SOC 2 Auditors

Service firms

Penetration testing firms: compare 60 providers by scope, delivery, and evidence

This directory helps buyers shortlist penetration testing firms for web applications, APIs, cloud infrastructure, mobile products, networks, and deeper adversary-led work.

61 pentest firms
39 verified records
14 published price

All 61 penetration testing firms

Search by name, specialty, or framework to narrow the list. Firms with verified records are listed first, then alphabetically.

Showing 61 firms

Verified

Startups, SMBs, and bootstrapped teams that need professional penetration testing at a price that fits — without the enterprise markup. Fixed-price engagements with auditor-ready reports.

Budget-friendly penetration testingWeb application pentestingAPI pentesting+4

Web app pentest from $1,500; full-scope from $3,500 (published)

MSP Pentesting

REMOTE · USA

Verified

MSPs, SaaS companies, and regulated organizations that need AI-powered penetration testing with continuous monitoring, compliance-aligned reports, and a platform that scales across client engagements.

AI-powered penetration testingWeb and API pentestingNetwork penetration testing+5

Pentest credits from $500; continuous pentesting from $2,000/mo (published)

Vulnscanners

REMOTE · USA

Verified

SaaS companies, startups, and growing tech teams that want fast, AI-powered vulnerability scanning and penetration testing with compliance-ready reports — automated scanning plus expert manual verification.

AI-powered vulnerability scanningWeb application pentestingCloud infrastructure assessment+4

Automated scans from $99/mo; manual pentest from $2,500 (published)

Adversis

REMOTE, USA · USA

Verified

B2B SaaS companies going up-market (often Series A or B) that need pentests and security advisory which hold up in enterprise buyer security reviews

Penetration testingAI red teamingSecurity advisory / fractional CISO+2

Archlight

MINNEAPOLIS, MN · USA

Verified

Healthcare, finance, and government organizations across MENA and GCC seeking ISO 27001, SOC 2, HITRUST, or data privacy certifications with regional regulatory expertise

HealthcareFinanceGovernment+8

Remote quarter-time ~10 hrs/wk: $7,500 USD/month; Remote half-time ~20 hrs/wk: $9,000 USD/month; Full-time onsite: $19,000 USD/month (published)

Axipro

BAHRAIN, UK, AND US · Bahrain

Verified

Startups and small businesses seeking fast, fixed-fee compliance readiness across SOC 2, ISO 27001, and GDPR — especially in the Gulf, UK, and US — with hands-on implementation support and compliance platform management

ISO 27001SOC 2GDPR+8

SOC 2 or ISO 27001 readiness and implementation: $4,000 under 50 employees, $5,500 over 50 (external CPA audit fee excluded); ongoing compliance + vCISO from $500/month; pentest from $1,000; internal audit from $1,000, scope-dependent (published)

BEMO

UNITED STATES · USA

Verified

SMBs in the Microsoft ecosystem needing fully managed compliance (SOC 2, CMMC, ISO 27001) alongside IT support and security under one roof

Microsoft 365 / AzureSMB marketCMMC+3

Bishop Fox

TEMPE, AZ · USA

Verified

Enterprises and high-growth tech companies that need senior-led offensive security across applications, networks, cloud, and AI, with reports that hold up to enterprise buyer and auditor scrutiny

Application penetration testingRed teamingCloud security+2

Cobalt

SAN FRANCISCO, CA · USA

Verified

Fast-moving product and security teams that need on-demand penetration tests they can launch in days, with findings and retests tracked in a platform and wired into developer workflows

Penetration testing as a service (PTaaS)Web and API application pentestingCloud penetration testing+2

Coral Esecure

NEW JERSEY, USA · USA

Verified

Globally-distributed organizations needing broad multi-framework compliance consulting - SOC 2, ISO 27001, PCI DSS, GDPR, HITRUST - with offices across 5 countries

Global multi-office (USA/Canada/Germany/India/Mauritius)AICPA SOC 1 & SOC 2GRC outsourcing+3

Cyber Forte

MELBOURNE, VIC · Australia

Verified

Australian businesses and government-adjacent organizations needing CREST-certified penetration testing combined with SOC 2 or ISO 27001 readiness

Australian government clearances (NV2/Baseline)CREST-certified pen testingEssential Eight+4

SOC 2 compliance program from $8,000 AUD fixed price (published)

CYBRI

NEW YORK, NY · USA

Verified

Companies that need manual, OSCP-led penetration testing with auditor-ready reports mapped to SOC 2, ISO 27001, HIPAA, or PCI compliance requirements

Web and mobile app pentestingAPI penetration testingCloud penetration testing (AWS, Azure, GCP)+2

