Logo Menu

Penetration testing firms: compare 58 providers by scope, delivery, and evidence.

This directory helps buyers shortlist penetration testing firms for web applications, APIs, cloud infrastructure, mobile products, networks, and deeper adversary-led work. Compare what each firm publishes, then verify the exact scope, tester allocation, retest terms, and final report in its proposal.

Compare firms ↓

Updated

Pentest firms
58
Verified records
34
Published price
11firms
Provider directory

58 penetration testing firms

The broad provider inventory across testing surfaces, regions, delivery models, framework support, specialties, and published price visibility. Use the search to narrow published attributes; confirm the final scope directly in each proposal.

Adversis

REMOTE, USA · USA
Verified
Provider type
Penetration testing firm
Location
Remote, USA, USA
Engagement model
Hands-on + advisory
Frameworks
SOC 2, ISO 27001, CMMC, GDPR
Specialties
Penetration testing, AI red teaming, Security advisory / fractional CISO, Security questionnaire support, SOC 2 and ISO 27001 readiness
Best fit
B2B SaaS companies going up-market (often Series A or B) that need pentests and security advisory which hold up in enterprise buyer security reviews.
Published price
Not published
View profile →

Archlight

MINNEAPOLIS, MN · USA
Verified
Provider type
Penetration testing firm
Location
Minneapolis, MN, USA
Engagement model
Hands-on + advisory
Frameworks
SOC 2, ISO 27001, HIPAA, HITRUST, GDPR, NIST
Specialties
healthcare, finance, government, MENA, GCC, UAE, data privacy, AI governance, ISO 27001/27701/42001/27017/27018, PDPL, GDPR
Best fit
Healthcare, finance, and government organizations across MENA and GCC seeking ISO 27001, SOC 2, HITRUST, or data privacy certifications with regional regulatory expertise.
Published price
Remote quarter-time ~10 hrs/wk: $7,500 USD/month; Remote half-time ~20 hrs/wk: $9,000 USD/month; Full-time onsite: $19,000 USD/month (published)
View profile →

Axipro

BAHRAIN, UK, AND US · Bahrain
Verified
Provider type
Penetration testing firm
Location
Bahrain, UK, and US, Bahrain
Engagement model
Hands-on implementation
Frameworks
SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR, CMMC, NIST CSF, DORA, ISO 42001
Specialties
ISO 27001, SOC 2, GDPR, ISO 9001, HIPAA, PCI DSS, EU AI Act, Drata Gold partner, Vanta partner, 6-week audit readiness, Gulf / Middle East
Best fit
Startups and small businesses seeking fast, fixed-fee compliance readiness across SOC 2, ISO 27001, and GDPR — especially in the Gulf, UK, and US — with hands-on implementation support and compliance platform management.
Published price
SOC 2 or ISO 27001 readiness and implementation: $4,000 under 50 employees, $5,500 over 50 (external CPA audit fee excluded); ongoing compliance + vCISO from $500/month; pentest from $1,000; internal audit from $1,000, scope-dependent (published)
View profile →

BEMO

UNITED STATES · USA
Verified
Provider type
Penetration testing firm
Location
United States, USA
Engagement model
Hands-on implementation
Frameworks
SOC 2, ISO 27001, CMMC, NIST 800-171, ISO 42001
Specialties
Microsoft 365 / Azure, SMB market, CMMC, Drata/Vanta GRC management, managed IT services, AI compliance (ISO 42001)
Best fit
SMBs in the Microsoft ecosystem needing fully managed compliance (SOC 2, CMMC, ISO 27001) alongside IT support and security under one roof.
Published price
Not published
View profile →

Bishop Fox

TEMPE, AZ · USA
Verified
Provider type
Penetration testing firm
Location
Tempe, AZ, USA
Engagement model
Hands-on implementation
Frameworks
Not published
Specialties
Application penetration testing, Red teaming, Cloud security, Attack surface management, AI/LLM security
Best fit
Enterprises and high-growth tech companies that need senior-led offensive security across applications, networks, cloud, and AI, with reports that hold up to enterprise buyer and auditor scrutiny.
Published price
Not published
View profile →

Cobalt

SAN FRANCISCO, CA · USA
Verified
Provider type
Penetration testing firm
Location
San Francisco, CA, USA
Engagement model
Hands-on implementation
Frameworks
Not published
Specialties
Penetration testing as a service (PTaaS), Web and API application pentesting, Cloud penetration testing, Mobile application pentesting, Secure code review
Best fit
Fast-moving product and security teams that need on-demand penetration tests they can launch in days, with findings and retests tracked in a platform and wired into developer workflows.
Published price
Not published
View profile →

Coral Esecure

NEW JERSEY, USA · USA
Verified
Provider type
Penetration testing firm
Location
New Jersey, USA, USA
Engagement model
Advisory
Frameworks
SOC 2, ISO 27001, HITRUST, HIPAA, GDPR, PCI DSS, CMMC, ISO 42001, ISO 22301, TISAX
Specialties
Global multi-office (USA/Canada/Germany/India/Mauritius), AICPA SOC 1 & SOC 2, GRC outsourcing, internal audit, healthcare, DPDP (India)
Best fit
Globally-distributed organizations needing broad multi-framework compliance consulting - SOC 2, ISO 27001, PCI DSS, GDPR, HITRUST - with offices across 5 countries.
Published price
Not published
View profile →

