NodeZero penetration testing: public prices, limits and who it fits
By The PenTest Index · Sources last checked October 10, 2026
NodeZero penetration testing is a self-run, autonomous pentest platform from Horizon3 with public list prices of $50 to $85 per asset per year. The smallest AWS Marketplace pack is $25,000 for 500 assets; a UK price sheet shows a 100-asset minimum. It fits repeat testing of networks, Active Directory and cloud. Ask your auditor before relying on it.
Horizon3's own website shows no prices. The table below puts the public ones side by side, so you can see what your asset count works out to before you book a demo.
How much does NodeZero cost?
The public list price is $50 (Core), $65 (Pro) or $85 (Elite) per asset for 12 months. Two sources show it: Horizon3.ai's own AWS Marketplace listing and two UK government G-Cloud price sheets published by resellers. All prices are US dollars, advertised list prices, checked October 10, 2026. They are not quotes and not what any buyer paid.
| Offer | AWS Marketplace (sold by Horizon3.ai) | UK G-Cloud 15 price sheets (resellers, dated January 2026) | What you are buying |
|---|---|---|---|
| Core | $25,000 per 12 months for 500 assets | $50 per asset, minimum 100 assets ($5,000) | Repeat autonomous testing with scheduling |
| Pro | $32,500 per 12 months for 500 assets | $65 per asset, minimum 100 ($6,500) | Core plus Tripwires and Rapid Response |
| Elite | $42,500 per 12 months for 500 assets | $85 per asset, minimum 100 ($8,500) | Pro plus Insights and risk intelligence features |
| Flex | $15,000 for 1,000 assets | Not listed | Described as a "one-time" autonomous pentest. No scheduling |
| WebApp add-on | $10,000 per 12 months. Number of licensed apps not stated | Not listed | Web application testing. How many apps this covers is not stated |
| Premium Support Gold | $100,000 per 12 months, up to 25,000 assets | Not listed | Premium support plus implementation up to 90 days and monthly customer success. AWS also lists 24/7 break-fix support for standard purchases |
The two sources agree on the rate and disagree on the minimum. Divide the AWS packs by 500 and you get $50, $65 and $85 per asset, the same numbers printed on the government sheets. The difference is the smallest amount you can buy: 500 assets on AWS, 100 through the reseller sheets. For Core, that is $25,000 against $5,000.
Four conditions sit on top of these numbers:
- The government sheet is a reseller's price for UK public-sector buyers. It says "Cost is subject to full scoping" and "GBP costs available on request." A second sheet lists the same rates as an "Annual List Price" and sets a 500-asset minimum for managed service providers.
- AWS says "All fees are non-cancellable and non-refundable except as required by law." It also offers 24 and 36-month terms, with no prices shown for those, and notes that extra AWS infrastructure costs may apply.
- Flex is unclear. AWS describes it as one-time but shows it under a 12-month contract. Ask how long you can test and how many times.
- The WebApp listing has no app quantity. The AWS-linked licence terms count each unique fully qualified domain name as one licensed web app unless otherwise agreed in writing. Until a written quote says how many applications $10,000 covers, your web app total is unknown, not $10,000.
AWS also lists upgrades, and the sums check out: Core to Pro is $7,500 ($25,000 + $7,500 = $32,500), Core to Elite is $17,500, and Pro to Elite is $10,000.
What your asset count works out to
At the reseller sheet's list rate, bought in blocks of 100:
| Assets | Core at $50 | Pro at $65 | Elite at $85 |
|---|---|---|---|
| 100 | $5,000 | $6,500 | $8,500 |
| 300 | $15,000 | $19,500 | $25,500 |
| 500 | $25,000 | $32,500 | $42,500 |
| 1,000 | $50,000 | $65,000 | $85,000 |
These are list-price sums for 12 months. Support upgrades and the WebApp add-on are extra. Your quote can be higher or lower.
Runs in the browser. Nothing is saved or sent.
NodeZero list-price estimator
Estimate the published 12-month list price from an asset count, package and purchase channel. This is not a quote.
To see the current figures yourself:
See NodeZero's published AWS prices
See what each NodeZero package includes
For how this compares with paying a firm per test, see our penetration testing cost page.
What counts as an asset, and what happens if you go over?