Cypro

LONDON, UK · UK

Verified

High-growth UK businesses that need fractional CISO leadership plus hands-on certification support for ISO 27001 and SOC 2 compliance

vCISOISO 27001 certificationSOC 2 readiness+5

Doyensec

NEW YORK, NY · USA

Verified

Product and engineering teams that need deep, source-assisted application security audits of complex platforms, including GraphQL, ElectronJS, and LLM-based systems

Web and API application securityMobile application securityCloud security+2

Fortbridge

LONDON, UK · UK

Verified

Companies that want senior-only, manual penetration testing across web, mobile, API, cloud, and network, with consultants who work directly with developers to fix what they find

Web application pentestingMobile and API pentestingCloud security assessment (AWS, Azure, GCP)+2

Include Security

NEW YORK, NY · USA

Verified

Teams that need deep, source-assisted security assessments for complex web, mobile, IoT, or hardware products and want findings other firms miss, right-sized to the codebase and budget

Web application assessmentsMobile application assessmentsIoT and hardware security+2

Isecurion

BANGALORE, INDIA · India

Verified

Indian SaaS, FinTech, and cloud companies targeting enterprise deals in US, UK, UAE, or Australia that need end-to-end SOC 2 readiness from a CERT-In empanelled partner

SOC 2 readiness and gap assessmentVAPTISO 27001+5

NCC Group

MANCHESTER, UK · UK

Verified

Larger enterprises and regulated organizations that need a global provider for penetration testing, security consulting, and incident response under one roof

Technical assurance and penetration testingSecurity consulting and implementationDigital forensics and incident response+2

NetSPI

MINNEAPOLIS, MN · USA

Verified

Large organizations and regulated enterprises that want continuous, expert-led penetration testing delivered through a managed platform rather than one-off point-in-time tests

Penetration testing as a service (PTaaS)Attack surface managementBreach and attack simulation+2

Practical Assurance

BOSTON, MA · USA

Verified

Startups and SMBs that need right-sized, affordable penetration testing and hands-on SOC 2 readiness support without the cost and overkill of enterprise engagements

SOC 2-scoped penetration testingCompliance readinessFractional CISO+2

Entry 'lay of the land' SOC 2 pentest from $2,800 (published)

Praetorian

AUSTIN, TX · USA

Verified

Organizations that want adversary-emulation-grade offensive security and continuous threat exposure management rather than a one-off checkbox penetration test

Advanced offensive securityContinuous threat exposure managementRed teaming+2

Precursor Security

LEEDS, UK · UK

Verified

UK organisations that want CREST-accredited penetration testing and ISO 27001 consultancy from one provider, with findings tied back to the controls auditors check

CREST penetration testingISO 27001 consultancyManaged detection and response+2

Penetration testing from £2,500; managed SOC from £900/month (published)

Raxis

ATLANTA, GA · USA

Verified

Security-conscious teams that want adversary-style penetration testing tied to SOC 2 Trust Services Criteria, not a reformatted vulnerability scan, with an auditor-ready report

Red teaming and adversary simulationExternal and internal network pentestingWeb application pentesting+2

Rhino Security Labs

SEATTLE, WA · USA

Verified

Companies from high-growth startups to the Fortune 1000 that want a deep, manual, research-driven pentest mapped to SOC 2 and vendor-security requirements rather than a scan

Network penetration testingAWS and cloud penetration testingWeb and mobile application testing+2

Rhymetec

NEW YORK, NY · USA

Verified

Startups and growth-stage SaaS companies seeking a one-stop cybersecurity partner covering vCISO, compliance readiness, penetration testing, and ISO 27001 internal audits

SaaSStartupsvCISO+8

RSI Security

SAN DIEGO, CA · USA

Verified

Organizations seeking end-to-end SOC 2 support from readiness assessment through ongoing Type I/Type II compliance with hands-on consulting approach

SOC 2 readinessPCI DSSHITRUST+2

SECNORA

HAASLAVA, ESTONIA AND GRAPEVINE, TX · Estonia

Verified

Cloud-native SaaS, fintech, and regulated companies that want an independent CREST-accredited pentest mapped to SOC 2, ISO 27001, or PCI, kept separate from their audit firm

CREST penetration testingWeb and API pentestingCloud configuration review+3

Securis360

PITTSBURGH, PA · USA

Verified

Organizations seeking a global cybersecurity partner covering SOC 2 readiness, ISO 27001 consulting, penetration testing, and managed SOC services across the US and India

Cloud securitySOC 2ISO 27001+6

Silent Sector

SCOTTSDALE, AZ · USA

Verified

US-based mid-market and emerging companies that need a full cybersecurity program: SOC 2 readiness, penetration testing, vCISO, and multi-framework compliance under one roof