Cyber Forte

MELBOURNE, VIC · Australia
Verified
Provider type
Penetration testing firm
Location
Melbourne, VIC, Australia
Engagement model
Hands-on implementation
Frameworks
SOC 2, ISO 27001, Essential Eight, PCI DSS, ISO 42001, RFFR, SOCI
Specialties
Australian government clearances (NV2/Baseline), CREST-certified pen testing, Essential Eight, iRAP, SOCI Act, SOC 2 readiness in 6-8 weeks, AWS/cloud security
Best fit
Australian businesses and government-adjacent organizations needing CREST-certified penetration testing combined with SOC 2 or ISO 27001 readiness.
Published price
SOC 2 compliance program from $8,000 AUD fixed price (published)
View profile →

CYBRI

NEW YORK, NY · USA
Verified
Provider type
Penetration testing firm
Location
New York, NY, USA
Engagement model
Not published
Frameworks
SOC 2, HIPAA, PCI DSS, ISO 27001, GDPR
Specialties
Web and mobile app pentesting, API penetration testing, Cloud penetration testing (AWS, Azure, GCP), Network and infrastructure testing, SOC 2 / ISO 27001 compliance testing
Best fit
Companies that need manual, OSCP-led penetration testing with auditor-ready reports mapped to SOC 2, ISO 27001, HIPAA, or PCI compliance requirements.
Published price
Not published
View profile →

Cypro

LONDON, UK · UK
Verified
Provider type
Penetration testing firm
Location
London, UK, UK
Engagement model
Hands-on + advisory
Frameworks
SOC 2, ISO 27001, ISO 42001, Cyber Essentials Plus, GDPR
Specialties
vCISO, ISO 27001 certification, SOC 2 readiness, penetration testing, MDR, cyber resilience, cyber strategy, Cyber Essentials Plus
Best fit
High-growth UK businesses that need fractional CISO leadership plus hands-on certification support for ISO 27001 and SOC 2 compliance.
Published price
Not published
View profile →

Doyensec

NEW YORK, NY · USA
Verified
Provider type
Penetration testing firm
Location
New York, NY, USA
Engagement model
Hands-on implementation
Frameworks
Not published
Specialties
Web and API application security, Mobile application security, Cloud security, Source-code auditing, Smart-contract and LLM security
Best fit
Product and engineering teams that need deep, source-assisted application security audits of complex platforms, including GraphQL, ElectronJS, and LLM-based systems.
Published price
Not published
View profile →

Fortbridge

LONDON, UK · UK
Verified
Provider type
Penetration testing firm
Location
London, UK, UK
Engagement model
Hands-on implementation
Frameworks
Not published
Specialties
Web application pentesting, Mobile and API pentesting, Cloud security assessment (AWS, Azure, GCP), Network penetration testing, Developer security training
Best fit
Companies that want senior-only, manual penetration testing across web, mobile, API, cloud, and network, with consultants who work directly with developers to fix what they find.
Published price
Not published
View profile →

Include Security

NEW YORK, NY · USA
Verified
Provider type
Penetration testing firm
Location
New York, NY, USA
Engagement model
Hands-on implementation
Frameworks
Not published
Specialties
Web application assessments, Mobile application assessments, IoT and hardware security, Software reverse engineering, Secure code review
Best fit
Teams that need deep, source-assisted security assessments for complex web, mobile, IoT, or hardware products and want findings other firms miss, right-sized to the codebase and budget.
Published price
Not published
View profile →

Isecurion

BANGALORE, INDIA · India
Verified
Provider type
Penetration testing firm
Location
Bangalore, India, India
Engagement model
Hands-on + advisory
Frameworks
SOC 2, ISO 27001, GDPR, DORA, DPDP, ISO 42001, RBI Audit, IRDA Audit
Specialties
SOC 2 readiness and gap assessment, VAPT, ISO 27001, vCISO, cloud security assessment, DevSecOps, DPDP compliance, managed MSSP
Best fit
Indian SaaS, FinTech, and cloud companies targeting enterprise deals in US, UK, UAE, or Australia that need end-to-end SOC 2 readiness from a CERT-In empanelled partner.
Published price
Not published
View profile →

NCC Group

MANCHESTER, UK · UK
Verified
Provider type
Penetration testing firm
Location
Manchester, UK, UK
Engagement model
Not published
Frameworks
SOC 2, ISO 27001, PCI DSS, FedRAMP
Specialties
Technical assurance and penetration testing, Security consulting and implementation, Digital forensics and incident response, Managed security services, Threat intelligence
Best fit
Larger enterprises and regulated organizations that need a global provider for penetration testing, security consulting, and incident response under one roof.
Published price
Not published
View profile →

NetSPI

MINNEAPOLIS, MN · USA
Verified
Provider type
Penetration testing firm
Location
Minneapolis, MN, USA
Engagement model
Hands-on implementation
Frameworks
Not published
Specialties
Penetration testing as a service (PTaaS), Attack surface management, Breach and attack simulation, Cloud penetration testing, AI penetration testing
Best fit
Large organizations and regulated enterprises that want continuous, expert-led penetration testing delivered through a managed platform rather than one-off point-in-time tests.
Published price
Not published
View profile →

