Guide
Penetration testing as a service, and when a project fits better
Penetration testing as a service, often called PTaaS, packages testing as a subscription with a platform for findings. It suits some teams well, but a fixed-fee project is often simpler, so here is how to choose.
- Fixed fee before we start
- Named tester in writing
- Retest and attestation letter
How penetration testing as a service works
A PTaaS provider usually sells credits or a subscription. Testers then work on demand, and findings appear in a web platform rather than a single report. So the appeal is speed and visibility.
Where penetration testing as a service helps
It helps teams that ship constantly. For example, a product team releasing every week may want small tests on new features, rather than one large test a year.
- Frequent small tests on new features
- Findings tracked in a shared platform
- Integration with ticketing tools
Is penetration testing as a service right for you?
Tick what describes your team. Mostly ticks suggests PTaaS; few suggests a project.
Your result appears here as you tick, so you can see what is still open.
Subscription or fixed-fee project
Both models can deliver real manual testing. However, they suit different buyers.
| PTaaS subscription | Fixed-fee project | |
|---|---|---|
| Best for | Continuous release cycles. | Annual audits and customer requests. |
| Cost shape | Recurring, so budget yearly. | One fixed fee agreed before work. |
| Deliverable | Platform findings. | Report, attestation and retest letters. |
| Audit fit | Varies, so check the export. | Built for auditors. |
Questions to ask a PTaaS provider
Ask how many manual hours each credit buys. Also ask whether testers are named, and whether you get an audit-ready report at the end. Otherwise, a platform full of findings may still not satisfy your auditor.
Our model, stated plainly
We sell fixed-fee projects, not a subscription. So each engagement has written scope, stated manual hours, a named tester and an included retest. Many clients repeat it each year, which covers most audit cycles.
Penetration testing as a service questions
Is penetration testing as a service cheaper?
Not always. It spreads cost across the year, but total spend depends on how many credits you use.
Does PTaaS include manual testing?
Good providers do, so ask how many manual hours each credit buys.
Do you offer a subscription?
No. We offer fixed-fee projects, which many clients repeat annually.
Which is better for SOC 2?
Either can work. However, a project with a report and retest letter is the simplest evidence.
Related guides
Compare penetration testing as a service with a fixed fee
Send your release cadence and scope. We quote a fixed project, so you can compare it with any subscription offer.
Get my fixed-fee quote