Top cybersecurity companies (August 2026 Rankings)

Buyer's GuideAug 12, 2026 · 13 min read

Short answer

Evaluating cybersecurity companies means checking for a verifiable testing methodology, tester certifications (CREST, OSCP, OSCE), and whether pricing and scope are transparent before signing. RaftLabs meets buyers partway: it builds the compliance and security-operations software regulated teams run on, SOC 2 and ISO 27001 evidence automation, at $29-49/hr, 4.9/5 on Clutch.

Key Takeaways

  • Cybersecurity companies split into two different purchases: project-based penetration testing or red team assessments, and continuous managed detection and response (MDR). Picking the wrong model wastes the budget regardless of which vendor you hire.
  • Certifications are the fastest filter. Individual testers holding OSCP or OSCE, and firms carrying organization-level CREST accreditation, have passed a standardized bar that most self-reported 'ethical hacker' claims haven't.
  • Pricing for offensive security engagements is rarely published. Nearly every firm on this list quotes per engagement based on target surface, application count, network segments, or red team objectives, rather than a flat published hourly rate.
  • A penetration test report with no retest included is half a deliverable. Confirm whether remediation verification is bundled into the original scope or billed as a second engagement before signing.
  • RaftLabs does not run penetration tests. It builds the compliance-evidence and security-operations software that regulated teams and SOC analysts run on day to day, a different but adjacent problem worth knowing about before you scope a security program.

Hiring a cybersecurity company is a harder buying decision than hiring a typical software vendor, because you're paying for two things that are almost impossible to verify in advance: whether the testers actually know what they're doing, and whether the report you get at the end tells you something you didn't already suspect. A shield icon and the word "elite" on a homepage prove neither. Certifications, a checkable public track record, and an honest answer about what the engagement won't cover are the filters that actually separate a firm worth hiring from one that isn't.

Part of the confusion is that "cybersecurity company" describes at least four different businesses wearing the same label. There are boutique offensive-security shops that sell a person's time and judgment against a defined scope. There are software-first PTaaS platforms that sell continuous testing through a dashboard. There are large, publicly listed firms that sell assessment, managed monitoring, and incident response as one bundled relationship. And there are companies, RaftLabs among them, that never test anything themselves but build the software the other three run their programs on. Comparing them on price alone misses the point, because they're not selling the same product.

The eight cybersecurity companies on this list are Bishop Fox, NCC Group, RaftLabs, TrustedSec, Cobalt.io, Praetorian, BreachLock, and Rapid7. RaftLabs is on this list. We wrote our own entry with the same directness we applied to everyone else.

How we evaluated this list

CriterionWhat we looked for
Production track recordPublic, checkable evidence of real engagements: named clients, third-party analyst recognition, or a documented history of findings and research
Technical depthBreadth of testing capability, application, cloud, network, red team, not a single narrow offering rebranded five ways
Pricing transparencyWhether the pricing model, engagement structure, or rate signal is publicly stated anywhere, or requires a sales call to learn anything
Client profile fitWho the firm actually serves, enterprise, mid-market, or SaaS-scale, and whether that matches the buyer profile most likely to be reading this
Certifications and accreditationIndividual tester credentials (OSCP, OSCE) and organizational accreditation (CREST) rather than self-described "ethical hacking" expertise

We deliberately mixed business models on this list rather than restricting it to seven near-identical boutique consultancies. A buyer comparing options usually doesn't know yet whether they need a one-time assessment, a continuous testing subscription, or a managed monitoring relationship, and a list of eight lookalike firms wouldn't help that buyer figure it out. No company paid for placement on this list.

The 8 companies

1. Bishop Fox

Bishop Fox is an offensive security firm founded in 2005 and headquartered in Tempe, Arizona. The company has built its entire reputation on one discipline: attacking systems the way a real adversary would, then documenting exactly how it got in. Their scope covers application, mobile, cloud, network, and AI or LLM penetration testing, alongside red team engagements and social engineering assessments.

What separates Bishop Fox from a generic penetration testing vendor is the scale of trust behind it. The company states it protects more than 1,700 customers, including 80% of the top ten tech companies and 26% of the Fortune 100, names that don't attach themselves to a security firm without real due diligence. Their Cosmos platform adds continuous attack surface testing on top of point-in-time engagements, so findings don't go stale the month after a report ships.

