| NetSPI |
Yes |
Enterprise PTaaS / continuous / project-based |
Human-led; AI/automation amplifies testers |
North America, Europe, APAC |
Mid-market through very large enterprise |
Estimated: $15,000–$40,000 (conventional medium engagement) |
| Cobalt |
Yes |
PTaaS / on-demand; also a separate Autonomous Pentest product |
Human-led PTaaS + AI augmentation; separate Autonomous Pentest offering |
Global / remote |
Startup/SMB through enterprise |
Estimated: $10,000–$30,000 (human PTaaS, medium engagement, quote-based) |
| Synack |
Yes |
PTaaS / vetted researcher pool / AI |
Vetted human researcher pool + AI-led option |
Global / remote |
Mid-market through global enterprise and government |
Published Price (starting): Sara Pentest (agentic AI) $4,181; Synack Standard (1 human pentester) $10,283; Synack14 (14-day team) $27,120; Synack365 (continuous) quote-based |
| NCC Group |
Yes |
Traditional consulting + continuous assurance |
Expert human testing + automated scanners/proprietary tooling |
APAC, Europe, Middle East, North America |
Large enterprise, multinational financial institutions, critical infrastructure, government |
Estimated: $15,000–$50,000 (standard projects) |
| Coalfire |
Yes |
Traditional consulting + Security On Demand (DivisionHex) |
Human consultants + tooling |
Europe, North America |
Mid-sized through major enterprise, especially regulated companies |
Estimated: $12,000–$40,000 (standard engagement) |
| Kroll |
Yes |
Consulting / threat-led |
Human experts + threat intelligence |
APAC, Europe, North America |
Large/global organizations and high-risk or heavily regulated companies |
Estimated: $15,000–$50,000 (standard engagement) |
| Bishop Fox |
Yes |
Specialist consulting + Cosmos continuous offensive security platform |
Human-led (traditional); Cosmos combines automation + expert-driven testing |
Europe, North America |
Mid-market and enterprise organizations with relatively mature cybersecurity programs |
Estimated: $15,000–$50,000 (traditional engagement) |
| GuidePoint Security |
Yes |
Consulting + PTaaS / automated controls validation |
Hands-on human assessments + automation; separate PTaaS/controls-validation model |
North America (published footprint) |
US mid-market through major enterprise and government |
Estimated: $10,000–$35,000 (standard engagement) |
| IBM X-Force Red |
Yes |
Enterprise consulting |
Expert human hackers + automation for discovery/prioritization/efficiency |
APAC, Europe, Middle East, North America |
Large and very large multinational enterprise |
Estimated: $20,000–$60,000 (conventional engagement) |
| Mandiant / Google Cloud |
Yes |
Premium threat-led consulting |
Strongly human-led, informed by real incident investigations |
Europe, Middle East |
Large to very large organizations, high-risk businesses, mature security programs |
Estimated: $20,000–$75,000 (conventional pentest) |
| Horizon3.ai NodeZero |
None found |
Autonomous pentesting platform + separate human compliance service |
Primarily autonomous (human-assisted compliance service available) |
Global / SaaS, US Federal (NodeZero Federal) |
Organizations of many sizes, especially those needing continuous internal attack-path validation |
Estimated: $25,000–$100,000+/year (license) |
| FireCompass |
None found |
Agentic AI / continuous automated red teaming, with an expert-in-the-loop PTaaS option |
AI agents / automation, with an expert-in-the-loop option |
Global / SaaS |
Mid-size through large enterprise, particularly organizations with hundreds or thousands of applications/APIs |
Published Price (platform range): roughly $450–$2,500 per application |
| Sophos |
Yes |
Project-based testing + Security Services Retainer + adversary exercises |
Human-led; threat-intelligence informed |
North America, Europe, APAC |
Mid-market through global enterprise |
Quote-based — priced in Service Units, no published dollar rate |
| BreachLock |
Yes |
PTaaS — one-time, periodic or continuous; separate autonomous capability |
Human-led PTaaS with automation acceleration |
North America, Europe, APAC |
SMB through enterprise |
Quote-based — no BreachLock rate published |
| Raxis |
None found |
Project-based testing + manual PTaaS subscription + remote internal-testing appliance |
Strongly human-led; tooling supports testers |
North America |
SMB through enterprise |
Published Price: PTaaS from $25,000/year; project testing quote-based |
| Schellman |
Yes |
Project-based independent testing and compliance assessment |
Human consultant-led |
North America |
Regulated organizations and cloud/SaaS providers |
Published Price: external network from $14,500; authenticated web app from $30,000 |
| Pen Test Partners |
Yes |
Consulting + PTaaS subscription / time-block model |
Human-led; automation as supporting tooling |
Europe, North America |
Mid-market and enterprise with unusual attack surfaces |
Quote-based — CREST project distribution published |
| Black Hills Information Security |
None found |
Project-based testing + ANTISOC continuous pentesting + Fusion AI-assisted external testing |
Strongly human-led; AI accelerates, humans sign off |
North America |
SMB through very large enterprise |
Quote-based — no published dollar rate |