Red teaming vs pentesting: which one you need

By The PenTest Index · Sources checked October 9, 2026

Red teaming vs pentesting comes down to the question you need answered. A pentest (penetration test) looks for as many weaknesses as it can in systems you name. A red team chases one goal to see whether your defenders notice and stop it. If a customer or auditor asked for a test, it's most likely a pentest. Confirm with them.

Four questions below settle which one fits you. After that, we show the same company buying each one, which rules name a red team, and what sellers say each costs.

Which one do you need?

Most companies asking this need a pentest. A red team makes sense once someone is watching for attacks and your last pentest findings are fixed, or when a rule names it.

Find your situation in the left column.

Table columns: Your situation; Route; Why; What would change it.
Your situationRouteWhyWhat would change it
A customer or auditor asked for "a pentest" or "a security test"PentestThey want a list of weaknesses in named systems and proof you fixed themThey say in writing that they want proof you detect attacks
Nobody said what the report must showAsk firstYou can't pick a test until you know what it has to proveTheir written answer
A named rule applies to youRead the ruleA few rules do name a red team. Most name a pentestThe rule's own words. See the table below
No person or service is watching for attacksPentestA red team measures how your defenders respond. With no defenders, there is nothing to measureYou add monitoring
Someone is watching, but old findings are still openPentest first, or a purple teamA red team will mostly walk through holes you already know aboutThe fixes land
Someone is watching, findings are fixed, and leadership asks "would we catch it?"Red teamThat is the question a red team is built to answerYou can't name a goal or free up people to act on the result

Not sure whether anyone is watching? Ask this: if a laptop were taken over at 2 a.m., who gets the alert and what do they do? If the answer is "no one," treat it as a no.

Route Check

Choose one answer in each group.

Who asked for this?
What do they need to receive?
Is a person or service watching for attacks today?
Have you had a pentest in the last 18 months and fixed what it found?

If your route is a pentest, the next job is writing down what needs testing so every provider prices the same work. Find My PenTest Match walks you through it and gives you a scope checklist to copy or print. It's free, with no email or sign-up.

If your route is a red team, skip that tool. It covers web app and API testing. Go to what to specify before asking for quotes.

Red teaming vs pentesting: what's the difference, side by side?

A pentest goes wide across the systems you name. A red team goes deep toward one goal, usually without telling your defenders.

Both use real attack techniques. What changes is what you ask for and what you get back.

Table columns: Comparison point; Pentest; Red team.
Comparison pointPentestRed team
The questionWhat weaknesses can be found in these systems?Could an attacker reach this goal, and would we notice?
What you name in the scopeApps, APIs, user roles, networks, and what's off-limitsA goal, where the attackers start, what's off-limits, and when to stop
Who knows it's happeningUsually your IT and security peopleUsually a small group only. Decide this on purpose
What you get backFindings you can reproduce, how serious each is, how to fix itThe story of the attack, what was noticed and when, where detection failed
What it does not tell youWhether anyone would notice a real attackEvery weakness in every app and API
The follow-up to priceA retest of your fixesA replay of the attack after you change your defenses
Who usually asks for itCustomers, auditors, card-payment rulesLeadership, boards, some financial and government rules

Two cautions about the labels.

First, the methods overlap. NIST's testing guide says a penetration test can also help determine "defenders' ability to detect attacks and respond appropriately" (NIST SP 800-115, section 5.2, read October 9, 2026). So a service name alone doesn't tell you what work is in the box. Read the scope.

Second, "red team" is not a bigger pentest. The U.S. government's security glossary defines a red team as a group authorized to copy a possible adversary's attack, with the aim of showing the impact of a successful attack and "what works for the defenders" (CNSSI 4009-2022, via the NIST glossary, read October 9, 2026). The subject of the test is your defense, not your app.

This page is about buying a test. For training and careers, see the certification bodies.

What would each one look like at the same company?

Same company, two different jobs. This example is made up. Nobody quoted for it.

Say you run a 60-person software company. You have one customer app, its API, two user roles, and an outside service that watches your systems for attacks.

Brief A, the pentest. A customer asked for a third-party test before they renew.

Find and document weaknesses in our app and API, tested as both user roles, including whether one customer can reach another's data. Give us findings we can reproduce, how serious each is, and how to fix it. State what you did not test. State the report date and the terms for checking our fixes.

Brief B, the red team. The board asked whether you'd catch a break-in.