Mid-market and emerging companiesSaaSFinancial services+4

Software Secured

OTTAWA, ON · Canada

Verified

High-growth SaaS companies preparing for SOC 2, HIPAA, or ISO 27001 that need manual, exploit-driven pentests with compliance mappings and built-in retesting to unblock enterprise deals

Web, API and mobile pentestingSecure code reviewCloud security review+2

Web & API pentest from $10,800; PTaaS from $21,400 (published)

Sprocket Security

MADISON, WI · USA

Verified

Organizations that ship frequently and want always-on, expert-driven penetration testing with unlimited retests and on-demand attestation reports rather than a single annual snapshot

Continuous penetration testingAttack surface managementAdversary simulation+2

Continuous pentest Starter package from $15,000 (published)

Testpros

RESTON, VA · USA

Verified

Organizations - especially federal, state/local, and defense contractors - needing independent IT testing, compliance readiness, and verification and validation across a broad stack of US government and commercial frameworks

Federal governmentDefense/CMMCFedRAMP+7

Tevora

IRVINE, CA · USA

Verified

Organizations requiring expert compliance and cybersecurity services across multiple frameworks with executive CISO-level support

SOC 2 readinessPCI DSSHITRUST+2

Trail of Bits

NEW YORK, NY · USA

Verified

Engineering-led and high-assurance organizations that need deep security audits of code, cryptography, blockchain, and complex systems, well beyond a standard pentest

Software security auditsCryptography reviewBlockchain and smart-contract security+2

Trava Security

INDIANAPOLIS, IN · USA

Verified

Startups, scale-ups, and defense industrial base companies that want managed compliance and security programs with expert practitioners, backed by a 100% certification success rate and G2 High Performer recognition

Startups and scale-upsDefense industrial baseCMMC+4

traztech

TORONTO, ON · Canada

Verified

Startups and growing technology companies that want one founder-led partner for hands-on SOC 2 or ISO 27001 readiness, security testing, and ongoing security leadership

SOC 2 Type I and Type II readinessISO 27001 readiness and internal auditsWeb, API, network, and cloud penetration testing+4

SOC 2 and ISO 27001 gap assessments from $3,000; penetration testing from $1,000; fractional CISO from C$3,000/month (published)

TrustedSec

FAIRLAWN, OH · USA

Verified

Organizations that want CREST-certified offensive testing and pragmatic security consulting from a widely recognized US practitioner team

Penetration testingRed teaming and adversary simulationActive Directory security+2

Truvantis

SAN FRANCISCO, CA · USA

Verified

Companies needing a full-service cybersecurity partner for SOC 2 readiness, PCI DSS QSA assessment, penetration testing, and vCISO - with expertise in managing the full audit lifecycle

SOC 2 readinessPCI DSS QSA assessmentsSaaS penetration testing+4

URM Consulting

UNITED KINGDOM · UK

Verified

UK organisations that want ISO 27001 certification support plus SOC 2 readiness, GDPR, and penetration testing from a single accredited consultancy

ISO 27001 consultancy and auditingSOC 2 readinessGDPR and data protection+2

Small businesses in the Caribbean / Bahamas region seeking foundational SOC 2 readiness and cybersecurity consulting

Incident responsePenetration testingSOC 1/2/3 compliance prep+2

ACOINFO

COLOMBIA · Colombia

Latin American organizations seeking a Spanish-language cybersecurity partner with 25+ years of experience across compliance certification and ethical hacking

ISO 27001PCI DSS v4SOC 2+5

Amomitto

UNITED STATES · USA

Growing tech companies (Series A-C, 50-500 employees) that need an embedded security team to handle SOC 2, ISO 27001, and enterprise sales security reviews end-to-end

SaaSFintechHealthtech+5

Astra Security

CLAYMONT, DELAWARE (US HQ); NEW DELHI, INDIA (OPERATIONS) · USA

SaaS and technology companies seeking continuous automated + manual penetration testing integrated into CI/CD pipelines, with compliance scan support for SOC 2 readiness

PTaaS platform (continuous pentesting)Web/API/mobile/cloud/network pentestSOC 2 / ISO 27001 pentest reports+2

DAST Scanner from $7 trial; Pentest plans: manual pentest pricing via custom quote (published partial pricing)

Atlant Security

SOFIA, BULGARIA · Bulgaria

Fast-moving SaaS companies needing founder-led security audits and compliance readiness delivered in weeks, not months

SaaS security auditCloud security (AWS/Azure/GCP)Fintech+4

SaaS Security Audit from $5,000, pay after delivery, fixed pricing (published)

Cognisys

LEEDS, UK · UK

UK-based companies seeking combined CREST-accredited penetration testing and compliance readiness, especially those on Vanta or pursuing ISO 27001 or SOC 2

Vanta implementation (#1 Global Service Partner)ISO 42001 (AI governance)CREST-accredited penetration testing+4