Practical Assurance

BOSTON, MA · USA
Verified
Provider type
Penetration testing firm
Location
Boston, MA, USA
Engagement model
Hands-on + advisory
Frameworks
SOC 2, ISO 27001, HIPAA
Specialties
SOC 2-scoped penetration testing, Compliance readiness, Fractional CISO, Startup and SMB security, Remediation retesting
Best fit
Startups and SMBs that need right-sized, affordable penetration testing and hands-on SOC 2 readiness support without the cost and overkill of enterprise engagements.
Published price
Entry 'lay of the land' SOC 2 pentest from $2,800 (published)
View profile →

Praetorian

AUSTIN, TX · USA
Verified
Provider type
Penetration testing firm
Location
Austin, TX, USA
Engagement model
Not published
Frameworks
Not published
Specialties
Advanced offensive security, Continuous threat exposure management, Red teaming, Cloud and application pentesting, Attack surface management
Best fit
Organizations that want adversary-emulation-grade offensive security and continuous threat exposure management rather than a one-off checkbox penetration test.
Published price
Not published
View profile →

Precursor Security

LEEDS, UK · UK
Verified
Provider type
Penetration testing firm
Location
Leeds, UK, UK
Engagement model
Hands-on + advisory
Frameworks
ISO 27001, PCI DSS, GDPR, Cyber Essentials
Specialties
CREST penetration testing, ISO 27001 consultancy, Managed detection and response, Cyber Essentials certification, Vulnerability assessment
Best fit
UK organisations that want CREST-accredited penetration testing and ISO 27001 consultancy from one provider, with findings tied back to the controls auditors check.
Published price
Penetration testing from £2,500; managed SOC from £900/month (published)
View profile →

Raxis

ATLANTA, GA · USA
Verified
Provider type
Penetration testing firm
Location
Atlanta, GA, USA
Engagement model
Hands-on implementation
Frameworks
Not published
Specialties
Red teaming and adversary simulation, External and internal network pentesting, Web application pentesting, Cloud security (AWS, Azure, GCP), Social engineering
Best fit
Security-conscious teams that want adversary-style penetration testing tied to SOC 2 Trust Services Criteria, not a reformatted vulnerability scan, with an auditor-ready report.
Published price
Not published
View profile →

Rhino Security Labs

SEATTLE, WA · USA
Verified
Provider type
Penetration testing firm
Location
Seattle, WA, USA
Engagement model
Hands-on implementation
Frameworks
Not published
Specialties
Network penetration testing, AWS and cloud penetration testing, Web and mobile application testing, Social engineering, Security research
Best fit
Companies from high-growth startups to the Fortune 1000 that want a deep, manual, research-driven pentest mapped to SOC 2 and vendor-security requirements rather than a scan.
Published price
Not published
View profile →

Rhymetec

NEW YORK, NY · USA
Verified
Provider type
Penetration testing firm
Location
New York, NY, USA
Engagement model
Hands-on + advisory
Frameworks
SOC 2, ISO 27001, PCI DSS, FedRAMP, HIPAA, GDPR, CMMC, NIST, DORA, NIS2, EU AI Act
Specialties
SaaS, startups, vCISO, penetration testing, ISO 27001 internal audits, PCI ASV scans, HIPAA, GDPR, FedRAMP, CMMC, AI/LLM security testing
Best fit
Startups and growth-stage SaaS companies seeking a one-stop cybersecurity partner covering vCISO, compliance readiness, penetration testing, and ISO 27001 internal audits.
Published price
Not published
View profile →

RSI Security

SAN DIEGO, CA · USA
Verified
Provider type
Penetration testing firm
Location
San Diego, CA, USA
Engagement model
Not published
Frameworks
Not published
Specialties
SOC 2 readiness, PCI DSS, HITRUST, CMMC, Penetration testing
Best fit
Organizations seeking end-to-end SOC 2 support from readiness assessment through ongoing Type I/Type II compliance with hands-on consulting approach
Published price
Not published
View profile →

Securis360

PITTSBURGH, PA · USA
Verified
Provider type
Penetration testing firm
Location
Pittsburgh, PA, USA
Engagement model
Hands-on + advisory
Frameworks
SOC 2, ISO 27001, ISO 27701, ISO 27017, ISO 27018, HIPAA, HITRUST, GDPR, PCI DSS, CMMC, NIST, DPDP
Specialties
cloud security, SOC 2, ISO 27001, HIPAA, HITRUST, GDPR, VAPT, web/mobile/API penetration testing, managed SOC
Best fit
Organizations seeking a global cybersecurity partner covering SOC 2 readiness, ISO 27001 consulting, penetration testing, and managed SOC services across the US and India.
Published price
Not published
View profile →

Silent Sector

SCOTTSDALE, AZ · USA
Verified
Provider type
Penetration testing firm
Location
Scottsdale, AZ, USA
Engagement model
Hands-on + advisory
Frameworks
SOC 2, ISO 27001, HIPAA, PCI DSS, CMMC, NIST 800-171, NIST 800-53, NIST CSF, CIS Controls, GDPR, CCPA, FedRAMP
Specialties
mid-market and emerging companies, SaaS, financial services, healthcare, manufacturing and defense, FedRAMP readiness, CMMC
Best fit
US-based mid-market and emerging companies that need a full cybersecurity program: SOC 2 readiness, penetration testing, vCISO, and multi-framework compliance under one roof.
Published price
Not published
View profile →