Under the G-Cloud reseller sheets, an asset is a networked entity with an IP address discovered during testing, and you cannot start new tests or use 1-Click Verify after exceeding the current 200% licence threshold. That comes from the G-Cloud price sheets, which spell out the licence rules in plain terms. They are a reseller's terms for UK public-sector buyers, so treat each one as a question to ask about your own contract.
| Rule | What the price sheet says | What it means for you |
|---|---|---|
| What counts | Servers, laptops, desktops, mobile devices, virtual machines, printers, IoT devices, public static IPs, serverless functions and Kubernetes pods | You pay for what the scan finds, not the servers you care about. Scan a whole office network and the printers count |
| Going over | You can keep testing up to 200% of your licence, "currently." Past that, no new pentests and no 1-click verify. Horizon3 reserves the right to lower the cap, down to 100% | Under this reseller rule, a 500-asset licence cannot run new tests or 1-Click Verify at 1,001 counted assets. That threshold could drop to 501 |
| True-up | When you reach your contracted amount you must buy more, pro-rated by the days left in your term | Adding 100 Core assets with 146 days left: 100 × $50 × 146 ÷ 365 = $2,000 |
| No way down | You cannot reduce assets mid-term, and unused assets do not roll over | Buy for the network you have, not the one you plan to have |
Two rules work in your favor. Assets not scanned for 12 months stop counting. And extra assets bought mid-term cost the rate you first negotiated.
Think of it like a phone plan with a hard data cap. You pick a size up front. You can go bigger mid-contract, but not smaller.
Which NodeZero package fits you?
NodeZero fits a company that wants to test its own network, Active Directory and cloud often, has a few hundred assets or more, and has one person who can run it and fix what it finds. It is a poor first purchase if your whole need is one web app with custom logic, a report signed by a named human tester, or a network well under 100 devices.
There are four ways to buy NodeZero testing. They are not the same product.
| Route | What you get | Who does the testing | Published price |
|---|---|---|---|
| Core, Pro or Elite subscription | The platform for 12 months. You start tests when you want | The software, on your command | $50, $65 or $85 per asset |
| Flex | A one-time test with the same test types. No scheduling | The software, on your command | $15,000 for 1,000 assets on AWS |
| Horizon3's PCI pentesting service | A Penetration Test Report, a Fix Action Report and 12 months of dashboard access | Horizon3 says its OSCP-certified testers | Not published |
| A testing firm that uses NodeZero | A firm's own engagement, with NodeZero as one of its tools | The firm's testers | Set by the firm |
On that last route: NCC Group said in March 2025 that NodeZero "enables our experts to deliver autonomous and hybrid penetration tests" (NCC Group). So "NodeZero" on a proposal can mean a person is involved or not. Ask which.
Here is how the choice plays out for three made-up buyers. We check each need against what Horizon3 has published and mark it Supported, Mismatch or Unresolved.
Say you run IT for a 420-device manufacturer and want to test the internal network every quarter. Nobody outside the company reads the report.
| What you need | Finding | Why |
|---|---|---|
| Internal network and Active Directory testing | Supported | Listed in every package |
| Tests on a schedule through the year | Supported on Core and up. Mismatch on Flex | Scheduling starts at Core |
| A price before the sales call | Supported, at list | 420 assets bill as 500: $25,000 for Core on either channel |
Result: Core. Pro adds detection and response tools. Elite also adds Advanced Data Pilfering, which can use discovered credentials for lateral movement and privilege escalation in an internal test. Skip those tiers unless you need those capabilities. Before you sign, ask whether the 200% cap is written into your order.
Say you run a 30-person software company with one web app and a GraphQL checkout. A customer wants a pentest report.
| What you need | Finding | Why |
|---|---|---|
| Testing for injection flaws and broken access control | Supported | Listed in Horizon3's WebApp documentation |
| Testing of GraphQL depth and batching abuse | Mismatch | The documentation lists these as not covered |
| Testing of custom checkout and refund logic | Mismatch | "General business-logic flaw coverage is not currently included" |
| A sensible minimum | Mismatch | A few dozen assets against a 100 or 500-asset minimum |
Result: not NodeZero as your first purchase. You need a web application test where a person commits in writing to those checkout flows. NodeZero could be a useful second layer later.
If that sounds like you, write the scope down before you ask anyone for a price. Our free tool asks a few questions and gives you a scope checklist to copy or print and send to the firms you choose. No email, no sign-up, and nothing is sent to providers.
Say you run security for a retailer that takes card payments. Your assessor is due in four months.
| What you need | Finding | Why |
|---|---|---|
| An internal and external test of the card data environment | Supported for Horizon3's PCI service | Its page says scope is set "from an internal and external perspective" |
| Human-led testing, if your assessor asks for it | Supported for the PCI service, by Horizon3's own statement. Unresolved for the self-run platform | The service page says Horizon3 testers conduct the test |
| Segmentation and application-layer coverage | Unresolved | The service page does not mention either |
| Price | Unresolved | Not published |
Result: the PCI service, on one condition. Ask Horizon3: "Does the PCI service cover segmentation checks and application-layer testing, and who signs the report?" If the answer is no, you need another firm for those parts.