The addition of AI and LLM testing to their scope reflects where the offensive-security market has moved in the last two years. Prompt injection, model extraction, and agentic workflow abuse are now assessment categories in their own right, not a footnote inside a standard web application test. A firm that added this category early, rather than bolting a slide about "AI security" onto an unchanged methodology, is one signal worth checking during due diligence. Ask what an AI-specific engagement actually covers before assuming it's included in a standard scope.

Notable work: Bishop Fox lists Google, Amazon, Zoom, Coinbase, LastPass, and Facebook among its customers and reports a Net Promoter Score of 70, which the company classifies as "excellent" against the standard NPS scale. Continuous threat exposure management and red team engagements are flagship offerings, not an add-on to a compliance checklist.

Pricing signal: Bishop Fox does not publish a rate card. Engagements are scoped individually against target surface, application count, cloud footprint, network segments, or red team objectives, and the client roster signals premium boutique pricing rather than commodity per-hour rates.

What to watch: Bishop Fox is built for organizations with a mature security program that already knows what it's testing and why. Early-stage companies without an existing detection capability to test against, or a budget under the mid five figures, will find the pace and engagement model better suited to a larger enterprise buyer.

  • Best for: Enterprise and high-growth tech companies that need offensive security testing at Fortune 100 depth

  • Specialization: Application, cloud, and network penetration testing; red team and social engineering; continuous threat exposure management

  • Pricing: Not published, engagement-based, premium tier

  • Clutch: Not on Clutch - verify via direct reference


2. NCC Group

NCC Group is a publicly traded information assurance firm headquartered in Manchester, UK, listed on the London Stock Exchange under the ticker NCC as part of the FTSE 250. Formed in 1999 when the National Computing Centre sold its commercial divisions to its own management team, the company has grown into one of the largest independent cybersecurity consultancies in the world, with roughly 2,140 employees and revenue of £238.9 million in its 2025 fiscal year.

Unlike the boutique offensive-security specialists on this list, NCC Group runs five service lines end to end: technical assurance (penetration testing and application security), managed detection and response, incident response, consulting and implementation, and threat intelligence. That breadth means a client can move from an initial assessment into 24/7 monitoring without switching vendors, though it also means the firm's pricing and delivery model sits closer to a systems integrator than a specialist penetration testing shop.

Being publicly listed changes what a buyer can verify before signing. A private boutique firm asks a prospect to trust its client list and its marketing. NCC Group publishes an annual report, discloses revenue by service line, and answers to a board and public shareholders for the quality of its work. That doesn't make the delivery better on any single engagement, but it does mean a procurement team can pull public financial and governance data as part of vendor due diligence, something none of the privately held firms on this list offer.

Notable work: NCC Group's public materials reference work with TikTok, Vodafone, Transport for London, and Tulane University. The firm holds CREST accreditation and NCSC Industry 100 status, was named a Leader in the 2026 IDC MarketScape for Managed Detection and Response Services, and was selected for OpenAI's Daybreak Cyber Partner Program.

Pricing signal: As a publicly listed firm serving large enterprise and government clients, NCC Group doesn't publish per-engagement rates. Managed detection and response is typically structured as a recurring subscription; technical assurance and consulting work is scoped and quoted per project.

What to watch: NCC Group's scale suits an organization that wants assessment, monitoring, and incident response from one accountable vendor, but that same scale usually means slower procurement cycles than a boutique offers. In 2020, the firm disclosed that internal CREST exam preparation materials had been leaked online and investigated the incident independently. It's a reasonable reminder to ask any large firm, not just this one, how it verifies certification integrity across its full tester bench.

  • Best for: Enterprises and regulated organizations that want assessment, managed detection, and incident response from a single accountable vendor

  • Specialization: Technical assurance, managed detection and response, incident response, threat intelligence

  • Pricing: Not published, subscription for managed services, project-based for assessments

  • Clutch: Not on Clutch - verify via direct reference


3. RaftLabs

RaftLabs is a custom software development company, not a penetration testing firm and not a managed security provider. It belongs on this list for a narrower, more practical reason: most of the companies above sell an assessment or a monitoring subscription, but the findings from that work still need somewhere to live. Evidence has to be collected, controls have to be monitored between audits, and SOC analysts still need a workflow layer on top of whatever SIEM or PTaaS platform a company already runs. RaftLabs builds that software.

