Pen Testing Vendor Comparison

NetSPI, Cobalt, Synack, NCC Group, Coalfire, Kroll, Bishop Fox, GuidePoint, IBM X-Force Red, Mandiant, Horizon3.ai and FireCompass compared side by side — human-led, PTaaS, researcher-pool and autonomous testing, with pricing and turnaround where each publishes them.

Research date: August 27, 2026

Filter vendors

Capability

Reset

Delivery model — any

Leave every box clear to match any.

Geographic coverage — any

Leave every box clear to match any.

Best-fit company size — any

Leave every box clear to match any.

Compliance / regulatory specialty — any

Leave every box clear to match any.

18 of 18 vendors match the selected filters.

Start here — which of these is for you

Shortlists drawn from the same research as the tables below. They are a starting point for a conversation, not a ranking: nobody here has paid for placement and no vendor has been briefed on this page.

Closest overall competitors to NetSPI's enterprise PTaaS balance

  • Cobalt — PTaaS with a strong AppSec/DevSecOps focus
  • Coalfire — PTaaS (Security On Demand) combined with deep compliance consolidation
  • GuidePoint Security — consulting plus PTaaS / automated controls validation

Best for large, multinational, or heavily regulated financial-sector organizations

  • NCC Group — CBEST, STAR-FS, TIBER-EU, iCAST, AASE, FEER, CORIE, and DORA TLPT threat-led testing frameworks
  • Kroll — 700+ cyber experts across 19 countries, positioned for high-risk or heavily regulated companies
  • Mandiant / Google Cloud — premium threat-led consulting informed by real incident investigations

Best compliance-framework consolidation in a single provider

  • Coalfire — penetration testing alongside PCI, FedRAMP, IRAP, BSI C5/TISAX, ISMAP, ECC/SAMA, ENS, and 100+ frameworks overall

Best large-scale crowdsourced / researcher-pool model

  • Synack — 1,500+ vetted researchers (Synack Red Team), FedRAMP Moderate authorization, and the broadest published compliance-framework list of any vendor here (PCI DSS, HIPAA, SOC 2, FISMA, NIS2, DORA, GDPR, NIST)

Best fast, AppSec / DevSecOps-oriented PTaaS

  • Cobalt — 500+ vetted security experts (Cobalt Core), PTaaS/on-demand plus a separate Autonomous Pentest product
  • NetSPI — mature PTaaS with broad technical coverage and workflow integration

Best for US federal / FedRAMP-facing engagements

  • Coalfire — FedRAMP penetration testing explicitly offered
  • Synack — FedRAMP Moderate authorization
  • GuidePoint Security — serves government among its target markets
  • Horizon3.ai NodeZero — NodeZero Federal is FedRAMP High Authorized (autonomous platform, not a CREST-accredited human-led test)

Best continuous / autonomous validation between formal human engagements

  • Horizon3.ai NodeZero — autonomous continuous internal attack-path validation, with a separate human-led compliance service available
  • FireCompass — agentic AI / continuous automated red teaming, with an expert-in-the-loop PTaaS option
  • Bishop Fox Cosmos — continuous offensive-security platform combining automation with expert-driven testing

Best premium, threat-intelligence-informed engagement

  • Mandiant / Google Cloud — strongly human-led, informed by real incident investigations
  • Kroll — human experts plus threat intelligence, 700+ cyber experts across 19 countries

Best specialist continuous-assurance platform for a mature security program

  • Bishop Fox — Cosmos continuous offensive-security platform, positioned for mid-market and enterprise organizations with relatively mature cybersecurity programs
If you need one shortlist rather than nine
  1. NetSPI — Best overall balance

    Human FTE testers, Strong enterprise scale, Mature PTaaS, Broad technical coverage, Workflow integration, Good fit for recurring enterprise testing

  2. NCC Group — Best global/regulatory candidate

    Multinational presence, Formal regulatory threat-led testing, Financial-sector frameworks, DORA/TIBER/CBEST-style capability, Critical-infrastructure fit

  3. Coalfire — Best compliance consolidation candidate

    Penetration testing, PCI, FedRAMP, SOC, HITRUST, ISO, Broad assurance/compliance expertise

  4. Synack — Best large-scale researcher model

    Large vetted researcher pool, Repeat/continuous testing, Broad asset coverage, Government use cases, Published human and AI options

  5. Cobalt — Best fast AppSec-oriented PTaaS

    Rapid startup, Web/API focus, DevSecOps fit, Human PTaaS, Geographic tester restrictions, Autonomous option

  6. Kroll or Mandiant — Premium benchmark bidder

    Include at least one premium threat-intelligence / traditional consulting vendor to gauge what additional value premium services deliver, whether real-world threat intelligence changes the outcome, and whether the price premium is justified.

