Web application penetration testing services: prices, scope and retest terms compared
By The PenTest Index · Offers checked October 8, 2026 · How we check offers
Web application penetration testing services are paid assessments where testers attack your web app the way an intruder would, then report what they found. Eight providers we checked on October 8, 2026 publish a starting price or price example for testing led by people, from $3,000 to about $12,000. Your user roles, API and retest deadline decide which figure applies.
This site may contain affiliate or referral links. If you buy through one, we may be compensated. How we make money
Below, one example job is priced against each published offer, with the deadline that rules some of them out.
Web application penetration testing services compared by price, scope and retest terms
Most providers describe this service in the same words and show no price. So we took the ones that do publish terms and asked each the same question.
The example job. Say you run a 30-person software company. You have one web app, the API it uses, and three kinds of signed-in user: admin, manager and viewer. Two customer organizations (tenants) share the app, and their data must stay apart. You will not share source code. A customer wants the report. Your developers need about six weeks to fix what the test finds, so you expect to ask for the fix check on day 45, counting from the day the findings and report reach you.
This buyer is made up. No provider has quoted for it. The prices are what each provider's own page showed on October 8, 2026, and the arithmetic is ours.
Table 1. Tests led by people, with a published price (A to Z)
| Offer | Published price and what it covers | For the example job | Fix check (retest) terms | Day-45 fix check |
|---|---|---|---|---|
| Astra · Pentest Expert | $5,999 a year for 1 target. One web or SaaS app with the APIs it uses counts as one target. Includes a manual pentest, autonomous testing and unlimited scans. | $5,999 for the year. Ask whether a separate admin login counts as a second target, and how many roles are covered. | 2 manual re-scans. Request within 30 days of the date the vulnerabilities were reported, after fixing at least half of the Critical and High findings. Extensions are case by case. | Mismatch unless Astra extends in writing |
| Blaze · Essentials | From $7,499. One-off, 1 target, up to 3 roles, business-logic testing included. The page does not define "target". | From $7,499 | 1 fix-validation round, up to 4 hours. Its terms require scheduling within 90 days of the initial report, subject to availability. Extra rounds, time beyond the cap and late requests cost extra. | Unresolved until scheduling is confirmed |
| Blaze · Lite | From $4,999. One-off, 1 target, up to 2 roles, OWASP Top 10 coverage. | Does not cover the third role | Not included. One round is a $799 add-on, subject to the same 4-hour cap and 90-day scheduling terms. | Mismatch on roles |
| Pentest-Tools.com · gray box | Starting from $3,400 plus $900 per user role. 4 or more working days, best effort. | From $6,100 (3,400 + 3 × 900). The API is not mentioned. | Not stated on the priced page. Its services page says a free re-testing phase is included, with no count or window. | Unresolved |
| Prescient · Traditional | Starting at $6,000 in US dollars, before tax. Human-led. Scales with applications, user roles, API endpoints and depth. | From $6,000; the real figure needs a quote | None on the pricing page for this offer. Its services page says "complimentary re-tests" with no count or window. | Unresolved |
| Siemba · Expert Engagement | From $3,000 per app for a small app: up to 3 roles, fewer than 5 APIs, fewer than 20 pages. Billed per project. | From $3,000 if your app is inside all three limits | Free within 60 days of the report on one-time engagements. Number of rounds not stated. | Unresolved; confirm a day-45 request can be retested within 60 days |
| Software Secured · Web & API | Starts at $10,800 USD. Each application is priced separately. Covers signed-in and signed-out paths, business logic and multi-tenant flaws. | From $10,800 | The offer card says 3 rounds over 12 months. The package table on the same page says 1, 3 or unlimited by package. Start of the 12 months not stated. | Unresolved on the clock and package mapping |
| Synack · SynackST | Starts at $10,283 for one test of 1 low-complexity signed-in web app. 1 human tester, 5-day window. The Synack Platform is required and is a separate line item; the page also describes a Basic Platform at no cost. | Total cannot be worked out until Synack says which platform tier applies | "Patch verification" is listed. No count or window. | Unresolved |
| Triaxiom · Web application test | Examples, not a price list: about $12,000 for a small app with one user role; closer to $23,000 with multiple roles and many pages. | Needs a scope-specific quote; the published examples do not price this job. API testing is listed as its own service, so ask. | One retest completed within 90 days of report delivery, free. | Unresolved until completion timing is confirmed |
Each offer name links to the page we read. Astra, Prescient and Software Secured identify US dollars, as does Blaze’s linked shop. The other pages show "$" with no currency code, so confirm the currency, tax and amount due at signing on your quote. "Supported" means the published wording covers that one condition. It is not a verdict on testing quality, and we have not bought or run any of these tests.
