NetSPI does not publish a service price that a buyer can use to build a budget. As of July 31, 2026, its public material describes custom contracts and a fixed-price annual PTaaS capacity model, while CodeAnt’s AI penetration testing product uses payment tied to confirmed high- and critical-severity findings.
Start with this penetration-testing cost guide before comparing proposals. It explains the scope choices that can make two prices describe very different tests.
TL;DR
Public NetSPI price: NetSPI does not publish one, so buyers need a custom quote.
Annual option: PTaaS Stream reserves annual testing capacity at a fixed price that is not publicly disclosed.
Capacity limit: NetSPI’s Stream brief says each subscription runs one penetration test at a time.
AWS Marketplace listing: The
$1NetSPI Platform line excludes pentest hours and is not a service price.Buying rule: Give each vendor the same written scope and retest terms. This PTaaS guide explains what continuous access should include.
How much does NetSPI cost?
The precise answer is “contact NetSPI for a quote.” Its public site does not show a starting rate for either an application test or a tester day.
NetSPI also leaves its PTaaS tiers unpriced. Buyers therefore need a proposal before they can compare the service with a published budget.
Public contract totals do not solve that gap because they rarely expose the purchased scope. A contract may cover one application or a cloud environment, while a larger agreement may span a wider security program.
The AWS Marketplace listing requires the same care. It shows a $1.00 12-month NetSPI Platform dimension, then excludes pentest hours and sends buyers to a private offer.
Treat that dollar as a transaction placeholder for platform access. To produce comparable proposals, give each supplier the same penetration-testing process and testing depth.
Use identical delivery terms in both requests. The reports should also meet the same evidence standard.
NetSPI pricing and packaging at a glance
Purchasing model visible in official material | Published price | What is publicly documented | What the quote must clarify |
|---|---|---|---|
Scoped penetration test | No | Cost changes with the environment, methodology, testing depth, remediation work, compliance needs, and tester expertise | Exact targets, access level, test window, tester effort, report, retests, and exclusions |
PTaaS Stream annual subscription | No amount; described as a fixed annual price | Dedicated testing capacity for web apps and APIs; one test at a time per subscription | Capacity, queue rules, maximum scope per test, rollover, concurrency, and overage |
NetSPI Platform via AWS Marketplace |
| 12-month contract mechanism and private-offer route | Full private-offer price, included entitlements, infrastructure charges, renewal, and refund terms |
Attack-surface or adversary-simulation work | No | Sold within NetSPI’s broader proactive-security platform | Asset-count basis, validation labor, scan cadence, service level, and whether work is bundled |
The proposal must define the unit behind its total. Separate the required types of penetration testing before asking for a quote, because an application assessment and a cloud configuration review require different scope descriptions.
What does each NetSPI purchasing model include?
Scoped penetration-testing engagements
NetSPI’s official cost guidance starts with the environment being tested, then adjusts for method and depth. Application scope may be measured through screens and endpoints, with roles and access levels establishing how many distinct paths testers must cover.
Cloud scope is described differently. The provider and deployed services shape the work, while account boundaries determine whether the tester is reviewing one environment or moving across several business units.
A request for proposal should therefore describe what a tester must traverse instead of labeling the target “one app.” For a multi-tenant service, use a multi-tenant SaaS testing guide to document tenant boundaries.
Choose the access model after defining those boundaries. This guide to pentest access models explains how much context each approach gives the tester.
An internet-facing test also needs a named methodology. This external penetration-testing methodology connects reconnaissance and authentication work to the evidence the final report should contain.
Source-code access needs its own line in the proposal. Code review and penetration testing answer different questions, so the supplier should state whether code is merely helping testers navigate the application or being reviewed as a separate deliverable.
PTaaS Stream annual testing capacity
NetSPI PTaaS Stream is the clearest public packaging signal. Its 2025 solution brief describes an annual subscription that reserves testing capacity for web applications and APIs, with depth adjusted to the application’s risk and functionality.
The same brief documents serialized delivery: one penetration test runs at a time per subscription. Buyers with overlapping releases therefore need to price the queue, not just the annual subscription.

