AI Pentesting

Burp Suite Pricing in 2026: What $499 Buys and What It Does Not

 Ninad Pathak - Tech Author
Ninad Pathak

Professional Code Breaker

Burp Suite Professional costs $499 per user per year, and the order form is unusually blunt about the “per user” part. Everyone on your team who touches it needs a seat.

That single number hides most of what you will actually spend. Community Edition is free but cannot save your work, Burp Suite DAST carries no published price at all, and Burp AI runs on a credit meter that starts with a bundle worth about five dollars.

What Burp Suite pricing really covers: you are buying a named-user desktop license for manual penetration testing, not continuous coverage of an application. Automated scanning at portfolio scale sits in a separate, quote-only product, and the AI features consume a metered credit balance on top of the seat.

Burp Suite Professional pricing page showing the TRY FOR FREE and BUY - $499 buttons under the Test like a pro headline

Below is every edition PortSwigger sells as of July 2026, what each price includes, the costs that never appear on the pricing page, and how the spend compares with CodeAnt AI.

How Much Does Burp Suite Cost in 2026?

Burp Suite costs nothing for Community Edition, $499 per user per year for Professional, and a custom quote for Burp Suite DAST. Only one of those three numbers is published.

Here is the full lineup as PortSwigger presents it today.

Edition

Published price

What the meter counts

How you buy it

Community Edition

Free

Nothing, no license required

Direct download

Professional

$499 per user per year

Named users, one seat each

Self-serve checkout

Burp Suite DAST

No published price

Scanning capacity and deployment model, users unlimited

Sales quote

Burp AI credits

Not published

Credits consumed per AI request

My Account, Pro license required

Burp AT

Not published

Credits deducted as agent tasks progress

Public beta, Pro users

The gap between one published price and four unpublished ones is the story of Burp Suite pricing. PortSwigger sells you the tester’s seat off the shelf and negotiates everything that scales.

Burp Suite Pro license cost and what it covers

Burp’s own order form removes any ambiguity about the licensing unit. Picking a quantity of one shows “Total: $499 per user per year”, and the note underneath spells out the restriction.

Burp Suite order form showing subscription options of 1, 3, and 10 years, US Dollar currency, and a total of $499 per user per year

PortSwigger’s wording on the buy page is worth quoting before you plan a shared license. “Everyone who uses Burp Suite Professional needs to have a subscription. You cannot share a single Burp Suite Professional subscription between multiple users, even if only one person uses it at a time.”

Floating and concurrent licenses do not exist here, so the Burp Suite Pro license cost scales linearly with headcount. A team of four testers costs you $1,996 a year before anyone runs a scan.

Subscription terms of one, three, and ten years are offered, with more options behind a link, priced in US dollars, euros, or pounds. PortSwigger frames the longer terms as “Predictable pricing when you lock in for longer”, which reads as a price lock, not a published volume discount.

Is Burp Suite Free? Community Edition vs Professional

Burp Suite Community Edition is genuinely free and permanently available, and it deliberately withholds the features that make testing efficient. PortSwigger positions it as an “Essential manual toolkit - perfect for learning more about AppSec.”

The official comparison is the clearest statement of what the $499 upgrade buys.

Burp Suite Community Edition versus Professional comparison showing Community with proxy, Repeater, Decoder, Sequencer, Comparer, and Burp Intruder demo, against Professional adding project files, full Intruder, scanner, OAST, and search for $499

Community gives you the HTTP(s) and WebSockets proxy with history, the essential tools (Repeater, Decoder, Sequencer, and Comparer), and what PortSwigger labels “Burp Intruder (demo)”.

Professional adds the seven capabilities below, each of which is a hard blocker, not a convenience.

  • Project files. Community holds everything in memory, so closing Burp discards your site map, history, and findings. Reopening means re-walking the application.

  • Burp Intruder, full version. The free build ships a demo. PortSwigger does not publish the throttle rate, so treat community reports of the exact delay as unofficial.

  • The web vulnerability scanner. Community has no Burp Scanner at all, which removes both crawling and auditing.

  • Burp Collaborator. Auto and manual out-of-band testing is Pro-only, and OAST is how blind SSRF, blind XSS, and asynchronous injection get caught.

  • Automatic crawling and content discovery. Free users map the application by hand.

  • Pro-exclusive BApp extensions. Part of the extension library requires a Pro license.

  • Search. Finding a string across captured traffic is a paid feature.

Community works for learning, for a one-off look at a request, and for the Web Security Academy labs, which PortSwigger keeps free. Sustained professional testing without project files is impractical, because you re-map the application every time you close the window.

Burp Suite DAST Pricing (Formerly Enterprise Edition)

Burp Suite DAST pricing is quote-only in 2026, with no list price anywhere on portswigger.net. PortSwigger removed its published rate card and now routes every buyer through sales.