Their two most relevant practice areas are security compliance software, automated evidence collection and continuous control monitoring for SOC 2, ISO 27001, NIST CSF, and other frameworks, built for companies whose control environment doesn't map cleanly to Vanta or Drata, and security operations software, alert triage workflows, incident response case management, and analyst dashboards built on top of an existing SIEM. Engagements are scoped and fixed-price, and the team that scopes the work is the team that builds it.

The gap RaftLabs is built to close is specific. Off-the-shelf compliance platforms work well when a company's control environment maps cleanly to standard SaaS integrations, and RaftLabs will say so rather than sell a custom build a company doesn't need. The build makes sense once the environment includes proprietary data sources those platforms don't integrate with, internal systems without standard APIs, or a custom control framework the platform's control library doesn't cover. The same logic applies on the SOC side, where a SIEM detects and stores, but the triage, investigation, and reporting workflow around it is usually improvised.

Notable work: RaftLabs has shipped compliance-critical security platforms for clients including Vodafone, T-Mobile, Aldi, Nike, Cisco, and Lockheed Martin. Its security compliance builds automate evidence collection from cloud infrastructure and SaaS tools, monitor controls continuously rather than at a single point in time, and maintain an audit evidence library organized by control for SOC 2, ISO 27001, NIST, and custom frameworks. Its SOC platform work covers alert aggregation and triage across SIEM, EDR, and cloud tools, detection rule version control and testing, and incident case management with evidence collection and timeline tracking.

Pricing signal: $29-49/hr, fixed-price engagements. A focused single-framework compliance tool or a SOC alert-triage workflow with dashboard runs $25,000 to $70,000; a full platform spanning multiple frameworks, incident case management, rule governance, and playbook automation runs $70,000 to $150,000, delivered in 10 to 16 weeks at a cost fixed before development starts.

What to watch: RaftLabs does not run penetration tests, red team engagements, or managed detection and response. If what you need is an assessment of your existing security posture or 24/7 monitoring, hire one of the other seven companies on this list instead. What RaftLabs does well is building the compliance-evidence and SOC operational software that regulated teams and security operations centers run on day to day, once the assessment or monitoring relationship is already in place.

  • Best for: Companies that need custom compliance-evidence or SOC operational software built around their own control framework and detection logic, not an assessment or managed monitoring service

  • Specialization: SOC 2, ISO 27001, and NIST CSF compliance automation; SOC alert-triage and incident case management software; fixed-price engineering delivery

  • Pricing: $29-49/hr, fixed-price engagements from $25K

  • Clutch: 4.9/5 (50+ verified reviews)


4. TrustedSec

TrustedSec is a cybersecurity consultancy headquartered in Fairlawn, Ohio, founded by David Kennedy, a well-known name in the offensive security community as the creator of the Social-Engineer Toolkit and a former U.S. Marine Corps signals intelligence analyst. The firm built its practice on custom security engagements rather than a productized testing menu: remediation, purple team exercises, and security strategy work scoped to what a specific client's environment actually needs.

More than a decade in, TrustedSec reports having completed over 7,400 custom security engagements and uncovered seven zero-day exploits along the way, credentials that come from doing the work rather than marketing it. The team also maintains a visible public presence, delivering more than 50 conference talks a year, which gives a buyer an unusually large body of public material to check a firm's technical depth against before signing anything.

David Kennedy's own history is part of what a buyer is evaluating here. As the creator of the Social-Engineer Toolkit, a widely used open-source framework for testing an organization's susceptibility to phishing and social engineering, his name carries weight inside the practitioner community in a way that's independently verifiable through conference archives, published tooling, and public commentary, rather than resting solely on the company's own marketing copy.

Notable work: TrustedSec serves Fortune 500 companies and government entities and reports a 92% Net Promoter Score across its engagement history. Its zero-day discovery record and conference presence function as a public, checkable technical record in a market where most vendors ask a buyer to take their expertise on faith.

Pricing signal: Not published on the company's site. Engagements are scoped individually, consistent with the firm's positioning around custom work rather than a fixed-menu testing package.

What to watch: TrustedSec's strength is a deep technical engagement shaped around a specific environment, a different buying motion from a fast, standardized compliance-driven test. If what a company needs is a quick annual box-check for PCI DSS or a cyber-insurance questionnaire, a faster, more standardized PTaaS provider will get a report sooner.

