THE PENTEST INDEX — PENETRATION TESTING MARKET DATA PACK
Checked: October 9, 2026 (UTC)
Planned page: https://thepentestindex.com/research/penetration-testing-market/

WHAT THIS IS

This pack records what publishers and other primary sources reported at the audit date.
The market figures are published estimates, not a measured total of market sales.
The PenTest Index's contribution is the compilation, source checks, classifications,
flags, calculations and charts. Figures from different publishers may count different
things. A source-read status verifies the source statement, not the publisher's model.

The main tracker contains 78 listed entries. Use only the 38 rows marked yes in
used_for_2025_median for the headline. Their median is $2.52 billion. Twenty-five
fall between $2 billion and $3 billion, inclusive. Seven accepted rows are flagged;
removing them leaves 31 and a $2.50 billion median. Seventeen accepted 2026 values
have a $2.91 billion median. The union of both years contains 40 entries.

These files are publication assets. The research URL and its download URLs were not
live during this editing task. The Markdown includes the required build specifications.

FILES

penetration-testing-market.md
  Complete page: YAML metadata, article, source list, non-publishing notes, BUILD SPEC,
  all three CHART SPEC blocks, and a DATASET block identical to the main CSV.
  Present in the complete page ZIP; the data-only ZIP does not contain the article.

penetration-testing-market-estimates.csv
  78 report entries, including accepted, excluded and unavailable sources.
penetration-testing-market-older-editions.csv
  Nine rows: seven edition comparisons, one same-period SNS conflict, and the current
  MarketsandMarkets chart baseline. The baseline is not an eighth comparison.
ptaas-market-estimates.csv
  12 entries, of which 11 were readable; one is an older edition. Unavailable QYResearch
  figures are withheld. Never add PTaaS estimates to whole-market totals.
penetration-testing-funding-rounds.csv
  16 announcements of at least $40 million, with explicit amount and grouping bases.
penetration-testing-rules.csv
  15 rule/standard entries, including different parts of the same framework. This is
  a text comparison, not legal advice or a finding that every rule applies to everyone.
penetration-testing-related-shares.csv
  Six 2025 slices on three publisher pages, with each page's total for the dollar check.
penetration-testing-supporting-data.csv
  39 numeric rows: UK survey percentages and samples, NCC revenue/comparators,
  NetSPI/Synack's revenue floor, Gartner's dated forecast, Pentera's survey and BLS data.
penetration-testing-market-classifications.csv
  One row for each of the 38 retained 2025 pages. Records leader statements, years,
  eligibility flags, qualifiers, source links and audit extraction locators.
reproduce_calculations.py
  Standalone standard-library Python script. Reads all eight CSVs and writes the
  full calculation-results.json beside it, including exact values and memberships.
render_charts.py
  Reads the final CSV files beside it and recreates the three PNG charts.
calculation-results.json
  Output of the included calculation script, with CSV SHA-256 hashes.
chart-1-penetration-testing-market-estimates-2025.png
chart-2-marketsandmarkets-editions.png
chart-3-uk-pen-test-use-by-size.png
  Charts with printed sources and check dates. Their input values are in the CSVs.

HOW TO REPEAT THE RESULTS

Keep the files together. Use Python 3.11 or later:

  python reproduce_calculations.py

This uses only Python's standard library and does not access the internet. It writes
calculation-results.json. Run it from any directory; inputs are found beside the script.

To recreate the charts, install Matplotlib if needed and run:

  python render_charts.py

The chart script uses the CSVs by default. Its optional --fallback-json argument was
used only during preparation and is not needed for this pack. Scripts reproduce the
dated compilation; they do not update publisher figures or verify future source edits.

Headline: filter used_for_2025_median = yes, sort usd_bn_2025, then average the 19th
and 20th values: (2.50 + 2.54) / 2 = 2.52. Use source precision, not rounded chart labels.
Cells are UTF-8 comma-separated values with standard quote escaping. Blank numeric
cells are unknown, withheld or not applicable; never treat them as zero. Dollar fields
are U.S. dollars; one billion equals 1,000 million. GBP is identified separately.

ROUNDING AND QUALIFIERS

Use decimal arithmetic and round half up only for display. The main table uses two
decimals in billions. The CSV retains greater source precision where available.
Keep 'about', 'approximately', 'nearly', 'over' and 'exceed' with the source value.
Do not round a strict lower bound upward: over $4.35847B is not over $4.36B.

