GetPentest

Pentest as a service (PtaaS) explained

PtaaS is a delivery model, not a different kind of testing. The same people do the same work, and what changes is how you buy it, how quickly you see findings, and who owns the platform in between.

Last reviewed 2026-08-27Written by Jacob Masse, TrazTech Inc.

Pentest as a service replaces the annual report with a subscription: testers work against your product in shorter recurring windows, findings appear in a platform as they are discovered rather than in a document six weeks later, and retests are requested through the same platform when your fix ships. Canadian buyers should expect $25,000 to $80,000 CAD a year for a meaningful subscription covering one product, which is more than a single annual engagement and buys more testing days spread across the year.

$25,000 to $80,000 A meaningful subscription, one product, per year, CAD

Continuous shipping The only profile it reliably suits

Ask first Whether it produces a scoped annual report your auditor accepts

The model is worth it if you ship continuously and your risk changes between releases. It is poor value if you ship twice a year and bought a test because a customer asked for a report, which describes most companies under fifty people.

What actually changes, and what does not

Traditional engagement and PtaaS compared
Traditional engagementPentest as a service
Who testsA named tester or small teamA named tester or a vetted pool, depending on the vendor
When findings arriveIn the report, after the window closesAs they are confirmed, usually within a day
CadenceOnce a year, plus after significant changeRecurring windows, monthly to quarterly
RetestOnce, inside a fixed window after the reportOn request, as fixes ship
Deliverable for an auditorA dated report with a scope statementA generated report per window, which needs checking for scope language
IntegrationEmail, then a spreadsheetIssue tracker integration, so findings land as tickets
Buying unitAn engagement, quoted per scopeA subscription or a pool of credits

What does not change is the work. A tester still needs credentials for each role, still needs to understand your data model, and still finds authorization flaws by comparing what two accounts can reach. A claim that the platform itself finds deeper issues is a claim about tooling, and tooling was never the constraint. The distinction between tooling and testing is on vulnerability assessment versus penetration test, and it applies to platforms as it does to consultancies.

When the subscription is worth it

Three conditions, and you want at least two of them.

Signals that PtaaS fits
SignalWhy it points this way
You deploy to production weekly or more oftenAn annual snapshot describes a product you no longer run
You have engineers who will fix findings within daysFast findings are only valuable to a team that can act on them. Otherwise they queue
Your product changes shape, not just contentNew roles, new tenancy models and new integrations create new authorization surface
Customers ask for evidence more than once a yearPer-window reports answer a question a yearly report cannot

Against that, the case for staying with an annual engagement: it is cheaper, the scope conversation happens once, and a named tester who spends ten uninterrupted days on your product often goes deeper than the same days chopped into four windows. Depth comes from context accumulated over consecutive days, which is what the subscription model spends.

The question to ask every PtaaS vendor

How many tester days a year does this subscription include, and are they the same tester. Subscriptions are priced in credits, windows or asset counts rather than days. Convert to days before you compare. If a vendor will not answer in days, you cannot tell whether you are buying more testing or a nicer interface around less of it.

The vendors, described rather than ranked

The category includes platform vendors that field their own vetted testers, managed bug bounty operators that also sell scoped testing windows, and traditional consultancies that have added a portal and a subscription price. Names you will meet include Cobalt, HackerOne, Bugcrowd and Synack, alongside Canadian consultancies offering their own subscription arrangements.

This site does not rank them, for the same reason it does not rank testing firms: a ranking published without having bought and run the engagements is opinion presented as evidence. That is what the vendor-published "best of" lists are. The evaluation method is on how to evaluate a penetration testing firm, and the questions transfer to platforms almost unchanged. Two additions apply to platforms: who is testing, since a pool model means the tester may differ between windows, and what happens to your findings if you cancel.

Where bug bounty fits, which is not here

A bug bounty is not testing you scoped. It is an open invitation with a price list, and what arrives is whatever researchers choose to look for, which skews to what is quick to find at scale. That has value once your product is mature: it catches things a scoped test would never have reached. It is a poor first purchase. An immature product generates a flood of low-severity submissions, and each one costs your team triage time whether or not it is paid.

Bounties also do not answer a compliance requirement on their own. An auditor asking for evidence of testing wants a scope statement and coverage. A bounty has neither by design: nobody agreed in advance what would be looked at.

Does PtaaS satisfy an auditor

Generally yes, with one thing to check. Auditors want a report with a scope statement, a date, an identified tester or firm, findings, and evidence of remediation. Platform-generated reports contain all of that, but the scope language is sometimes thin, describing assets rather than what was covered and what was not. Read the generated report the way your auditor will before your first evidence request, and ask the vendor to strengthen the scope section if it is vague.

For PCI DSS there is an extra step. Requirement 11.4 expects a documented methodology and specific coverage of the cardholder data environment perimeter. Confirm the vendor maps their windows to it before you assume the subscription replaces the annual test.

Compare a subscription against an engagement

Tell us how often you ship and what needs testing, and we will scope both so you can price them side by side.

Get matched

Common questions

What does PtaaS stand for?

Pentest as a service, sometimes penetration testing as a service. It describes buying testing as a recurring subscription delivered through a platform, with findings reported as they are found, rather than as a one-off engagement ending in a document.

Is pentest as a service more expensive than a normal test?

Per year, usually yes. Expect $25,000 to $80,000 CAD a year for one product against $10,000 to $30,000 CAD for a single annual engagement. The comparison is only fair on a per-day basis, so ask each vendor how many tester days the subscription includes and divide. Some subscriptions include more testing than an annual engagement, and some include less at a higher price.

Can we replace our annual penetration test with a subscription?

Yes for most SOC 2 and ISO 27001 purposes, provided the per-window reports carry a scope statement your auditor can read and you can show remediation evidence. Check the report format before the subscription starts rather than at evidence review. For PCI DSS, confirm the vendor maps their work to requirement 11.4 including segmentation testing, which many platform subscriptions do not cover.

Is a bug bounty the same thing?

No. A bounty is unscoped and paid per finding, so you receive whatever researchers happen to look for. PtaaS is scoped testing on an agreed schedule with coverage you can describe. Bounties complement testing for a mature product and do not satisfy a compliance requirement on their own, because there is no scope statement and no coverage claim to show.

Do we still need a scoping conversation with a platform vendor?

Yes, and it matters more rather than less, because the person testing may change between windows. Everything the tester needs has to live in the platform: roles, test accounts, tenancy structure, what is out of bounds, and what changed since the last window. The scoping questionnaire produces that document, and it is worth keeping current as a living page rather than writing it once.