Executive comparison

Pen testing vendors matching the current filters
VendorCRESTDelivery Model Human vs. AutomationRegions Served Best Organizational FitEstimated / Published Engagement
NetSPI Yes Enterprise PTaaS / continuous / project-based Human-led; AI/automation amplifies testers North America, Europe, APAC Mid-market through very large enterprise Estimated: $15,000–$40,000 (conventional medium engagement)
Cobalt Yes PTaaS / on-demand; also a separate Autonomous Pentest product Human-led PTaaS + AI augmentation; separate Autonomous Pentest offering Global / remote Startup/SMB through enterprise Estimated: $10,000–$30,000 (human PTaaS, medium engagement, quote-based)
Synack Yes PTaaS / vetted researcher pool / AI Vetted human researcher pool + AI-led option Global / remote Mid-market through global enterprise and government Published Price (starting): Sara Pentest (agentic AI) $4,181; Synack Standard (1 human pentester) $10,283; Synack14 (14-day team) $27,120; Synack365 (continuous) quote-based
NCC Group Yes Traditional consulting + continuous assurance Expert human testing + automated scanners/proprietary tooling APAC, Europe, Middle East, North America Large enterprise, multinational financial institutions, critical infrastructure, government Estimated: $15,000–$50,000 (standard projects)
Coalfire Yes Traditional consulting + Security On Demand (DivisionHex) Human consultants + tooling Europe, North America Mid-sized through major enterprise, especially regulated companies Estimated: $12,000–$40,000 (standard engagement)
Kroll Yes Consulting / threat-led Human experts + threat intelligence APAC, Europe, North America Large/global organizations and high-risk or heavily regulated companies Estimated: $15,000–$50,000 (standard engagement)
Bishop Fox Yes Specialist consulting + Cosmos continuous offensive security platform Human-led (traditional); Cosmos combines automation + expert-driven testing Europe, North America Mid-market and enterprise organizations with relatively mature cybersecurity programs Estimated: $15,000–$50,000 (traditional engagement)
GuidePoint Security Yes Consulting + PTaaS / automated controls validation Hands-on human assessments + automation; separate PTaaS/controls-validation model North America (published footprint) US mid-market through major enterprise and government Estimated: $10,000–$35,000 (standard engagement)
IBM X-Force Red Yes Enterprise consulting Expert human hackers + automation for discovery/prioritization/efficiency APAC, Europe, Middle East, North America Large and very large multinational enterprise Estimated: $20,000–$60,000 (conventional engagement)
Mandiant / Google Cloud Yes Premium threat-led consulting Strongly human-led, informed by real incident investigations Europe, Middle East Large to very large organizations, high-risk businesses, mature security programs Estimated: $20,000–$75,000 (conventional pentest)
Horizon3.ai NodeZero None found Autonomous pentesting platform + separate human compliance service Primarily autonomous (human-assisted compliance service available) Global / SaaS, US Federal (NodeZero Federal) Organizations of many sizes, especially those needing continuous internal attack-path validation Estimated: $25,000–$100,000+/year (license)
FireCompass None found Agentic AI / continuous automated red teaming, with an expert-in-the-loop PTaaS option AI agents / automation, with an expert-in-the-loop option Global / SaaS Mid-size through large enterprise, particularly organizations with hundreds or thousands of applications/APIs Published Price (platform range): roughly $450–$2,500 per application
Sophos Yes Project-based testing + Security Services Retainer + adversary exercises Human-led; threat-intelligence informed North America, Europe, APAC Mid-market through global enterprise Quote-based — priced in Service Units, no published dollar rate
BreachLock Yes PTaaS — one-time, periodic or continuous; separate autonomous capability Human-led PTaaS with automation acceleration North America, Europe, APAC SMB through enterprise Quote-based — no BreachLock rate published
Raxis None found Project-based testing + manual PTaaS subscription + remote internal-testing appliance Strongly human-led; tooling supports testers North America SMB through enterprise Published Price: PTaaS from $25,000/year; project testing quote-based
Schellman Yes Project-based independent testing and compliance assessment Human consultant-led North America Regulated organizations and cloud/SaaS providers Published Price: external network from $14,500; authenticated web app from $30,000
Pen Test Partners Yes Consulting + PTaaS subscription / time-block model Human-led; automation as supporting tooling Europe, North America Mid-market and enterprise with unusual attack surfaces Quote-based — CREST project distribution published
Black Hills Information Security None found Project-based testing + ANTISOC continuous pentesting + Fusion AI-assisted external testing Strongly human-led; AI accelerates, humans sign off North America SMB through very large enterprise Quote-based — no published dollar rate

