Penetration Testing Firms: 10 Companies compared
Independent penetration testing firms compared on services, specialisms, delivery model, and standards coverage. From global FTSE 250 consultancies to boutique research-driven firms.
10 Penetration Testing Firms, side by side
Featured listings are paid placements.
| Company | Founded | Engagement | Specialism | Standards / accreditations |
|---|---|---|---|---|
| A-LIGNFeatured | 2009 | Project-based testing + audit engagements | Companies running testing alongside a formal audit who want one accredited firm across bo… | SOC 2, ISO 27001, CMMC |
| PCA Cyber SecurityFeatured | 2019 | Project-based engagements | Manufacturers and operators of payment devices, vehicles, industrial systems and other em… | TISAX Assessment Level 3, PCI SSC Associate Participating Organization, ISO/SAE 21434 |
| SBS CyberSecurityFeatured | 2004 | Project-based testing and advisory engagements | Community banks, credit unions and other regulated financial institutions that want testi… | CMMC (NIST SP 800-171), NIST CSF, PCI DSS |
| Bishop Fox | 2005 | Project + Cosmos subscription | Mid-to-large enterprises wanting continuous offensive testing rather than annual point-in… | PCI DSS, HIPAA, SOC 2 |
| IOActive, Inc. | 1998 | Project-based engagements | OEMs, semiconductor vendors, automotive, and critical-infrastructure operators that need… | Open Compute Project (OCP) S.A.F.E. Security Review Provider |
| Lorikeet Security | 2021 | Annual programs, prepaid credits and per-service pricing | Engineering-led companies that want continuous testing between annual pentests, with huma… | — |
| Mandiant (part of Google Cloud) | 2004 | Project-based engagements | Enterprises needing top-tier incident response, nation-state threat intelligence, or boar… | PCI DSS, HIPAA, NIST CSF |
| NCC Group | 1999 | Project + retainer + managed services | Regulated enterprises and public-sector buyers wanting CREST-accredited testing, MDR, and… | CREST, CHECK, CBEST |
| Praetorian | 2010 | Chariot subscription + project work | Tech and regulated enterprises wanting continuous offensive testing folded into a single… | PCI DSS, HIPAA, GLBA |
| Trail of Bits | 2012 | Fixed-scope research engagements | Crypto/DeFi protocols and security-conscious tech companies needing deep code, cryptograp… | SOC 2, ISO 27001 |
By use case
Our read on which firm suits which job. Editorial, not paid, and separate from the alphabetical listing below.
Nation-state IR
Mandiant (part of Google Cloud)
The strongest reputation for top-end incident response when a breach lands at board level.
Cloud
Continuous offensive testing
Bishop Fox
Cosmos delivers human-validated continuous testing instead of annual point-in-time pentests.
Cloud
Crypto + smart contracts
Trail of Bits
Research-grade audits across cryptography, blockchain, and AI security with widely used open-source tooling.

A-LIGN
A-LIGN is a compliance audit firm that helps organisations start and grow their compliance programmes across SOC 2, ISO 27001, CMMC and ISO 42001.
Founded in 2009 and headquartered in Tampa, Florida, A-LIGN is a compliance audit firm that helps organizations start and grow their compliance programs across SOC 2, ISO 27001, CMMC, and ISO 42001 frameworks. Testing sits alongside those audits through a single, consolidated provider relationship, scoped to satisfy SOC 2 and ISO 27001 requirements and run by a team kept independent from the audit side.
