Flamingo Raises $4.5M Seed Round

Search for penetration testing services and nearly every result is a firm that sells them. That makes the buying advice hard to weigh, because the people writing it are also quoting you. We don't sell penetration tests, so here is what separates a test from a scan, which frameworks require one, and what belongs in the quote before you sign.

TL;DR

  • A pentest is manual exploitation. If nobody attempts to exploit a finding and pivot further, you bought a vulnerability scan.
  • Fewer frameworks require one than vendors imply. PCI DSS, CMMC Level 3 and NYDFS mandate it. SOC 2, ISO 27001 and HIPAA do not.
  • Published price tables contradict each other. Vendors disagree by 10x on whether white-box testing costs more or less.
  • Get retest terms in writing. One included retest is common, not universal.

A Pentest and a Vulnerability Scan Are Not the Same Purchase

A scanner enumerates known issues on assets you already know about. A penetration test adds a person who chains those issues into a working route in, then proves it works. Kevin Johnson, founder and CEO of Secure Ideas, drew the line on the Packet Protector podcast: "If they're not attempting to do that, it's not a pen test, period." The "that" is exploitation and pivoting.

The UK's National Cyber Security Centre frames the purchase in a way that saves money. A pentest is a method for gaining assurance that your vulnerability management works, not the primary method for finding vulnerabilities. Ideally you already know what the testers will find before they find it.

If the test is the first time anyone has looked, you're paying senior consultant rates for output a scanner produces. That's a question about your vulnerability management rather than your pentest budget.

Johnson also offers a screening question that costs nothing. Ask which tools they use, then ask how many of those tools have been released publicly. If the answer is none because it's their secret sauce, he suggests ending the conversation there. What that phrase often describes, in his words, is "a version of Nessus that they've changed the logo on the report."

Practitioners screen for this the same way. The thread below is a sysadmin asking what to ask on vendor calls, and the top answer tells him to sign an NDA, demand a de-identified sample report, and expect a proof of concept per finding rather than CVSS output.

Which Frameworks Require a Pentest, and Which Only Imply It

Ask three vendors whether SOC 2 requires a penetration test and you may get three yeses. The Trust Services Criteria say otherwise. The phrase "penetration testing" appears nowhere in the criteria themselves. It appears in a single point of focus under CC4.1, listed alongside vulnerability scans, security assessments and third-party assessments as things management might use. The AICPA then states that use of the criteria "does not require an assessment of whether each point of focus is addressed."

FrameworkRequired?What the text says
PCI DSS v4.0.1YesReq 11.4: internal and external testing at least every 12 months and after significant change. Corrections must be verified by retesting (11.4.4)
CMMC Level 3YesCA.L3-3.12.1e: at least annually or on significant security change. Levels 1 and 2 say nothing
NYDFS 23 NYCRR 500.5YesAnnual, from inside and outside the boundary. Covered financial entities only
SOC 2NoOne point of focus under CC4.1, and points of focus are not themselves required
ISO 27001:2022NoAnnex A 8.8 and 8.29 never name it. It appears as one example technique in ISO 27002 guidance
HIPAANoThe word appears nowhere in the Security Rule. Proposed at 164.312(h)(2)(iii) in January 2025, projected for 2027, not enforceable today
NIST SP 800-171NoZero occurrences in Rev 2 or Rev 3

That distinction changes what you buy. A SOC 2 auditor works from your control description, not from a preference of their own. If you wrote that you perform an annual third-party external penetration test, your own sentence is what binds you. Teams discover this the hard way, and the thread below is a good example: the practical answer in it is that auditors look at two things on the letter, the completion date and the remediation status of findings.

None of this argues against testing. It argues against buying one because a salesperson said an auditor demands it. Read your own control language first, then decide what the test is for. If you're mapping several frameworks at once, our cybersecurity frameworks list sets them side by side.

What Cyber Insurance Carriers Ask For

One claim circulates constantly: policies above $1M in coverage require an annual third-party pen test, and $5M and up requires documented internal and external testing. It appears near-verbatim across at least ten sites. Every one of them sells penetration testing or compliance software, and not one cites a carrier or broker document.

The carrier forms say something different. Travelers asks about annual penetration testing on its full CyberRisk application, including whether a third party performs it. Its short form, for applicants at or below $50M in revenue, doesn't ask at all. Beazley's US application for companies under $250M in revenue has no penetration testing question either. Chubb does ask for annual internal and external testing, on its UK proposal form.

Brokers behave the same way. Gallagher's 2026 cyber market outlook doesn't mention penetration testing once, and neither does the Q1 2026 market update from Risk Placement Services, despite a dedicated section on where underwriting is heading. Marsh lists it as a sub-bullet under patch and vulnerability management rather than among its twelve key controls. Howden names it as one mitigation among several, while noting that the controls which got effectively mandated were multi-factor authentication and backups.