Pricing snapshot

Two figures, because a per-engagement price is the wrong question for anyone buying a testing program rather than a single test. Whether a figure is published by the vendor or estimated by this research is its own column — that difference matters more than the number.

Engagement and annual program pricing for the vendors matching the current filters
VendorBasisOne standard engagementAnnual program
NetSPI Estimated Estimated: $15,000–$40,000 (conventional medium engagement)
Cobalt Mixed Estimated: $10,000–$30,000 (human PTaaS, medium engagement, quote-based)
Synack Published Published Price (starting): Sara Pentest (agentic AI) $4,181; Synack Standard (1 human pentester) $10,283; Synack14 (14-day team) $27,120; Synack365 (continuous) quote-based
NCC Group Estimated Estimated: $15,000–$50,000 (standard projects)
Coalfire Estimated Estimated: $12,000–$40,000 (standard engagement)
Kroll Estimated Estimated: $15,000–$50,000 (standard engagement)
Bishop Fox Estimated Estimated: $15,000–$50,000 (traditional engagement)
GuidePoint Security Estimated Estimated: $10,000–$35,000 (standard engagement)
IBM X-Force Red Estimated Estimated: $20,000–$60,000 (conventional engagement)
Mandiant / Google Cloud Estimated Estimated: $20,000–$75,000 (conventional pentest)
Horizon3.ai NodeZero Estimated Estimated: $25,000–$100,000+/year (license)
FireCompass Mixed Published Price (platform range): roughly $450–$2,500 per application
Sophos Estimated Quote-based — priced in Service Units, no published dollar rate
BreachLock Estimated Quote-based — no BreachLock rate published
Raxis Published Published Price: PTaaS from $25,000/year; project testing quote-based
Schellman Published Published Price: external network from $14,500; authenticated web app from $30,000
Pen Test Partners Estimated Quote-based — CREST project distribution published
Black Hills Information Security Estimated Quote-based — no published dollar rate
How these estimates were arrived at

This tab is a best-effort compilation from public vendor research to make side-by-side comparison easier. It is not official information from any vendor, and it is not a substitute for a vendor engagement or RFP. For the most accurate or current information, visit each vendor's own website.

Services matrix

Two states, and deliberately not three. Documented means this research found the vendor listing that service. Not documented means it did not — which is not the same as the vendor confirming it does not offer it, and this page will not say the second when it only knows the first. Ask them directly.