Burp Suite DAST plans page listing unlimited users, tailored subscriptions, deployment preferences, and scalable scanning requirements with no dollar figures

The DAST pricing page states four commitments instead of numbers. Subscriptions include “no limits on the number of users”, they are “customized based on your specific requirements”, you choose “between self-hosted options or running DAST scans via PortSwigger’s secure cloud”, and scanning ranges “From ad-hoc scanning managed by the hour to unlimited scalable scanning capabilities.”

A useful commercial detail sits in the DAST FAQs rather than the pricing page. PortSwigger says “You don’t pay per URL, making it an extremely flexible solution for growing enterprises”, which distinguishes it from per-app and per-FQDN competitors.

The name change that confuses quotes

Burp Suite Enterprise Edition became Burp Suite DAST in May 2025. PortSwigger described it as “just a new, clearer name for Burp Suite Enterprise Edition” and explained that the old name “often led to confusion, with some assuming it was merely a multi-user version of Burp Suite Professional.”

Old quotes, procurement records, and third-party pricing pages still use the Enterprise name. Match the product by capability, not by label, when you compare a 2024 renewal against a 2026 proposal.

What Enterprise pricing used to look like

Archived versions of PortSwigger’s own pricing page show what the model was before the numbers came down, and the shape of that model is still the best guide to how a DAST quote gets built.

Archived snapshot

Tier

Published annual price

February 2023

Starter, 5 concurrent scans

$8,395

February 2023

Grow, 20 concurrent scans

$17,380

February 2023

Accelerate, 50+ concurrent scans

From $35,350

April 2024

Pay as you scan

$3,600 cloud or $1,999 self-hosted, plus $25 or $9 per hour scanned

April 2024

Classic

$54,990 cloud at 10 concurrent scans, $19,121 self-hosted at 20

April 2024

Unlimited

$249,999 cloud or $49,999 self-hosted

Those figures come from Wayback captures of portswigger.net and are historical, not a current offer. Quote them to a PortSwigger rep in 2026 and you will be corrected.

A pair of patterns survives the deletion, though. Concurrent scans were the meter, and self-hosting cost dramatically less than PortSwigger’s cloud at the same capacity, which is why the current page asks about deployment preference before anything else.

What Do Burp AI and Burp AT Add to the Bill?

Burp AI runs on credits, and the free allocation is small enough to be a trial rather than an allowance. PortSwigger gave “all Burp Suite Professional users 10,000 free AI credits” at launch in March 2025, and its release notes describe that bundle as “equivalent to $5 USD.”

The credit rules matter more than the balance.

  • Credits expire. PortSwigger’s documentation states that “Unused credits expire 12 months after purchase.”

  • Credits cannot be pooled. They are “assigned to an individual user” and cannot be shared across a team, so a five-seat team manages five separate balances.

  • A Pro license is required to buy them. Credits are purchased from My Account and attach to a Professional license.

  • Consumption varies by feature. Explainer requests are cheap, while Explore Issue sends larger requests and costs more per use.

Top-up pack prices are not published anywhere on portswigger.net, so budget your AI layer by asking PortSwigger directly instead of extrapolating from the $5 anchor.

The 2026 additions

PortSwigger now sells Burp AI subscriptions alongside credit packs, which is the option to ask about if you would rather not track balances per person. The page describes seat-based annual pricing with unrestricted usage, and it publishes no figures, only a demo form.

Burp AT, the agentic AI product, entered public beta for Professional users in July 2026. Its billing follows the same meter, with credits “deducted as tasks progress”, and no rate card. The Burp Suite features guide covers what Burp AT and the rest of the toolkit actually do.

What Is the Real Total Cost of Burp Suite?

The license is the smallest line in a Burp Suite budget. Every serious deployment carries four costs the pricing page never shows.

Cost driver

What it adds

Where it comes from

Operator time

The dominant cost, since Burp is a manual toolkit driven by a skilled tester

Salary or consulting rate, not PortSwigger

Hardware

Recommended 16GB RAM, 32GB for large scans and complex attacks

PortSwigger’s published system requirements

AI credits

Metered per request beyond the initial bundle, per user, expiring yearly

Burp AI credits documentation

DAST infrastructure

Self-hosted scanning machines, or PortSwigger cloud at a higher rate

DAST deployment model

PortSwigger’s system requirements are candid about the hardware floor. Basic proxying runs on two cores and 4GB of RAM, general-purpose use wants 16GB, and intensive scanning or complex attacks want four cores and 32GB.

Project files start around 2GB each and grow from there, which is the detail that turns a laptop refresh into part of the license decision.