What this means for the example job
Three offers deserve a closer look for three roles and a fix check on day 45, with these conditions still to settle:
- Blaze Essentials, from $7,499, if the fix check can be scheduled within 90 days of the initial report and the 4-hour cap covers the work.
- Siemba Expert, from $3,000, only if the app has fewer than 20 pages and fewer than 5 APIs, and the day-45 request can be retested within its 60-day window.
- Software Secured, from $10,800, with the longest window and a Web & API offer that explicitly names multi-tenant flaws; confirm the three-role scope and when the 12 months start.
Triaxiom's retest terms fit too if the retest is completed within 90 days of report delivery, but its price examples do not price this job and the API may be quoted apart. Astra Expert is ruled out by its 30-day request window unless Astra confirms an extension in writing. Pentest-Tools.com, Prescient and Synack each stay open until the retest terms are confirmed; Synack also needs the platform charge confirmed.
Two things would change this. Move the fix-check request to day 25 and it fits Astra’s request window, provided at least half the Critical and High findings are fixed; roles and target scope still need confirmation. Raise the roles to five and Blaze moves to Assurance (from $8,999), Siemba's starting price stops applying, and Pentest-Tools.com starts from $7,900 (3,400 + 5 × 900).
A starting price is not a quote. If one of the three fits your app, go straight to it:
View Siemba Expert Engagements
Price your own scope
Change the example to match your app. Enter counts only.
Enter counts only. Nothing you enter is sent to us.
| Offer | Published starting amount, not a quote | Finding for the fix check | Question to send |
|---|---|---|---|
| Astra · Pentest Expert | $5,999 a year for 1 target. | Mismatch The request day is after the published 30-day window. | Can you include a manual re-scan requested on day 45 after findings are reported, and what does the extension cost? |
| Blaze · Essentials | From $7,499. | Unresolved The MSA requires scheduling within 90 days of the initial report, subject to availability. One round is capped at 4 hours; extra rounds, time beyond the cap and late requests cost extra. Confirm the schedule. | Can you schedule our fix-validation round within 90 days of the initial report, and will the 4-hour cap cover it? |
| Pentest-Tools.com | Gray box, starting from $6,100 ($3,400 + 3 × $900). API not mentioned on the page. | Unresolved Retesting is not stated on the priced page. | Is our API in scope at this price, and how many retests are included, until when? |
| Prescient · Traditional | Starting at $6,000 USD, before tax; scales with roles and API endpoints. | Unresolved Retest terms are not stated on the pricing page for this offer. | How many retests are included in a Traditional engagement, and until when? |
| Siemba · Expert Engagement | Starting at $3,000. | Unresolved Free within 60 days of the report; a request-by deadline is not stated. | How many retest rounds are free within the 60 days? |
| Software Secured · Web & API | Starts at $10,800 USD. | Unresolved 3 rounds over 12 months on the Web & API card; the start date and mapping to the separate 1, 3 or unlimited package counts are not stated. | Which package is the $10,800 price, and how many retest rounds does it include? |
| Synack · SynackST | Starts at $10,283; total incomplete: required platform line item not priced here. | Unresolved Patch verification is listed; no count or window is stated. | Which platform tier does this purchase need, and what is the complete price? |
| Triaxiom · Web application test | Provider examples: about $12,000 (one role) to closer to $23,000 (multiple roles, many pages). | Unresolved One retest must be completed within 90 days of report delivery; confirm completion timing. | Is our API included in the web application test or quoted separately? |
Intruder's AI web app pentest is white-box and starts with connecting your codebase, so it does not fit a no-source-code brief as published.
Quote-only services and the terms they do publish
These offers show no price for a web app test. An unpublished price says nothing about quality. It does mean the terms below are all you can check before a call.
