Skip to content
Thornbury Labs
Authorised testing only. We test with your written authorisation, so scope and rules are agreed before testing begins. Testing is delivered by vetted third-party practitioners, and we do not describe our work as certified.

Guide

Penetration testing as a service, and when a project fits better

Penetration testing as a service, often called PTaaS, packages testing as a subscription with a platform for findings. It suits some teams well, but a fixed-fee project is often simpler, so here is how to choose.

  • Fixed fee before we start
  • Named tester in writing
  • Retest and attestation letter
Penetration testing as a service: define the need, compare models and choose and scope

How penetration testing as a service works

A PTaaS provider usually sells credits or a subscription. Testers then work on demand, and findings appear in a web platform rather than a single report. So the appeal is speed and visibility.

Where penetration testing as a service helps

It helps teams that ship constantly. For example, a product team releasing every week may want small tests on new features, rather than one large test a year.

  • Frequent small tests on new features
  • Findings tracked in a shared platform
  • Integration with ticketing tools

Is penetration testing as a service right for you?

Tick what describes your team. Mostly ticks suggests PTaaS; few suggests a project.

Your result appears here as you tick, so you can see what is still open.

Subscription or fixed-fee project

Both models can deliver real manual testing. However, they suit different buyers.

PTaaS subscriptionFixed-fee project
Best forContinuous release cycles.Annual audits and customer requests.
Cost shapeRecurring, so budget yearly.One fixed fee agreed before work.
DeliverablePlatform findings.Report, attestation and retest letters.
Audit fitVaries, so check the export.Built for auditors.

Questions to ask a PTaaS provider

Ask how many manual hours each credit buys. Also ask whether testers are named, and whether you get an audit-ready report at the end. Otherwise, a platform full of findings may still not satisfy your auditor.

Our model, stated plainly

We sell fixed-fee projects, not a subscription. So each engagement has written scope, stated manual hours, a named tester and an included retest. Many clients repeat it each year, which covers most audit cycles.

Penetration testing as a service questions

Is penetration testing as a service cheaper?

Not always. It spreads cost across the year, but total spend depends on how many credits you use.

Does PTaaS include manual testing?

Good providers do, so ask how many manual hours each credit buys.

Do you offer a subscription?

No. We offer fixed-fee projects, which many clients repeat annually.

Which is better for SOC 2?

Either can work. However, a project with a report and retest letter is the simplest evidence.

Related guides

Compare penetration testing as a service with a fixed fee

Send your release cadence and scope. We quote a fixed project, so you can compare it with any subscription offer.

Get my fixed-fee quote