What the claims books agree on is where attackers get in. Coalition found that 58% of its 2024 ransomware claims began with a compromised perimeter appliance such as a VPN or firewall. Beazley Security's Q4 2025 threat report attributes 54% of ransomware initial access to VPN-compromised credentials. Travelers' Corvus unit put VPNs at 44% of ransomware and system intrusion claims across 2025, up from 36% the year before. Coalition has also published odds rather than shares: businesses with internet-exposed Cisco ASA devices were nearly five times more likely to file a claim in 2023.

Carriers increasingly check for themselves rather than asking. Coalition scans applicants and policyholders continuously, and says unfixed findings lead to contingencies at renewal. Chubb reports that claims from severe vulnerability exploits fell from nearly 22% in 2022 to 9.5% in 2025, which it credits to its own programme alerting policyholders to exploitable issues.

So the insurance argument for a pentest isn't a requirement. It's a scoping instruction. If you're testing to reduce the thing carriers pay out on, point it at the external perimeter and remote access, which is also what our cyber insurance requirements guide works through.

Why Published Price Tables Disagree With Each Other

Here is a check you can run in five minutes. Pull up two vendor pricing guides and compare what each says white-box testing costs.

DeepStrike's 2026 guide puts white-box work at $7,000 to $40,000 and above, higher than its black-box range, on the logic that more access means more surface to review. Astra's guide, updated in August 2026, puts white box at $500 to $2,000 per asset, which is 10 to 25 times cheaper than its own black-box figure. Both are vendor marketing pages. Both cannot be right.

There is no independent pricing dataset for US penetration testing. No analyst house, no trade body and no government rate card publishes one. Every range in circulation traces back to a vendor's own marketing, including the widely repeated $18,300 average, which appears on multiple sites with no derivation shown on any of them.

Test typeAdvertised rangeAs published by
External network$4,000 to $12,000Synack, June 2026
Internal network$5,000 to $35,000Synack, June 2026
Web application$5,000 to $30,000Synack, June 2026
API$5,000 to $30,000Synack, June 2026
Cloud$10,000 to $50,000Synack, June 2026
Social engineering$3,000 to $12,000Synack, June 2026
Red team$30,000 to $150,000 and upSynack, June 2026

Treat those as advertised, not as market rates. The numbers worth more to you are units. DeepStrike quotes skilled tester rates at $100 to $300 an hour, with senior testers at $200 to $300 and above. Astra prices network work at $150 to $1,000 per device, with external testing at $5,000 to $10,000 for up to 25 IPs. A rate and a count you can check against your own asset inventory beat a range you can't audit.

What a Legitimate Quote Contains

PCI DSS is worth reading even when it doesn't apply to you, because Requirement 11.4.1 is the only place a standards body writes down what a penetration testing methodology has to contain. Use it as a checklist against any quote:

  • A named, industry-accepted methodology
  • Coverage of the full perimeter and critical systems
  • Testing from both inside and outside the network
  • Validation of segmentation and scope-reduction controls
  • Application-layer testing covering injection, access control and business logic flaws
  • Network-layer testing across components and operating systems
  • A review of threats from the previous 12 months
  • A documented approach to risk-ranking findings
  • Retention of results and remediation records for at least 12 months

Then check the methodology they name. NIST SP 800-115 is the most cited one and it was published in September 2008 with no revision announced since, so a vendor page titled "NIST SP 800-115 (2026)" is telling you something about their content practices. PTES is still at version 1.0 with a note promising version 2.0 "soon", and its canonical site doesn't serve HTTPS at all. OWASP's Web Security Testing Guide sits at v4.2 with v5.0 in development, and it's the one under active maintenance.

Credentials are worth a question too. OSCP has no expiry while OSCP+ lapses after three years, and GIAC standardised the GPEN passing score at 73% in July 2025. Ask which named individuals will run your engagement and what they hold, rather than what the firm holds collectively.

Scoping Decides the Price

Scope is the variable that moves the number, and it's the one you control. Chris Dale, a principal instructor at SANS, makes the point that gets skipped: "Perhaps even more important than what to include is determining what not to include." Attackers ignore your scope document. The testers you hire cannot.

Two failure modes cost money. Scope too narrowly and the report confirms what you already knew. Scope too broadly against a fixed budget and depth collapses across the whole engagement. Luke Bremer, a senior security consultant at TrustedSec, describes the second one: "Assessments without full coverage can lead to critical-severity findings being missed simply because there is too much to review in the time given."

Johnson's opening scoping question is the one to answer before you call anyone. Why are you doing this? An audit deadline, a customer security questionnaire, a newly shipped feature and a genuine wish to know what an attacker could reach are four different engagements with four different price tags.