Starting from a normal employee laptop account that we supply, try to reach a set of fake customer records we have planted. Tell us how far you got, what stopped you, and what help we gave you. Line up your actions, with times, against what our monitoring service saw and did. Agree the report, a debrief, and a replay after we make changes.

Now two made-up proposals come back. We check each against each brief the same way we check real offers: one requirement at a time, against the written words.

Table columns: What the brief requires; Proposal P; Proposal R.
What the brief requiresProposal PProposal R
A: the app and API, both roles, customer-to-customer checksSupported. Named in the scopeMismatch. Says it will not cover every function and role
A: findings you can reproduce, with fixesSupportedSupported only for what the team happens to run into
B: supplied starting account and an agreed goalMismatch. ExcludedSupported
B: attacker timeline matched to what defenders sawMismatch. ExcludedSupported
A and B: full price, report date, follow-up termsUnresolved. Not statedUnresolved. Not stated

Where that leaves this company. Proposal P is the one to pursue for the customer's request. Proposal R is the one to pursue for the board's question. Neither is ready to sign, because price, dates and follow-up are still blank. And R's attack story, however good, does not make up for the app coverage it left out. A must-have that is missing rules the proposal out for that job.

If you need both answers, ask for both sets of work and how the days are split. One report title won't cover two jobs.

"Supported" here means the written scope supports that one line. It is not a grade for the provider. Silence is "unresolved," never a yes. More on the method: how our Purchase Check works.

Why does the starting point matter?

Because access you hand over proves nothing about the defenses it skipped.

A real case shows it. In an advisory released August 25, 2026, the U.S. cyber agency CISA described red team tests at two organizations. At the first, the team moved through the network undetected. At the second, defenders "quickly detected the initial compromise and quarantined the affected systems." The test then continued only because trusted staff gave the red team access to a machine, and defenders caught the later activity too (CISA AA26-237A, read October 9, 2026).

Our takeaway: a good red team report separates access the team earned from access it was given, and it records what your defenders got right. "They reached the target" is half a result.

Can a red-team report replace the pentest we were asked for?

Don't swap one for the other based on the title. Compare the work that was done with what the requester needs.

Send the person who asked this question:

"Will a goal-based red team test meet your requirement, or do you need a penetration test that covers specific systems? Please confirm the systems, the report contents, and any proof of fixes you expect."

Their answer decides it. A provider's package name does not.

Do compliance rules require a red team or a pentest?

Most everyday requests name a penetration test. A few rules name a red team, for specific kinds of organizations. Whoever receives your report decides what they accept.

Here is what we could confirm from the rules' own text on October 9, 2026.

Table columns: Rule; What its text names; Who it applies to.
RuleWhat its text namesWho it applies to
PCI DSS v4.0.1, Requirement 11.4 (card payments)Penetration testing. The heading reads: "External and internal penetration testing is regularly performed, and exploitable vulnerabilities and security weaknesses are corrected." Requirement 11.4.1 calls for a defined testing method that includes testing from inside and outside the network, at the application layer and the network layerEntities that store, process or transmit cardholder data or sensitive authentication data, or can impact the security of the cardholder data environment. Payment brands, acquirers and other compliance-program owners determine who must comply and how compliance is validated
NIST SP 800-53 Rev. 5, control CA-8 (U.S. federal systems)Both, as separate items. CA-8 is "Penetration Testing." Its add-on CA-8(2) is "Red Team Exercises," and says they "extend the objectives of penetration testing by examining the security and privacy posture of organizations and the capability to implement effective cyber defenses"Depends on which controls your program selects. If you sell cloud services to U.S. agencies, ask your assessor whether the red team add-on applies to you
EU DORA, Article 26 (financial firms)Threat-led penetration testing. The law defines it as a framework that mimics real-life threat actors' tactics, techniques and procedures and delivers a "controlled, bespoke, intelligence-led (red team) test of the financial entity's critical live production systems." Firms picked for it "shall carry out at least every 3 years advanced testing" of this kind, although the competent authority may reduce or increase that frequency based on risk and operational circumstancesOnly financial firms their regulator identifies. Microenterprises and the entities referred to in Article 16(1), first subparagraph, are excluded
SOC 2We have not read the criteria for this pageAsk your auditor: "Do you expect a penetration test this period, and of what?"
A customer contract or questionnaireWhatever its words sayYou. Ask the customer if the wording is vague

Sources: PCI SSC document library for the official PCI DSS, which we read in a university-hosted copy because the official file sits behind a form; NIST SP 800-53 Rev. 5, control CA-8; Regulation (EU) 2022/2554, Articles 3(17) and 26. None of these bodies endorses this site.