Software Secured

OTTAWA, ON · Canada
Verified
Provider type
Penetration testing firm
Location
Ottawa, ON, Canada
Engagement model
Hands-on implementation
Frameworks
SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR
Specialties
Web, API and mobile pentesting, Secure code review, Cloud security review, Penetration testing as a service (PTaaS), Red teaming
Best fit
High-growth SaaS companies preparing for SOC 2, HIPAA, or ISO 27001 that need manual, exploit-driven pentests with compliance mappings and built-in retesting to unblock enterprise deals.
Published price
Web & API pentest from $10,800; PTaaS from $21,400 (published)
View profile →

Sprocket Security

MADISON, WI · USA
Verified
Provider type
Penetration testing firm
Location
Madison, WI, USA
Engagement model
Hands-on implementation
Frameworks
Not published
Specialties
Continuous penetration testing, Attack surface management, Adversary simulation, Network penetration testing, Web application testing
Best fit
Organizations that ship frequently and want always-on, expert-driven penetration testing with unlimited retests and on-demand attestation reports rather than a single annual snapshot.
Published price
Continuous pentest Starter package from $15,000 (published)
View profile →

Testpros

RESTON, VA · USA
Verified
Provider type
Penetration testing firm
Location
Reston, VA, USA
Engagement model
Hands-on implementation
Frameworks
SOC 2, ISO 27001, CMMC, FedRAMP, NIST 800-53, NIST 800-171, NIST CSF, PCI DSS, HIPAA, HITRUST, FISMA
Specialties
federal government, defense/CMMC, FedRAMP, Section 508/ADA accessibility, FISMA, NIST 800-53/800-171, SOC 2, ISO 27001, PCI DSS, healthcare
Best fit
Organizations - especially federal, state/local, and defense contractors - needing independent IT testing, compliance readiness, and verification and validation across a broad stack of US government and commercial frameworks.
Published price
Not published
View profile →

Tevora

IRVINE, CA · USA
Verified
Provider type
Penetration testing firm
Location
Irvine, CA, USA
Engagement model
Not published
Frameworks
Not published
Specialties
SOC 2 readiness, PCI DSS, HITRUST, CMMC, Penetration testing
Best fit
Organizations requiring expert compliance and cybersecurity services across multiple frameworks with executive CISO-level support
Published price
Not published
View profile →

Trail of Bits

NEW YORK, NY · USA
Verified
Provider type
Penetration testing firm
Location
New York, NY, USA
Engagement model
Hands-on implementation
Frameworks
Not published
Specialties
Software security audits, Cryptography review, Blockchain and smart-contract security, Reverse engineering, Application security
Best fit
Engineering-led and high-assurance organizations that need deep security audits of code, cryptography, blockchain, and complex systems, well beyond a standard pentest.
Published price
Not published
View profile →

Trava Security

INDIANAPOLIS, IN · USA
Verified
Provider type
Penetration testing firm
Location
Indianapolis, IN, USA
Engagement model
Hands-on + advisory
Frameworks
SOC 2, ISO 27001, ISO 42001, CMMC, PCI DSS, HIPAA, GDPR, CCPA, NIST AI RMF, EU AI Act
Specialties
startups and scale-ups, defense industrial base, CMMC, SaaS, AI risk management, compliance as a service, PTaaS
Best fit
Startups, scale-ups, and defense industrial base companies that want managed compliance and security programs with expert practitioners, backed by a 100% certification success rate and G2 High Performer recognition.
Published price
Not published
View profile →

TrustedSec

FAIRLAWN, OH · USA
Verified
Provider type
Penetration testing firm
Location
Fairlawn, OH, USA
Engagement model
Hands-on implementation
Frameworks
Not published
Specialties
Penetration testing, Red teaming and adversary simulation, Active Directory security, Incident response readiness, Security program consulting
Best fit
Organizations that want CREST-certified offensive testing and pragmatic security consulting from a widely recognized US practitioner team.
Published price
Not published
View profile →

Truvantis

SAN FRANCISCO, CA · USA
Verified
Provider type
Penetration testing firm
Location
San Francisco, CA, USA
Engagement model
Hands-on + advisory
Frameworks
SOC 2, ISO 27001, PCI DSS, HIPAA, HITRUST, NIST 800-53, NIST 800-171, NIST CSF
Specialties
SOC 2 readiness, PCI DSS QSA assessments, SaaS penetration testing, vCISO, privacy consulting (GDPR/CCPA/HIPAA), risk assessments, security program development
Best fit
Companies needing a full-service cybersecurity partner for SOC 2 readiness, PCI DSS QSA assessment, penetration testing, and vCISO - with expertise in managing the full audit lifecycle.
Published price
Not published
View profile →

URM Consulting

UNITED KINGDOM · UK
Verified
Provider type
Penetration testing firm
Location
United Kingdom, UK
Engagement model
Hands-on + advisory
Frameworks
SOC 2, ISO 27001, PCI DSS, CMMC, NIST CSF
Specialties
ISO 27001 consultancy and auditing, SOC 2 readiness, GDPR and data protection, CREST penetration testing, Cyber Essentials certification
Best fit
UK organisations that want ISO 27001 certification support plus SOC 2 readiness, GDPR, and penetration testing from a single accredited consultancy.
Published price
Not published
View profile →
Provider type
Penetration testing firm
Location
BS, Bahamas
Engagement model
Hands-on + advisory
Frameworks
SOC 2
Specialties
incident response, penetration testing, SOC 1/2/3 compliance prep, security awareness training, governance and audit
Best fit
Small businesses in the Caribbean / Bahamas region seeking foundational SOC 2 readiness and cybersecurity consulting
Published price
Not published
View profile →

