Independent cybersecurity directory, built from public sources. Featured listings are paid placements and always labelled. How we work

Penetration Testing Firms: 10 Companies compared

Independent penetration testing firms compared on services, specialisms, delivery model, and standards coverage. From global FTSE 250 consultancies to boutique research-driven firms.

10 companies|Updated June 2026

10 Penetration Testing Firms, side by side

Featured listings are paid placements.

CompanyFoundedEngagementSpecialismStandards / accreditations
A-LIGNFeatured2009Project-based testing + audit engagementsCompanies running testing alongside a formal audit who want one accredited firm across bo…SOC 2, ISO 27001, CMMC
PCA Cyber SecurityFeatured2019Project-based engagementsManufacturers and operators of payment devices, vehicles, industrial systems and other em…TISAX Assessment Level 3, PCI SSC Associate Participating Organization, ISO/SAE 21434
SBS CyberSecurityFeatured2004Project-based testing and advisory engagementsCommunity banks, credit unions and other regulated financial institutions that want testi…CMMC (NIST SP 800-171), NIST CSF, PCI DSS
Bishop Fox2005Project + Cosmos subscriptionMid-to-large enterprises wanting continuous offensive testing rather than annual point-in…PCI DSS, HIPAA, SOC 2
IOActive, Inc.1998Project-based engagementsOEMs, semiconductor vendors, automotive, and critical-infrastructure operators that need…Open Compute Project (OCP) S.A.F.E. Security Review Provider
Lorikeet Security2021Annual programs, prepaid credits and per-service pricingEngineering-led companies that want continuous testing between annual pentests, with huma…—
Mandiant (part of Google Cloud)2004Project-based engagementsEnterprises needing top-tier incident response, nation-state threat intelligence, or boar…PCI DSS, HIPAA, NIST CSF
NCC Group1999Project + retainer + managed servicesRegulated enterprises and public-sector buyers wanting CREST-accredited testing, MDR, and…CREST, CHECK, CBEST
Praetorian2010Chariot subscription + project workTech and regulated enterprises wanting continuous offensive testing folded into a single…PCI DSS, HIPAA, GLBA
Trail of Bits2012Fixed-scope research engagementsCrypto/DeFi protocols and security-conscious tech companies needing deep code, cryptograp…SOC 2, ISO 27001

By use case

Our read on which firm suits which job. Editorial, not paid, and separate from the alphabetical listing below.

Nation-state IR

Mandiant (part of Google Cloud)

The strongest reputation for top-end incident response when a breach lands at board level.

Cloud

Continuous offensive testing

Bishop Fox

Cosmos delivers human-validated continuous testing instead of annual point-in-time pentests.

Cloud

Crypto + smart contracts

Trail of Bits

Research-grade audits across cryptography, blockchain, and AI security with widely used open-source tooling.

A-LIGN logo

A-LIGN

A-LIGN is a compliance audit firm that helps organisations start and grow their compliance programmes across SOC 2, ISO 27001, CMMC and ISO 42001.

Founded
2009
Pricing
Project-based testing + audit engagements
Certifications
SOC 2, ISO 27001, CMMC

Founded in 2009 and headquartered in Tampa, Florida, A-LIGN is a compliance audit firm that helps organizations start and grow their compliance programs across SOC 2, ISO 27001, CMMC, and ISO 42001 frameworks. Testing sits alongside those audits through a single, consolidated provider relationship, scoped to satisfy SOC 2 and ISO 27001 requirements and run by a team kept independent from the audit side.

Capabilities

  • Penetration testing (external, internal, web application, cloud)
  • Red team services and social engineering
  • Vulnerability assessment services
  • Ransomware preparedness assessments
  • SOC 1, SOC 2, and SOC 3 examinations
  • ISO 27001, ISO 27701, ISO 22301, and ISO 42001 certification
  • CMMC and NIST 800-171 assessments
  • FedRAMP and GovRAMP authorization support
  • HITRUST and HIPAA assessments
  • PCI DSS and PCI SSF assessments
  • A-SCEND audit management platform

Certifications

SOC 2, ISO 27001, CMMC, FedRAMP, HITRUST, PCI DSS

PCA Cyber Security

Munich- and Budapest-based embedded cybersecurity experts for financial services, automotive and mobility, manufacturing and industrial automation, and energy

Founded
2019
Pricing
Project-based engagements
Deployment
Cloud
Certifications
TISAX Assessment Level 3, PCI SSC Associate Participating Organization, ISO/SAE 21434

