notra·
2026 pricing guide

What does a penetration test cost in 2026?

Short answer: between $2,500 and $50,000 for a one-shot engagement, or $2,999+/year per target on a continuous platform — unless your threat model fits a $149 verified audit. Here are the real ranges, what drives them, and a calculator for your own numbers.

The honest price ranges

WhoModelPriceWhat that buys
One-shot consultancyPer engagement$5,000–$15,000 typicalFull market spans $2,500 for a scoped 1–2 day test to $50,000+ for large, multi-target engagements.
Astra SecurityContinuous hybrid, per target$2,999–$9,999 / yrPentest Auto $2,999/yr per target; Expert plans $5,999–$9,999/yr.
Aikido SecurityPentest add-on~$4,000+Sold as an add-on on top of their platform plans.
Beagle SecurityPer-app subscription$99–$299 / moPer-app monthly subscriptions; automated testing with human review at the top tiers.
NotraOne-time, per audit$149Flat, published, no sales call. Re-tests cost the same $149.

Platform prices (Astra, Aikido, Beagle) are their public pricing as of September 2026 — check their sites for current terms; quotes vary with scope. Consultancy ranges reflect common market quotes, not a published list.

What actually drives the price

Number of targets

Most engagement quotes are per app or per target. Three web apps roughly triples a one-shot price — which is also why per-target subscriptions get expensive fast.

Depth

A scoped external scan costs a fraction of weeks-long testing with authenticated sessions, multiple roles, and business-logic hunting. Authenticated testing alone moves quotes up a tier.

Human attestations

If your deliverable is a signed letter for SOC 2 or an enterprise reviewer, you're paying for a certified human to sign their name. That's a large slice of what consultancies charge.

Re-tests

You fixed the findings — now prove it. Consultancies often charge for a re-scan or put you back in the queue. Re-test frequency is where annual costs quietly double.

Where Notra fits — and what you give up

NotraPriceWhat it covers
Free scorecard$0Grades your site in about a minute. No card, no sales call.
First verified audit$0Free trial Deep Audit after you prove domain ownership.
Deep Audit$149 one-timeFull unauthenticated deep budget; report in ~35–60 minutes with per-finding exploit evidence.
Deep+$299 one-timeAdds authenticated testing with your session cookie and an extended request ceiling.
Monitor$49 / domain / moDaily re-scans with email on every change — between full audits.

The honest rows: a Notra audit comes with no attestation letter — it's evidence, not a signed assurance from a certified assessor — and no human chaining of novel multi-step, business-logic attacks. If either of those is the deliverable you need, a manual engagement is the right buy and the ranges above are what it costs. Where Notra wins is the verified-evidence slice, same-day, at a price that makes re-testing after every release affordable. The full trade-off is laid out in Notra vs manual penetration testing.

Price your own year

Pick your app count and re-test cadence. The comparison uses the consultancy math from the table above ($5,000 per app per engagement, ~$1,500 per re-test, attestation included) against Notra's flat $149 per audit.

Signed letter from a certified assessor, for auditors.

TYPICAL CONSULTANCY, PER YEAR
$13,000

2 × $5,000 + 2 × $1,500 re-tests · attestation included in the quote

NOTRA, PER YEAR
$596
Free scorecard$0
2 apps × 2 re-tests × Deep Audit$596
Human attestation$0 (not offered)
YOU KEEP
$12,404

per year, vs the consultancy math above

Cost questions, answered straight

Why is there such a huge range — $2,500 to $50,000?

You're buying different amounts of human time and different deliverables. A $2,500 test is usually one tester for a couple of days on one app. A $50,000 engagement is weeks of multi-role testing with re-tests and an attestation letter your auditor accepts. The number mostly tracks targets × depth × human attestations × re-tests — which is what the calculator above lets you price out.

Is a $149 audit a 'real' penetration test?

It is a real test with a narrower slice: Notra autonomously verifies the exploit classes it has proofs for — injection, exposed secrets and files, JWT and auth weaknesses, CVE-exposed components — and ships the exact request/response evidence for every finding. What it does not do is human creativity (novel multi-step chaining, business-logic abuse) or a signed attestation letter. See the honest side-by-side with manual pentests below.

Can I use the results for SOC 2 or a customer security review?

You can share a Notra report as evidence of proactive testing — every finding carries its own proof, and runs are manifest-pinned. But it is not a signed attestation from a certified assessor, and some auditors specifically want that letter. If the letter is the deliverable, budget for a manual engagement; the consultancy quotes in the table above are what that costs.

How often should I re-test?

Every time your attack surface meaningfully changes: a major release, a new auth flow, a new integration. With one-shot consultancies that means re-entering their queue and paying again; with Notra a re-test is another flat $149 credit you can run the same day. Continuous monitoring at $49/domain/month catches regressions daily in between.

Know the price before you spend $5,000.

Run the free scorecard first — it grades your site in about a minute and tells you whether a $149 verified audit is worth it.

Get your free scorecard

Next steps: the full pricing page, a sample verified report, the honest manual-pentest comparison, and continuous monitoring for between-audits coverage. Competitor prices referenced from public sources as of September 2026 — if something here is out of date, tell us.