Capabilities
- Penetration testing (external, internal, web application, cloud)
- Red team services and social engineering
- Vulnerability assessment services
- Ransomware preparedness assessments
- SOC 1, SOC 2, and SOC 3 examinations
- ISO 27001, ISO 27701, ISO 22301, and ISO 42001 certification
- CMMC and NIST 800-171 assessments
- FedRAMP and GovRAMP authorization support
- HITRUST and HIPAA assessments
- PCI DSS and PCI SSF assessments
- A-SCEND audit management platform
Certifications
SOC 2, ISO 27001, CMMC, FedRAMP, HITRUST, PCI DSS
PCA Cyber Security
Munich- and Budapest-based embedded cybersecurity experts for financial services, automotive and mobility, manufacturing and industrial automation, and energy
PCA Cyber Security is an embedded cybersecurity firm based in Munich and Budapest, founded in 2019. It tests and monitors connected and embedded products for clients in financial services, automotive and mobility, manufacturing and industrial automation, energy, rail and healthcare, and its services and platform support the security requirements of the Cyber Resilience Act, PCI PTS, UN R155, ISO/SAE 21434 and related standards. Penetration testing covers payment terminals, PIN pads, unattended terminals and ATMs; ECUs, telematics, vehicles and EV chargers; SCADA, PLCs and OT networks; IoT, embedded and medical devices; railway systems; and the web, mobile and cloud applications around them, with hardware and firmware research done in its CyberLab and CyberGarage facilities. PCA also builds PCA Cervus, a device-centric vulnerability monitoring and threat intelligence platform that takes a supplier's SBOM through to remediation evidence. The firm holds TISAX Assessment Level 3 with protection of prototype parts, is a registered Associate Participating Organization of the PCI Security Standards Council, took part in Pwn2Own Automotive in 2024 and 2025, and its researchers have spoken at Black Hat, Hexacon, Escar and Hacktivity.
Capabilities
- Payment-device penetration testing (POS, PIN pads, unattended terminals)
- Fuel-pump and EV-charging payment system testing
- Embedded and IoT device security testing
- Automotive security testing and research
- PCA Cervus: device-centric vulnerability monitoring and threat intelligence platform for embedded products
- Security assessments and continuous monitoring
- Software composition analysis and SBOM validation by firmware reverse engineering
- Extended bill of materials (xBOM) with CVE mapping, built from the binary rather than vendor documentation
- Automotive and embedded penetration testing (ECUs, IVI, telematics, EV chargers)
- Vehicle and product threat intelligence
- Product Security Operations Center (PSOC) / Vehicle SOC monitoring
- Threat Analysis and Risk Assessment (TARA)
- Cybersecurity verification and validation (V&V) services
- Remote attack surface analysis (mobile apps, backend APIs, cloud)
- Security assessments supporting ISO/SAE 21434 compliance
- UNECE R155 cybersecurity assessment support
- Hardware and firmware research via dedicated CyberLab and CyberGarage facilities
- Vulnerability research and coordinated responsible disclosure
- ICS and OT penetration testing (SCADA, PLCs, industrial networks)
- Medical device penetration testing
- Railway penetration testing (signalling, communication and control networks)
- Application penetration testing (web, mobile and cloud)
Certifications
TISAX Assessment Level 3, PCI SSC Associate Participating Organization, ISO/SAE 21434, UNECE R155
Sources
- PCA Payment Device Penetration Testing
- PCA Cyber Security joins PCI SSC as APO
- PCA: software composition analysis and SBOM validation service
- PCA Cyber Security: TISAX AL3, PCI SSC APO, Pwn2Own Automotive 2024 and 2025, conference speaking
- PCA Cyber Security: penetration testing services
- PCA Cervus platform
SBS CyberSecurity
US cybersecurity consulting, audit and testing firm founded in 2004, focused on community banks and credit unions, with penetration testing plus CMMC Level 1 and 2 readiness work for defense contractors.
SBS CyberSecurity is a US cybersecurity consulting, audit and testing firm founded in Madison, South Dakota in 2004. Its core market is regulated financial institutions, community banks and credit unions, served through risk management programmes, IT and network security audits, penetration testing, and the TRAC governance, risk and compliance platform. Co-founders Chad Knutson and Jon Waldman acquired full ownership of the company in July 2022. Penetration testing covers external network, internal network, web application, wireless, and PCI DSS Requirement 11 engagements, aligned to NIST, OWASP and PTES. Alongside testing, SBS runs red team, purple team and social engineering assessments, and advisory work including virtual CISO, NIST Cybersecurity Framework assessments, cybersecurity maturity assessments, and vendor risk management. For defense contractors, SBS provides CMMC readiness for Level 1 and Level 2: gap identification, documentation and preparation for assessment. Certification itself is completed by a separate Certified Third Party Assessment Organization (C3PAO); SBS is not listed on the Cyber AB Marketplace as an RPO or C3PAO.