PCA Cyber Security is an embedded cybersecurity firm based in Munich and Budapest, founded in 2019. It tests and monitors connected and embedded products for clients in financial services, automotive and mobility, manufacturing and industrial automation, energy, rail and healthcare, and its services and platform support the security requirements of the Cyber Resilience Act, PCI PTS, UN R155, ISO/SAE 21434 and related standards. Penetration testing covers payment terminals, PIN pads, unattended terminals and ATMs; ECUs, telematics, vehicles and EV chargers; SCADA, PLCs and OT networks; IoT, embedded and medical devices; railway systems; and the web, mobile and cloud applications around them, with hardware and firmware research done in its CyberLab and CyberGarage facilities. PCA also builds PCA Cervus, a device-centric vulnerability monitoring and threat intelligence platform that takes a supplier's SBOM through to remediation evidence. The firm holds TISAX Assessment Level 3 with protection of prototype parts, is a registered Associate Participating Organization of the PCI Security Standards Council, took part in Pwn2Own Automotive in 2024 and 2025, and its researchers have spoken at Black Hat, Hexacon, Escar and Hacktivity.

Capabilities

  • Payment-device penetration testing (POS, PIN pads, unattended terminals)
  • Fuel-pump and EV-charging payment system testing
  • Embedded and IoT device security testing
  • Automotive security testing and research
  • PCA Cervus: device-centric vulnerability monitoring and threat intelligence platform for embedded products
  • Security assessments and continuous monitoring
  • Software composition analysis and SBOM validation by firmware reverse engineering
  • Extended bill of materials (xBOM) with CVE mapping, built from the binary rather than vendor documentation
  • Automotive and embedded penetration testing (ECUs, IVI, telematics, EV chargers)
  • Vehicle and product threat intelligence
  • Product Security Operations Center (PSOC) / Vehicle SOC monitoring
  • Threat Analysis and Risk Assessment (TARA)
  • Cybersecurity verification and validation (V&V) services
  • Remote attack surface analysis (mobile apps, backend APIs, cloud)
  • Security assessments supporting ISO/SAE 21434 compliance
  • UNECE R155 cybersecurity assessment support
  • Hardware and firmware research via dedicated CyberLab and CyberGarage facilities
  • Vulnerability research and coordinated responsible disclosure
  • ICS and OT penetration testing (SCADA, PLCs, industrial networks)
  • Medical device penetration testing
  • Railway penetration testing (signalling, communication and control networks)
  • Application penetration testing (web, mobile and cloud)

Certifications

TISAX Assessment Level 3, PCI SSC Associate Participating Organization, ISO/SAE 21434, UNECE R155

SBS CyberSecurity logo

SBS CyberSecurity

US cybersecurity consulting, audit and testing firm founded in 2004, focused on community banks and credit unions, with penetration testing plus CMMC Level 1 and 2 readiness work for defense contractors.

Founded
2004
Pricing
Project-based testing and advisory engagements
Certifications
CMMC (NIST SP 800-171), NIST CSF, PCI DSS

SBS CyberSecurity is a US cybersecurity consulting, audit and testing firm founded in Madison, South Dakota in 2004. Its core market is regulated financial institutions, community banks and credit unions, served through risk management programmes, IT and network security audits, penetration testing, and the TRAC governance, risk and compliance platform. Co-founders Chad Knutson and Jon Waldman acquired full ownership of the company in July 2022. Penetration testing covers external network, internal network, web application, wireless, and PCI DSS Requirement 11 engagements, aligned to NIST, OWASP and PTES. Alongside testing, SBS runs red team, purple team and social engineering assessments, and advisory work including virtual CISO, NIST Cybersecurity Framework assessments, cybersecurity maturity assessments, and vendor risk management. For defense contractors, SBS provides CMMC readiness for Level 1 and Level 2: gap identification, documentation and preparation for assessment. Certification itself is completed by a separate Certified Third Party Assessment Organization (C3PAO); SBS is not listed on the Cyber AB Marketplace as an RPO or C3PAO.

Capabilities

  • External and internal network penetration testing
  • Web application penetration testing
  • Wireless penetration testing
  • PCI DSS Requirement 11 testing
  • Red team, purple team and social engineering assessments
  • CMMC Level 1 and 2 readiness (gap assessment, documentation, assessment preparation)
  • Virtual CISO and NIST Cybersecurity Framework assessments
  • TRAC governance, risk and compliance platform

Certifications

CMMC (NIST SP 800-171), NIST CSF, PCI DSS, OWASP, PTES

Sources

A-LIGN

Penetration Testing Firms
Best fit for

Companies running testing alongside a formal audit who want one accredited firm across both

Founded in 2009 and headquartered in Tampa, Florida, A-LIGN is a compliance audit firm that helps organizations start and grow their compliance programs across SOC 2, ISO 27001, CMMC, and ISO 42001 frameworks. Testing sits alongside those audits through a single, consolidated provider relationship, scoped to satisfy SOC 2 and ISO 27001 requirements and run by a team kept independent from the audit side.