Service types documented for each vendor matching the current filters
ServiceNetSPICobaltSynackNCC GroupCoalfireKrollBishop FoxGuidePoint SecurityIBM X-Force RedMandiant / Google CloudHorizon3.ai NodeZeroFireCompassSophosBreachLockRaxisSchellmanPen Test PartnersBlack Hills Information Security
Web application testing Documented Documented Documented Documented Documented Documented Documented Documented Documented Documented Not documentedDocumented Documented Documented Documented Documented Documented Documented
API testing Documented Documented Documented Not documentedNot documentedDocumented Not documentedNot documentedNot documentedNot documentedNot documentedDocumented Documented Documented Documented Documented Documented Documented
Mobile testing Documented Documented Documented Documented Documented Not documentedDocumented Not documentedDocumented Documented Not documentedNot documentedDocumented Documented Documented Documented Documented Not documented
Internal network testing Documented Documented Documented Documented Documented Documented Documented Documented Documented Documented Documented Not documentedDocumented Documented Documented Documented Documented Documented
External network testing Documented Documented Documented Documented Documented Documented Documented Documented Documented Documented Documented Documented Documented Documented Documented Documented Documented Documented
Cloud testing Documented Documented Documented Not documentedNot documentedDocumented Documented Documented Documented Documented Not documentedNot documentedDocumented Documented Documented Documented Documented Documented
Wireless testing Documented Not documentedNot documentedDocumented Documented Not documentedNot documentedNot documentedNot documentedNot documentedNot documentedNot documentedDocumented Not documentedDocumented Documented Not documentedNot documented
OT / ICS testing Documented Not documentedNot documentedNot documentedNot documentedNot documentedNot documentedDocumented Not documentedDocumented Not documentedNot documentedNot documentedNot documentedDocumented Not documentedDocumented Not documented
Hardware / IoT testing Documented Not documentedNot documentedNot documentedDocumented Not documentedDocumented Not documentedDocumented Documented Not documentedNot documentedDocumented Documented Not documentedDocumented Documented Not documented
AI / LLM testing Documented Documented Documented Not documentedNot documentedDocumented Not documentedNot documentedDocumented Not documentedNot documentedNot documentedNot documentedNot documentedDocumented Documented Not documentedDocumented
Social engineering Documented Not documentedNot documentedNot documentedDocumented Documented Not documentedDocumented Documented Documented Not documentedNot documentedDocumented Documented Documented Documented Not documentedDocumented
Physical testing Not documentedNot documentedNot documentedNot documentedDocumented Not documentedNot documentedDocumented Documented Documented Not documentedNot documentedDocumented Not documentedDocumented Documented Not documentedNot documented
Red team Documented Not documentedNot documentedDocumented Documented Not documentedDocumented Documented Not documentedDocumented Not documentedDocumented Documented Not documentedNot documentedDocumented Documented Documented
Purple team Not documentedNot documentedNot documentedNot documentedNot documentedNot documentedNot documentedDocumented Not documentedNot documentedNot documentedNot documentedDocumented Not documentedNot documentedDocumented Not documentedDocumented
Threat-led testing Documented Not documentedNot documentedDocumented Not documentedDocumented Not documentedNot documentedNot documentedDocumented Not documentedNot documentedDocumented Not documentedNot documentedNot documentedDocumented Not documented

Before you rely on this

Important disclaimer

Penetration Testing Vendor Disclaimer: EVULNABLE provides independent informational comparisons of penetration-testing providers. Accreditation, tester availability, delivery locations, regulatory capabilities, pricing, staffing, and service timelines can change. Information labeled Official/Verified or Published Price/Published Timeline is based on vendor or accreditation documentation available as of the listed verification date. Values labeled Estimated Price or Estimated Timeline are independent planning estimates and are not vendor quotes or SLAs. Company-size fit, shortlist rankings, and "best for" recommendations are labeled EVULNABLE Assessment because they are this tab's own independent judgment, not a vendor claim. Organizations should confirm the applicable legal entity, accreditation scope, tester residency, data residency, regulatory acceptance, pricing, and rules of engagement directly with the provider before contracting.

Independent Comparison Notice: EVULNABLE is an independent informational resource and is not affiliated with, sponsored by, endorsed by, or acting on behalf of the vendors listed on this page unless explicitly stated otherwise. Vendor names and trademarks are used solely to identify the products and services being discussed.

Market pricing context

Most enterprise pentest firms do not publish price lists or contractual lead-time SLAs. Where a vendor publishes a number, it is labeled **Published Price** below; everything else labeled **Estimated** is an independent planning/budget estimate, not a vendor quote. Current 2026 market data places many conventional penetration-testing engagements around **$10,000–$30,000** for a common/standard engagement (rough all-types market average: approximately **$18,300**). Complex cloud, enterprise, red-team, hardware, regulatory, or highly specialized work can exceed $50,000, $100,000, and in some advanced cases $150,000+. Source: Synack, "Penetration Testing Cost" — https://www.synack.com/blog/penetration-testing-cost/

Checkmarks reflect only the specific service types this research explicitly lists for each vendor. An unchecked box does not necessarily mean the vendor lacks that capability — confirm directly with the vendor. See the services matrix.