Com Sec

WASHINGTON, DC · USA

Startups and SMBs across healthcare, AI/ML, and FinTech needing combined SOC 2 readiness and penetration testing with access to discounted GRC platform partnerships

Cloud security (AWS/Azure/GCP)AI/ML companiesHealthcare+4

Compass IT Compliance

NORTH PROVIDENCE, RI · USA

Mid-market organizations across diverse industries seeking a single partner for SOC 2 readiness, penetration testing, vCISO, and multi-framework compliance consulting, with the attest work handled by affiliated CPA firm Compass Assurance Team

SOC 2 readiness and gap assessmentsPenetration testing (network, web app, wireless, social engineering)Virtual CISO+13

Cybervantage 360

NAVI MUMBAI, INDIA · India

Organizations across Asia-Pacific, Middle East, and global markets needing multi-framework compliance consulting (SOC 2, PCI DSS, ISO 27001, HIPAA, GDPR) with a technology-assisted approach

Multi-framework global consultingPhilippines Privacy MarkAI-powered GRC platform+3

Echelon Risk Cyber

UNITED STATES · USA

Mid-market organizations across regulated industries seeking an integrated vCISO-led security team that combines GRC advisory, penetration testing, and managed security services

vCISOSecurity Team as a Service (STaaS)Offensive security+7

Eden Data

AUSTIN, TX · USA

High-growth SaaS companies wanting a hands-on compliance team with prior Big 4 experience to get audit-ready 3x faster on GRC platforms

SaaSStartups to IPODrata+7

Compliance Sprint begins at $5K/mo (published)

Illume Intelligence

CALICUT, KERALA, INDIA · India

Indian and Middle East-based technology companies seeking VAPT, SOC 2 readiness, and ISO 27001 consulting from a cybersecurity specialist

Penetration testingVAPTSOC 2 assessment/readiness+4

IT Governance USA

UNITED STATES · USA

Organizations needing a broad range of GRC consulting, penetration testing, and training across SOC 2, ISO 27001, GDPR, and regulatory frameworks in the US, UK, and EU

SOC 2 readinessISO 27001GDPR+6

Kratikal

NOIDA, INDIA · India

Enterprises and SMEs in Fintech, Telecom, Healthcare, and E-commerce seeking CERT-In empanelled VAPT services, compliance audits, and an AI-driven vulnerability management platform

VAPTCompliance auditsvCISO+5

Kroll

NEW YORK, NY · USA

Large enterprises needing a globally recognized firm for incident response, penetration testing, and comprehensive cyber risk advisory across the full security lifecycle

Incident responsePenetration testingCyber transformation+4

Netragard

MASSACHUSETTS, US · USA

Organizations needing rigorous, research-driven penetration testing backed by 20+ years of exploit development expertise, with deliverables suitable for SOC 2 and PCI compliance evidence

Penetration testingExploit developmentVulnerability research+5

Enterprises needing a full-spectrum, CREST-accredited cybersecurity partner covering testing, vCISO, managed SOC, and compliance readiness across EMEA and globally

CREST-accredited penetration testingManaged detection and responseIncident response+5

Optiv Security

LEAWOOD, KS · USA

Large enterprises needing a top-tier security consulting partner with deep QSA/compliance expertise across PCI DSS, HIPAA, HITRUST, CMMC, and SOC 2 for program-level risk reduction

Enterprise security consultingPCI DSS QSAHIPAA+7

P1sec

KOPER, SLOVENIA · Slovenia

Organizations developing connected physical products or embedded systems that need deep hardware-level security testing: embedded firmware analysis, IoT architecture review, and hardware reverse engineering. P1sec operates from Slovenia, serving engineering teams across the EU building connected products for regulated and enterprise markets.

Hardware and embedded securityIoT securityFirmware analysis+2

Sig Sol

MCLEAN, VA · USA

US government agencies and defense contractors needing penetration testing and vulnerability scanning as part of broader security research and threat surface reduction engagements, with deep experience in the federal contracting ecosystem.

Penetration testingVulnerability scanningCybersecurity research+2

Socially Adept

LEESBURG, VA · USA

Organizations that want to test their human attack surface through social engineering assessments — phishing, pretexting, physical tailgating — and build a security awareness program from the results.

Social engineering penetration testingPhishing simulationsPhysical security assessments+2

Zscaler Cyber Security

UNITED STATES · USA

Mid-to-large enterprises needing adversarial-focused red team testing, tabletop exercises, and SOC maturity assessments to validate that their security operations actually work under realistic attack scenarios.

Red team and purple team engagementsAdversarial attack simulationTabletop exercises+2

Get 3 quotes that fit.

Tell us your stage, framework, and timeline once. We match you with three firms that fit — one short call, not five sales pitches.

Free for buyers · No spam · Independent of every firm listed