  • Best for: Organizations that need a custom-scoped security engagement shaped around a specific environment rather than a standardized test package

  • Specialization: Custom penetration testing, purple team exercises, incident response, security strategy consulting

  • Pricing: Not published, engagement-based

  • Clutch: Not on Clutch - verify via direct reference


5. Cobalt.io

Cobalt is a Pentesting as a Service (PTaaS) platform that pairs a network of vetted freelance testers with a software layer for scoping, tracking, and remediating findings. The company built its practice on unbundling penetration testing from the traditional consultancy model: instead of booking a firm and waiting weeks for a report, a client launches a test through the platform and pulls findings directly into existing ticketing and remediation workflows as they're found.

The company describes its dataset as 13 years of real-world exploit data drawn from more than 5,000 pentests run annually through a pool of over 500 vetted testers it calls the Cobalt Core. That volume is the core pitch: standardized methodology and continuous availability, rather than a single firm's bench of consultants, delivered under a flexible credit-based subscription rather than a one-off statement of work.

The PTaaS category Cobalt helped establish exists because the traditional pentest cycle (scope, wait, receive a PDF weeks later) doesn't match how modern software ships. A team pushing code weekly can't operate on an annual testing cadence and call its security posture current. Platform-delivered testing turns penetration testing from an annual event into something closer to a continuous control. The tradeoff is some of the deep, adversary-specific customization a boutique red team engagement offers.

Notable work: Cobalt serves financial services, SaaS and technology companies, healthcare, and insurance clients, spanning small businesses through large enterprises. Its positioning around AI-assisted autonomous testing alongside human-led pentests reflects a broader shift in the PTaaS category toward blending automation with manual testing rather than replacing one with the other.

Pricing signal: Cobalt uses a credit-based subscription model that scales with testing volume rather than a flat hourly rate or a single fixed project fee; specific credit pricing isn't published and requires a quote.

What to watch: The PTaaS model trades the deep, sustained relationship of a boutique consultancy for speed and standardization. For a one-time, highly specialized assessment, a red team exercise against a specific threat model, for instance, a firm built around bespoke engagements may go deeper than a platform optimized for repeatable, scalable testing.

  • Best for: Companies that need recurring, platform-managed penetration testing integrated into existing remediation workflows

  • Specialization: Pentesting as a Service, application and cloud testing, AI-assisted and human-led hybrid testing

  • Pricing: Credit-based subscription, not published

  • Clutch: Not on Clutch - verify via direct reference


6. Praetorian

Praetorian is an offensive security firm that positions its staff as security engineers rather than consultants, built around adversarial emulation: testing a system the way an actual attacker would rather than running a standardized checklist. Its core offering is continuous threat exposure management delivered through a platform called Chariot, which combines automated discovery with hands-on security engineering to find exploitable vulnerabilities and guide remediation, not just list them.

The firm markets its team as drawn from computer scientists, software and security engineers, including open-source contributors and researchers, and leans on that framing to differentiate itself from firms that staff engagements with generalist consultants. Praetorian's own materials list Amazon, Google, Microsoft, Netflix, Salesforce, Stripe, Toyota, and Equifax among its customers, a client list spanning technology, retail, automotive, and financial services that points to engagements at meaningful technical depth.

The "material risk" framing is worth pressing on during a sales call. Plenty of firms promise to prioritize findings by severity, but the harder, more useful claim is prioritizing by what's actually reachable and exploitable given the rest of a company's specific environment, not a generic CVSS score. Ask a prospective vendor, Praetorian or otherwise, to walk through how a single finding moved from "theoretically possible" to "confirmed exploitable" in a past engagement. The answer tells you more about their methodology than any platform demo will.

Notable work: Praetorian's stated focus on "material risk," identifying what's actually exploitable rather than every theoretical finding, is the throughline across both its client list and its Chariot platform positioning.

Pricing signal: Not published. Engagements combine platform access (Chariot) with hands-on security engineering time, and pricing is quoted per scope.

What to watch: Praetorian's engineering-first framing and enterprise client list point to a firm built for organizations with technically mature internal teams that want a peer-level adversarial partner. Smaller organizations earlier in their security maturity may get more value from a firm built around guiding a first-time engagement, not just executing one.

