What is PTaaS?
PTaaS is a delivery and pricing model for penetration testing, not a different kind of test. What changes is how you buy it (a subscription, often in credits or per target), how you receive it (findings in a portal as they are confirmed, not a PDF at the end) and how you close it out (retests requested per finding in the same platform).
Providers use the term for everything from human testers on a platform to fully automated agents, so ask which model a quote is for.
How is it different from a traditional pentest and from bug bounty?
A traditional engagement sells a scoped block of tester time; PTaaS sells access to repeated tests through a platform; bug bounty pays per valid finding.
| Traditional engagement | PTaaS | Bug bounty | |
|---|---|---|---|
| What you buy | A statement of work for one test | A subscription: credits, targets or tests per year | Rewards per valid finding, plus a platform fee |
| Who tests | The firm's staff | Platform-vetted testers, automated agents, or both | Any researcher admitted to the program |
| Coverage | Defined by scope and methodology | Defined per test, often against a checklist | Whatever researchers choose to look at |
| Findings arrive | In the final report | In the portal during the test | As researchers submit them |
| Retest | Often a separate line item | Usually included within a window | Handled per report, sometimes with a reward |
| Report for auditors | Yes | Yes, generated by the platform | Not by default |
The coverage row is the real difference with bug bounty. A bounty program pays for results, so nobody is obliged to test your password reset flow or your admin API. A pentest, delivered either way, commits someone to a scope and a method. HackerOne's pentest product illustrates the split: its pentest overview says pentests "don't award bounties" for new findings, and testers follow OWASP-based checklists over a set testing period.
What does a PTaaS platform include?
Four components show up in almost every platform.
- Portal and scoping. You describe targets, roles and environments, upload credentials or API specs, and schedule tests. Scoping is still the step that sets quality; see rules of engagement.
- Findings workflow. Each finding is a record with severity, evidence, reproduction steps and a state. Cobalt's docs, for example, move a finding from Pending Fix to Ready for Retest to Fixed, or back to Pending Fix if the issue persists.
- Retest. You mark a fix as ready and the tester verifies it. Terms vary: Cobalt documents a seven-day retest turnaround and a free retest period of six or twelve months depending on tier, while HackerOne documents a remediation period "typically lasting 30 or 90 calendar days." See pentest retest.
- Integrations and reports. Ticket sync with Jira, GitLab or Azure DevOps, APIs and webhooks, plus generated reports and attestation letters for customers and auditors.
Human-led vs automated and AI-driven PTaaS
The market splits three ways.
- Human-led, platform-delivered. Vetted testers do the work; the platform handles scoping, findings and retests. Depth depends on the tester and the hours bought. Cobalt defines one credit as eight hours of testing.
- Autonomous or AI-driven. Software agents run the test, often on demand or on a schedule, and report findings they could exploit. Coverage of business logic and multi-step authorization flaws depends heavily on the tool, so ask for sample findings. What AI pentests find covers that question in detail.
- Hybrid. Automated testing runs continuously and humans test on a schedule or validate what the automation reports.
Compliance frameworks still describe a pentest as largely human work. The PCI SSC guidance calls it "a manual process that may include the use of vulnerability scanning or other automated tools," and FedRAMP's guidance says the test "should not be strictly limited to automated scanning techniques." If a PTaaS subscription is meant to cover a compliance test, confirm with your assessor which parts of it they will accept.
How do you evaluate a PTaaS provider?
Ask for specifics you can verify:
- Who or what tests? Human, automated, or both, and for which targets. Ask for named tester qualifications and whether the same tester retests.
- What is the unit of purchase? Credits, targets or tests. Convert it to tester-hours or runs per year so you can compare quotes. Penetration testing cost lists published figures.
- What coverage is promised per test? A methodology (OWASP WSTG, API Top 10), authenticated roles and tenants, and what is excluded.
- How is a finding evidenced? Request a sanitized sample finding with its reproduction steps. A finding without a working reproduction is a scanner result.
- What are the retest terms? Turnaround, how many retests, and how long after the test they remain free.
- What do reports look like? Check that the auditor-facing report and the attestation letter show scope, dates, method and retest status.
- Where does data go? Credential handling, data residency, and how long evidence is retained after the contract ends.
- What happens at renewal? Price per unit, and whether unused credits carry over.
Where does PTaaS fall short?
The platform does not make the testing better by itself. Common gaps:
- Credit rationing. A fixed credit pool can push teams to test fewer targets or shorter windows, which recreates the coverage gaps of an annual test.
- Checklist depth. Checklist-driven tests are consistent but can miss chained or business logic flaws that need a tester to spend unplanned time.
- Label drift. "PTaaS" can mean a scheduled scanner with a portal. Ask how exploitation is confirmed before trusting a finding count.
- Lock-in. Findings history, retest records and integrations live in the provider's platform. Check export options before you sign.
[ Sources ]
Written by Parameter · Last reviewed