Request a correction — See outdated information? Vendor capabilities, pricing, certifications, and accreditation status can change. If you represent a vendor or notice information that may be outdated, use the link below to request a review or correction.

Export comparison

Pick the vendors to include, then download a self-contained PDF or Excel comparison. Each carries its own Methodology section, a Sources & Verification section with links, and the disclaimer, so the file stands on its own for procurement, management or legal review.

Vendors to include

Vendor profile

Cells above are trimmed to five lines; each vendor's full text is in the profile below, which the table's vendor names link to. One profile at a time — each vendor's record runs to forty-odd fields, and all twelve at once is a scroll nobody reads. Every profile is its own URL, so a link to one is a link you can send.

Pen Test Partners

CREST-accredited human-led

The specialists to call when the target is a ship, a car, a plane or a factory floor.

  • YesCREST
  • YesPTaaS / on-demand
  • NoContinuous testing
  • Not itemized in source research.First-engagement turnaround
CREST / accreditation
CREST member with Penetration Testing, Incident Response, Vulnerability Assessment, Application and Mobile Application Security Testing, and two Threat Led Penetration Testing accreditations. (verified as of August 27, 2026)
Other accreditations
ISO 27001, UK NCSC Cyber Essentials and Cyber Essentials Plus
Delivery model
Consulting + PTaaS subscription / time-block model
Human vs. automation
Manual testing with automation used to support testers. 100–499 employees per its CREST listing.
Tester pool / employment model
Not itemized in source research. — In-house testing organization
Tester locations
United Kingdom, United States
Regions served
Europe, North America
Geographic tester restrictions
Not itemized in source research.
Data residency
UK and U.S. offices. Confirm tester residency and data-storage location contractually.
Services tested
Web application testing, API testing, Mobile testing, Internal network testing, External network testing, Cloud testing, OT / ICS testing, Hardware / IoT testing, Red team, Threat-led testingAlso: compiled software and source-code review, automotive, aviation, maritime, and other connected systems.
Compliance / regulatory specialties
None itemizedThreat-led testing accreditations are the relevant credential for financial-sector frameworks.
Government / FedRAMP capability
Not itemized in source research.
Pricing
Quote-based — CREST project distribution publishedNo rate card. Its CREST listing reports the distribution of past security-testing projects: about 50% under £10k, 20% £10k–£25k, 10% £25k–£50k, 10% £50k–£100k and 10% £100k–£500k; red-team work splits evenly between £50k–£100k and £100k–£500k. That is where their work has landed historically, not a price you are quoted.
Estimated annual program
Not itemized in source research.
Retesting model
PTaaS can cover ongoing and change-based retesting. Traditional project retest terms are engagement-dependent.
Findings available live
Not itemized in source research.
API / workflow integration
Not itemized in source research.
Best-fit company size (EVULNABLE Assessment)
Mid-market and enterprise with unusual attack surfacesOT/ICS, automotive, aviation, maritime, connected devices, critical infrastructure and financial services — the environments where a generalist firm's methodology runs out.
Potential limitations / evaluation considerations (EVULNABLE Assessment)
Europe and North America only. Wireless, social engineering and physical testing were not itemized in this research — ask if you need them.

First-engagement timeline

Estimated elapsed time for a first engagement with Pen Test Partners
Scoping / QuoteContract & Onboarding Info / SetupRecon Active TestingReport After Testing Approx. Total Elapsed
Not itemized in source research.Not itemized in source research. Not itemized in source research.Not itemized in source research. Not itemized in source research.Not itemized in source research. Not itemized in source research.

Last verified: August 27, 2026

First-engagement turnaround

These figures assume a moderately complex web/API or network pentest, a responsive customer, no unusually complicated onsite work, no unusual regulator approval, and normal legal/procurement processes. These are planning estimates, not contractual vendor SLAs. The contract/procurement portion is particularly uncertain because the customer's own legal, purchasing, privacy, and vendor-risk review can take longer than the technical engagement itself. (bd = business days)