Bremer adds a scheduling note worth acting on early. Leave the booking to the last few months of the year and the firms worth hiring may have no availability left.

The Report Is Not the Deliverable

Remediation is where the value leaks out. Cobalt's State of Pentesting research, drawn from its own customer base, found that 48% of pentest findings ever get resolved, with a median time to resolve of 67 days. Its 2026 edition sharpens the split: teams running a programmatic approach reach a 10-day half-life on high-risk findings, while the slowest tenth leave them open for 249 days. That sample is Cobalt's own buyers rather than a market cross-section, so read the direction rather than the decimal.

Verizon's 2026 Data Breach Investigations Report shows the same pattern outside any vendor's customer list. Exploitation of vulnerabilities became the most common initial access vector for breaches at 31%, passing stolen credentials for the first time in 19 years. Only 26% of vulnerabilities in CISA's Known Exploited Vulnerabilities catalogue were fully remediated during 2025, down from 38%, and the median time to full resolution rose to 43 days from 32.

One wrinkle worth knowing before you scope: Sophos found exploited vulnerabilities falling as a ransomware root cause over the same period, as identity-based attacks took over. Read together, the two support testing identity and external application surface rather than network alone.

So put the retest in the contract. HackerOne's published policy gives a 30-day remediation window on its entry tier and 90 days above it, with unlimited retests inside the window. Triaxiom includes one retest within 90 days in every quote and states outright that this isn't universal across vendors. DeepStrike prices a standalone retest at $2,000 to $5,000. Under PCI DSS the question is settled for you, because Requirement 11.4.4 says corrections have to be verified by repeating the test.

Kelli Tarala, a GRC consultant at Black Hills Information Security, suggests settling the follow-through before the engagement begins: "Even before you get a pen test internally decide an organization, what are you going to do with the results?" The failure she describes is the one to design against: "The goal is not a pretty little report that sits on my desk and I say, hit the check mark."

Where to Start

Answer Johnson's question first. If you're testing for an audit, read your own control language before you read a vendor's brochure, because the sentence you wrote is the one that binds you. If you're testing with insurance in mind, scope the external perimeter and remote access, because that's where four independent carrier claims books say the losses start.

If nobody has run a scanner across the estate yet, do that first and fix what it finds. A penetration test is how you check that your vulnerability management works, and paying consultant day rates to discover missing patches is an expensive way to learn something a scheduled scan reports every week.

Then ask for the sample report, the named testers, the nine methodology elements and the retest window in writing. A firm that answers all four quickly is showing you how the engagement will run.

For what sits around the test, our MSP security stack guide covers the tooling layer.

SOC as a service covers the monitoring side, which is what watches the estate on the 364 days a point-in-time test doesn't.

Vladislav Marchenko

Head Of Marketing

Hi all! My name is Vlad and I’ve been brought on to head the marketing team at Flamingo. Thankfully, this isn’t the first time I will be building a marketing department from scratch, so the experience should come in handy. Now it’s time to dive into the world of MSPs and find myself in this new world.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

penetration-testing-services

A vulnerability scan enumerates known issues on assets you already know about. A penetration test adds a person who attempts to exploit those issues and pivot further, then documents the route with a proof of concept. If nobody attempts exploitation, the deliverable is a scan report regardless of what the engagement was called.
No. The phrase does not appear in the Trust Services Criteria themselves. It appears in one point of focus under CC4.1, alongside vulnerability scans and third-party assessments, and the AICPA states that using the criteria does not require an assessment of whether each point of focus is addressed. What binds you is the control description you wrote, so read your own language before booking a test.
PCI DSS v4.0.1 (Requirement 11.4), CMMC Level 3 (CA.L3-3.12.1e) and the NYDFS Cybersecurity Regulation (23 NYCRR 500.5) all require it in their own text. ISO 27001, HIPAA and NIST SP 800-171 do not. A HIPAA penetration testing requirement was proposed in January 2025 but is projected for 2027 and is not enforceable today.
No independent pricing dataset exists for US penetration testing, and published vendor tables contradict each other by as much as 10x on the same test type. Advertised ranges run from roughly $4,000 for external network work to $150,000 and up for red team engagements. Unit figures are more reliable than ranges: ask for the day or hour rate and the number of IPs, endpoints or application roles in scope.
Sometimes, and it is worth confirming in writing before signing. Published vendor policies cluster around a 30 to 90 day remediation window, with some firms including one retest and others pricing a standalone retest separately. Under PCI DSS Requirement 11.4.4 the retest is not optional, because corrections have to be verified by repeating the test.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
In the cloud, on US soil. Your data stays stateside.
Both. It's built for MSPs and MSSPs alike.

MSP AI Agents

Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.