ACOINFO

COLOMBIA · Colombia
Provider type
Penetration testing firm
Location
Colombia, Colombia
Engagement model
Hands-on + advisory
Frameworks
SOC 2, ISO 27001, HIPAA, PCI DSS, HITRUST
Specialties
ISO 27001, PCI DSS v4, SOC 2, HIPAA, HITRUST, AWS/Azure/GCP pentesting, security framework certification, SIEM/SOC monitoring
Best fit
Latin American organizations seeking a Spanish-language cybersecurity partner with 25+ years of experience across compliance certification and ethical hacking.
Published price
Not published
View profile →

Amomitto

UNITED STATES · USA
Provider type
Penetration testing firm
Location
United States, USA
Engagement model
Hands-on implementation
Frameworks
SOC 2, ISO 27001, HIPAA, PCI DSS
Specialties
SaaS, fintech, healthtech, infrastructure companies, Series A-C, 50-500 employees, enterprise sales enablement, GRC platform management (Vanta, Drata, Thoropass)
Best fit
Growing tech companies (Series A-C, 50-500 employees) that need an embedded security team to handle SOC 2, ISO 27001, and enterprise sales security reviews end-to-end.
Published price
Not published
View profile →

Astra Security

CLAYMONT, DELAWARE (US HQ); NEW DELHI, INDIA (OPERATIONS) · USA
Provider type
Penetration testing firm
Location
Claymont, Delaware (US HQ); New Delhi, India (operations), USA
Engagement model
Hands-on + advisory
Frameworks
SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR
Specialties
PTaaS platform (continuous pentesting), web/API/mobile/cloud/network pentest, SOC 2 / ISO 27001 pentest reports, DAST scanner (15,000+ vulnerability checks), SaaS / fintech / healthcare / ecommerce verticals
Best fit
SaaS and technology companies seeking continuous automated + manual penetration testing integrated into CI/CD pipelines, with compliance scan support for SOC 2 readiness.
Published price
DAST Scanner from $7 trial; Pentest plans: manual pentest pricing via custom quote (published partial pricing on getastra.com/pricing)
View profile →

Atlant Security

SOFIA, BULGARIA · Bulgaria
Provider type
Penetration testing firm
Location
Sofia, Bulgaria, Bulgaria
Engagement model
Hands-on + advisory
Frameworks
SOC 2, ISO 27001, HIPAA, CMMC, NIST, PCI DSS, HITRUST
Specialties
SaaS security audit, cloud security (AWS/Azure/GCP), fintech, healthcare, legal, e-commerce, enterprise sales enablement
Best fit
Fast-moving SaaS companies needing founder-led security audits and compliance readiness delivered in weeks, not months.
Published price
SaaS Security Audit from $5,000, pay after delivery, fixed pricing (published)
View profile →

Cognisys

LEEDS, UK · UK
Provider type
Penetration testing firm
Location
Leeds, UK, UK
Engagement model
Hands-on + advisory
Frameworks
SOC 2, ISO 27001, ISO 42001, GDPR, CMMC, Cyber Essentials, NIS2, DORA, FedRAMP
Specialties
Vanta implementation (self-claimed #1 Global Service Partner), ISO 42001 (AI governance), CREST-accredited penetration testing, startup to enterprise, EU AI Act, DORA, NIS2
Best fit
UK-based companies seeking combined CREST-accredited penetration testing and compliance readiness, especially those on Vanta or pursuing ISO 27001 or SOC 2.
Published price
Not published
View profile →

Com Sec

WASHINGTON, DC · USA
Provider type
Penetration testing firm
Location
Washington, DC, USA
Engagement model
Hands-on + advisory
Frameworks
SOC 2, ISO 27001, HIPAA, GDPR, PCI-DSS, NIST, HITRUST, CMMC
Specialties
Cloud security (AWS/Azure/GCP), AI/ML companies, healthcare, FinTech, EdTech, SOC 2 readiness, partner ecosystem (Vanta/Drata/Prescient)
Best fit
Startups and SMBs across healthcare, AI/ML, and FinTech needing combined SOC 2 readiness and penetration testing with access to discounted GRC platform partnerships.
Published price
Not published
View profile →

Compass IT Compliance

NORTH PROVIDENCE, RI · USA
Provider type
Penetration testing firm
Location
North Providence, RI, USA
Engagement model
Hands-on implementation
Frameworks
SOC 1, SOC 2, SOC 3, PCI DSS, HIPAA, NIST, CMMC, HECVAT, GLBA, CJIS, ISO 27002, GDPR, CIS Controls, MA 201 CMR 17
Specialties
SOC 2 readiness and gap assessments, penetration testing (network, web app, wireless, social engineering), virtual CISO, PCI DSS QSA assessments, CMMC consulting (CMMC RPO), HIPAA, NIST, GLBA, CJIS, GDPR, HECVAT compliance, financial services, healthcare, higher education, manufacturing, government
Best fit
Mid-market organizations across diverse industries seeking a single partner for SOC 2 readiness, penetration testing, vCISO, and multi-framework compliance consulting, with the attest work handled by affiliated CPA firm Compass Assurance Team.
Published price
Not published
View profile →