Estimated first-engagement elapsed time for the CREST-accredited vendors
VendorScoping / QuoteContract & Onboarding Info / SetupReconActive Testing Report After TestingApprox. Total Elapsed
NetSPI EST. 2–5 bdEST. 5–15 bd 1–3 bd1–2 bd 5–10 bdEST. 2–5 bd ~3–6 weeks
Cobalt 1–3 bdEST. 3–10 bd ~1 bdLargely integrated 5–10 bd typicalAt/near close ~2–4 weeks first time
Synack 1–3 bdEST. 3–10 bd 1–2 bdPlatform-assisted 5 or 14 days for published productsAt/near close ~2–4 weeks
NCC Group 2–5 bdEST. 5–20 bd 1–3 bd1–3 bd 5–10+ bd3–7 bd ~4–8 weeks
Coalfire 2–5 bdEST. 5–15 bd 1–3 bd1–2 bd 5–10 bd3–7 bd ~3–6 weeks
Kroll 2–5 bdEST. 5–20 bd 1–3 bd1–3 bd 5–10 bd3–7 bd ~4–8 weeks
Bishop Fox 2–5 bdEST. 5–15 bd 1–3 bd1–2 bd 5–10 bd3–5 bd ~3–6 weeks
GuidePoint Security 2–5 bdEST. 5–15 bd 1–3 bd1–2 bd 5–10 bd3–7 bd ~3–6 weeks
IBM X-Force Red 3–7 bdEST. 10–25 bd 1–5 bd1–3 bd 5–15 bd5–10 bd ~5–10 weeks
Mandiant / Google Cloud 3–7 bdEST. 10–25 bd 1–5 bd1–3 bd 5–15 bd5–10 bd ~5–10 weeks
Sophos Not itemized in source research.Not itemized in source research. Not itemized in source research.Not itemized in source research. Not itemized in source research.Not itemized in source research. Not itemized in source research.
BreachLock Not itemized in source research.Not itemized in source research. Not itemized in source research.Not itemized in source research. Not itemized in source research.Not itemized in source research. Not itemized in source research.
Raxis Not itemized in source research.Not itemized in source research. Not itemized in source research.Not itemized in source research. Not itemized in source research.Not itemized in source research. Not itemized in source research.
Schellman Not itemized in source research.Not itemized in source research. Not itemized in source research.Not itemized in source research. Not itemized in source research.Not itemized in source research. Not itemized in source research.
Pen Test Partners Not itemized in source research.Not itemized in source research. Not itemized in source research.Not itemized in source research. Not itemized in source research.Not itemized in source research. Not itemized in source research.
Black Hills Information Security Not itemized in source research.Not itemized in source research. Not itemized in source research.Not itemized in source research. Not itemized in source research.Not itemized in source research. Not itemized in source research.
Repeat testing after a Master Agreement is signed

After an MSA, security review, vendor onboarding, payment terms, standard legal terms, data-processing requirements, and procurement approval are complete, the operating model changes significantly — this is one of the main advantages of PTaaS. Cobalt publishes post-MSA test-start targets of approximately 1 business day (Enterprise), 2 business days (Premium), and 3 business days (Standard). Synack markets the ability to start testing in days rather than weeks or months. Traditional procurement often requires repeated scoping calls, quotes, SOW negotiation, purchase orders, scheduling, and consultant allocation — PTaaS attempts to remove or reduce these repeated delays, which can make it strategically useful even where the underlying pentest methodology is otherwise similar.

Reporting model comparison

Traditional consulting providers (NCC Group, Mandiant, IBM, Kroll, GuidePoint, Coalfire) generally produce a formal package — executive summary, technical findings, severity ratings, evidence, reproduction steps, business impact, remediation guidance, appendices, methodology, retest information — with the full report commonly following active testing. PTaaS changes the workflow because findings can appear while testing is still in progress: Cobalt findings appear live with a Cobalt Core Lead final review; NetSPI's manually validated findings appear in-platform and can enter remediation workflows before the final PDF; Synack vulnerabilities appear through the platform with patch verification and audit-ready reporting. For a vulnerability-management program, live findings can meaningfully reduce mean time to remediate and dependence on manual report parsing.

Selection guidance

How EVULNABLE Evaluates Vendors: Rankings and recommendations below (including the Recommended RFP Shortlist, the Automated Platform Pilot Recommendation, and the Overall Strategic Conclusion) are independent assessments based on documented capabilities, delivery model, accreditation, geographic availability, regulatory support, pricing transparency, and intended organizational fit. They do not represent vendor endorsements, paid placement, or guaranteed suitability for every organization.