Notice what NIST does there. The control catalog that U.S. federal programs draw on lists the two as different things, with the red team as an extension. That is the cleanest evidence we found that one does not stand in for the other.

For more on what auditors and customers ask for, see what the person asking actually requires.

Is red teaming more expensive than a pentest?

By the sellers' own numbers, yes, mostly because it takes senior people more days. But few providers publish a red team price, so every range you see is one seller's claim. We found no neutral market average and won't make one up.

Here is what named sources publish, in their own units.

Table columns: Source; What it says; What kind of number it is.
SourceWhat it saysWhat kind of number it is
TrustedSec, a testing firmRed team for a 100 to 1,000 person company: $40,000 to $80,000, and $100,000 or more for advanced work. Pentest: $10,000 to $30,000TrustedSec's own estimate, which it dates to "market data as of Q1 2025." Not a quote
CovertSwarm, a testing firmOne-off engagement, pentest or red team: "From £1,725/$2,395 PER DAY"A published starting day rate. The same page's description says $2,300, so ask which applies. A day rate is not a total
Pentest-Tools.com (from our index)One web app, no sign-in, human testers: $3,400 per testA published fixed price for that scope
Astra (from our index)Pentest Expert: $5,999 per year for one targetA published yearly plan, not a single test

Sources: TrustedSec and CovertSwarm, read October 9, 2026. Pentest-Tools.com and Astra prices are from our comparison, provider pages checked October 7 and 8, 2026. All in US dollars unless shown.

Three things to take from it.

The pentest numbers don't agree with each other. TrustedSec puts a pentest at $10,000 and up. Two providers on our index publish human-led web app tests for less than that. The difference is scope, not a bargain. A three-day test of one app is a smaller job than a network-wide test.

A day rate needs a day count. At CovertSwarm's published starting rate, 10 days would be 10 × $2,395 = $23,950 and 30 days would be 30 × $2,395 = $71,850. Those sums are ours, for illustration. They are not quotes, and "from" means your rate may be higher. Ask every provider how many tester-days are in the price.

Don't rank the two by price. They are different purchases. A cheap red team with no defenders to test is money spent on the wrong question.

For pentest budgets, see penetration testing cost.

How long does each take?

A pentest usually runs days to a few weeks. For red teams, sellers' estimates run from two weeks to six months, and they don't agree.

Table columns: Source; Pentest; Red team.
SourcePentestRed team
Mitnick Security (post dated August 20, 2026)2 to 3 weeks3 weeks to several months
OffSec (post dated September 18, 2025)1 to 3 weeks2 to 6 months
TrustedSec1 to 2 weeks2 to 8 weeks

Sources: Mitnick Security, OffSec, TrustedSec, checked October 9, 2026. Each is that company's own statement.

The spread tells you the label doesn't set the length. The goal and the scope do. Ask for the start date, the days of active work, and the final report date as three separate things, in writing.

What should you specify before asking for quotes?

Give every provider the same goal, limits, evidence and deadline. Then their answers line up and you can see the real differences.

Copy this and fill it in. Where you don't know, leave the question in. Don't guess.

Assessment buying brief

  1. The decision this test must help us make: [for example: renew a customer contract, or learn whether we would catch a break-in]
  2. What we think we need: [pentest / red team / purple team / please recommend, with reasons]
  3. Coverage or goal: [apps, APIs, user roles and networks to cover, or the one goal to reach and what counts as reaching it]
  4. Where testing happens: [production, staging, which sites, and anything owned by a third party]
  5. Starting access: [none / test accounts / a supplied employee account / documents / source code. List each]
  6. Who will know: [who is told, who is not, and who can pause and restart the test]
  7. Off-limits: [systems, hours, and activities that need separate approval, such as phishing staff or entering a building]
  8. Evidence we need back: [for a pentest: what was and wasn't tested, reproducible findings, fixes. For a red team: a timed record of actions, how far the team got, help we supplied, and what our defenders saw]
  9. Who reads the report, and by when: [name, their written requirements, date]
  10. Full price and commitment: [what's included, what's extra, any minimum term or platform fee, tester-days in the price]
  11. Follow-up: [what gets checked again, how many times, the fee, the window, what starts the clock, and what updated report we get]
  12. What we already have: [any current provider, bundled test or recent report, and the gap it leaves]

Please send back: your proposed scope, exclusions, assumptions, deliverables, dates, total commitment, and any requirement you cannot meet.