Cybervantage 360

NAVI MUMBAI, INDIA · India
Provider type
Penetration testing firm
Location
Navi Mumbai, India, India
Engagement model
Hands-on + advisory
Frameworks
SOC 2, ISO 27001, ISO 27701, ISO 42001, ISO 22301, PCI DSS, HIPAA, GDPR, CMMC, NIST, CCPA, DPDP
Specialties
Multi-framework global consulting, Philippines Privacy Mark, AI-powered GRC platform, ISO 27001/27701/42001, PCI DSS, 1,000+ organizations across 50+ countries
Best fit
Organizations across Asia-Pacific, Middle East, and global markets needing multi-framework compliance consulting (SOC 2, PCI DSS, ISO 27001, HIPAA, GDPR) with a technology-assisted approach.
Published price
Not published
View profile →

Echelon Risk Cyber

UNITED STATES · USA
Provider type
Penetration testing firm
Location
United States, USA
Engagement model
Hands-on + advisory
Frameworks
SOC 2, CMMC, NIST, HIPAA
Specialties
vCISO, Security Team as a Service (STaaS), offensive security, penetration testing, GRC advisory, financial services, healthcare, higher education, manufacturing, defense industrial base
Best fit
Mid-market organizations across regulated industries seeking an integrated vCISO-led security team that combines GRC advisory, penetration testing, and managed security services.
Published price
Not published
View profile →

Eden Data

AUSTIN, TX · USA
Provider type
Penetration testing firm
Location
Austin, TX, USA
Engagement model
Hands-on implementation
Frameworks
SOC 2, ISO 27001, HIPAA, GDPR, HITRUST, CMMC, FedRAMP, ISO 42001
Specialties
SaaS, startups to IPO, Drata, Vanta, AWS, Big 4 alumni, GDPR, FedRAMP, HITRUST, CMMC
Best fit
High-growth SaaS companies wanting a hands-on compliance team with prior Big 4 experience to get audit-ready 3x faster on GRC platforms.
Published price
Compliance Sprint begins at $5K/mo (published)
View profile →

Illume Intelligence

CALICUT, KERALA, INDIA · India
Provider type
Penetration testing firm
Location
Calicut, Kerala, India, India
Engagement model
Hands-on + advisory
Frameworks
SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, PDPA, CDR, NIST, DPDP
Specialties
penetration testing, VAPT, SOC 2 assessment/readiness, ISO 27001 consulting, vCISO, red team testing, mobile/web/network security
Best fit
Indian and Middle East-based technology companies seeking VAPT, SOC 2 readiness, and ISO 27001 consulting from a cybersecurity specialist.
Published price
Not published
View profile →

IT Governance USA

UNITED STATES · USA
Provider type
Penetration testing firm
Location
United States, USA
Engagement model
Hands-on + advisory
Frameworks
SOC 2, ISO 27001, ISO 42001, Cyber Essentials, PCI DSS, GDPR, ISO 22301
Specialties
SOC 2 readiness, ISO 27001, GDPR, PCI DSS, AI governance, NIS2, DORA, Cyber Essentials, CREST/CHECK accredited pentest
Best fit
Organizations needing a broad range of GRC consulting, penetration testing, and training across SOC 2, ISO 27001, GDPR, and regulatory frameworks in the US, UK, and EU.
Published price
Not published
View profile →

Kratikal

NOIDA, INDIA · India
Provider type
Penetration testing firm
Location
Noida, India, India
Engagement model
Hands-on + advisory
Frameworks
SOC 2, ISO 27001, GDPR, PCI DSS, HIPAA
Specialties
VAPT, compliance audits, vCISO, AI-powered pentest platform (AutoSecT), SOC 2 compliance audit, ISO 27001 audit, red team, OT/ICS security
Best fit
Enterprises and SMEs in Fintech, Telecom, Healthcare, and E-commerce seeking CERT-In empanelled VAPT services, compliance audits, and an AI-driven vulnerability management platform.
Published price
Not published
View profile →

Kroll

NEW YORK, NY · USA
Provider type
Penetration testing firm
Location
New York, NY, USA
Engagement model
Hands-on + advisory
Frameworks
SOC 2, PCI DSS, ISO 27001, NIST, HIPAA, FedRAMP
Specialties
incident response, penetration testing, cyber transformation, managed detection and response, digital forensics, SOC 2 GRC, financial advisory
Best fit
Large enterprises needing a globally recognized firm for incident response, penetration testing, and comprehensive cyber risk advisory across the full security lifecycle.
Published price
Not published
View profile →

Netragard

MASSACHUSETTS, US · USA
Provider type
Penetration testing firm
Location
Massachusetts, US, USA
Engagement model
Hands-on implementation
Frameworks
SOC 2, PCI DSS, FINRA
Specialties
penetration testing, exploit development, vulnerability research, cloud penetration testing, AWS, Azure, GCP, compliance-oriented pen testing
Best fit
Organizations needing rigorous, research-driven penetration testing backed by 20+ years of exploit development expertise, with deliverables suitable for SOC 2 and PCI compliance evidence.
Published price
Not published
View profile →

Nettitude (LRQA Cyber Security)