Table 2. Tests led by people, quote only (A to Z)
| Offer | Who tests, in the provider's words | Fix check terms | Other published terms | Ask this |
|---|---|---|---|---|
| Bishop Fox | "Our consultants" | Retesting is a listed deliverable. No count or window. | 1 to 2 weeks of scoping, 1 to 3 weeks of fieldwork, 1 to 2 weeks for reporting | "How many fix checks, and until when?" |
| BreachLock | "In-house" testers | 1, 2 or custom free manual re-tests by package. No window. Its home page says "unlimited retesting" for its platform service. | Responds within 24 hours | "Which retest term goes in my contract?" |
| Bugcrowd · Standard | A vetted crowd of testers | 12 months of retesting with 1 report update | Launch within 3 business days. Publishes a sample web app report. | "What does one report update cover?" |
| Cobalt · Standard, Premium, Enterprise | Its Cobalt Core tester community | Free retest requests for 6, 12 or 12 months by tier, only while your contract is active, and no later than 10 days before it ends | Sold as yearly credits. One credit is "the equivalent of 8 hours" across automation and people. Start within 3, 2 or 1 business days by tier, depending on engagement type. | "How many credits does my app need, and what is the yearly total?" |
| HackerOne · Pentest | Community testers who "are not HackerOne employees" | Its two help pages disagree. See the retest section. | Fixed cost, not published | "Which retest rule applies to my test?" |
| Kroll | "Our in-house team"; "manual, human-directed" | Not stated | Final assessment goes through technical review | "Send one scope, one report date and the retest terms." |
| NetSPI | "Employed, not outsourced" | Not stated on its web app page | Names role-based access checks, API security and business logic | "Count and window, in writing?" |
| Raxis | Senior US-based engineers; "never outsourced" | Fix verified "at no extra cost". No count or window. | 1 to 2 weeks of active testing | "How many rounds, and until when?" |
| Red Sentry | "Human-led testing" | Normally one round of remediation testing within 90 days for findings reported during the engagement | Further rounds are agreed at scoping | "What does a second round cost?" |
| TCM Security | Its own testers, with direct access | "We offer retesting." Not stated as free. No count or window. | Quote within 48 hours after an introductory call; 1 to 2 weeks typical | "Is the retest included in the price?" |
Statements about who does the testing are the providers' own. We did not check employment or credentials with anyone else.
Which web app pentest offers deserve a closer look?
Start with the one requirement that would rule an offer out, then look only at the offers that survive it.
| Your priority | Where to look first | Confirm before you book |
|---|---|---|
| A published price for a small first test | Siemba Expert, Blaze Essentials, Pentest-Tools.com gray box | Your role, API and page counts against each limit; the number of fix checks |
| Fixes will take longer than a month | Software Secured and Bugcrowd (12 months), Cobalt (6 or 12), Blaze, Red Sentry and Triaxiom (90 days) | What starts the clock, and for Cobalt, your contract end date |
| The report reader wants employed testers, not a crowd | Kroll, NetSPI, BreachLock, Raxis, Siemba, Software Secured | Who is assigned to your test. All six claims are company-stated. |
| A fast start through a platform | Cobalt, Bugcrowd | The yearly commitment and which retest rule applies |
| Several customers share your app | Software Secured names multi-tenant flaws on its offer card | Which cross-customer cases will be tested. Ask every other provider the same. |
| You want to read a report before you call | Bugcrowd publishes one; Red Sentry links one from its web app page | Whether it would satisfy the person asking you for a report |
Already have a provider, or a test that came with a compliance platform? Put it through the same three questions: how many roles, is the API in, and when does the fix check expire. If it covers your app and the person asking for the report agrees, you do not need to buy another one.
The offers split on your roles, your API and your fix-check date. Write those down once, and every provider answers the same job. Find My PenTest Match walks you through that for a web app and its API and gives you a scope checklist to copy or print. It is free and asks for no contact details. It does not pick a provider for you.
What should a web application pentest include?
It should cover what an attacker can do without signing in and what a signed-in user can do that they should not. In plain terms:
- Signed-out testing. Everything reachable from the login page and the public site.
- Signed-in testing, per role. What each kind of user can see and change.
- Access control. Whether a viewer can reach a manager's functions, and whether one customer can reach another customer's data.