Automated platform pilot recommendation

NodeZero and FireCompass should be evaluated separately from the human-provider RFP — they solve a different problem. A recommended model uses a CREST-accredited human provider as the formal assurance layer (annual/biannual formal pentests, regulatory testing, customer assurance, business-logic testing, complex adversarial simulation) and an autonomous/agentic platform as the continuous validation layer between human engagements (continuous attack-path validation, high-frequency testing, rapid exploitability confirmation, remediation verification, coverage of large environments, new-CVE response).

Option A: NetSPI + NodeZero

  • Strong human enterprise PTaaS
  • Continuous internal attack-path testing
  • Fast validation
  • Formal human reporting

Option B: NCC Group or Coalfire + FireCompass

  • Strong regulatory/compliance human testing
  • Continuous automated app/API/offensive testing
  • Useful for very large attack surfaces
Overall strategic conclusion

The organization should first decide whether it is buying a penetration-test vendor or building a repeatable enterprise penetration-testing program. For a one-off engagement, many traditional firms can satisfy the need. For a repeatable enterprise program, the providers that rise significantly in value are NetSPI, Cobalt, Synack, NCC Group, and Coalfire, because they combine repeat testing, continuous assurance, platform-based workflow, faster findings delivery, enterprise contracting models, programmatic testing, and regulatory support. Autonomous platforms such as Horizon3.ai NodeZero and FireCompass should not automatically replace human penetration testing — their strongest role is often complementing formal human engagements by providing much more frequent validation between those engagements.

The penetration-testing market splits into several distinct delivery layers, and an RFP should compare providers within a layer before comparing across them. **Traditional CREST-accredited human-led consulting.** NCC Group, Kroll, Bishop Fox, IBM X-Force Red, and Mandiant / Google Cloud remain the clearest formal-assurance providers — project-based engagements delivered by in-house expert teams, often the deliverable regulators and auditors expect by default. **PTaaS / pentest-on-demand.** NetSPI, Cobalt, Coalfire, and GuidePoint Security layer a platform — live findings, faster turnaround, workflow integration — on top of human testing, which suits organizations that need to test more often than a single annual engagement allows. **Researcher-pool / crowdsourced testing.** Synack is the clearest example: a large vetted external researcher pool rather than one firm's in-house staff, adding breadth and government-grade authorization (FedRAMP Moderate) that traditional single-firm staffing does not itemize. **Autonomous / agentic-AI comparators.** Horizon3.ai NodeZero and FireCompass are not CREST-accredited human-led providers and are not presented as equivalent to one; their strongest role is continuous, high-frequency validation between formal human engagements rather than replacing them. **Regulatory threat-led testing.** NCC Group and Kroll stand out for formal threat-led frameworks (CBEST, TIBER-EU, DORA TLPT, and similar) — a materially different deliverable from a standard scoped penetration test, and usually mandated rather than optional for the organizations that need it.

Global / local regulatory capability — procurement checklist (14 items)
Tester residency
Specify allowed and prohibited tester locations (e.g. US-only, US-person only, EU-only, UK-only, India allowed/not allowed, specific country restrictions).
Employees vs subcontractors / freelancers
Require the vendor to disclose employees, contractors, freelancers, researcher-pool members, and subprocessors.
Data residency
Specify where findings, screenshots, credentials, tokens, exploit artifacts, logs, reports, recordings, and test data may be stored.
Testing source locations
Document source IPs, source countries, VPN/bastion usage, and cloud testing regions.
Cross-border data transfer
Address GDPR, Standard Contractual Clauses, international transfer requirements, and local privacy requirements.
Background checks / clearances
Specify criminal background checks, government clearance, US-person requirements, and sector-specific requirements.
Regulatory mapping
Require explicit support/experience for relevant frameworks: PCI DSS, HIPAA, DORA, NIS2, TIBER-EU, CBEST, FedRAMP, CMMC, FISMA, SOC 2, ISO, HITRUST, and country-specific financial-sector frameworks.
Rules of engagement
Require written authorization, testing windows, prohibited systems, destructive-testing restrictions, emergency contacts, and escalation procedures.
Legal authorization by jurisdiction
Confirm testing is legal and contractually authorized in every affected jurisdiction.
Emergency stop mechanism
Require a documented method to immediately pause/stop testing.
Regulatory/auditor acceptance
Don't assume a generic report is acceptable — ask whether the deliverable is explicitly acceptable to customer auditors, regulators, PCI assessors, FedRAMP assessors, or other external assurance parties.
Accreditation scope
Verify whether CREST accreditation applies to the exact legal entity, region, service, and contracting organization.
Retesting
Clarify whether retesting is included, the number of retests, the retest window, cost, whether it produces an updated report, and whether only fixed findings are retested.
Workflow integration
Ask about ServiceNow, Jira, VM platform APIs, ticketing automation, findings API, webhooks, CSV/JSON export, SIEM/SOAR integration, and remediation workflow support.
Suggested enterprise RFP questions (38 items)