Founded

2009

Engagement

Project-based testing + audit engagements

Standards & accreditations

SOC 2, ISO 27001, CMMC, FedRAMP, HITRUST, PCI DSS

Bishop Fox

Penetration Testing Firms
Best fit for

Mid-to-large enterprises wanting continuous offensive testing rather than annual point-in-time pentests

Founded in 2005 (originally as Stach & Liu), Bishop Fox positions itself as 'the leading authority in offensive security' and is headquartered in Tempe, Arizona. Beyond traditional consulting it sells Cosmos, a continuous attack-surface management and offensive-testing platform that pairs automated discovery with human operator validation.

Founded

2005

Engagement

Project + Cosmos subscription

Standards & accreditations

PCI DSS, HIPAA, SOC 2, ISO 27001, NIST CSF

IOActive, Inc.

Penetration Testing Firms
Best fit for

OEMs, semiconductor vendors, automotive, and critical-infrastructure operators that need silicon-to-cloud security expertise

Founded in 1998 by Joshua Pennell and led since 2008 by Jennifer Sunshine Steffens, IOActive is headquartered in Seattle with offices in Atlanta, London, Madrid, and Dubai. The firm is known for full-stack security assessments and deep specialism in hardware, embedded systems, semiconductors, automotive, industrial control, and other safety-critical environments.

Founded

1998

Engagement

Project-based engagements

Standards & accreditations

Open Compute Project (OCP) S.A.F.E. Security Review Provider

Lorikeet Security

Penetration Testing Firms
Best fit for

Engineering-led companies that want continuous testing between annual pentests, with human sign-off on findings and published pricing.

Lorikeet Security, founded in 2021, is a security services firm that runs its work through a client portal called Talon. Its AI pentester, Lory, runs recon, chains exploits and drafts findings with evidence within a signed scope, and a human pentester countersigns each finding before it reaches the client. Alongside that it offers manual penetration testing across web, API, mobile, cloud, network, Active Directory, containers, wireless and IoT, red and purple teaming, compliance readiness for frameworks including SOC 2, ISO 27001, PCI DSS and HIPAA, managed detection and response, incident response retainers and vCISO services. Findings arrive in Talon with evidence and free retesting, and can route to Slack, Jira and code repositories.

Founded

2021

Engagement

Annual programs, prepaid credits and per-service pricing

Mandiant (part of Google Cloud)

Penetration Testing Firms
Best fit for

Enterprises needing top-tier incident response, nation-state threat intelligence, or board-defensible breach engagement

Founded in 2004 by Kevin Mandia, Mandiant built a global reputation responding to the world's most high-profile breaches. After acquisition by FireEye in 2013 and by Google for ~$5.4B in 2022, the firm retained its brand and now operates inside Google Cloud as a specialist consultancy for incident response, threat intelligence, and offensive security.

Founded

2004

Engagement

Project-based engagements

Standards & accreditations

PCI DSS, HIPAA, NIST CSF, ISO 27001, SOC 2

NCC Group

Penetration Testing Firms
Best fit for

Regulated enterprises and public-sector buyers wanting CREST-accredited testing, MDR, and software escrow under one global vendor

NCC Group was formed in 1999 when the National Computing Centre's commercial divisions were spun out and is headquartered in Manchester, listed on the London Stock Exchange. With 2,000+ staff across the UK, North America, Europe, and APAC, the group operates technical assurance, managed services, and software escrow divisions and is a founding CREST member.

Founded

1999

Engagement

Project + retainer + managed services

Standards & accreditations

CREST, CHECK, CBEST, TIBER-EU, PCI DSS, ISO 27001

PCA Cyber Security

PCI PTS Compliance Testing Companies
Best fit for

Manufacturers and operators of payment devices, vehicles, industrial systems and other embedded products who need hands-on product security testing and monitoring against the CRA, PCI PTS, UN R155 and ISO/SAE 21434

PCA Cyber Security is an embedded cybersecurity firm based in Munich and Budapest, founded in 2019. It tests and monitors connected and embedded products for clients in financial services, automotive and mobility, manufacturing and industrial automation, energy, rail and healthcare, and its services and platform support the security requirements of the Cyber Resilience Act, PCI PTS, UN R155, ISO/SAE 21434 and related standards. Penetration testing covers payment terminals, PIN pads, unattended terminals and ATMs; ECUs, telematics, vehicles and EV chargers; SCADA, PLCs and OT networks; IoT, embedded and medical devices; railway systems; and the web, mobile and cloud applications around them, with hardware and firmware research done in its CyberLab and CyberGarage facilities. PCA also builds PCA Cervus, a device-centric vulnerability monitoring and threat intelligence platform that takes a supplier's SBOM through to remediation evidence. The firm holds TISAX Assessment Level 3 with protection of prototype parts, is a registered Associate Participating Organization of the PCI Security Standards Council, took part in Pwn2Own Automotive in 2024 and 2025, and its researchers have spoken at Black Hat, Hexacon, Escar and Hacktivity.

