Short answer: Continuous pentesting has no single price. Published 2026 figures include $2,500 a month, billed annually, for 12 assessments across up to three apps (Noscope), and $20,000 to $100,000 or more a year for PTaaS subscriptions (Synack). The number of apps, cadence, depth and human review hours set your price. Checked 2026-09-26.
You've been asked to budget for continuous pentesting, and the three quotes on your desk don't line up. One vendor sells four tests a year, another a monthly subscription, and a third sells credits worth eight tester-hours each.
They aren't pricing the same thing. This page lays out what vendors publish, what moves the number and what to ask before you sign. If you're pricing a single test, how much a penetration test costs covers that.
How do vendors price continuous pentesting?
There are four common models: a bundle of tests used over a year, a PTaaS subscription paid in credits or tester time, a per-target annual plan, and a platform fee with testing on top. Most vendors don't publish the price of an always-on program. The table shows what they do publish, read from each vendor's own page on 2026-09-26.
| Vendor | Pricing model | Published price | What the price covers |
|---|---|---|---|
| Intruder | Per test, or a bundle | $3,500 per test, or $12,000 for a pack of 4 used within a year. Continuous pentesting is quoted separately | White-box web app pentest with CREST-certified experts, unlimited retesting |
| Cobalt | Credits in annual packages | Credit prices are quote-only. One credit is 8 hours of testing. Autonomous Pentest is $3,500 per test (offer runs to 2026-12-31) | Human and AI testing, unlimited on-demand retesting for the contract term, on every tier |
| Noscope | Subscription | $2,500 a month, billed annually | 12 pentest assessments a year across up to 3 applications |
| Astra | Per target per year | $2,999 a year (Pentest Auto) or $5,999 (Pentest Expert) for one target. The plan with continuous autonomous pentesting starts at $9,999 a year | Autonomous or manual pentest, 1 or 2 human re-scans, multiple targets on the top plan |
| Equixly | Per test, or platform | €4,999 per API pentest. The platform with unlimited tests is custom | Agentic API testing, report within 2 days |
| Aikido | Per assessment, or custom | $4,000 per assessment. Continuous testing is custom | One app with one set of APIs per assessment |
| BreachLock | Packages | Quote only | 1 or 2 free manual retests, depending on package |
| Escape | Platform | Quote only | Continuous DAST and API testing |
| Barrion | Credits per run, program scoped | Per-run level prices on pricing. Continuous programs are scoped with sales | AI pentest of web apps and APIs, retest included, expert review from Standard up |
For a market-wide view, Synack's 2026 cost guide puts an annual PTaaS subscription at $20,000 to $100,000 or more, against $10,000 to $30,000 for a typical single engagement.
We don't publish a continuous price either. A daily light pass on one app and a weekly deep run on twelve APIs are different purchases, and one list price would be wrong for almost everyone.
What drives the cost of continuous pentesting?
Seven things, and the first three do most of the work.
| Cost driver | Why it moves the price | What to pin down |
|---|---|---|
| Number of apps and APIs | Each target is tested on its own, every time | Does one API with 40 endpoints count as one target or several? |
| Cadence | More runs per year means more testing work | Is the rhythm fixed, or can runs fire only when the app changed? |
| Depth per run | A quick pass and a deep run use very different effort | Can one app run shallow daily and deep monthly? |
| Authenticated roles and tenants | Each role multiplies the access-control surface to test | How many roles are included per target? |
| Human review hours | Tester or reviewer time is the most expensive input | Which runs get a human, and for how long? |
| Retest terms | Some vendors include unlimited retests, others 1 or 2 | Is a retest a separate run you pay for? |
| Reporting and compliance evidence | Auditor-ready reports and attestation letters take effort | Which report formats come with each run? |
Why test daily rather than once a year?
Because attackers now move in days, and sometimes before a patch exists. Mandiant measured the average time from disclosure to exploitation at 63 days in 2018 and 2019, and at 5 days in 2023 (Google Cloud, October 2024). Its M-Trends 2026 report (March 2026) estimates the mean time to exploit at minus 7 days, which means exploitation now routinely starts before a patch is out. Exploits were the most common way in for the sixth year running, at 32% of intrusions.
VulnCheck found that 28.96% of known exploited vulnerabilities in 2025 were exploited on or before the day their CVE was published, up from 23.6% in 2024 (State of Exploitation 2026, January 2026).
AI is likely to push it further. In November 2025, Anthropic reported a state-sponsored campaign in which AI performed 80 to 90% of the work against about thirty targets, making thousands of requests, often several per second. Its conclusion was that the barriers to sophisticated attacks "have dropped substantially".
Two fair caveats. These figures are about known vulnerabilities in vendor products, not bugs in your own code. And M-Trends 2026 says 2025 "was not the year where breaches were the direct result of AI". The lesson for your app still holds: a broken access check you ship on Tuesday is open from Tuesday. An annual test might find it eleven months later. A daily run finds it the next morning.
So our recommendation is to test the app surface daily and keep a deeper run and an annual human test for business logic and compliance. The annual test is the minimum an auditor accepts, not a security cadence. What continuous pentesting is explains how the runs fit together.
Why doesn't daily testing cost 365 manual pentests?