About/approximately/nearly describe estimated point values in this compilation.
Over/exceed/more than are lower bounds. The forecast table excludes those bounds
from point medians. Research Nester's over-16.4% CAGR cannot cross the middle of
the 38-rate list, so the full median remains identified at 14.45%, displayed about 14.5%.
It cannot be counted definitely inside the 13%–17% band. There are 27 definite rates
in that band. The 37 point-rate range is 5%–21.4%.

Forecast groups use the selected main forecast of the 38 headline pages. The broader
six-entry 2030 comparison uses selected main forecasts among the 78 entries, excluding
alternate/conflicting passages. It does not count every occurrence of a 2030 forecast.
For 2035, ten point forecasts have a median of $11.95B; Research Nester's separate
over-$9.63B statement is not an exact input. Six unflagged point forecasts have a
$17.38B median. This is a comparison of forecasts, not a forecast made by this site.

SELECTIONS AND SOURCE CONFLICTS

status_2025 values:
  used: 38 accepted current 2025 estimates.
  set_aside: six readable entries without an acceptable comparable market figure.
  unavailable: three main URLs that could not be retrieved during the audit.
  no_2025_value: 31 entries without an accepted 2025 figure; two supply 2026 values.

Inclusion always follows the explicit used_for_[year]_median flags, not the presence
of a number or the publisher's brand. Main-market numeric cells are withheld for
Cognitive's illustrative figures, unverified reseller sizing, and unavailable pages.
Source notes can describe disputed or alternate figures; these are not accepted values.

The opening size sentence takes priority. When it has no 2025 value, an explicit
year-labelled summary or FAQ may supply one. A table that merely shifts an opening
value from another year to 2025 does not qualify. Readable opening conflicts remain
flagged, with the alternative shown. No value is excluded merely because it is high.

The 11 sensitivity checks remove flagged pages, the lowest, the highest, the top three,
Emergen, or MRFR and Value; substitute Emergen's FAQ figure; keep 2026-dated pages;
hypothetically add GIS's disputed figure; average each verified owner pair; or retain
only the three named benchmark firms. The seven deletion rules used in stacked cuts
are fixed from the full sample before combining them. Combining means taking the
union of excluded IDs. Swaps, additions, owner averaging and the three-firm benchmark
are not deletion rules. Exact memberships are in calculation-results.json.

Owner-pair averaging uses MRFR/WiseGuy and Growth Market Reports/Market Intelo.
Those pairs name the same legal parent within each pair. The similarly named Dataintelo
is not silently added to the second pair without proof of the same legal entity.

REGIONS AND LEADER COUNTS

The strict North America comparison contains 17 dated estimates, median 37.5%,
range 32%–about43%, with 12 of 17 in35%–40%. A year may come from an explicitly
dated regional breakdown, as for Market Intelo. It is not inferred merely from the
page's overall base year. Global Growth Insights' undated 36% is kept in the classification
audit trail but is ineligible and blank in the main dated numeric field. Precedence's
share retains 'nearly 38%'. Fortune's conflicting 35.1%/39.7% is visible.

2025 leader counts filter the Boolean eligibility columns in the classification CSV:
  industry: banking/finance on 8 of 10 clear pages;
  system tested: network/infrastructure on 9 of 12 clear pages;
  component: services on 5 of 6 clear pages, with FMI's conflicting page separate.
2025 projections are included and labelled. Other years and undated leader claims
remain in the data but outside these counts. Asset tested, black/white-box method,
and internal/external scope are different taxonomies and are not merged into one rank.
Across differing forecast periods, 23 pages clearly name Asia Pacific fastest; two
conflict between Asia Pacific and North America. These are counts of source statements.

LOCATORS AND RECHECKING

Source URLs point to live primary documents or clearly identified issuer-release copies.
Some classification locator strings identify line numbers in the audit's extracted text.
They are audit capture locators, not stable line numbers on the live publisher page;
full commercial page captures are not redistributed in this pack. Use source_url,
the group/year fields, the nearby section description and the source value to re-find
the statement. Read the source itself, not a search snippet. Pages can change after the
check date. Failed retrievals establish a limit, not that no report exists anywhere.

