Penetration testing services put a qualified attacker against your systems under contract, on a fixed scope, and hand you a report you can act on. Sthenos runs penetration testing services, vulnerability assessment services, and IT security audit engagements for enterprise and government teams across network, web, API, cloud, and application layers, following NIST SP 800-115 and the OWASP Testing Guide. Every engagement ends with a retest, because a finding you have not re-verified is still an open finding.
From kickoff to final report for a single application or network segment.
Executed alongside the OWASP Testing Guide, PTES, and MITRE ATT&CK.
Every confirmed finding is re-tested after your fix, at no extra charge.
A technical findings report and a board-readable executive summary.
What penetration testing services cover
A penetration test is scoped by attack surface, not by product name. Most engagements combine two or three of the areas below. Naming the surfaces up front is what keeps the quote honest and the results comparable between vendors.
Attack surfaces we test
Scope is agreed in writing before testing begins. Anything outside the signed scope is not touched.
Vulnerability assessment vs penetration testing
These get quoted against each other constantly, and they answer different questions. A vulnerability assessment tells you what is exposed. A penetration test tells you what an attacker can actually do with it. Buying the wrong one is the most common waste in this category.
Vulnerability assessment
Breadth
- Automated scanning across the whole estate
- Produces a ranked list of known weaknesses
- Runs monthly or quarterly on a schedule
- Does not confirm whether a flaw is exploitable
- Lower cost, wider coverage
Penetration test
Depth
- Human-led, chained exploitation of real weaknesses
- Proves impact: what data moved, what access was gained
- Runs annually, or after a significant release
- Eliminates false positives by demonstrating them
- Higher cost, decisive evidence
Most regulated programmes need both: continuous assessment for coverage, an annual test for proof.
How much does penetration testing cost?
Penetration testing cost is driven by scope size and testing depth, not by vendor size. Below is what the market charges, compiled from third-party industry sources, and what we charge for the same scope. Our figures include the retest.
What the market charges, and what we charge
Market figures are published ranges compiled from Astra Security, Software Secured and Blaze Information Security, current as of 2026. Sthenos figures are our own indicative ranges for the same scope, with the retest included rather than billed on top. Your quote is fixed in writing before work begins.
Three things move the number more than anything else: how many distinct applications or subnets are in scope, whether testing is black box or credentialed, and whether the engagement includes a retest. We quote all three explicitly rather than as a single line item.
Our penetration testing methodology
Every engagement runs the same five phases, whether it is a single API or a full internal network. The phases come from NIST SP 800-115 and the Penetration Testing Execution Standard, so the output is comparable against any other competent firm’s work.
- Scoping and rules of engagementWe agree assets, testing windows, escalation contacts, and what is explicitly out of bounds. Signed before anything is touched.Week 0
- Reconnaissance and enumerationMapping the real attack surface, which is routinely larger than the asset inventory says. Forgotten subdomains and stale services surface here.Days 1 to 3
- Exploitation and chainingConfirming weaknesses by using them, then chaining them. A medium plus a medium is often a critical, and only chaining reveals it.Days 4 to 10
- ReportingTwo documents: reproducible technical findings with evidence, and an executive summary that states business impact without jargon.Days 11 to 14
- Remediation support and retestWe re-test every confirmed finding after your fix and reissue the report with the status updated. Included, not billed separately.After your fix
Testing is scheduled around your change freezes and business hours. Destructive testing is never run without explicit written approval.
Cyber security assessment and IT security audit services
Not every question needs an attacker. Cyber security assessment services and IT security audit services evaluate your controls, policy and architecture against a named framework, and are usually what a board, insurer or prime contractor is actually asking for when they say they want a security review.
- Information security audit services and cyber security audit services measured against ISO/IEC 27001 Annex A or the NIST Cybersecurity Framework, producing a control-by-control gap register.
- Cyber security compliance services mapping your current state to the framework your contract names, whether that is SOC 2 criteria, HIPAA, PCI DSS, CMMC or FedRAMP.
- Architecture and configuration review against CIS Benchmarks for the platforms you actually run, rather than a generic checklist.
- Identity and access review covering privileged accounts, service principals, joiner-mover-leaver handling and standing access that should have expired.
Application security and cloud security services
Application security services move testing left, into the build, so the annual penetration test stops finding the same class of defect every year. Cloud security services address the configuration layer, which is where most cloud incidents actually begin.
Application security
- Secure code review on the paths that handle authentication, authorisation and money.
- Threat modelling at design time for new services, using STRIDE or attack trees.
- SAST and dependency scanning wired into CI so a vulnerable package fails the build.
- Developer remediation sessions, so fixes hold rather than recur next release.
Cloud security
- AWS, Azure and Google Cloud configuration review against CIS Benchmarks.
- Identity and role analysis, targeting over-broad permissions and unused standing access.