BIRMINGHAM, UK · UK
Provider type
Penetration testing firm
Location
Birmingham, UK, UK
Engagement model
Hands-on + advisory
Frameworks
SOC 2, ISO 27001, PCI DSS, NIST CSF, CMMC, DORA, Cyber Essentials
Specialties
CREST-accredited penetration testing, managed detection and response, incident response, SOC 2 readiness, ISO 27001, financial services, banking, TIBER-EU framework testing
Best fit
Enterprises needing a full-spectrum, CREST-accredited cybersecurity partner covering testing, vCISO, managed SOC, and compliance readiness across EMEA and globally.
Published price
Not published
View profile →

Optiv Security

LEAWOOD, KS · USA
Provider type
Penetration testing firm
Location
Leawood, KS, USA
Engagement model
Hands-on + advisory
Frameworks
SOC 2, PCI DSS, HIPAA, HITRUST, ISO 27001, NIST CSF, CMMC
Specialties
enterprise security consulting, PCI DSS QSA, HIPAA, HITRUST, CMMC, ISO 27001, risk management, Fortune 500, financial services, healthcare
Best fit
Large enterprises seeking a full-service cybersecurity advisory firm with deep compliance expertise (PCI QSA), managed services, and penetration testing across virtually every regulatory framework.
Published price
Not published
View profile →

Secur01

ANJOU, QC · Canada
Provider type
Penetration testing firm
Location
Anjou, QC, Canada
Engagement model
Hands-on + advisory
Frameworks
SOC 2, ISO 27001, HIPAA, GDPR, NIST, PCI DSS
Specialties
Canadian SMBs, bilingual French/English, Quebec, managed cybersecurity, vCISO, SOC-as-a-Service, penetration testing, Bill 25 compliance, cyber insurance support
Best fit
Canadian SMBs (5-1,000 employees) - especially Quebec-based - seeking bilingual French/English cybersecurity services including vCISO, SOC-as-a-Service, penetration testing, and compliance support.
Published price
Not published
View profile →

Secureleap

PORTO, PORTUGAL · Portugal
Provider type
Penetration testing firm
Location
Porto, Portugal, Portugal
Engagement model
Hands-on implementation
Frameworks
SOC 2, ISO 27001, HIPAA, GDPR, DORA
Specialties
SOC 2, ISO 27001, startups, Seed to Series B, SaaS, Drata, Vanta, Secureframe, penetration testing, audit facilitation
Best fit
Seed-to-Series B startups needing SOC 2 or ISO 27001 compliance consulting, penetration testing, and virtual CISO support with transparent published pricing.
Published price
SOC 2 consulting from $8,000 to $12,000 USD for a full program; penetration testing from $4,000 USD per assessment; virtual CISO retainers from $2,000 USD per month (published)
View profile →

Secuvant

FARMINGTON, UT · USA
Provider type
Penetration testing firm
Location
Farmington, UT, USA
Engagement model
Hands-on + advisory
Frameworks
SOC 2, HIPAA, PCI DSS, NIST, ISO 27001
Specialties
SMB and mid-market, healthcare, financial services, manufacturing, agriculture, Cyber7 methodology, MDR, board-level advisory
Best fit
Small to large businesses seeking enterprise-grade cybersecurity through Secuvant's proprietary Cyber7 methodology, covering risk assessments, penetration testing, vCISO, and compliance alignment.
Published price
Not published
View profile →

Sidekick Security

BETHESDA, MD · USA
Provider type
Penetration testing firm
Location
Bethesda, MD, USA
Engagement model
Hands-on + advisory
Frameworks
SOC 2, HIPAA, HITRUST, FedRAMP, ISO 27001, CMMC
Specialties
AI-native security consulting, AI security and LLM red teaming, offensive security and penetration testing, SOC 2 compliance readiness, security program transformation, CISO-level advisory
Best fit
Companies wanting AI-native security consulting with rapid risk identification, root-cause analysis, and embedded implementation - not just a static report.
Published price
Not published
View profile →

UnderDefense

NEW YORK, NY · USA
Provider type
Penetration testing firm
Location
New York, NY, USA
Engagement model
Hands-on + advisory
Frameworks
SOC 2, ISO 27001, HIPAA
Specialties
MDR/SOC-as-a-Service (24/7), penetration testing, SOC 2 compliance automation, vCISO support, incident response, SIEM management, AI-augmented SOC (MAXI platform)
Best fit
Mid-market organizations seeking a combined MDR + compliance automation platform, with hands-on vCISO support for SOC 2 and ISO 27001 readiness delivered through the proprietary MAXI AI platform.
Published price
Not published
View profile →

Virtue Security

NEW YORK, NY · USA
Provider type
Penetration testing firm
Location
New York, NY, USA
Engagement model
Hands-on implementation
Frameworks
SOC 2, HIPAA, PCI DSS
Specialties
web application penetration testing, network penetration testing, API and mobile app testing, healthcare/HealthIT pentesting (HIPAA), financial application pentesting, AI-enabled application pentesting, red team assessments
Best fit
SaaS and technology companies needing depth-focused application, API, or AWS penetration testing from a senior-only team.
Published price
Not published
View profile →

List or upgrade your firm on this page →

Which penetration testing service fits your scope?

Web and API tests focus on application logic, authentication, authorization, and data flow. Cloud tests examine configuration and identity paths. Mobile tests add device and platform behavior. Network tests focus on exposed and internal infrastructure. Red-team engagements go wider by testing how people, systems, and detection controls respond across an attack chain.