FUNDING, REVENUE AND SURVEYS

The $771.5M sum is 8 announcements by 6 editorially grouped companies since January 2025.
Novee's 51.5M is cumulative funding disclosed at launch. Bishop Fox's 129M is a combined
round total including earlier funding. NetSPI's 410M includes a prior investor buyout.
The Armadin amounts 189.9M and 255.5M sum to 445.4M; its issuer rounds cumulative funding
to 445M. Armadin is shown separately as an editorial grouping choice, not because its
products could not overlap with pen testing. Funding is not revenue or a market total.

NCC revenue periods must not be added: its May 2024 and September 2024 annual periods
overlap. Constant-currency changes use restated prior-period comparators in the supporting
CSV. NetSPI/Synack's 'well over $200M' has no stated period and is not an audited
pen-testing-only total. These company figures cannot produce a revenue ranking.

The UK survey percentages are weighted self-reports from August–December 2025.
Sample counts are unweighted. The four business-size samples sum to 2,112. A survey
edition is not the same as a calendar-year measured count. Pentera's 187,000-dollar
budget figure applies to U.S. enterprises with more than 3,000 staff; the 500-person
survey covered four countries. BLS counts a broader occupation than penetration testers.
Gartner's figures are its explicitly dated July 29, 2025 forecast for 2025, not actual sales.

REUSE AND CITATION

Credit The PenTest Index for its calculations, compilation, classifications and charts.
Credit each original publisher for its own estimate and respect the terms for its material.
No hyperlink is required. This note does not license third-party reports or artwork.

Ready-to-copy sentence:
The median of 38 published estimates puts the global penetration testing market at
about $2.52 billion in 2025, according to The PenTest Index (October 9, 2026).

COLUMN DICTIONARY

penetration-testing-funding-rounds.csv (16 rows)
  date
    Announcement date shown by the issuer/transaction participant.
  company
    Company named in the financing announcement.
  group
    Editorial grouping used for the displayed subtotal.
  round
    Issuer financing label; some announcements cover cumulative or combined amounts.
  usd_millions
    Amount disclosed, in US$ millions.
  lead_investors
    Lead investor(s) named in the source.
  source_url
    Primary source or identified issuer-release copy for this row.
  note
    Source qualification or interpretation needed with this value.
  checked_on
    Actual UTC date of source checking, ISO format.
  included_in_771_5_total
    yes/no; explicitly selects the eight announcements in the subtotal.
  amount_basis
    New round, cumulative disclosure, combined round or buyout-containing investment.

penetration-testing-market-classifications.csv (38 rows)
  id
    Stable row key; table ranks are not IDs.
  publisher
    Publisher brand and, where relevant, page or reseller identity.
  source_url
    Primary source or identified issuer-release copy for this row.
  checked_on_utc
    UTC date of the source classification check.
  retained_whole_market_page
    true for these 38 accepted main-market entries.
  source_snapshot
    Audit capture identifier; full commercial captures are not redistributed.
  industry_leader
    Leader stated by the page; not stated/conflicting values are not clear leaders.
  industry_year_or_period
    Year or forecast period explicitly attached to the leader statement.
  industry_source_locator
    Source extraction location; use with the URL and source statement.
  industry_note
    Qualification, conflict or scope detail for this category.
  test_type_leader
    Leader stated by the page; not stated/conflicting values are not clear leaders.
  test_type_year_or_period
    Year or forecast period explicitly attached to the leader statement.
  test_type_source_locator
    Source extraction location; use with the URL and source statement.
  test_type_note
    Qualification, conflict or scope detail for this category.
  component_leader
    Leader stated by the page; not stated/conflicting values are not clear leaders.
  component_year_or_period
    Year or forecast period explicitly attached to the leader statement.
  component_source_locator
    Source extraction location; use with the URL and source statement.
  component_note
    Qualification, conflict or scope detail for this category.
  fastest_region_leader
    Leader stated by the page; not stated/conflicting values are not clear leaders.
  fastest_region_year_or_period
    Year or forecast period explicitly attached to the leader statement.
  fastest_region_source_locator
    Source extraction location; use with the URL and source statement.
  fastest_region_note
    Qualification, conflict or scope detail for this category.
  industry_clear_leader_any_year
    true for a clear leader even if the year is outside the 2025 subset.
  industry_2025_count_eligible
    true only for a clear 2025 leader, including labelled projections.
  industry_2025_exclusion_reason
    Why this statement is outside the clear 2025 leader count.
  test_type_clear_leader_any_year
    true for a clear leader even if the year is outside the 2025 subset.
  test_type_2025_count_eligible
    true only for a clear 2025 leader, including labelled projections.
  test_type_2025_exclusion_reason
    Why this statement is outside the clear 2025 leader count.
  component_clear_leader_any_year
    true for a clear leader even if the year is outside the 2025 subset.
  component_2025_count_eligible
    true only for a clear 2025 leader, including labelled projections.
  component_2025_exclusion_reason
    Why this statement is outside the clear 2025 leader count.
  industry_count_group
    Normalized clear industry label used in the industry count.
  test_type_count_group
    Normalized comparable asset-type label used in the count.
  test_type_taxonomy
    Distinguishes asset tested from box method and internal/external scope.
  services_share_pct
    Printed services share, where supplied; not necessarily count eligible.
  services_share_qualifier
    Exact services-share qualifier.
  software_or_solutions_share_pct
    Printed software/solutions share, where supplied.
  software_or_solutions_share_qualifier
    Exact software/solutions share qualifier.
  fastest_region_clear_count_eligible
    true if one clear fastest-region claim is present.
  fastest_region_conflicted
    true when the page names different fastest regions.
  north_america_share_2025_pct
    Accepted dated share in percent; qualifiers and year basis apply.
  north_america_2025_comparison_eligible
    true only for the strict dated regional subset.
  north_america_share_qualifier
    Publisher wording around the regional percentage.
  north_america_year_basis
    How the share was tied to 2025, or why it was excluded.
  north_america_source_locator
    Locator in the source extraction; see locator limits above.
  north_america_note
    Regional source conflict, year inference or exclusion detail.
  checked_on
    Actual UTC date of source checking, ISO format.