A fixed annual price can stabilize the budget without guaranteeing parallel throughput. Ask NetSPI to show how a representative test moves through the queue, including when retesting uses the reserved slot.
Deployment frequency then determines whether the model fits. The choice between continuous and annual pentesting is an operational decision, and this comparison of continuous pentest tools for CI/CD shows the delivery models available when several releases need coverage.
Remediation testing
NetSPI’s cost article treats remediation testing as an additional cost and describes an a la carte model for selected findings. The proposal should state whether the billable unit is a finding or a test window.
If NetSPI prices the work through tester time, the quote should show the allocated effort. That makes an expanded retest easier to price before a customer requests it.

The retest clause should also define how a customer requests another cycle and what proof closes the finding. A penetration-test retest guide gives procurement and engineering a shared definition before either team interprets “retest included” differently.
Does NetSPI offer a free trial or free tier?
No public NetSPI free tier or self-serve trial appeared in the official sources reviewed as of July 31, 2026. The company directs prospective buyers into a sales conversation or a private offer.
If sales offers a pilot, begin with a target and a permitted access model. Then require the pilot agreement to say whether a human tester participates and whether the delivered findings include reproducible evidence.
The agreement should also define what the buyer receives when the pilot ends. A dashboard preview is not a full report, and remediation validation should not be assumed unless it appears in writing.
Give each provider the same scope through an automated-pentesting checklist. The follow-up questions for automated-pentesting vendors help distinguish an inventory scan from a service that attempts and documents an exploit path.
What drives a NetSPI quote?
1. Target count and application complexity
NetSPI names screens and unique API requests as application cost inputs. Roles and access levels add separate test paths, so they belong in the scope sheet rather than an appendix added after the quote arrives.

The method must be equally specific. The OWASP Web Security Testing Guide gives buyers a coverage vocabulary, while NIST SP 800-115 separates planning from execution and analysis.
2. Cloud and infrastructure boundaries
NetSPI’s guidance connects cloud cost to the provider and the systems included in the review. Account and tenant boundaries then determine how far the tester must move, while a production target introduces operating constraints that a test environment may not have.
Convert “test our cloud” into a named inventory before procurement sends it out. This cloud pentest checklist covers provider-neutral scope, and the AWS penetration-testing guide narrows the exercise for AWS accounts.
3. Testing depth and specialist labor
NetSPI’s official explanation treats the methodology and tester expertise as pricing inputs. Ask the proposal to distinguish automated discovery from human validation, then name any specialist path that requires different experience.
A reference to MITRE ATT&CK does not replace that plan. The proposal still needs to identify the techniques allowed for the scoped assets and the conditions that stop a test.
When a provider uses AI, ask how it handles reconnaissance before it attempts an action. This AI penetration-testing methodology follows that work through exploit validation and the safety controls around it.
4. Compliance evidence and reporting
Customized reporting adds work because the same finding may need technical proof for engineering and control evidence for an auditor. For a payment-card environment, compare the promised artifact with the current PCI Security Standards document library instead of accepting a generic “PCI-ready” label.
Give the vendor the applicable control language before the test begins. Compliance penetration testing explains the audit context, while this SOC 2 penetration-testing requirement guide separates auditor evidence from the technical evidence engineers need to fix a defect.
5. Retests, timing, and concurrency
PTaaS Stream’s serialized delivery makes concurrency a commercial term. A one-off engagement instead needs a fixed test window and report date, with any work outside the agreed schedule priced explicitly.
Remote and on-site delivery also create different access requirements. Use a remote penetration-testing guide to document communications and evidence transfer, then price travel separately if the engagement includes an on-site phase.
Prioritization belongs in the service definition. CISA’s Known Exploited Vulnerabilities Catalog records vulnerabilities with evidence of active exploitation, while FIRST’s EPSS estimates the probability of exploitation during the next 30 days.
Ask whether NetSPI adds either signal to the finding workflow and whether it changes retest order. Neither source proves exploitability inside the buyer’s environment, so the service must still validate the path it reports.
