Parameter

Penetration testing as a service (PTaaS)

Also known as

  • Pentest as a service
  • PTaaS platform

Penetration testing as a service (PTaaS) is a way of buying pentests as a subscription delivered through a web platform: you scope and launch tests in a portal, testers or automated agents post findings there as they confirm them, and you track fixes and request retests in the same place, usually under an annual contract.

Last reviewed

What is PTaaS?

PTaaS is a delivery and pricing model for penetration testing, not a different kind of test. What changes is how you buy it (a subscription, often in credits or per target), how you receive it (findings in a portal as they are confirmed, not a PDF at the end) and how you close it out (retests requested per finding in the same platform).

Providers use the term for everything from human testers on a platform to fully automated agents, so ask which model a quote is for.

How is it different from a traditional pentest and from bug bounty?

A traditional engagement sells a scoped block of tester time; PTaaS sells access to repeated tests through a platform; bug bounty pays per valid finding.

Traditional engagementPTaaSBug bounty
What you buyA statement of work for one testA subscription: credits, targets or tests per yearRewards per valid finding, plus a platform fee
Who testsThe firm's staffPlatform-vetted testers, automated agents, or bothAny researcher admitted to the program
CoverageDefined by scope and methodologyDefined per test, often against a checklistWhatever researchers choose to look at
Findings arriveIn the final reportIn the portal during the testAs researchers submit them
RetestOften a separate line itemUsually included within a windowHandled per report, sometimes with a reward
Report for auditorsYesYes, generated by the platformNot by default

The coverage row is the real difference with bug bounty. A bounty program pays for results, so nobody is obliged to test your password reset flow or your admin API. A pentest, delivered either way, commits someone to a scope and a method. HackerOne's pentest product illustrates the split: its pentest overview says pentests "don't award bounties" for new findings, and testers follow OWASP-based checklists over a set testing period.

What does a PTaaS platform include?

Four components show up in almost every platform.

  • Portal and scoping. You describe targets, roles and environments, upload credentials or API specs, and schedule tests. Scoping is still the step that sets quality; see rules of engagement.
  • Findings workflow. Each finding is a record with severity, evidence, reproduction steps and a state. Cobalt's docs, for example, move a finding from Pending Fix to Ready for Retest to Fixed, or back to Pending Fix if the issue persists.
  • Retest. You mark a fix as ready and the tester verifies it. Terms vary: Cobalt documents a seven-day retest turnaround and a free retest period of six or twelve months depending on tier, while HackerOne documents a remediation period "typically lasting 30 or 90 calendar days." See pentest retest.
  • Integrations and reports. Ticket sync with Jira, GitLab or Azure DevOps, APIs and webhooks, plus generated reports and attestation letters for customers and auditors.

Human-led vs automated and AI-driven PTaaS

The market splits three ways.

  1. Human-led, platform-delivered. Vetted testers do the work; the platform handles scoping, findings and retests. Depth depends on the tester and the hours bought. Cobalt defines one credit as eight hours of testing.
  2. Autonomous or AI-driven. Software agents run the test, often on demand or on a schedule, and report findings they could exploit. Coverage of business logic and multi-step authorization flaws depends heavily on the tool, so ask for sample findings. What AI pentests find covers that question in detail.
  3. Hybrid. Automated testing runs continuously and humans test on a schedule or validate what the automation reports.

Compliance frameworks still describe a pentest as largely human work. The PCI SSC guidance calls it "a manual process that may include the use of vulnerability scanning or other automated tools," and FedRAMP's guidance says the test "should not be strictly limited to automated scanning techniques." If a PTaaS subscription is meant to cover a compliance test, confirm with your assessor which parts of it they will accept.

How do you evaluate a PTaaS provider?

Ask for specifics you can verify:

  1. Who or what tests? Human, automated, or both, and for which targets. Ask for named tester qualifications and whether the same tester retests.
  2. What is the unit of purchase? Credits, targets or tests. Convert it to tester-hours or runs per year so you can compare quotes. Penetration testing cost lists published figures.
  3. What coverage is promised per test? A methodology (OWASP WSTG, API Top 10), authenticated roles and tenants, and what is excluded.
  4. How is a finding evidenced? Request a sanitized sample finding with its reproduction steps. A finding without a working reproduction is a scanner result.
  5. What are the retest terms? Turnaround, how many retests, and how long after the test they remain free.
  6. What do reports look like? Check that the auditor-facing report and the attestation letter show scope, dates, method and retest status.
  7. Where does data go? Credential handling, data residency, and how long evidence is retained after the contract ends.
  8. What happens at renewal? Price per unit, and whether unused credits carry over.

Where does PTaaS fall short?

The platform does not make the testing better by itself. Common gaps:

  • Credit rationing. A fixed credit pool can push teams to test fewer targets or shorter windows, which recreates the coverage gaps of an annual test.
  • Checklist depth. Checklist-driven tests are consistent but can miss chained or business logic flaws that need a tester to spend unplanned time.
  • Label drift. "PTaaS" can mean a scheduled scanner with a portal. Ask how exploitation is confirmed before trusting a finding count.
  • Lock-in. Findings history, retest records and integrations live in the provider's platform. Check export options before you sign.

Written by Parameter · Last reviewed