- Business logic. Misusing a real feature. For example, changing the price in a checkout request, or approving your own refund.
- Input and session handling. Injection, cross-site scripting, and how logins and sessions hold up.
- The API the app talks to.
Many providers name the OWASP Web Security Testing Guide as their method. Its current version, 4.2, includes test categories for authentication, authorization, session management, input validation and business logic. A provider naming the guide tells you the checklist it works from. It does not tell you how much of your app is in the price.
Is the API included, or separate?
It depends on the offer, and the published terms differ. Astra counts the APIs your app uses inside one target. Software Secured sells web and API together. Cobalt says a standard web test covers APIs that serve application content and points deeper API work to a dedicated or combined test. Siemba's starting price requires fewer than five APIs. Triaxiom and Blaze each list API testing as its own service as well.
Ask every provider this: "Which of our API endpoints are inside the quoted price, and which would need a separate test?"
How do user roles change the price?
Roles are the clearest price driver in the published terms. Pentest-Tools.com charges $900 per role. Blaze caps roles by package at 2, 3 and 5. Siemba's starting price stops at 3. Triaxiom's own examples nearly double between one role and many.
Count roles, not accounts. Our example has three roles across two tenants. Testing whether one customer's manager can see the other customer's data takes at least two manager accounts, so a tester may need five or six accounts. That is still three roles. Ask each provider how it counts.
Is retesting included, and how long do you have?
Usually yes, for one round. The deadline matters more than the word "included". Here is each published window as a plain rule.
| Provider | The rule, as published |
|---|---|
| Astra (Expert) | Ask within 30 days of the date the vulnerabilities were reported, with at least half the Critical and High findings fixed |
| Siemba (Expert) | Free within 60 days of the report |
| Blaze (Essentials, Assurance) | 1 round, up to 4 hours; schedule within 90 days of the initial report, subject to availability |
| Red Sentry | Normally 1 round within 90 days for findings from the engagement |
| Triaxiom | 1 retest completed within 90 days of report delivery |
| Bugcrowd (Standard) | 12 months, with 1 report update |
| Software Secured | 3 rounds over 12 months on the offer card |
| Cobalt | Retest requests within 6 or 12 months by tier, no later than 10 days before your active contract ends |
Four providers publish retest terms that need a closer check. That is not a reason to avoid them. It is a reason to get the term in writing.
- HackerOne. Its retesting article, dated March 24, 2026, says unlimited retests during a remediation period that typically lasts 30 or 90 calendar days, then paid retests with a proposed fee of at least $50 USD while your HackerOne platform service is active. Its pentest FAQ, dated July 17, 2024, says a 60-day window and two retests per report.
- Software Secured. The offer card says 3 rounds. The package table says 1 for Standard, 3 for Standard Plus, unlimited for Premium. The page does not say which package the $10,800 price is.
- Cobalt. The tier table and help docs say 6 or 12 months inside an active contract. The pricing FAQ says "unlimited on-demand retesting throughout your contract term."
- Blaze. Its pricing page makes fix validation a paid add-on for Lite. Its AWS Marketplace listing, also from $4,999, says "Free re-test if performed within 90 days from the final report." These may be different offers. Ask which terms your quote carries.
A contract-end example. Say your Cobalt contract ends November 30, 2026. The retest-request cutoff is 10 days earlier: November 20, 2026. A test that finishes in early November leaves you about two weeks to fix and resubmit, whatever the tier's 6 or 12 months say.
One more word to watch is "re-scan". Astra uses it for a manual check by its testers. Elsewhere it can mean an automated scan. Ask what is rechecked, who does it, and whether you get an updated report.
Send this to any provider on your list: "What date starts our retest window, what is the exact end date, must we request or finish the retest by then, which findings qualify, and what does an extra round cost?"
How much does a web application pentest cost?
Published starting prices for tests led by people run from $3,000 (Siemba, small app) to $10,800 (Software Secured), and Triaxiom's own examples run from about $12,000 to about $23,000. Most providers publish nothing and quote per scope. We are not turning eight data points into a market average.
Three things in the published terms can make a price look lower than it is:
- A yearly price read as a one-time fee. Astra's $5,999 is per year for one target.