Capabilities
- External and internal network penetration testing
- Web application penetration testing
- Wireless penetration testing
- PCI DSS Requirement 11 testing
- Red team, purple team and social engineering assessments
- CMMC Level 1 and 2 readiness (gap assessment, documentation, assessment preparation)
- Virtual CISO and NIST Cybersecurity Framework assessments
- TRAC governance, risk and compliance platform
Certifications
CMMC (NIST SP 800-171), NIST CSF, PCI DSS, OWASP, PTES
Sources
- SBS CyberSecurity: official website
- SBS CyberSecurity: Our Company (founding year, TRAC, SBS Institute)
- SBS CyberSecurity: penetration testing services
- SBS CyberSecurity: CMMC readiness (states it does not act as assessor or certifying body)
- American Bankers Association Partner Network directory listing
- Inc. 5000 company profile
- SBS CyberSecurity: NIST Cybersecurity Framework Assessment
- SBS CyberSecurity: Cybersecurity Maturity Assessment
- SBS CyberSecurity: Vulnerability Assessment
- SBS CyberSecurity: Virtual CISO
- SBS case study: Long-Term Banking Client Strengthens Security with Pen Test and Vulnerability Assessment
- SBS case study: Community Bank Gains Cybersecurity Roadmap from IT and Network Security Audits
- SBS case study: Community Bank Identifies Security Gaps with Successful Red Team Assessment
- Investing.com: Chad Knutson and Jon Waldman on AI-driven cyber threats
- International Business Times: Chad Knutson and Toni Meyer on spreadsheet-based compliance
- SBS CyberSecurity: Chad Knutson June 2026 banking AI speaking engagements
- Graduate School of Banking: Chad Knutson, Program Coordinator
A-LIGN
Penetration Testing FirmsCompanies running testing alongside a formal audit who want one accredited firm across both
Founded in 2009 and headquartered in Tampa, Florida, A-LIGN is a compliance audit firm that helps organizations start and grow their compliance programs across SOC 2, ISO 27001, CMMC, and ISO 42001 frameworks. Testing sits alongside those audits through a single, consolidated provider relationship, scoped to satisfy SOC 2 and ISO 27001 requirements and run by a team kept independent from the audit side.
Bishop Fox
Penetration Testing FirmsMid-to-large enterprises wanting continuous offensive testing rather than annual point-in-time pentests
Founded in 2005 (originally as Stach & Liu), Bishop Fox positions itself as 'the leading authority in offensive security' and is headquartered in Tempe, Arizona. Beyond traditional consulting it sells Cosmos, a continuous attack-surface management and offensive-testing platform that pairs automated discovery with human operator validation.
IOActive, Inc.
Penetration Testing FirmsOEMs, semiconductor vendors, automotive, and critical-infrastructure operators that need silicon-to-cloud security expertise
Founded in 1998 by Joshua Pennell and led since 2008 by Jennifer Sunshine Steffens, IOActive is headquartered in Seattle with offices in Atlanta, London, Madrid, and Dubai. The firm is known for full-stack security assessments and deep specialism in hardware, embedded systems, semiconductors, automotive, industrial control, and other safety-critical environments.
Lorikeet Security
Penetration Testing FirmsEngineering-led companies that want continuous testing between annual pentests, with human sign-off on findings and published pricing.
Lorikeet Security, founded in 2021, is a security services firm that runs its work through a client portal called Talon. Its AI pentester, Lory, runs recon, chains exploits and drafts findings with evidence within a signed scope, and a human pentester countersigns each finding before it reaches the client. Alongside that it offers manual penetration testing across web, API, mobile, cloud, network, Active Directory, containers, wireless and IoT, red and purple teaming, compliance readiness for frameworks including SOC 2, ISO 27001, PCI DSS and HIPAA, managed detection and response, incident response retainers and vCISO services. Findings arrive in Talon with evidence and free retesting, and can route to Slack, Jira and code repositories.
Mandiant (part of Google Cloud)
Penetration Testing FirmsEnterprises needing top-tier incident response, nation-state threat intelligence, or board-defensible breach engagement
Founded in 2004 by Kevin Mandia, Mandiant built a global reputation responding to the world's most high-profile breaches. After acquisition by FireEye in 2013 and by Google for ~$5.4B in 2022, the firm retained its brand and now operates inside Google Cloud as a specialist consultancy for incident response, threat intelligence, and offensive security.
