Security · Concept

Penetration testing

Hiring security specialists to attack your own app or network, with written permission and an agreed scope, so weaknesses are found and fixed before criminals find them.

Testing and research · Paid · updated

How it works

A pentest starts with a scope and rules of engagement: which systems are in, which test accounts to use, the dates, and what is off limits, all signed off by someone with authority over those systems. Testers then work through the target by hand and with tools such as Burp Suite, following methods like the OWASP Web Security Testing Guide. Black-box tests start with no inside knowledge, grey-box tests get user accounts, and white-box tests also see the source code.

The deliverable is a report that ranks each finding by severity (often with a CVSS score), explains the impact in plain terms, gives developers enough detail to reproduce it and suggests fixes. A retest after the fixes confirms they worked. The report is often what customers, investors and auditors ask for: PCI DSS requires penetration testing at least once a year and after significant changes, and SOC 2 and ISO 27001 audits commonly expect one.

A vulnerability scan is automated and finds known issues quickly; a pentest adds human judgement and catches broken business logic, such as paying for one item and receiving ten. A red team exercise goes further and tests whether defenders notice a realistic, stealthy attack.

Penetration testing pros and cons

Pros

  • A scoped, methodical look at the systems that matter most
  • Finds business logic flaws that automated scanners miss
  • Produces a formal report for customers, auditors and PCI DSS
  • Testers explain the fixes and retest them

Cons

  • A snapshot in time: code shipped after the test is not covered
  • Quality varies widely between firms and testers
  • You pay for the time whether or not serious issues turn up
  • A fixed number of days limits how deep testers can go

When to use Penetration testing

Pick it when

  • Before launching a product that handles money, health or personal data
  • A client, investor or auditor asks for a recent report
  • After major changes to login, payments or infrastructure

Skip it when

  • The product is still a prototype that changes every week
  • Automated scans and dependency updates have not been run yet

Penetration testing pricing

Paid

Quoted per engagement, based on the scope and the number of testing days. Pentest-as-a-service firms such as Cobalt sell yearly packages of testing credits, also priced on request.

Penetration testing pricing page (opens in a new tab)Approximate, checked September 2026.What the other tools cost

Penetration testing vs the alternatives

More in Security

Testing and research

All 20 Security terms

Crafted in the dark. Shipped to the world.

Tell us what you are building. You get a private project space with a proposal and a line-by-line quote within a day.