- A required extra line. Synack's $10,283 is the test. The platform is a separate, required line item, and the page also describes a free Basic Platform. Until Synack says which applies, the total is unknown. Unknown is not zero.
- A missing fix check. Blaze Lite starts at $4,999 without one. Add the $799 round and it is $5,798, still capped at two roles.
Cobalt's Standard, Premium and Enterprise prices are not published. It sells yearly credits, and one credit is the equivalent of 8 hours across automation and human work, so do not read credits as tester hours.
When you ask for a quote, ask for this: "Please show the total, the currency, the amount due at signing, the billing schedule, tax, what testing and fix checks are included, and the cost of a scope change or an extra retest." If you already hold quotes, the questions to compare offers line them up against the same job.
Is a scan or an AI-led test enough?
It depends on what the person asking for the report will accept, so ask them before you buy. A vulnerability scan is software checking for known problems. A penetration test (pentest) has someone try to break in and show how. An AI-led test automates some or all of that attempt. Several offers below use the word "pentest", so read what each one does.
Buyers worry about this. In one Reddit thread about choosing a web app pentest vendor, the poster asks, "What are some red flags I should watch out for?" The clearest one is a price that buys a scan when your customer expects a person.
Table 3. Tests led by AI (A to Z)
| Offer | Published price | Human role, as stated | The condition that decides |
|---|---|---|---|
| Astra · Pentest Auto | $2,999 a year for 1 target | Autonomous agents do the test. One human re-scan checks fixes. | Request within 30 days of the date the vulnerabilities were reported, after fixing at least half the Critical and High findings |
| Cobalt · Autonomous Pentest | $3,500 per test, a limited-time offer. The test must be started and finished before December 31, 2026. | AI testing with a Cobalt Core tester directing the plan and scope | The price after the offer ends is not published |
| Intruder · AI web app pentest | $4,000 per test; $3,500 for platform subscribers. A 4-test pack is $12,000 ($10,500 for subscribers), to use within 1 year. | "AI-powered, built by CREST-certified experts." No human review of your test is stated. | White-box: the process starts with connecting your code repository |
| Prescient · Cait | $1,500 per asset one time, or $850 a month per asset, in US dollars before tax | AI tester. A human reviewer is a $1,000 add-on per test. | Up to 2 retests within 30 days of each scan report; $250 each after that |
| Siemba · Autonomous Pentesting | From $500 a month for 25 test runs | Siemba's own words: "AI-native DAST" | DAST is automated testing of a running app. Siemba says to add its Expert service for business-logic depth. |
| Synack · Sara Pentest | Starts at $4,181 for 1 low-complexity web app | "AI-led testing" | Platform line item is separate, so the total is incomplete |
Prescient also lists "Compliance Penetration Testing" starting at $3,000. Its pricing page does not say whether people or its Cacilian tool do that testing, so ask before comparing it with the offers in Table 1.
Intruder promises a full refund if your auditor rejects its report. That is a refund promise. It is not a sign your auditor will accept it.
For any offer, three checks settle it: who runs the first test, what a person reviews, and what your report reader has agreed to accept.
Do you need a web app pentest for PCI DSS or SOC 2?
For PCI DSS, the text calls for application-layer penetration testing. For SOC 2, ask your auditor in writing. In both cases the assessor, auditor or customer decides what they accept, not the provider and not us.
PCI DSS. The PCI Security Standards Council lists v4.0.1 as the current standard. We read the requirement wording in the Council's own Prioritized Approach for PCI DSS v4.0.1, which leaves out the standard's applicability notes. It says:
- Requirement 11.4.1. The penetration testing methodology includes "application-layer penetration testing to identify, at a minimum, the vulnerabilities listed in Requirement 6.2.4." That list covers injection attacks, attacks on business logic and attacks on access control, among others.
- Requirement 11.4.3. External penetration testing is performed "at least once every 12 months" and "after any significant infrastructure or application upgrade or change," by a qualified internal resource or qualified external third party with organizational independence. The tester is "not required to be a QSA or ASV."
- Requirement 11.4.4. Exploitable vulnerabilities are corrected and "penetration testing is repeated to verify the corrections."
That last line is why the retest deadline matters so much to a PCI buyer. If your fixes land after the window closes, the repeat test becomes a new cost. Whether these requirements apply to your app is a question for your QSA.
