 45 days after findings (must have)UnresolvedRetesting is available. Count, window and price are not published, and NetSPI's sources differ on whether it is included."Can we request a manual retest 45 days after findings, and what does it cost?"
Final report within four weeks (must have)UnresolvedWe found no lead time or report date on the pages we read. Live findings in a platform are not a final report."Confirm the start date, the end of testing and the final report date for this scope."
Full commitment known before approval (must have)UnresolvedNo price is published."Itemize the test, platform access, retesting and extras, with term, renewal and payment schedule."
A year of access to findings (nice to have)Supported for the arrangement the data sheet describesThe data sheet pairs a point-in-time test with platform access "for a year"."Confirm the access period and export options for our order."

Sources: NetSPI's web application page, API page and PTaaS data sheet, checked October 9, 2026. The findings are our reading of those pages. NetSPI has not quoted for this made-up brief.

One route is ruled out. Buying only the AWS Marketplace platform line cannot meet this brief, because that line excludes pentest hours. That is a Mismatch for the platform-only purchase. It says nothing against a separately quoted NetSPI test.

How the answers change the outcome. If NetSPI confirms the day-45 retest and its price, that row becomes Supported. If its window closes earlier and it will not extend, that row becomes a Mismatch for this buyer, and a must-have mismatch takes the offer off the list no matter how good the rest looks. If a question goes unanswered, it stays Unresolved and you do not sign.

On timing, agree five dates in writing: scope and access ready, testing starts, testing ends, final report delivered, retest report delivered. Ask how critical findings are flagged before the report. If your deadline is fixed, put the date in the proposal request.

What does NetSPI's sample report show?

NetSPI publishes a full sample web application report, which lets you see the kind of document you would hand to a customer or auditor before you spend anything. We read the first 12 of its 42 pages.

What a buyer should checkWhat we saw in the sample
Scope and environmentSeen. Two assets are named, an API endpoint and the app front end. Two test accounts are listed by role. Testing was on a non-production version, and everything else is stated as out of scope.
Test datesSeen. "Testing and verification was performed between June 3rd, 2024 and June 7th, 2024." The cover is dated June 11, 2024.
Findings and severitySeen. Eight findings, grouped by severity, with a table explaining how severity maps to CVSS scores.
Steps to reproduce and proofSeen in the first finding. Numbered steps with the requests and responses used.
Fix guidanceSeen. Each finding we read has a recommendation.
Correct framework labelsOne mismatch. See below.
Status after a retestNot seen in the pages we read. Ask for an example.

The mismatch is small and specific. On page 7, the first finding is labeled "OWASP API 2023 Category: A3-Injection". In OWASP's API Security Top 10 for 2023, the third item is Broken Object Property Level Authorization. "A3-Injection" matches the web application category list that the same report prints in its own summary table. The next finding in the report is labeled "OWASP 2021 Category". So one label in a marketing sample names the wrong list. It tells you nothing about how NetSPI tests. It is a reason to ask for a current sample for the service you are buying, especially if your customer wants findings mapped to a named framework.

The sample's dates are from a made-up engagement. Do not read June 3 to June 11 as a delivery promise.

Open NetSPI's sample report (PDF)

Whether a report is accepted is up to the customer, auditor or regulator who asked for it. Show them a sample before you buy.

What to send NetSPI before you ask for a quote

Send the same written request you will use to compare the answer. It works like handing every supplier the same question so the answers line up. Fill in the brackets and send it.

Quote request

Do not put passwords, keys or other credentials in this request.

Please quote the NetSPI service that fits the assessment below, and name that service in the quote.

Purpose and recipient: [Why we need the test. Who will receive the report. What they have asked for in writing.]

Scope: [Applications, APIs and versions. User roles. Tenant-to-tenant testing. Environment. The workflows that matter most.] Please list anything excluded and anything priced separately.

Testing work: State whether this is a point-in-time test, H-DAP or continuous testing. Describe the manual testing, the automated testing, the access you assume and who will be assigned. If the offer is recurring, state how often people test and what triggers a new test. Show platform access as its own line.

Dates: We need the final report by [date]. Please confirm what you need from us first, the test start, the end of testing and the report delivery date.

Retesting: We expect fixes to be ready [timing]. State which findings and how many rounds are included, what starts the window, whether the deadline applies to requesting or finishing the retest, any extra charge and the updated report we receive.

Complete commitment: Itemize the test, platform access, retesting and any extras. State the currency, contract term, renewal terms, payment schedule and anything that would change the total.

Deliverables and access: Please share a current sample report for this service and an example of a report after a retest. Confirm export formats and how long we keep access to reports and findings.

This request is a buying document. It does not give anyone permission to test. Written authorization has to name the real systems and the activities allowed.

Use the answers to ask for an itemized offer.

Contact NetSPI about this scope

Stuck on the scope paragraph? NetSPI cannot quote until you know which apps, APIs and roles are in. Our free scope checklist walks through what to settle, and you can copy or print it. No contact details needed. It prepares your request. It does not pick a provider for you.

Find My PenTest Match

What did the NetSPI and Synack merger change?

For a current customer, nothing yet, according to NetSPI. Its merger page says the two companies "have officially closed their merger" in October 2026 and that "nothing changes for existing engagements". Testing schedule, scope, platform access and contacts stay the same. The deal was announced on September 2, 2026. If you are a NetSPI or Synack customer, start with the representative you already have and ask what your agreement already covers before buying anything new.