Founded

2019

Engagement

Project-based engagements

Standards & accreditations

TISAX Assessment Level 3, PCI SSC Associate Participating Organization, ISO/SAE 21434, UNECE R155

Praetorian

Penetration Testing Firms
Best fit for

Tech and regulated enterprises wanting continuous offensive testing folded into a single subscription rather than annual one-offs

Founded in 2010 by Nathan Sportsman and headquartered in Austin, Texas, Praetorian positions itself around 'continuous offensive security.' It pairs traditional consulting with Chariot, a platform combining external attack-surface management, continuous testing, and AI-driven workflow automation to surface exploitable issues on an ongoing basis.

Founded

2010

Engagement

Chariot subscription + project work

Standards & accreditations

PCI DSS, HIPAA, GLBA, NERC CIP, NYDFS

SBS CyberSecurity

Penetration Testing Firms
Best fit for

Community banks, credit unions and other regulated financial institutions that want testing, audit and governance from one firm, plus organizations preparing for a CMMC Level 1 or Level 2 assessment

SBS CyberSecurity is a US cybersecurity consulting, audit and testing firm founded in Madison, South Dakota in 2004. Its core market is regulated financial institutions, community banks and credit unions, served through risk management programmes, IT and network security audits, penetration testing, and the TRAC governance, risk and compliance platform. Co-founders Chad Knutson and Jon Waldman acquired full ownership of the company in July 2022. Penetration testing covers external network, internal network, web application, wireless, and PCI DSS Requirement 11 engagements, aligned to NIST, OWASP and PTES. Alongside testing, SBS runs red team, purple team and social engineering assessments, and advisory work including virtual CISO, NIST Cybersecurity Framework assessments, cybersecurity maturity assessments, and vendor risk management. For defense contractors, SBS provides CMMC readiness for Level 1 and Level 2: gap identification, documentation and preparation for assessment. Certification itself is completed by a separate Certified Third Party Assessment Organization (C3PAO); SBS is not listed on the Cyber AB Marketplace as an RPO or C3PAO.

Founded

2004

Engagement

Project-based testing and advisory engagements

Standards & accreditations

CMMC (NIST SP 800-171), NIST CSF, PCI DSS, OWASP, PTES

Trail of Bits

Penetration Testing Firms
Best fit for

Crypto/DeFi protocols and security-conscious tech companies needing deep code, cryptography, and AI assurance work

Co-founded in 2012 by Dan Guido and headquartered in New York City, Trail of Bits combines academic-style security research with hands-on engineering. The firm is best known for advanced software assurance work across cryptography, AI/ML, blockchain, and low-level systems, and for releasing widely used open-source tooling such as the Slither smart contract analyzer.

Founded

2012

Engagement

Fixed-scope research engagements

Standards & accreditations

SOC 2, ISO 27001

Related guides

Other categories you might be evaluating alongside penetration testing firms.

About this listing

Penetration Testing Firms companies, compared on public information. The comparison table is ordered by reader upvotes, then A to Z, with paid Featured listings shown first and labelled; the full entries run A to Z. How we work →

Frequently Asked Questions

A penetration test is a controlled, simulated attack on a system or organisation to find security weaknesses before adversaries do. Modern engagements span web and mobile apps, APIs, internal and cloud networks, hardware and embedded devices, and red team exercises that test detection and response.

A vulnerability scan is an automated discovery of known issues. A penetration test combines automation with human attackers who chain weaknesses into realistic attack paths and validate exploitability. Most compliance frameworks require both, but annual pentests are the validated-by-humans layer.

Most reputable firms scope per engagement and do not publish list pricing. Typical ranges sit around mid-five figures for focused application or network tests, six figures for red team engagements, and ongoing subscription contracts for continuous-testing platforms like Bishop Fox Cosmos or Praetorian Chariot.

CREST (CHECK, CBEST, STAR) and TIBER-EU are the strongest accreditations in regulated UK and EU sectors. In the US, expect to see OSCP/OSCE/OSEE expertise listed on consultant teams. PCI DSS, SOC 2, ISO 27001, HIPAA, and FedRAMP map onto compliance-driven testing programs.