See Horizon3's PCI pentesting service
Already have a test? If a pentest came with your compliance platform, or your current firm's report already satisfies the person asking, you may not need to buy anything. Ask that person first.
What does NodeZero penetration testing cover?
Every package lists internal, external, cloud and Kubernetes pentesting, an Active Directory audit, phishing impact testing, reports and fix checks. Web application testing is a separate paid add-on with its own limits. This is from Horizon3's packaging page, read October 10, 2026.
"Autonomous" means the software picks and chains the attacks itself once you start it, with no person steering. That is different from a vulnerability scan, which lists possible weaknesses without proving anyone can use them. We explain the gap in penetration testing vs vulnerability scanning.
What each step up adds:
| Package | Adds |
|---|---|
| Flex | The core test types, run as a one-time ("episodic") test |
| Core | Scheduling and Threat Informed Perspectives |
| Pro | Tripwires (decoy credentials that alert you) and Rapid Response (alerts on new threats) |
| Elite | Insights, High-Value Targeting, Advanced Data Pilfering and Threat Actor Intelligence |
To run internal tests you host a small Linux virtual machine with 40GB of storage and outbound HTTPS access, according to a reseller's G-Cloud listing.
Does NodeZero test web apps?
Yes, through the WebApp add-on, but Horizon3's own documentation lists several things it does not test yet. This matters because the marketing page says NodeZero will "test logged-in workflows and business logic," while the documentation is narrower: it covers role-based checks and says "General business-logic flaw coverage is not currently included."
| Covered, per the documentation | Not covered yet, per the documentation |
|---|---|
| Cross-site scripting (reflected, stored, DOM-based) | Race conditions and TOCTOU |
| SQL injection | Deserialization |
| Server-side request forgery (SSRF) | File upload leading to remote code execution |
| Broken access control, including IDOR and BOLA | GraphQL depth and batching issues |
| Role testing with two or more logins | Business-logic flaws beyond role and authorization checks |
| OS command injection, template injection, XXE, open redirects | Apps that depend heavily on WebSockets, WebAssembly or WebGL |
| Detection of known CVEs | Client-side template injection, arbitrary file writes |
The documentation says GraphQL endpoints can still get standard injection and authentication-bypass checks, and that coverage is expected to grow. So recheck this list before you buy.
The add-on comes in two forms. WebApp Flex is a one-time test and can be added to any package. WebApp Continuous is "unlimited testing of each licensed app" and needs Core, Pro or Elite. If your app has custom money-moving logic, compare web application penetration testing services run by people.
Will an auditor accept a NodeZero pentest?
That is your auditor's call, not Horizon3's and not ours, so ask before you buy. One clue is worth knowing. For PCI DSS, Horizon3 does not point buyers at the self-run platform alone. It sells a separate PCI pentesting service that it says is delivered by its own OSCP-certified testers.
Send this to whoever will read the report:
"Will you accept a report from an autonomous testing platform that we ran ourselves, or do you need a report from a named tester? Which dates, scope details and retest evidence must it show?"
- "The platform report is fine." Core or Flex can work.
- "We need a named tester." Look at Horizon3's PCI service, a testing firm, or a different provider.
- "Not sure." Send them a sample NodeZero report before you sign anything.
Horizon3 says the PCI service delivers a Penetration Test Report and a Fix Action Report, plus 12 months of dashboard access. Its page does not give a price, name who signs the report, or mention segmentation or application-layer testing. We have not checked the testers' certifications with the issuer. For what the standards themselves say, see our PCI penetration testing and SOC 2 penetration testing pages.
Does NodeZero include a retest?
It includes a fix check called 1-Click Verify, but only for some findings. Horizon3's documentation says it "is available only on results from Internal, Phishing, and Insider Threat tests." Weaknesses that need "complex chains involving multiple hosts and credentials" are not eligible.
Three things follow:
- External test findings are not on that list. To check an external fix, plan to run the test again.
- WebApp findings are checked by "re-running the relevant WebApp pentest," per the WebApp documentation. On WebApp Flex, ask whether that second run costs extra.
- A clean result is limited proof. In Horizon3's words, "the only definitive statement we can make is that NodeZero did not rediscover the weakness."
This is the software rechecking its own finding. It is not a person retesting and signing off. If your auditor wants the second kind, say so in the question above. Our penetration testing report page lists what readers usually look for.
Does NodeZero replace a manual pentest?
For frequent checks of your own network, it can do work a once-a-year manual test cannot. For custom application logic, or a reader who wants a person's judgment, it does not.