One provider may cover several surfaces, but breadth on a services page does not prove equal depth in each. Ask who will test your specific stack, how much manual time is included, and whether source-assisted review, authenticated roles, cloud control-plane access, or social engineering are inside or outside the engagement.

Point-in-time pentest vs. PTaaS or continuous testing

A point-in-time pentest answers whether a defined system can be exploited during a fixed window. PTaaS and continuous models add a portal, recurring access, or repeated testing as the system changes. The best model depends on release frequency and how quickly stakeholders need updated evidence.

Continuous branding is not a substitute for reading the service terms. Confirm whether testing is human-led, how often testers actively work, whether new features can be added to scope, how retests are requested, and what report or attestation artifact is available on demand.

How region and credentials affect the shortlist

Region affects working-hour overlap, data handling, procurement, and which credentials buyers recognize. CREST is commonly requested in the UK and other markets, while technology-specific certifications can support an individual tester's credentials. Neither replaces checking the named team, methodology, and relevant project experience.

Confirm where testing will be performed, whether subcontractors are used, what data leaves your environment, and whether the proposal commits qualified staff to the engagement. A company-level accreditation or badge does not guarantee that the assigned tester has the experience your application or infrastructure requires.

How much does penetration testing cost?

There is no honest universal price because quotes change with surface area, architecture, authenticated roles, testing depth, timeline, and retest coverage. 11 firms in this directory currently show a published price signal; every other record says “Not published” instead of substituting an estimate.

Use price only after normalizing scope. A proposal covering one web application with two roles is not comparable to one covering web, API, cloud configuration, mobile builds, internal networks, and multiple retests. Ask each shortlisted firm to separate base scope, optional surfaces, rush fees, and retest terms.

How this directory handles evidence and ordering

A firm is eligible here when its validated directory record carries the penetration-testing service tag. Records use firm-published details where available; absent framework, engagement-model, accreditation, or price data renders as “Not published.” Each profile shows its record-level verification date and source website. Eligibility is not a certification, endorsement, or claim that every firm fits every use case.

Base ordering is deterministic: verified records first, then alphabetical by firm name. Paid placement does not change that order. A visible Featured label may identify an active commercial placement, but it does not change eligibility, verification, or any claim about service quality.

Evidence quality

A real pentest proposal defines the attack surface and the proof you receive.

Provider labels matter less than the engagement design. Compare the statement of work and sample deliverable before treating two quotes as equivalent.

Factor Stronger engagementWeaker engagement
Scope Named assets, roles, APIs, cloud boundaries, and exclusionsA device or URL count with unclear exclusions
Method Human-led testing with tools used to support the workScanner output sold as a penetration test
Tester Named lead or documented skill match for the technologyStaff assigned only after purchase with no skill commitment
Retest Terms, window, and closure evidence defined in writingRetesting priced or scoped only after findings appear
Report Reproduction steps, impact, severity, remediation, and executive summaryFinding list without evidence or business context
Buying sequence

How to shortlist a penetration testing firm

Start with what must be tested and why. Credentials and price become meaningful only after the scope and expected evidence are comparable.

01Define the testing surface and decision deadline

List the applications, APIs, cloud accounts, mobile builds, networks, user roles, and excluded systems. State whether the test supports a release, customer review, compliance cycle, or broader risk decision.

02Choose point-in-time, PTaaS, or adversary-led depth

A bounded annual test fits stable scope. PTaaS or continuous access fits frequent releases and repeated retesting. Red-team work tests detection and response across a wider attack path and should not be purchased as a substitute for an application pentest.

03Compare the report and retest package before price

Request a redacted sample report, confirm who performs the work, and put retest limits and evidence format in the statement of work. A cheaper quote is not comparable when it excludes critical surfaces or closure evidence.

FAQ

Penetration testing firm selection: common questions

Answers about engagement design and provider fit, separate from any one compliance framework.

What does a penetration testing firm do?

A penetration testing firm defines an authorized scope, attempts to exploit weaknesses using human-led testing, documents business impact, and delivers remediation guidance. The useful output is evidence about exploitable paths, not merely a scanner export.

How do I choose a penetration testing company?

Choose by testing surface, named tester experience, methodology, retest terms, report quality, region, and delivery model. Ask for a redacted report and a precise statement of work before comparing prices, because two proposals can cover very different attack surfaces.

What is the difference between a pentest and a vulnerability scan?

A vulnerability scan automatically flags known weaknesses. A penetration test adds human validation, exploitation attempts, attack-path chaining, and business-impact analysis. Scanning can support continuous hygiene, but it is not equivalent to a human-led test.

Should I choose a point-in-time test or continuous pentesting?

Choose a point-in-time engagement for a defined release, buyer request, or annual assurance cycle. Choose PTaaS or continuous testing when the application changes frequently and you need recurring access to testers, faster retests, or an always-current findings workflow.

Are all firms on this page suitable for SOC 2?

No. This broad directory includes every firm tagged for penetration testing, regardless of framework. 43 currently publish SOC 2 in their supported frameworks; use the narrower SOC 2 directory when auditor-ready framework support is required.
Tell us your scope

Need comparable penetration-testing quotes?

Share the systems in scope, testing surface, deadline, and evidence requirements. We’ll route the request for manual review so firms respond against the same brief.

Free and anonymous. We’ll follow up by email.