A manual web app test is priced in tester days. BrightDefense's 2026 guide works it out at $1,000 to $1,500 a day over 3 to 15 days, so $3,000 to $22,500 per test. Run the cheapest version of that every day and you'd spend $1,095,000 a year on one app. Nobody buys that, which is why manual testing stays annual.
Automation changes the maths. AI agents do the repetitive part of a test, such as crawling, trying every parameter and replaying requests, and that costs compute rather than tester days. Quiet days can be skipped too: if a schedule only runs when the app has changed, a quiet week doesn't trigger a run.
Human time, the expensive input, goes where it earns its keep. A daily light pass can go out without review, while the monthly deep run gets an engineer.
A common setup is a daily light run that fires only on change, a monthly deep run that always fires, and a human test once a year. The daily run catches a release that broke something, and the deep run and human test cover depth and business logic.
Annual test, quarterly PTaaS or continuous AI pentesting: what do you get per year?
Per app, per year, typical setups. Prices appear only where a vendor or guide publishes them. For how the two models differ beyond price, see PTaaS vs continuous AI pentesting.
| Annual manual test | Quarterly tests or PTaaS | Continuous AI pentesting | |
|---|---|---|---|
| Tests per year | 1, plus a retest | 4 | Up to 365 on a daily schedule, fewer if runs fire only on change |
| Longest gap between a bad release and a test | Up to 12 months | Up to 3 months | One day on a daily schedule |
| Start after you ask | Set by the firm's calendar | 1 to 3 business days at Cobalt, by tier | A new run starts when you launch it |
| Regression coverage | None between tests | Once a quarter, if the scope stays the same | Every run compared with the last, if the tool tracks it |
| Depth per test | Highest: days of human judgement | High: human testers, often AI-assisted | Varies by level. Business logic still favours a human |
| Published price example | $3,000 to $22,500 per web app test (BrightDefense). $10,000 to $30,000 for a typical engagement (Synack) | $12,000 for 4 tests (Intruder). $20,000 to $100,000+ a year for PTaaS (Synack) | $2,500 a month billed annually, 12 assessments, 3 apps (Noscope). From $9,999 a year (Astra) |
The rows that matter most for security are the second and the fourth. A test you run once a year can't tell you that a fix came undone in June.
Questions to ask in a quote
Get these answered in writing before you compare numbers. Our best continuous pentesting tools comparison already answers some of them for 12 vendors.
- What counts as one app or target? Are the API and the web front end one target or two?
- How many runs or tests per year does the price include, and what happens if we need more?
- Can runs fire only when the app has changed, and what counts as a change?
- What depth does each run get, and can different schedules run at different depths?
- How many user roles and tenants are tested on each run?
- Which runs get human review, and how many hours?
- Are retests included, and are they limited?
- How is each finding checked before it reaches us, and is a finding the tool couldn't confirm labelled as such?
- Are findings tracked across runs as new, still open, resolved or regressed?
- Which report formats do we get for auditors and customers, and on which runs?
- What isn't tested? Internal networks, mobile apps and social engineering are out of scope for most web-focused tools.
How Barrion does it
Barrion's AI agents test web apps and APIs the way an attacker would, at five levels from Light (3 agents) to Maximum (100 agents). You can start a pentest yourself and put it on a schedule: daily, weekly, monthly, quarterly, every six months, yearly, or a custom rhythm. You can also trigger runs from your CI/CD pipeline via the Barrion API.
Each schedule has its own scope and depth, and you choose whether it runs every time or only when your app has changed. So one app can have a daily Light schedule that runs on change and a monthly Deep schedule that always runs.
Every run labels its findings new, still open, resolved or regressed. Findings are checked against the live app before they're reported, and ones that couldn't be confirmed are kept as lower-confidence leads. From Standard level up, a security engineer reviews each report. Every level covers 8 testing areas and all 97 OWASP WSTG v4.2 test cases.
We don't test internal networks, Active Directory, mobile apps, physical security or social engineering, and we don't run TLPT.
Per-run level prices are public on the pricing page. Continuous programs are scoped to your apps, cadence and depth. Talk to us and we'll price it for your setup.
Sources
All sources checked 2026-09-26.
Intruder, AI pentest pricing: $3,500 per test, $12,000 for 4
Cobalt, pricing: credit definition, Autonomous Pentest $3,500, plan tiers
Noscope, pricing: Continuous plan $2,500 a month billed annually
Astra Security, pricing: Pentest Auto, Pentest Expert and Enterprise plans
Equixly, pricing: €4,999 per penetration test
Aikido, pricing: $4,000 per pentest assessment
BreachLock, penetration testing pricing: packages and retest terms
Escape, pricing: quote only
Synack, How Much Does a Pentest Cost? (2026), published 2026-06-25
BrightDefense, Penetration Testing Pricing in 2026: day-rate example
Google Cloud (Mandiant), How Low Can You Go? An Analysis of 2023 Time-to-Exploit Trends, published 2024-10-15
Google Cloud (Mandiant), M-Trends 2026, published 2026-03-23
VulnCheck, State of Exploitation 2026, published 2026-01-21
Anthropic, Disrupting the first reported AI-orchestrated cyber espionage campaign, published 2025-11-13
Barrion product facts, facts page