Scope & methodology

  • Which service types are covered (web, API, mobile, internal network, external network, cloud, wireless, OT/ICS, hardware/IoT, AI/LLM, social engineering, physical, red team, purple team, threat-led)?
  • Is testing manual/human-led, automated, or a hybrid, and what is the split?
  • What testing methodology or standard is followed (e.g. OWASP, PTES, NIST)?
  • Is business-logic testing included, or only automated/technical coverage?
  • Are exploitation and post-exploitation in scope, or discovery only?
  • How is scope defined, and can it be adjusted mid-engagement?

Tester qualifications & delivery model

  • Are testers employees, contractors, freelancers, or researcher-pool members?
  • What is the size of the tester pool or team assigned to this engagement?
  • What certifications do assigned testers hold (OSCP, OSCE, CREST, or similar)?
  • Are background checks, clearances, or US-person status required and available?
  • Is the delivery model traditional project-based, PTaaS/on-demand, continuous, researcher-pool/crowdsourced, or autonomous/agentic-AI?
  • Can the same tester(s) be requested for repeat engagements for continuity?

Reporting & retesting

  • Are findings available live during testing, or only in a final report?
  • How quickly is the final report delivered after testing concludes?
  • Is retesting included, and if so, how many retests and within what window?
  • Does retesting produce an updated report, or only confirm fixed findings?
  • Is the report format accepted by the organization's auditors, regulators, or customers as-is?
  • Can findings be exported via API, CSV, JSON, or pushed directly into a ticketing system?

Regulatory & compliance support

  • Which regulatory frameworks does the vendor explicitly support (PCI DSS, HIPAA, FedRAMP, DORA, NIS2, TIBER-EU, CBEST, SOC 2, ISO, or other regional frameworks)?
  • Is threat-led testing (TIBER-EU/CBEST/DORA TLPT-style) available if required?
  • Does the vendor hold CREST accreditation, and does it apply to the exact legal entity and service being contracted?
  • Is a FedRAMP-authorized option available if the engagement involves federal systems?
  • Will the vendor's deliverable be accepted by the organization's specific auditor or regulator without modification?

Data handling & residency

  • Where are findings, screenshots, credentials, exploit artifacts, and reports stored?
  • Are tester-location or citizenship restrictions available (e.g. US-only, EU-only)?
  • From what source countries or regions does testing traffic originate?
  • How does the vendor handle cross-border data transfer requirements (GDPR, Standard Contractual Clauses, or similar)?
  • What is the vendor's data retention and deletion policy after engagement close?

Workflow & integration

  • Is there a published API for findings, scheduling, or reporting?
  • Which ticketing/ITSM systems are natively supported (Jira, ServiceNow, or similar)?
  • Can findings be correlated with vulnerability-management or attack-surface-management data already in use?
  • Is continuous or always-on testing available, or only scheduled engagements?
  • Are webhooks or automated notifications available for new findings?

Pricing & contracting

  • Is pricing published, or quote-based per engagement?
  • What is the estimated cost for a standard engagement of this scope?
  • What is the estimated total elapsed time from scoping to final report?
  • Are multi-year or enterprise program pricing models available?
  • What is included versus billed separately (retesting, report revisions, expedited turnaround)?

About this comparison

Research date: August 27, 2026. See the disclaimer at the top of this page for sourcing and accuracy caveats. EVULNABLE has no commercial relationship with any vendor listed here.