SOC 2. The AICPA's criteria document sits behind a login and we did not read it, so we will not tell you what it requires. Many providers say their reports are "audit-ready". That is their claim. Your auditor's answer is the one that counts.
Send the person asking for the report this before you book: "Will a report covering these URLs, APIs and roles meet your request? Do you need the full findings or a summary letter, proof that fixes were retested, a particular tester qualification, or testing done by people?" The questions for your report recipient cover the rest.
When you see a sample report, check five things: the scope and dates are named, the method and its limits are stated, each finding has evidence, the fix advice is specific, and the status after retesting is clear.
How long does a web app pentest take?
Published testing times cluster around one to two weeks. Getting on the calendar and getting the report add to that, and providers state those parts differently.
| Stage | What providers publish |
|---|---|
| Quote | TCM Security: within 48 hours after an introductory call. BreachLock: a response within 24 hours. |
| Start | Cobalt: within 3, 2 or 1 business days by tier, depending on engagement type. Bugcrowd: within 3 business days. Blaze: current average start time of two weeks. |
| Testing | Raxis, TCM Security and Triaxiom: 1 to 2 weeks. Astra: 10 to 15 working days from when its engineers have what they need. Pentest-Tools.com black box: 3 working days. |
| Report | Pentest-Tools.com black box: on the 4th day. Bishop Fox: 1 to 2 weeks for reporting and remediation support. Raxis: within days of testing. |
Astra gives "10 to 15 working days" on its help and pricing pages and "10-14 business days" on its web app page. Small gap, same lesson: a stated duration is an estimate, not a reserved date. Ask for your report date in writing.
Before you ask, settle one thing with whoever set your deadline: does it mean the first report, or proof that the fixes were checked? The second needs time for your fixes and a retest on top.
Questions people ask before booking
Do testers need our source code?
Not usually. A black-box test gives testers no inside knowledge. A gray-box test gives them logins and some context, and it is the common choice for a web app. A white-box test adds fuller inside information, sometimes the code. Ask the provider which extra information would improve the test of your app. If you cannot share code, rule out offers that start from it.
Can the test run against our live app?
It can, if you and the provider agree what is allowed. Settle the target, the test data, the actions that are off limits, and who to call to stop the test. A staging copy is the other option. Write down any way it differs from production, because those gaps limit what the results prove.
Do we need a provider near us?
Rarely for a web app. Ask whether anything must happen on site, where the assigned testers work, and whether your contracts restrict tester location or data handling.
Does a scope checklist authorize testing?
No. A checklist or brief is a buying document. NIST's testing guide, SP 800-115, describes rules of engagement as set before a test starts, giving the test team authority for defined activities. Written authorization from the system owner must cover the actual targets and actions. Hosting providers may have their own rules too. Never put passwords or keys in a brief.
How we checked these offers
We read each provider's own pricing, service and help pages on October 8, 2026, applied one example job to the terms we found, and did the arithmetic shown. The service terms in the tables are provider-published. We did not buy these services, test them, or check any provider's credentials with the issuing body. Where a page left something out, we wrote "not stated" instead of guessing.
The PenTest Index does not sell penetration testing. Payment does not decide which offers appear, their order or their findings; tables run A to Z. More on how we check offers and how we make money.
Sources
All checked October 8, 2026.
- Astra: pricing · rescan quota · rescanning vulnerabilities · duration · web app service
- Bishop Fox: application penetration testing
- Blaze: pricing · linked shop · terms, section 2.8 · web service · AWS Marketplace listing
- BreachLock: pricing · home page
- Bugcrowd: pen test as a service · sample web app report
- Cobalt: pricing · retest rules · web methodology
- HackerOne: retesting article · pentest FAQ
- Intruder: pentest pricing
- Kroll: web application penetration testing
- NetSPI: web application testing
- Pentest-Tools.com: managed web app testing · services
- Prescient: pricing · services
- Raxis: web app pentest
- Red Sentry: pentest cost
- Siemba: pricing
- Software Secured: pricing
- Synack: pricing
- TCM Security: web application testing
- Triaxiom: web application penetration test · timing and retest completion
- PCI Security Standards Council: document library · Prioritized Approach for PCI DSS v4.0.1
- OWASP: Web Security Testing Guide
- NIST: SP 800-115