NCC Group
Penetration Testing FirmsRegulated enterprises and public-sector buyers wanting CREST-accredited testing, MDR, and software escrow under one global vendor
NCC Group was formed in 1999 when the National Computing Centre's commercial divisions were spun out and is headquartered in Manchester, listed on the London Stock Exchange. With 2,000+ staff across the UK, North America, Europe, and APAC, the group operates technical assurance, managed services, and software escrow divisions and is a founding CREST member.
PCA Cyber Security
PCI PTS Compliance Testing CompaniesManufacturers and operators of payment devices, vehicles, industrial systems and other embedded products who need hands-on product security testing and monitoring against the CRA, PCI PTS, UN R155 and ISO/SAE 21434
PCA Cyber Security is an embedded cybersecurity firm based in Munich and Budapest, founded in 2019. It tests and monitors connected and embedded products for clients in financial services, automotive and mobility, manufacturing and industrial automation, energy, rail and healthcare, and its services and platform support the security requirements of the Cyber Resilience Act, PCI PTS, UN R155, ISO/SAE 21434 and related standards. Penetration testing covers payment terminals, PIN pads, unattended terminals and ATMs; ECUs, telematics, vehicles and EV chargers; SCADA, PLCs and OT networks; IoT, embedded and medical devices; railway systems; and the web, mobile and cloud applications around them, with hardware and firmware research done in its CyberLab and CyberGarage facilities. PCA also builds PCA Cervus, a device-centric vulnerability monitoring and threat intelligence platform that takes a supplier's SBOM through to remediation evidence. The firm holds TISAX Assessment Level 3 with protection of prototype parts, is a registered Associate Participating Organization of the PCI Security Standards Council, took part in Pwn2Own Automotive in 2024 and 2025, and its researchers have spoken at Black Hat, Hexacon, Escar and Hacktivity.
Praetorian
Penetration Testing FirmsTech and regulated enterprises wanting continuous offensive testing folded into a single subscription rather than annual one-offs
Founded in 2010 by Nathan Sportsman and headquartered in Austin, Texas, Praetorian positions itself around 'continuous offensive security.' It pairs traditional consulting with Chariot, a platform combining external attack-surface management, continuous testing, and AI-driven workflow automation to surface exploitable issues on an ongoing basis.
SBS CyberSecurity
Penetration Testing FirmsCommunity banks, credit unions and other regulated financial institutions that want testing, audit and governance from one firm, plus organizations preparing for a CMMC Level 1 or Level 2 assessment
SBS CyberSecurity is a US cybersecurity consulting, audit and testing firm founded in Madison, South Dakota in 2004. Its core market is regulated financial institutions, community banks and credit unions, served through risk management programmes, IT and network security audits, penetration testing, and the TRAC governance, risk and compliance platform. Co-founders Chad Knutson and Jon Waldman acquired full ownership of the company in July 2022. Penetration testing covers external network, internal network, web application, wireless, and PCI DSS Requirement 11 engagements, aligned to NIST, OWASP and PTES. Alongside testing, SBS runs red team, purple team and social engineering assessments, and advisory work including virtual CISO, NIST Cybersecurity Framework assessments, cybersecurity maturity assessments, and vendor risk management. For defense contractors, SBS provides CMMC readiness for Level 1 and Level 2: gap identification, documentation and preparation for assessment. Certification itself is completed by a separate Certified Third Party Assessment Organization (C3PAO); SBS is not listed on the Cyber AB Marketplace as an RPO or C3PAO.
Trail of Bits
Penetration Testing FirmsCrypto/DeFi protocols and security-conscious tech companies needing deep code, cryptography, and AI assurance work
Co-founded in 2012 by Dan Guido and headquartered in New York City, Trail of Bits combines academic-style security research with hands-on engineering. The firm is best known for advanced software assurance work across cryptography, AI/ML, blockchain, and low-level systems, and for releasing widely used open-source tooling such as the Slither smart contract analyzer.
Related guides
Other categories you might be evaluating alongside penetration testing firms.
About this listing
Penetration Testing Firms companies, compared on public information. The comparison table is ordered by reader upvotes, then A to Z, with paid Featured listings shown first and labelled; the full entries run A to Z. How we work →