Keep NodeZero for:
- Testing the internal network and Active Directory many times a year
- Proving which weaknesses can really be used, with the attack path shown
- Rechecking fixes on internal findings without waiting for a consultant
Keep a person for:
- Custom business logic in an application
- Anything on the WebApp not-covered list above
- A signed opinion from a named tester
Horizon3's reseller listing says NodeZero "executes 50x faster than a qualified human penetration tester." That is the vendor's claim. We have not tested it, and speed is not the same as coverage.
Many buyers end up with both: a platform for routine network checks and a person for the application. That is a fair outcome if the budget allows it.
Can you try NodeZero before you buy?
Yes. Horizon3's documentation describes a 30-day free trial for a verified company email address. You can only verify a company email once, group addresses are not accepted, and when the trial ends the account goes back to read-only, where you cannot run pentests or verify fixes (Horizon3 docs). A UK reseller's listing describes a shorter "proof of value" that typically runs one to two weeks.
A trial can help you check what assets NodeZero discovers, but the terms linked from AWS limit evaluation to internal, non-production and non-commercial use. It will not tell you whether your auditor accepts the report.
What do NodeZero buyers say?
Public reviews are mixed on price. One G2 reviewer whose comment appears on AWS Marketplace wrote in July 2026, "Pricing seems very reasonable for what you get, and what it gives back to you is very valuable." A PeerSpot reviewer wrote, "The pricing of The NodeZero Platform by Horizon3.ai is too much for what it yields."
These are single buyers describing their own purchase. We did not verify their contracts. The useful takeaway is the pattern: whether the price feels fair depends on how many assets you have and how often you test.
What to ask Horizon3 before you sign
Public prices are a starting point. These nine answers, in writing, turn them into a number you can trust.
Subject: NodeZero proposal: assets, WebApp, retesting and total cost
- 1. Which systems count as assets under my licence, and do excluded IP ranges count?
- 2. Is the 200% cap written into my order, and can it change mid-term?
- 3. What is the smallest true-up I would have to buy if I go over?
- 4. On Flex, how long can I test and how many times?
- 5. For WebApp, is it Flex or Continuous, how many applications are covered, and is the price on top of my package?
- 6. Which of my findings can 1-Click Verify recheck, and what does a WebApp re-run cost?
- 7. Does a person review or sign any report, and can I see a sample report?
- 8. What is my total for the term, when is each payment due, and what are the renewal and cancellation terms?
- 9. How long from signing to a first finished test?
Holding a quote already? Our Quote Check page shows how to line it up against a second offer.
Frequently asked questions
Who makes NodeZero?
Horizon3, which also appears as Horizon3.ai on AWS Marketplace and in older material. NodeZero is its main product.
Is NodeZero the same as NodeZero Linux?
No. NodeZero Linux was an older Ubuntu-based toolkit for penetration testers. It is unrelated to Horizon3's platform.
Is NodeZero safe to run in production?
A reseller listing describes it as "designed to run in live systems." Any pentest carries some risk. Agree the scope, the time window and who to call if something breaks before the first test.
Does buying NodeZero give me permission to test anything?
No. You may only test systems you own or have written permission to test. That includes systems hosted by someone else. A scope checklist from us is a planning aid, not permission.
Sources and check dates
All sources were read on October 10, 2026. We read published pages and price sheets. We did not buy or run NodeZero, and nobody paid to be on this page. Our method is on the methodology page.
- Horizon3.ai NodeZero Platform, AWS Marketplace: pack prices, upgrades, refund line, contract terms
- G-Cloud 15 pricing document, January 28, 2026: per-asset rates, minimum, asset rules
- G-Cloud 15 pricing document, January 27, 2026: annual list price, reseller and managed-service minimums
- G-Cloud 15 service listing: setup needs, proof of value, vendor claims
- Horizon3 NodeZero Packaging: packages and add-ons
- Horizon3 terms linked from AWS Marketplace: asset definition, WebApp licence unit, evaluation-use restrictions; confirm governing version before a purchase
- Horizon3 docs, Advanced Data Pilfering: Elite testing capability
- Horizon3 NodeZero WebApp: marketing description
- Horizon3 docs, What NodeZero Tests: WebApp coverage and gaps
- Horizon3 docs, Findings and Results: WebApp fix checks
- Horizon3 docs, Run 1-Click Verify: which findings can be rechecked
- Horizon3 docs, Upgrade to Free Trial: trial terms
- Horizon3 Pentesting Services for Compliance: PCI service
- NCC Group newsroom, March 18, 2025: use of NodeZero in its tests
- AWS Marketplace reviews and PeerSpot: buyer comments