What NetSPI pricing gets right
NetSPI’s public explanation connects price to the scope and depth of the assessment instead of attaching a low rate to an undefined pentest. Its a la carte retesting model can also let a buyer reserve paid validation for findings the internal team cannot close independently.
PTaaS Stream adds a fixed annual price for reserved capacity. A team with a known test queue can budget that model, provided its release calendar fits the one-test-at-a-time limit.
What to watch before signing
Confirm the billable unit
The proposal should say whether it prices an application or tester time. An annual contract may instead price a capacity slot, while remediation work may use a finding as its unit.
If the supplier combines these units, require a subtotal for each. The breakdown keeps a later scope change from becoming an untraceable overage.
Model scope changes and concurrency
Ask NetSPI to price a realistic expansion before signing, such as adding another role or running two tests during the same release window. The answer shows how the Stream queue and one-off engagement terms behave when the initial scope no longer fits.
Define the report and retest
Review a sample pentest report against the promised deliverable. The contract should then state the retest window and the evidence required to close a finding.
Protect access and exit rights
The AWS listing says platform entitlements expire when the contract is not renewed or replaced. Ask how long reports remain accessible and what export format is available before access ends.
Testing authority belongs in the same contract package. Put the permitted targets and test dates in the authorization letter and statement of work, with emergency contacts and stop conditions written for the people running the engagement.
Run both candidates through the same AI pentesting provider evaluation, even if one proposal centers on human-led testing. The contract owner can use these pentest authorization-letter elements to catch scope gaps before the final signature.
NetSPI pricing compared with CodeAnt AI
NetSPI sells expert-led testing and platform workflows through custom contracts, while PTaaS Stream reserves annual testing capacity. CodeAnt publishes a different mechanism on its pricing page: the first full scan is included and low- or medium-severity findings stay visible for free.
Payment unlocks the high- and critical-severity findings. The pricing model therefore attaches the purchase to the result instead of a reserved block of testing capacity.
CodeAnt’s confirmed pentest page describes working proof-of-concept evidence with a 48-hour report and free unlimited rescans. Buyers should confirm the service boundary for either product in the proposal rather than infer it from the billing model.
This is not a scanner-only comparison. The difference between AI pentesting and traditional DAST lies in whether the workflow reasons through and validates an attack path, not whether it sends automated HTTP requests.
Buyer question | NetSPI | CodeAnt AI |
|---|---|---|
Can I see a usable public service price? | No; request a quote | Pricing mechanism is public, but no fixed dollar amount is shown |
What is the commercial unit? | Scoped engagement or annual dedicated capacity, depending on purchase | Confirmed high/critical findings unlocked on payment |
Is human-led delivery central? | Yes | AI-led testing; confirm any human-services requirement separately |
Is concurrency documented? | Stream says one test at a time per subscription | Not stated as a queue-based subscription on the public pricing page |
How are retests handled? | A la carte retesting is described in NetSPI’s cost guidance | Public pentesting page says rescans are free and unlimited |
Best fit | Enterprise programs that want expert-led assessments and custom scope | Teams that want fast, outcome-linked application testing |
Choose NetSPI when the engagement needs specialist human testing or an assessment outside application pentesting, provided the custom quote supplies enough capacity. Choose CodeAnt when the target is an application and the team wants to start without purchasing tester hours upfront.
Compare the evidence and test coverage before the invoice structure. A cheaper commercial unit does not help if it omits the attack path or report the buyer needs.
NetSPI quote checklist
Send one scope document to every bidder so the responses describe the same work:
Identify each target and its boundary. Record the application or network first, then attach the relevant account and role model.
Define the access model and whether source code is available. State any production restriction next to the affected target.
Name the test method and required coverage. Put exclusions in the same section so they cannot be mistaken for included work.
Set the delivery schedule. Include release dates and state whether tests must run in parallel.
Describe the report and closure evidence. Specify the retest unit and the number of cycles included in the quoted price.
Price each add-on separately. The final terms should also cover renewal notice, data retention, and the format used to export evidence.
A bidder that cannot price this scope can still explain which field prevents it from doing so. That explanation is more useful than a low total built on unstated assumptions.