  • Best for: Technically mature organizations that want continuous adversarial testing paired with a platform, not just a periodic report

  • Specialization: Continuous threat exposure management, adversarial emulation, exploit-focused offensive security

  • Pricing: Not published, platform plus engagement-based

  • Clutch: Not on Clutch - verify via direct reference


7. BreachLock

BreachLock is a PTaaS provider headquartered in New York with an additional office in Amsterdam, built around combining continuous attack surface management, autonomous adversarial exposure validation, and certified human-led penetration testing in a single platform. The company's pitch centers on triage: instead of handing a client a long list of theoretical vulnerabilities, BreachLock says its models are trained on more than 40,000 real-world penetration tests to help surface which findings are actually exploitable.

BreachLock reports serving more than 1,200 customers across over 20 countries and is CREST-certified, with testers holding OSCP and OSCE certifications, the same accreditations that anchor credibility for the boutique firms on this list. The company was named a Representative Vendor in Gartner's 2026 Market Guide for Adversarial Exposure Validation, third-party analyst recognition rather than a self-reported claim, and its platform supports compliance mapping across SOC 2, PCI DSS, ISO 27001, HIPAA, GDPR, and NIST.

Being named in an analyst market guide is a meaningfully different signal than a vendor's own case study page, because Gartner's inclusion criteria and category definitions are set independently of any single vendor's marketing. For a compliance-heavy buyer trying to shortlist a PTaaS vendor without running a full bake-off, third-party analyst placement is one of the few genuinely external checks available before a contract is signed.

Notable work: BreachLock's own materials list Bosch, EY, and DocuSign among its customers, spanning manufacturing, professional services, and technology. The company reports a 5.0 out of 5.0 rating on Gartner Peer Insights based on verified customer reviews.

Pricing signal: Not published in specific dollar figures. Access is structured as subscription-based platform access covering continuous attack surface management and scheduled PTaaS engagements rather than a single project invoice.

What to watch: BreachLock's platform-first model suits an organization that wants continuous coverage and audit-ready reporting across a compliance calendar. A company that needs a single, deep, adversary-specific red team simulation rather than ongoing coverage may be better served by a firm built around that one engagement type.

  • Best for: Organizations that need continuous, compliance-mapped penetration testing across multiple frameworks rather than a single annual test

  • Specialization: PTaaS, attack surface management, adversarial exposure validation, compliance-mapped reporting

  • Pricing: Subscription-based platform access, not published

  • Clutch: Not on Clutch - Gartner Peer Insights 5.0/5.0


8. Rapid7

Rapid7 is a publicly traded cybersecurity company (NASDAQ: RPD) headquartered in Boston, Massachusetts. Unlike the boutique and PTaaS firms elsewhere on this list, Rapid7 built its business around software products first, vulnerability management (InsightVM), managed detection and response, and its Command Platform, with professional services layered on top, including penetration testing, incident response, and continuous red teaming.

The company's most widely recognized asset in the security community is Metasploit, the open-source penetration testing framework it acquired in 2009 and has maintained as both a free tool and a commercial product since. Rapid7 also maintains Velociraptor, an open-source digital forensics and incident response tool, giving it a rare footprint in the tooling that security teams use daily, not just the services layered on top of it. The company reports serving more than 11,500 customers worldwide.

Metasploit's position is unusual in cybersecurity. Because the framework is open source and freely available, it's simultaneously one of the most widely used tools by professional penetration testers and one of the most widely used tools by actual attackers. Rapid7 has spent two decades keeping it useful for defenders while its exploit modules stay public knowledge, a balancing act that gives the company a different kind of standing in the security community than a firm that only sells services.

Notable work: Rapid7 Labs functions as a public research and threat intelligence arm, publishing vulnerability research and threat analysis that the wider security community, customers and non-customers alike, draws on directly.

Pricing signal: Not published for professional services engagements. Rapid7's product lines have historically used tiered subscription pricing; penetration testing and incident response services are quoted per engagement.

What to watch: Rapid7's strength is breadth, one vendor spanning vulnerability management software, managed detection and response, and testing services, which suits an organization that wants to consolidate tooling and services under a single contract. A company that specifically wants an independent, adversarial second opinion should think carefully about using the same vendor for both its detection tooling and the penetration test that's supposed to find gaps in it.