This brief does not give anyone permission to test. Before work starts, you need a signed agreement that covers the exact targets and activities. Have your legal owner review anything that touches staff, buildings or systems owned by someone else.

Already holding a quote? Check a penetration testing quote against the same lines. For a full pentest scope, see how to write a penetration testing scope.

What do real providers publish about red team services?

Enough to tell the two services apart. Not enough to price one. Neither service page below publishes a red team price or length, so both need a written quote.

We picked these two because each publishes separate pages for penetration testing and red teaming, which makes the difference easy to inspect. They are examples, listed A to Z, not a ranking or a full market list. We checked their public pages on October 9, 2026. We did not buy or run either service.

This site may contain affiliate or referral links. If you buy through one, we may be compensated. How we make money

Table columns: Provider; What its red team page says; What its pentest page says; Still to confirm.
ProviderWhat its red team page saysWhat its pentest page saysStill to confirm
Mandiant (Google Cloud)Goals are "tailored" to your risks, and the test assesses your "security team's detection and response capabilities in real-time"Lists "technical documentation to recreate our findings" and test types by system: network, web app, cloud, and othersPrice, length, starting access, what defender evidence you get, replay terms
NetSPILists three approaches: assumed breach, black box, and threat intelligence-ledLists manually validated findings, reports and remediation testingPrice, length, which approach fits your goal, retest and replay terms

"Assumed breach" means the test starts from access you supply, as in Brief B above. "Black box" means the team starts with nothing.

Already know your route? Read the matching page and send that provider your brief.

Mandiant Red Team Assessment

Mandiant penetration testing

NetSPI Red Team Operations

NetSPI penetration testing as a service

For web app and API pentests with published prices, compare published offers.

Is your organization ready for a red team?

You're ready when you have a goal worth testing, someone who will see the attack, and time to act on what you learn. Company size isn't the test.

What if we don't have a security operations team?

You don't need a department with that name. You need someone who would see an alert and do something about it. An outside monitoring service counts.

If no one fills that role, a red team will tell you what you already know: nobody noticed. Spend the money on a pentest and on getting monitoring in place first. That is our advice, not a rule any provider or standard sets.

Should our security team be told?

Decide based on what you want to learn. Keeping defenders in the dark tests how they respond on a normal day. Telling them turns the exercise into practice.

Either way, a small group must know, with the power to pause the test. "Nobody knows" and "anything goes" are not how a safe test runs. NIST's control text says red team exercises run "in accordance with applicable rules of engagement," meaning written rules agreed before anyone starts.

What is purple teaming?

It is the same attack techniques done in the open, with attackers and defenders working side by side. The attackers run a technique, the defenders check whether they saw it, and they tune the alerts on the spot.

It fits when you have monitoring but aren't sure it works, or when a past test showed gaps you haven't closed. You learn faster, and nobody is surprised.

Common questions

Can a small business benefit from red teaming?

Rarely as a first step. A small company usually gets more from a pentest of the systems it runs, plus someone watching for attacks. Once both are in place, a short red team with one goal can be worth it.

Should we do a pentest before a red team?

In most cases, yes. A pentest clears out the weaknesses you could have found cheaply. Then a red team can spend its days testing your defenders, not walking through open doors.

Is this the same as AI red teaming?

No. AI red teaming tests an AI model or feature to see if it can be pushed into leaking data or misbehaving. This page is about testing a company's defenses. If you need an AI feature in your product tested, see the AI row in which type of test you need.

How we checked this

We read the standards and the law, and checked each company page named above, on October 9, 2026, and recorded what they say with their limits. Seller figures are shown as that seller's claim. The company, briefs and proposals in the worked example are made up, and we say so where they appear.

We did not buy, run or watch any test, and we did not inspect sample reports for this page. The PenTest Index does not sell testing, perform it or authorize it. See our method and how we make money.

Sources

Standards, law and official pages, read October 9, 2026:

Company pages, checked October 9, 2026. Each is the company's own statement:

Index prices: our comparison, provider pages checked October 7 and 8, 2026.