penetration-testing-market-estimates.csv (78 rows)
  id
    Stable row key; table ranks are not IDs.
  publisher
    Publisher brand and, where relevant, page or reseller identity.
  page_url
    URL checked for this entry; redirects may be canonicalized.
  page_type
    Report page, second report, issuer blog or reseller listing.
  status_2025
    used, set_aside, unavailable or no_2025_value; see selection rules.
  usd_bn_2025
    Accepted published 2025 amount, in US$ billions; see qualifier and use flag.
  used_for_2025_median
    yes/no; authoritative flag for headline inclusion.
  usd_bn_2026
    Accepted published 2026 amount, in US$ billions.
  used_for_2026_median
    yes/no; authoritative flag for 2026 inclusion.
  forecast_year
    Selected main forecast end year, including verified no-2025 entries.
  forecast_usd_bn
    Selected forecast amount in US$ billions, subject to its qualifier.
  stated_cagr_pct
    Rate the source states; it is not overwritten with a calculated rate.
  page_date_shown
    Publisher date as printed; not necessarily a number-change date.
  flagged
    yes/no; a recorded reason this page should not be cited on its own.
  says_counts_services_and_software
    Legacy column name: yes means an explicit services and software/solutions split; not stated otherwise. Solutions need not mean software alone.
  north_america_share_2025_pct
    Accepted dated share in percent; qualifiers and year basis apply.
  us_2025_usd_millions
    Accepted U.S. 2025 estimate in millions; not a global value.
  where_2025_figure_sits
    Source location for the accepted 2025 value.
  other_figures_or_reason
    Other dated figures or explanation when no 2025 point qualifies.
  check_before_citing
    Conflicts, scope issues and source cautions.
  checked_on
    Actual UTC date of source checking, ISO format.
  verification_status
    source_read, reseller_only, illustrative or unavailable; source_read does not validate the underlying model.
  usd_bn_2025_qualifier
    Publisher wording around the 2025 value.
  usd_bn_2026_qualifier
    Publisher wording around the 2026 value.
  forecast_qualifier
    Preserve this with the forecast; over/exceed are lower bounds.
  cagr_qualifier
    Preserve this with the stated rate; a floor has no known upper limit.
  north_america_share_qualifier
    Publisher wording around the regional percentage.
  north_america_year_basis
    How the share was tied to 2025, or why it was excluded.
  north_america_source_locator
    Locator in the source extraction; see locator limits above.