  • Best for: Organizations that want vulnerability management software, managed detection and response, and testing services from one consolidated vendor

  • Specialization: Vulnerability management, managed detection and response, penetration testing, digital forensics tooling

  • Pricing: Tiered subscription for products, engagement-based for services

  • Clutch: Not on Clutch - verify via direct reference

Side-by-side comparison

CompanyPrimary strengthTypical engagementPricing
Bishop FoxElite offensive security, Fortune 100 client baseProject-based, premium tierNot published
NCC GroupFull-service assurance, managed detection, incident responseEnterprise, subscription plus projectNot published
RaftLabsCompliance and SOC operational software, fixed price$25K-$150K, 10-16 weeks$29-49/hr
TrustedSecCustom-scoped consulting, zero-day track recordProject-based, engagement-scopedNot published
Cobalt.ioPTaaS, standardized continuous testingCredit-based subscriptionNot published
PraetorianContinuous adversarial emulation, engineer-ledPlatform plus engagementNot published
BreachLockCompliance-mapped PTaaS, attack surface managementSubscription, multi-frameworkNot published
Rapid7Consolidated vulnerability management, MDR, and testingProduct subscription plus servicesTiered subscription

The question that separates penetration testing firms from managed security providers

The most common mistake in procuring cybersecurity services is treating "penetration test" and "managed security" as the same purchase decision with different vendors attached to it. They are two different products solving two different problems, and picking the wrong one wastes the budget no matter how good the vendor is.

Bishop Fox, TrustedSec, Praetorian, Cobalt.io, and BreachLock all operate primarily in the first category: a defined scope, a testing window, and a report, or in Cobalt's and BreachLock's platform-driven models, a continuous stream of findings mapped to that same point-in-time logic. This is what a company buys to answer "can someone break in right now, and how." It's also what a compliance framework like PCI DSS or SOC 2 typically requires on an annual cadence.

NCC Group and Rapid7 both also run managed detection and response as a core service line, continuous monitoring, alerting, and response delivered as an ongoing subscription rather than a bounded engagement. This is what a company buys to answer "is someone breaking in right now," a fundamentally different question that a once-a-year penetration test report can't answer on its own.

Getting the model wrong is more expensive than getting the vendor wrong. A company that buys a one-time red team engagement expecting ongoing monitoring will have a gap between engagements that nobody is watching. A company that buys a monitoring subscription expecting a definitive answer on exploitable vulnerabilities will get alerts, not an assessment. And a company that buys neither, and instead hires a firm like RaftLabs to build the software layer connecting the two, needs an assessment or a monitoring relationship already in place first. The software has nothing to automate until there's a testing or detection program generating the evidence and alerts it operates on.

A useful gut check before signing anything: ask the vendor to describe, in one sentence, what happens the day after the engagement ends. A penetration testing firm should describe a report, a debrief call, and a retest window. A managed security provider should describe an ongoing dashboard, an escalation path, and a named point of contact. If the answer is vague on either side, the scope wasn't defined clearly enough before the contract was signed.

"Security is a process, not a product." - Bruce Schneier, security technologist, from The Process of Security (2000)

According to Verizon's 2026 Data Breach Investigations Report, which analyzed incidents between November 2024 and October 2025, 31% of breaches now originate from software vulnerabilities, putting exploited software ahead of stolen credentials as the leading entry point in this year's analysis. The same report found that 48% of breaches involve ransomware, though the report also notes that ransom payouts are declining as more organizations decline to pay. That shift toward software vulnerabilities as the leading entry point is the practical argument for penetration testing as a recurring discipline instead of a once-a-year compliance exercise. The vulnerability that gets exploited next year likely doesn't exist in the codebase being tested today, and a report written eighteen months ago says nothing about it.

Five questions to ask before signing

None of these questions are about price, on purpose. Price is the easiest thing to compare and the least useful predictor of whether an engagement will actually find something that matters. Ask these five instead, and treat a vague or deflected answer to any of them as a reason to keep shopping.

1. Can you show me a redacted sample report from an engagement similar to mine?

Not a sales deck. An actual findings report, redacted for client confidentiality, showing how issues are described, rated, and mapped to remediation steps. A vague or overly polished sample is a signal that the firm's real deliverables look thinner than its marketing.

2. What certifications do the specific people assigned to my engagement hold, not just the company?

A firm can be CREST-accredited at the organizational level while staffing a specific test with a junior tester still working toward OSCP. Ask for the certifications and tenure of the individuals actually doing the work, not the aggregate credentials on the company's about page.

3. Is remediation retesting included, or is it a separate line item?

A penetration test that ends at the findings report, with no verification that fixes actually closed the gaps, is half a deliverable. Confirm whether a retest is bundled into the original scope or billed as a second engagement, and get the answer in writing before signing.

