PTaaS pricing has a transparency problem: most pentest as a service vendors won't print a number until you've sat through a demo, filled in a lead form, and met an account executive with a discount that expires Friday. That's not because the math is hard. It's because the model is the product. So here's the structure instead: PTaaS gets priced three ways (credit packages, per-target subscriptions, and fixed-scope quotes delivered through a platform), and once you know which model you're looking at, you know exactly which questions expose the real cost. Affordable Pentesting sits at the fixed-quote end of that spectrum, and we'll get to why, but this isn't a pitch dressed as a guide. It's the pricing anatomy nobody's sales deck shows you.
The three models, and who each one favors
Every PTaaS offer you'll see this year is one of these under the paint:
| Model | How you pay | What moves the number | Watch for |
|---|---|---|---|
| Credits | Annual package of testing units | Credits per test, set by asset complexity | Expiring credits, opaque conversion rates |
| Per-target subscription | Flat annual fee per app or asset | Target count and tier features | How a target is defined, auto-renewal |
| Fixed-scope quote | One price for a defined engagement | Scope size and testing depth | Whether retesting is included |
Credits favor big programs that test constantly and can actually forecast usage. Per-target subscriptions favor teams with one or two stable apps. Fixed quotes favor anyone who needs a defined test and a defined report by a defined date, which describes most SMBs with an auditor or a customer waiting.
The numbers vendors actually publish
We promised no invented figures, so everything with a dollar sign here comes from a vendor's own public pricing page, checked in August 2026.
Astra Security is the rare PTaaS vendor that prints prices. Its published plans run per target, per year: a Pentest Auto tier at $2,999, a Pentest Expert tier at $5,999 that adds manual testing by certified pentesters, and an Enterprise tier starting at $9,999, alongside scanner-only plans from $699 to $1,999. Just as instructive is how Astra defines a target: one SaaS app with all its APIs counts as one target, but your customer dashboard and your admin dashboard with separate logins count as two. That definition, not the sticker, is where your real total gets decided.
Cobalt, widely credited with pioneering PTaaS, publishes its model but not its rates. A Cobalt Credit equals 8 hours of testing effort, credits are sold in annual packages, and the number of credits an asset consumes depends on scope and complexity. Its published tier grid answers a different question, which features sit behind which tier: faster start times at higher tiers, retesting included, and credits that don't roll over into the next contract year (the top tier allows up to 10 percent). The dollar figure itself is quote-only. That's not an accident, and it's not unique to Cobalt. When the unit is abstract, comparing vendors takes real work.
So the honest market picture looks like this: published per-target plans from the low four figures to five figures a year depending on depth, credit programs that only make sense at volume, and a large quote-only middle where the price reflects your procurement patience as much as your scope.
Two caveats before you screenshot any of that into a budget deck. First, published prices move, so treat the vendor's live pricing page as the source of truth and this post as the map to reading it. Second, the sticker is never the total: overage on extra targets, add-on scans, and seat expansions all land after you've signed, which is why the renewal quote deserves more scrutiny than the first one. Ask what last year's customers paid at renewal versus signing. It's a rude question, and the answer's worth real money.
What actually moves the number

Scope is the big lever: how many targets, how big each one is, how many endpoints and roles a tester has to cover. Depth is the second: automated scanning with human validation costs a fraction of genuine manual testing, which is why the same vendor's tiers can sit thousands of dollars apart. Then come the quiet multipliers: retest windows (is verifying your fixes included, or a change order?), platform seats and SSO gated to higher tiers, compliance-branded reports sold as add-ons, and multi-year terms traded for discounts. If you're evaluating continuous penetration testing rather than a point-in-time engagement, the subscription framing is at least honest, since you're genuinely consuming the service year-round. If you needed one credible report for one audit, it's twelve months of platform for two weeks of testing.
The subscription math nobody does out loud
Here's the exercise a sales deck never walks you through. Take the annual subscription price. Subtract what the automated scanning would cost from a standalone scanner vendor. Divide the remainder by the hours of human testing you'll actually receive. That's your effective hourly rate for expertise, and it's the only number that lets you compare a credit package, a per-target plan, and a fixed quote side by side. Vendors don't hate this math because it's unfair. They hate it because it's clarifying.
Run it and you'll notice something: for a company that tests once or twice a year, the fixed-scope quote usually wins, and it isn't close. The subscription earns its keep when you ship weekly, when findings need to flow into Jira the moment they're confirmed, and when someone on your team will actually log into that dashboard in month seven. No shame in either answer, but you should know which company you are before you sign.
There's also a middle path vendors don't advertise because it doesn't recur: buy the fixed-scope test now, and if you genuinely find yourself wanting quarterly testing a year from now, upgrade then with a working relationship and a baseline report already in hand. Nobody's ever been hurt by starting with the smaller commitment. Plenty of teams are still paying for dashboards they stopped opening in February.
How to buy it without overpaying

List your targets first, in writing, before any demo, because every model prices off that list and a vague list gets priced defensively. Pick the model that matches your testing cadence, not the one with the best-looking dashboard. Get at least one quote from each model so the comparison keeps everyone honest. Probe the fine print with the questions from the checklist above, especially credit expiry and retest terms. Then book the window, because tester availability, not paperwork, is what actually sets your start date. Choosing the vendor itself is a bigger topic, and our guide to choosing a penetration testing provider covers the vetting side: certifications, sample reports, and who's actually doing your testing.
PTaaS pricing questions worth asking out loud
Is PTaaS cheaper than a traditional pentest?
Per test, often no. The pitch isn't that it's cheaper, it's that it's faster to start and continuous. If a vendor claims both cheaper and deeper, ask them to show the manual hours in writing, because one of those claims is usually decorative.
What does a credit actually buy me?
Whatever the vendor's scoping team says it buys, which is the problem. Cobalt at least defines the unit publicly, 8 hours of testing effort. Before you buy any credit package, get the conversion for your specific assets in writing, and ask what happens to credits you don't use. The common answer is that they expire with the contract year.
Do I need a PTaaS platform to pass SOC 2?
No. Your auditor needs credible testing evidence. Nothing in SOC 2 orders a pentest outright (CC4.1's illustrative points of focus are as close as the criteria come), but auditors ask for a report anyway, and a fixed-scope test with a retest letter satisfies that just as well as a platform subscription. Buy the platform if your engineering workflow will use it, not to make an auditor happy.
Why won't most vendors publish prices?
Because scope varies, sure, but plumbers face that too and still print call-out rates. The fuller answer is that quote-only pricing lets vendors price the buyer, not just the work: your industry, your funding, your urgency. It's also why two companies with near-identical apps can pay very different amounts for the same tier. Getting a second quote is the entire defense, and it costs you a day.
Are multi-year deals worth the discount?
Only if you'd buy year two anyway at full price. A discount for committing to a service you haven't experienced yet isn't a discount, it's the vendor buying down their churn risk with your money. If the year-one experience is great, they'll still want your year-two signature, and you'll negotiate it from a far stronger seat. The exception is a genuinely stable program, multiple apps on a known cadence, where locking rates against price increases makes defensible sense.
Put a number on it before the demo
You now know the three models, the two vendors who publish, and the one piece of math that makes them comparable. What's left is your own number. Ours takes a two-minute scoping form and comes back as a fixed quote with manual testing, a retest, and a report your auditor will accept, no credits, no seat licenses, no renewal surprise. Start with a pentest quote, or look at what a booked test includes first if you'd rather see the deliverable before you share your scope.
