Cobalt pricing has one published dollar amount: $3,500 per Autonomous Pentest. Its Standard, Premium, and Enterprise PTaaS plans are quote-only. They use Cobalt Credits, and each credit represents eight hours of blended AI-assisted and human-led testing. Cobalt does not publish the price per credit or the number of credits needed for a given asset.
For buyers who need a transparent payment trigger instead of a prepaid credit pool, CodeAnt AI is the clearer alternative with our pentesting offer and a $0 engagement fee and payment when a working proof-of-concept exploit ships.
Cobalt Pricing Plans, Tiers, and Credit Costs at a Glance
Offer | Public price | What is public | What is not public |
|---|---|---|---|
Autonomous Pentest | $3,500 per test | Web-app testing, 24-hour findings, proof of exploit, remediation guidance | Whether your app qualifies; the credit impact for an existing customer |
Standard | Quote-only | 3-business-day start target; 6 months of free retesting | Contract price, credit rate, credit count per asset |
Premium | Quote-only | 2-business-day start target; 12 months of free retesting; named CSM | Contract price, credit rate, credit count per asset |
Enterprise | Quote-only | 1-business-day start target; quarterly planning; custom tester requests | Contract price, credit rate, credit count per asset |
The table comes from Cobalt’s pricing page, checked July 27, 2026. It is better evidence than marketplace estimates, which are estimates, not a Cobalt offer.
What Does Cobalt’s $3,500 Autonomous Pentest Include?
Cobalt calls this a web-application test. The page lists findings in 24 hours, proof of exploit, remediation guidance, Cobalt Core pentester direction, integrations with Jira, GitHub, Slack, and 50+ tools, and a report generated when the engagement closes.
There are two catches worth reading before you put $3,500 in a budget spreadsheet:
It is a limited-time offer. Cobalt says the test must be initiated and completed by December 31, 2026.
It is not a price for a full PTaaS program. It does not tell you what Cobalt will charge for multiple applications, APIs, cloud or network assets, ongoing testing, or a compliance calendar.
That makes it a useful entry point for a web app, not a shortcut for pricing the rest of the platform.
How Do Cobalt Credits Work and How Much Do They Cost?
A Cobalt Credit is eight hours of offensive-security testing delivered through automation plus human expertise. Credits are sold in annual packages. Cobalt says those packages include scoping, testing, retesting, and access to the platform.
Do not turn that into an hourly rate. A credit is a unit in Cobalt’s commercial model, not eight billable pentester hours. Cobalt assigns credits after it knows the asset scope and delivery options. Until the quote includes both numbers below, you cannot calculate the cost of a test.
Your negotiated price per credit.
The number of credits Cobalt assigns to each asset.
Ask for that asset schedule before signing. Get separate estimates for the web app, APIs, authenticated flows, user roles, environments, mobile apps, cloud assets, and network assets. A quote that says “a credit pool” without this schedule is not a budget.
What to ask Cobalt sales
How many credits will each named asset consume, and what assumption sits behind that number?
What raises the credit count: endpoints, roles, environments, integrations, or business-logic testing?
What is the price and minimum purchase if we need credits mid-contract?
What happens to unused credits at renewal?
That last question needs a written answer. Cobalt’s FAQ says credits do not roll into the next contract year. The tier comparison also has a credit-rollover row, with Enterprise listing up to 10%. Ask which rule applies to your agreement.
Cobalt Pricing Tiers: Standard vs Premium vs Enterprise
All three plans include the platform basics Cobalt lists: SAML-based SSO, access controls, a methodology checklist, findings with fixes, Slack and platform collaboration, Insights Dashboard, and Attack Surface Monitoring.
Standard
Standard is the plan Cobalt positions for a fast annual test driven by compliance or a customer request. The page lists a three-business-day start target, six months of free retesting, pooled customer-success support, and email onboarding. Those are the service terms worth comparing in a PTaaS provider SLA.
Use Standard if you have a single, bounded test and do not need a formal program cadence.
Premium
Premium adds a two-business-day start target, 12 months of free retesting, a named customer-success manager, live onboarding, annual planning, native integrations, customizable reports, and one DAST target.
This is the tier for a team that has more than an annual checkbox: releases, fixes, and audit dates need to be coordinated over the year. That is the same planning problem behind continuous versus annual pentesting.
Enterprise
Enterprise lists a one-business-day start target, quarterly planning, and custom pentester requests for geography, time zone, or testing windows. It is where Cobalt puts portfolio-scale governance and buyer-specific testing constraints.
Ask whether the controls you need are actually in the tier you are buying. “Enterprise” is not a feature description.
Cobalt Pricing Features: What Is Included and What Still Needs a Quote
Cobalt’s page lists DAST, strategic planning, integrations, customizable reports, and custom pentester requests across the tier comparison. Teams deciding how a running scanner differs from code analysis can use this SAST vs DAST guide before treating either as a substitute for a pentest. It also says its PTaaS model provides unlimited on-demand retesting during the contract term, while the plan table lists different retesting windows by tier.

Those details are useful for evaluating the service, but they are not price transparency. You still need the unit rate, asset-credit mapping, overage rules, and renewal treatment. Cobalt makes the delivery model legible; it does not make the full cost legible before a sales conversation.
Cobalt Pricing vs CodeAnt AI: Which Is the Better Choice?
Cobalt sells a managed PTaaS program through an annual, quote-only credit pool. CodeAnt AI’s pentesting offer states a $0 engagement fee and says payment starts when it ships a working proof-of-concept exploit. It also states a 48-hour audit-grade report and free unlimited re-scans after a fix.
Question | Cobalt | CodeAnt AI |
|---|---|---|
What does the meter measure? | Quote-only 8-hour credits | A working PoC exploit, per CodeAnt’s stated model |
Is there a public entry price? | $3,500 Autonomous Pentest promotion | $0 engagement fee |
What is the main buying motion? | Scoped annual PTaaS program | Start with a pentest; payment follows a proven exploit |
Where does it fit best? | Teams that want a managed human-led PTaaS program | Teams that want code-aware offensive testing connected to developer workflows |
For a buyer who needs a managed PTaaS program, Cobalt is a neutral, viable option. For a buyer who needs to know what causes payment, wants a report in 48 hours, and wants testing informed by code and developer workflows, CodeAnt AI is the better choice. It removes the two missing inputs in a Cobalt quote—the credit rate and asset-credit schedule—and makes the commercial trigger a verified exploit. The fuller product distinction is in CodeAnt AI vs Cobalt.
Is Cobalt Worth the Cost in 2026?
Yes, if Cobalt gives you a quote that maps credits to your actual assets and the program needs match the tier. The $3,500 offer is also a concrete way to evaluate the web-app product before expanding the scope.
CodeAnt AI is the better answer when the security team wants payment tied to a working exploit, not to prepaid testing capacity. It is also the clearer answer when developers need security testing connected to code review and the CI/CD workflow. Cobalt can remain in the shortlist for its PTaaS program; CodeAnt should lead it when transparent, outcome-based buying is the deciding criterion.


