Pricing

Penetration testing pricing, from one-off to continuous

One-off pentests from $4,999, continuous testing, and vCISO support.

Continuous penetration testing

Annual pentest credits for recurring security testing. Choose 15, 30, or 50 credits.

Starter

$19,999

15 annual credits · No rollover

Flexible starting point

An annual credit pool for teams building a recurring pentest program.

Credits per year

15

Validity

12 months

Rollover

None

Retest

1 per assessment

  • 15 credits · valid 12 months
  • Scoping support
  • Audit-ready pentest report + attestation
  • Findings debrief + Slack
  • 1 fix-validation round per assessment

Growth

Most Popular

$35,999

30 annual credits · 20% rollover

Regular testing

More credits for recurring assessments throughout the year.

Credits per year

30

Validity

12 months

Rollover

Up to 20%

Retest

1 per assessment

  • 30 credits · valid 12 months
  • Everything in Starter
  • 20% rollover
  • Quarterly testing recaps
  • Named project manager

Scale

$53,999

50 annual credits · 30% rollover

Multiple products

For frequent assessments across products and environments.

Credits per year

50

Validity

12 months

Rollover

Up to 30%

Retest

1 per assessment

  • 50 credits · valid 12 months
  • Everything in Growth
  • 30% rollover
  • Fast-track scheduling
  • Annual testing roadmap
  • Extra credits: $1,099 each · packs of 5

One-off penetration testing

Fixed-price pentest packages for web apps, APIs, mobile apps, and external networks.

Lite

From $4,999

Web / API / network $4,999 · Mobile $5,499

Focused starting point

A defined assessment for an initial audit or customer review. Fix validation is optional.

Testing target

1

Roles / external IPs

Up to 2 / 15

Fix validation

Optional

Report

Audit-ready

  • Manual penetration testing
  • OWASP Top 10 coverage
  • Audit-ready report + attestation
  • Findings Q&A for 30 days‍
  • Up to 2 roles or 15 external IPs‍
  • Fix validation available as an add-on

Essentials

Most Popular

From $7,499

Web / API / network $7,499 · Mobile $7,999

More depth for growing teams

For applications with sensitive data and recurring customer reviews. One fix-validation round within 90 days is included.

Testing target

1

Roles / external IPs

Up to 3 / 50

Fix validation

1 within 90 days

Report

Executive summary + export

  • Everything in Lite
  • Business-logic testing
  • Executive summary + Jira/CSV export
  • 1 fix-validation round within 90 days
  • Up to 3 roles or 50 external IPs

Assurance

From $8,999

Web / API / network $8,999 · Mobile $9,499

Deeper testing for complex systems

For regulated teams and complex applications, including AI or LLM features. Deeper manual testing with fix validation within 90 days.

Testing target

1

Roles / external IPs

Up to 5 / 100

Fix validation

1 within 90 days

Test depth

Extended attack paths

  • Everything in Essentials
  • Advanced attack paths + deeper business logic
  • Fix validation within 90 days
  • Optional attestation refresh
  • Fast-track add-on at 50% off
  • Up to 5 roles or 100 external IPs

vCISO & fractional CISO

Fractional security leadership scoped to the level of support your team needs.

Advisor

Custom

Scoped to responsibilities, cadence, and outcomes

Partner

Custom

Scoped to responsibilities, cadence, and outcomes

Executive

Custom

Scoped to responsibilities, cadence, and outcomes

How credits work

One credit = one day of penetration testing

Use credits for agreed web, API, mobile, cloud, and network pentests. Assessments start at 3 credits. Credits last 12 months; rollover depends on your plan.

Add-ons when you need more

Extend a standard one-off engagement with faster scheduling, additional validation, remediation support, or stakeholder-ready presentation support.

Fast-track SLA — $999

Priority scheduling; target start within 1 week.

Fix validation — $799

One additional round of re-testing.

Remediation support — $499

45-minute call with the testing team.

Executive presentation — $699

Slides plus a 45-minute stakeholder presentation.

Included by default

Every Blaze engagement includes

Human-led testing, clear findings, practical remediation guidance, and direct access to the people doing the work.

01

CREST-accredited penetration testing

Manual testing by experienced security researchers, not a scanner-only assessment.

02

Real-time findings

Live results in the Blaze Portal as they're confirmed.

03

Fix validation options

Included with Essentials, Assurance, and every annual credit plan; available as an add-on for Lite.

04

Actionable reporting

Clear severity, impact, reproduction steps, and remediation guidance, with evidence for audit or customer assurance where applicable.

05

Findings support

Get practical clarification through the communication channel included in your package.

What drives penetration testing cost?

Cost depends on scope, complexity, access, testing depth, specialist expertise, compliance needs, and validation. Focused packages start at $4,999; broader scopes and annual programs cost more.

PTaaS
Custom scope

Need a custom solution?

Larger scope, unusual environments, or multiple frameworks? We'll scope it and give you a fixed quote.