For a new buyer, the merger creates three easy mistakes.

It is tempting to assumeWhat the sources say
Synack's published prices are now NetSPI's prices.They are separate offers. Synack's pricing page lists packages starting at $4,181 for an AI-led test, $10,283 for a test by one human tester and $27,120 for a 14-day test by a team. It also says the Synack Platform "is a separate line item", so those are not complete totals. NetSPI's tests remain quote-only.
The testers are one big pool.NetSPI describes "350+ NetSPI in-house pentesters and 1,500+ vetted Synack Red Team researchers" as "two different delivery models rather than one larger pool". Ask which model your quote uses.
Synack's FedRAMP status now covers NetSPI.NetSPI says the FedRAMP Moderate authorization "applies specifically to the Synack platform" and "does not extend to NetSPI products or any future combined offering".

All checked October 9, 2026. On any new proposal, ask which company you are contracting with, which platform you will use and which testers will do the work.

What can you check about NetSPI yourself?

Three things, each at its source.

CREST. CREST's own marketplace lists NetSPI with Penetration Testing accreditation and a Threat Led Penetration Testing specialism, and lists Europe and North America. If your contract names CREST, confirm on CREST's site that the listing covers the NetSPI company and region you are buying from.

NetSPI's own security. NetSPI's trust page states SOC 2 Type II and Cyber Essentials Plus. That is NetSPI's statement. Ask for the report through its client portal if your vendor review needs it.

Customer accounts. NetSPI's AWS listing shows 13 customer reviews collected by G2. One, dated April 28, 2026, says the platform lets the reviewer's team "conduct retests" and track fixes, and complains that customers have to ask NetSPI to add their own users to an engagement. These are individual accounts. They can give you questions to ask. They cannot tell you what your contract includes.

Which alternatives are worth pricing alongside NetSPI?

Price one other offer against the same written scope, and pick it by the thing NetSPI's answer left you unsure about. If that was price, add an offer that publishes one. If you want a second quoted firm with a similar model, add one of those.

OfferWhy price it alongsideWhat still needs confirming
Bishop Fox, application penetration testingAnother quote-based firm. Its service page describes manual and automated testing by assessors chosen for your application type and language.Everything NetSPI leaves open: scope, total, retests and dates. We are not saying it costs less or tests better.
Pentest-Tools.com, managed web app testIt publishes a price. A black-box test (no login) is $3,400. A gray-box test (with logins) starts at $3,400 plus $900 per user role.The formula is a starting point. API coverage, added scope and retesting are not priced by it. This is its managed service, not its scanning software.

Listed A to Z. Pentest-Tools.com prices checked October 9, 2026. Bishop Fox checked October 7, 2026.

To see why the formula is only a start: three roles on the gray-box test works out to $3,400 + (3 × $900) = $6,100 as a starting amount for our made-up buyer. The API and the retest are not in that figure.

View Bishop Fox application testing

View Pentest-Tools.com managed testing

If you already have a provider, or a test included with something you already pay for, check that option against the same eight paragraphs first. Keeping what you have can be the right answer.

For more offers, including annual packages and AI-led tests, compare penetration testing offers.

Quick answers

Are NetSPI's testers employees or contractors?

NetSPI states its "350+ pentesters" are "Employed, not outsourced". Synack, now part of the same company, works with a vetted community of outside researchers. NetSPI describes these as two separate delivery models, so ask which one your quote uses.

Does NetSPI test AI systems?

Yes, and it uses "AI" for two different things. NetSPI lists testing of your AI and large language model applications as a service. Separately, it describes its continuous testing as AI-assisted work that its people validate. If AI matters to your purchase, ask which of the two you are being quoted.

Where is NetSPI based?

NetSPI is headquartered in Minneapolis, Minnesota. CREST's listing describes offices across the United States, Canada, the United Kingdom and India. If your contract limits where testers can work or where data can go, put that in your request.

Sources

All checked October 9, 2026 unless noted. Statements about NetSPI's services are NetSPI's own. We did not buy a test or confirm any term with NetSPI in writing.

SourceUsed for
NetSPI PTaaS pageService list, tester statement, continuous services
NetSPI web application testingManual testing, signed-in roles, API focus area
NetSPI API testingSeparate API service
NetSPI H-DAPLighter assessment description
NetSPI continuous testingContinuous service description
NetSPI PTaaS data sheetOne year of platform access, remediation testing
AWS Marketplace: NetSPIPlatform line, exclusion of pentest hours, refund policy, customer accounts
NetSPI cost article (September 7, 2022)Paid-per-finding retest description
Mission Fed customer storyCustomer account of included retesting and pricing basis
NetSPI sample report (PDF)Report check; first 12 of 42 pages read
OWASP API Security Top 10, 2023Category list for the label check
NetSPI and Synack merger pageClosing, continuity, delivery models, FedRAMP statement
Merger press release (September 2, 2026)Announcement date
Synack pricingPackage starting prices, separate platform line
CREST marketplace: NetSPIAccreditation, specialism and regions
NetSPI trust pageNetSPI's stated certifications
Vendr: NetSPIThird-party contract figures
Pentest-Tools.com managed web app testingPublished prices
Bishop Fox application penetration testing (October 7, 2026)Service description
Find My PenTest Match