4. What is your protocol for testing production systems without causing an outage?

Aggressive testing against a live production environment can take down the system it's meant to secure. Ask what safeguards are in place, staging environment options, rate limits on active exploitation attempts, and a clear communication channel if something breaks mid-test.

5. If your team finds evidence of an active, ongoing compromise, what happens next?

A penetration test occasionally surfaces a real intrusion already in progress, not a hypothetical vulnerability. Ask what the firm's obligation and process is in that scenario: do they stop and notify immediately, is incident response a separate engagement, and how fast can they mobilize if the answer is yes.

The verdict

Bishop Fox for enterprise and high-growth tech companies that want offensive security testing at Fortune 100 depth.

NCC Group for organizations that want assessment, managed detection, and incident response from one accountable, publicly listed vendor.

RaftLabs for companies that need custom compliance-evidence or SOC operational software built around their own framework, not another assessment.

TrustedSec for a custom-scoped engagement shaped around a specific environment, backed by a public zero-day and conference-talk track record.

Cobalt.io for recurring, platform-managed penetration testing that plugs into existing remediation workflows.

Praetorian for technically mature organizations that want continuous adversarial testing paired with a platform.

BreachLock for continuous, compliance-mapped testing across multiple frameworks and a Gartner-recognized platform.

Rapid7 for organizations that want vulnerability management software, managed detection and response, and testing services under one contract.

The mistake to avoid is picking a vendor before deciding which of these products a company is actually buying. A one-time report and a continuous monitoring subscription solve different problems, and no amount of vendor quality fixes a mismatched model. Write down the question the engagement needs to answer before requesting a single quote, whether it's "can someone break in right now," "is someone breaking in right now," or "where does the evidence for our next audit come from," and the right shortlist gets a lot shorter on its own.


RaftLabs builds the compliance-evidence and security-operations software that regulated teams and SOC analysts run on, not the penetration test itself. Fixed price, 10-16 week delivery, 4.9/5 on Clutch. Talk to a founder about the software layer behind your security program.

Ask an AI

Get an instant summary of this post from your preferred AI assistant.

Frequently asked questions

Published industry guidance typically frames a focused external network or web application penetration test in the $5,000 to $15,000 range. Red team engagements, multi-asset programs, or continuous PTaaS subscriptions covering ongoing testing across a full attack surface commonly run well past $50,000 a year. The biggest cost driver is scope, how many applications, network segments, and environments are in play, not the number of days on-site.
A vulnerability scan is automated: software checks systems against a database of known weaknesses and returns a list, often with false positives mixed in. A penetration test is human-led: a tester actively attempts to exploit weaknesses the way a real attacker would, chains smaller issues into a larger compromise, and confirms which findings are actually exploitable. Most compliance frameworks that require a 'penetration test' will not accept a vulnerability scan as a substitute.
OSCP (Offensive Security Certified Professional) and OSCE (Offensive Security Certified Expert) are the most widely recognized individual tester credentials. At the organizational level, CREST accreditation signals the firm itself has passed a structured technical and process audit, not just its individual staff. Ask for the certifications held by the specific people assigned to your engagement, not just the logos on the company's homepage.
PTaaS delivers penetration testing through a software platform rather than a traditional statement-of-work engagement. Findings appear in a dashboard as they're discovered, integrate directly with ticketing tools, and testing can be scheduled continuously rather than as a single annual event. Cobalt.io and BreachLock, both on this list, are built around this model. The tradeoff is standardization and speed over the deep, bespoke relationship a boutique consultancy offers.
Most compliance frameworks, including PCI DSS and SOC 2, require at least an annual penetration test, plus a retest after any significant change to the environment being tested, a new application, a major infrastructure migration, or a material network change. Organizations with a fast release cadence or a large attack surface often move to continuous or quarterly testing rather than waiting for the annual compliance deadline to find out what changed.
Not in the penetration-testing or managed-security sense. RaftLabs is a custom software development company that builds the compliance-evidence and security-operations software regulated teams and SOC analysts run on. That includes SOC 2 and ISO 27001 evidence automation, continuous control monitoring, and SOC alert-triage or incident-response case management built on top of an existing SIEM. Fixed-price engagements, 10 to 16 weeks, $29-49/hr, 4.9/5 on Clutch across 50+ verified reviews.

Stay on topic

More on compliance & security