Which penetration testing service fits your scope?
Web and API tests focus on application logic, authentication, authorization, and data flow. Cloud tests examine configuration and identity paths. Mobile tests add device and platform behavior. Network tests focus on exposed and internal infrastructure. Red-team engagements go wider by testing how people, systems, and detection controls respond across an attack chain.
One provider may cover several surfaces, but breadth on a services page does not prove equal depth in each. Ask who will test your specific stack, how much manual time is included, and whether source-assisted review, authenticated roles, cloud control-plane access, or social engineering are inside or outside the engagement.
Point-in-time pentest vs. PTaaS or continuous testing
A point-in-time pentest answers whether a defined system can be exploited during a fixed window. PTaaS and continuous models add a portal, recurring access, or repeated testing as the system changes. The best model depends on release frequency and how quickly stakeholders need updated evidence.
Continuous branding is not a substitute for reading the service terms. Confirm whether testing is human-led, how often testers actively work, whether new features can be added to scope, how retests are requested, and what report or attestation artifact is available on demand.
How region and credentials affect the shortlist
Region affects working-hour overlap, data handling, procurement, and which credentials buyers recognize. CREST is commonly requested in the UK and other markets, while technology-specific certifications can support an individual tester's credentials. Neither replaces checking the named team, methodology, and relevant project experience.
Confirm where testing will be performed, whether subcontractors are used, what data leaves your environment, and whether the proposal commits qualified staff to the engagement. A company-level accreditation or badge does not guarantee that the assigned tester has the experience your application or infrastructure requires.
How much does penetration testing cost?
There is no honest universal price because quotes change with surface area, architecture, authenticated roles, testing depth, timeline, and retest coverage. 11 firms in this directory currently show a published price signal; every other record says “Not published” instead of substituting an estimate.
Use price only after normalizing scope. A proposal covering one web application with two roles is not comparable to one covering web, API, cloud configuration, mobile builds, internal networks, and multiple retests. Ask each shortlisted firm to separate base scope, optional surfaces, rush fees, and retest terms.
How this directory handles evidence and ordering
A firm is eligible here when its validated directory record carries the penetration-testing service tag. Records use firm-published details where available; absent framework, engagement-model, accreditation, or price data renders as “Not published.” Each profile shows its record-level verification date and source website. Eligibility is not a certification, endorsement, or claim that every firm fits every use case.
Base ordering is deterministic: verified records first, then alphabetical by firm name. Paid placement does not change that order. A visible Featured label may identify an active commercial placement, but it does not change eligibility, verification, or any claim about service quality.