- Storage exposure review across buckets, blobs, snapshots and backups.
- Infrastructure-as-code policy checks, so a corrected setting cannot be reintroduced by the next deploy.
Cybersecurity consulting services
Testing tells you where you stand. Cybersecurity consulting services decide what to do about it. Our cyber security consulting work is advisory rather than tool-led: we help you sequence remediation against risk and budget, and we do not resell the products we recommend.
- Fractional security leadership. A named advisor acting as vCISO for organisations that need the judgement without a full-time hire.
- Security programme design. Building the policy set, risk register and control map from nothing, or rebuilding one that has drifted.
- Remediation roadmaps. Turning a findings report into a sequenced plan with owners, effort estimates and dependencies.
- Third-party and vendor risk. Assessing the suppliers inside your boundary, which is where an increasing share of incidents originate.
- Incident readiness. Tabletop exercises and runbook review, so the first time you practise is not during an actual breach.
Organisations approach this under several names. IT security consulting, information security consulting and cyber security consultancy all describe the same engagement shape here: a senior practitioner, a defined question, and a written answer you own.
Security testing in the software development lifecycle
Security testing belongs inside delivery, not only at the annual audit. Where conventional software testing asks whether the system does what it should, security testing services ask what else it can be made to do. Teams that treat software testing and security testing as one discipline find defects while they are still cheap to fix.
- Requirements and design. Abuse cases written alongside user stories; threat modelling before the first commit.
- Build. SAST and software composition analysis gated in CI, so a known-vulnerable dependency fails the pipeline.
- Pre-release. Targeted DAST and manual testing on authentication, authorisation and payment paths.
- Production. Continuous vulnerability assessment services plus an annual penetration test for proof.
What a penetration test satisfies
Most organisations buy a test because a framework, a customer or an insurer asked for one. Here is what each commonly expects, so you can scope once and satisfy the requirement rather than testing twice.
| Requirement | What it expects | Typical cadence |
| PCI DSS | Internal and external testing, plus segmentation testing where segmentation is claimed | Annually and after significant change |
| SOC 2 | Evidence of a vulnerability management programme; testing commonly requested by auditors | Annually |
| HIPAA | Technical evaluation of safeguards protecting electronic protected health information | Periodically and after material change |
| ISO/IEC 27001 | Technical compliance review supporting Annex A control assurance | Annually |
| CMMC / NIST 800-171 | Security assessment covering controlled unclassified information boundaries | Per assessment cycle |
| Customer security review | A current report with findings remediated and retested | On request, usually annually |
What to ask any penetration testing company
The quality gap between penetration testing companies is wide and is not visible in the proposal. Directory lists of top pen testing companies rank by marketing spend, not by testing depth, so use the questions below instead. These five questions separate human-led testing from a rebadged scan.
- Who is testing, and what are their certifications? Ask for named testers with OSCP, CREST or GPEN, not a company-level claim.
- Is a retest included in the price? If it is billed separately, the quote is not comparable to one that includes it.
- Can I see a redacted sample report? A serious firm will send one. The report is the deliverable, so judge it before you buy.
- What proportion of the work is manual? Automated scanning is a starting point. Business-logic flaws are only found by a person.
- How are findings evidenced? Every finding should carry reproduction steps a developer can follow without you in the room.
Frequently asked questions
How long does a penetration test take?
Most pen testing services quote two to four weeks end to end for a single application or network segment: roughly ten working days of testing, then reporting. Full-scope red team engagements run six to twelve weeks.
What is the difference between a vulnerability assessment and penetration testing?
A vulnerability assessment identifies and ranks known weaknesses using automated scanning across a wide surface. A penetration test is human-led and proves exploitability and business impact on a narrower scope. Regulated programmes typically run continuous assessment plus an annual test.
Will testing disrupt production systems?
Testing is scheduled around your change windows, and destructive techniques such as denial-of-service are excluded unless you request them in writing. Escalation contacts are agreed before testing starts so anything unexpected is stopped immediately.
Do you test cloud environments?
Yes, across AWS, Azure and Google Cloud, covering identity and role configuration, storage exposure, network boundaries and infrastructure-as-code. Note that cloud providers require notification for certain test types, which we handle as part of scoping.
What do we receive at the end?
A technical findings report with severity ratings, evidence and reproduction steps; an executive summary written for a non-technical reader; a remediation session with your engineers; and a retest with an updated report once fixes are in place.
Do you work with government agencies?
Yes. Roughly a third of our work is public sector, and engagements are scoped against NIST SP 800-115 and NIST 800-171 where controlled unclassified information is in play. The remainder of our work is commercial, and the methodology is the same in both.
Ready to scope a penetration test? Tell us what is in scope and what is driving the requirement, and we will come back with a fixed-price proposal for penetration test services that names the testers, the standards, and the retest terms. Talk to our security team or call +1 301-793-3980.