penetration-testing-market-older-editions.csv (9 rows)
  publisher
    Publisher brand and, where relevant, page or reseller identity.
  edition_date
    Date of the older issuer release or current baseline edition.
  source_url
    Primary source or identified issuer-release copy for this row.
  start_year
    Year of the published starting figure.
  start_usd_bn
    Published starting figure in US$ billions.
  end_year
    Year of the published endpoint forecast.
  end_usd_bn
    Published endpoint forecast in US$ billions.
  stated_growth_pct
    The older edition’s own stated annual growth rate, in percent.
  same_publisher_now
    Current edition statement or labelled aligned calculation.
  difference_pct
    Rounded comparison recorded in the source table; full computation is in calculation-results.json.
  how_compared
    Year alignment, formula and source-copy qualification.
  checked_on
    Actual UTC date of source checking, ISO format.
  comparison_role
    comparison, same_period_conflict or current_baseline.
  current_source_url
    Current publisher page used in the edition comparison.
  difference_basis
    Meaning and direction of the comparison; negative means current lower.

penetration-testing-related-shares.csv (6 rows)
  slice_2025
    One of six market-share categories as mapped across three pages.
  mordor_intelligence_pct
    Mordor’s printed percentage for this slice.
  market_research_future_pct
    MRFR’s printed percentage for this slice.
  value_market_research_pct
    Value’s printed percentage for this slice.
  mordor_url
    Mordor source URL.
  mrfr_url
    MRFR source URL.
  value_url
    Value source URL.
  checked_on
    Actual UTC date of source checking, ISO format.
  mordor_global_2025_usd_bn
    Mordor’s own total used to turn its share into dollars.
  mrfr_global_2025_usd_bn
    MRFR’s own total used to turn its share into dollars.
  value_global_2025_usd_bn
    Value’s own total used to turn its share into dollars.

penetration-testing-rules.csv (15 rows)
  rule
    Named framework and part compared; multiple rows may share one framework.
  section
    Exact provision, control or standard section read.
  what_the_text_says
    Educational summary of the operative or proposed text.
  how_often
    Cadence, exemptions and scope; read with the other cells.
  status
    Current, proposed, legacy, transition or suspended rollout status.
  source_url
    Primary source or identified issuer-release copy for this row.
  checked_on
    Actual UTC date of source checking, ISO format.
  additional_source_urls
    Further primary texts supporting status, exceptions or frequency.
  scope_note
    Reason or source nuance needed to interpret the row.

penetration-testing-supporting-data.csv (39 rows)
  measure
    What the numeric value measures.
  group_or_period
    Population, company period or comparison period.
  value
    Numeric value in the stated unit; qualifier may make it a lower bound.
  unit
    Percent, respondents, USD, USD/GBP millions, billions, jobs or pay.
  year
    Data year, survey edition or forecast period, not necessarily publication year.
  source
    Name of issuer, official dataset or publication.
  source_url
    Primary source or identified issuer-release copy for this row.
  note
    Source qualification or interpretation needed with this value.
  checked_on
    Actual UTC date of source checking, ISO format.
  qualifier
    Source qualifier for this value.
  source_locator
    Source section or table; see extracted-line locator limits.

ptaas-market-estimates.csv (12 rows)
  publisher
    Publisher brand and, where relevant, page or reseller identity.
  page_date_shown
    Publisher date as printed; not necessarily a number-change date.
  page_url
    URL checked for this entry; redirects may be canonicalized.
  usd_bn_2025
    Accepted published 2025 amount, in US$ billions; see qualifier and use flag.
  usd_bn_2026
    Accepted published 2026 amount, in US$ billions.
  usd_bn_2024
    Published 2024 PTaaS estimate in US$ billions.
  forecast_year
    Selected main forecast end year, including verified no-2025 entries.
  forecast_usd_bn
    Selected forecast amount in US$ billions, subject to its qualifier.
  stated_cagr_pct
    Rate the source states; it is not overwritten with a calculated rate.
  what_it_says_it_counts
    Definition the publisher gives, not a harmonized market definition.
  note
    Source qualification or interpretation needed with this value.
  checked_on
    Actual UTC date of source checking, ISO format.
  verification_status
    source_read, reseller_only, illustrative or unavailable; source_read does not validate the underlying model.
  forecast_qualifier
    Preserve this with the forecast; over/exceed are lower bounds.