The operator cost dwarfs all of it. Putting that $499 seat in the hands of an engineer billing $150 to $250 an hour turns a two-week engagement into $12,000 to $20,000 of labour, so your license is roughly 3% of what the test costs you.

Training is the one genuinely free extra. PortSwigger’s Web Security Academy costs nothing, and the BApp Store extensions are free to install.

Burp Suite Pricing vs CodeAnt AI

Burp Suite prices the tester. CodeAnt AI prices the platform for the code team and the outcome for the pentest, which is why the two rarely produce comparable quotes.

Question

Burp Suite

CodeAnt AI

Published entry price

$499 per user per year for Professional

$24 per user per month for Premium

Free tier

Community Edition, no scanner or project files

14-day trial, 100 PR reviews, unlimited seats

What the meter counts

Named users, plus AI credits per user

Users for the platform, proven exploits for pentesting

Automated scanning at scale

Separate quote-only product, Burp Suite DAST

Included in the platform

Pentest payment trigger

Buy the license, then pay a tester

Payment follows a working proof-of-concept exploit

Retesting

New engagement and new tester hours

Free unlimited re-scans after a fix

Source-code analysis

Not offered, Burp is a black-box DAST toolkit

SAST, secrets, IaC, and dependency analysis on every pull request

CodeAnt AI pricing page showing a free 14-day trial, the $24 per user per month Premium plan, and a contact-us Enterprise plan

CodeAnt AI publishes $24 per user per month on its pricing page, with unlimited pull-request reviews, static analysis on pull requests, CI/CD integration, and audit reports in the Premium plan. Enterprise adds SSO, audit logs, and on-prem or VPC deployment, and open-source projects pay nothing.

The pentesting product inverts the engagement model entirely. CodeAnt states that payment starts when it ships a working proof-of-concept exploit and never when nothing exploitable is found, with reports in 48 hours against the traditional two to four weeks, plus free unlimited re-scans after you fix.

Neither model is universally better. Buy Burp Suite Professional when you have a skilled tester who needs maximum manual control over individual requests. Choose CodeAnt AI when you want the offensive work priced against results and running continuously against the code you are shipping now, which is the distinction the CodeAnt AI and Burp Suite comparison covers in depth.

Is Burp Suite Worth the Price?

Burp Suite Professional is worth $499 if you have a trained tester who will use it regularly. PortSwigger reports 88,000 customers across 18,000 organizations and 165 countries with a Net Promoter Score of +73, and the Pro page claims over 70,000 security professionals.

The value case breaks in three specific situations.

  • Nobody on your staff runs manual tests. A seat you open twice a year is expensive shelfware, and an outcome-priced pentest covers the same ground without the license.

  • You need breadth rather than depth. Burp Professional tests what your tester points it at, so covering a portfolio continuously means buying DAST separately at an unpublished price.

  • Your risk starts in the code. Burp is a black-box toolkit with no source-code analysis, so anything that needs static analysis alongside dynamic testing requires a second product.

Reviewers consistently flag the same friction. G2’s summary of Burp Suite reviews cites the cost of the Professional version and occasional false positives in automated scans among the recurring complaints, alongside strong marks for the interface and real-time interception.

Questions to Settle Before You Buy

Get written answers to these before the purchase order goes out, particularly for a DAST quote where nothing is published.

  • How many people genuinely need a seat, given that sharing one is prohibited?

  • Does the term length lock the price, and what happens at renewal?

  • For DAST, what defines scanning capacity, and how does the price move when it grows?

  • Is the deployment self-hosted or PortSwigger cloud, and what infrastructure does self-hosting require?

  • Who pays for AI credits once the initial bundle is spent, and does a subscription work out cheaper than packs?

  • What covers the application between manual engagements?

That last question is the one that decides whether a Burp license is your whole programme or one instrument in it. Comparing continuous and annual pentesting models is a better next step than negotiating the seat count.

Where This Leaves You

Burp Suite pricing is transparent exactly where the product is a desktop tool and opaque everywhere it becomes a platform. You can buy a $499 seat this afternoon without speaking to anyone, and you cannot learn what portfolio scanning costs without a sales call.

Budget the seat, then budget the tester, the hardware, the credits, and whatever covers your applications during the fifty weeks nobody is testing them. For the capability side of the decision, the Burp Suite features breakdown and the best Burp Suite alternatives cover what you get and what else can do it.

FAQs

How much does Burp Suite Pro cost in 2026?

Is Burp Suite free?

What is the difference between Burp Suite Community and Professional?

What is Burp Suite Enterprise or DAST pricing?

Do Burp AI credits cost extra?

Start Your 14-Day Free Trial

AI code reviews, security and quality trusted by modern engineering teams.

Table of Content
No headings found on page
Ship clean & secure code faster

Get Pentest Report

NO CC REQUIRED