What is penetration testing as a service?
PTaaS is penetration testing sold as a subscription with a platform wrapped around it. The testing itself is not new — the delivery model, the reporting cadence and the retesting economics are.
Updated 8/8/2026 · The Tool Money Lab editorial team · Foundation · 9 min read
← Cybersecurity Learning Centre
- PTaaS is a delivery model, not a testing technique. The techniques are the same ones used in a traditional engagement.
- The platform is the real product: findings arrive continuously, with ticket integrations, retest requests and exportable evidence rather than a PDF at the end.
- Most PTaaS pricing is per target or per asset on an annual subscription, which makes the cost predictable but caps scope.
- Fully automated 'PTaaS' is closer to vulnerability scanning. Ask specifically how much human testing is included and how often.
- PTaaS does not replace scoped specialist testing for complex logic, hardware, or a bespoke internal application estate.
The problem PTaaS was invented to solve
The traditional penetration test is a consulting project. You scope it in a call, wait for a slot in the firm's calendar, testers work for a fixed window — often one to two weeks — and some days later you receive a PDF report. You then fix what it found, and if you want proof the fixes worked, you buy a retest, or you wait until next year's engagement and hope.
That model has two structural problems for any business shipping software regularly. First, the report describes a system that no longer exists: by the time you read it you have deployed new code, added a subdomain, changed a cloud permission. Second, the cost structure discourages verification. Retests are billed, so remediation frequently goes unproven, which is exactly the part an auditor or an enterprise customer cares about.
PTaaS is the commercial answer to both. Instead of buying a project, you subscribe to a service. Instead of receiving a document, you get access to a portal where findings appear as they are confirmed, remediation guidance sits alongside each finding, and requesting a retest is a button rather than a purchase order.
What the platform layer actually adds
It is easy to dismiss the portal as packaging. In practice the platform changes who inside the business can act on security findings, which is usually the bottleneck.
A PDF report has one audience: whoever commissioned it. A platform can push a confirmed finding into Jira with a severity and an owner, notify a Slack channel, expose an API so your own dashboards can count open issues, and produce an export an auditor will accept. That difference is why engineering-led organisations tend to prefer PTaaS even when the underlying testing quality is comparable.
| Dimension | Traditional penetration test | PTaaS |
|---|---|---|
| Commercial shape | Fixed-scope project, quoted per engagement | Subscription, usually per target or asset per year |
| Cadence | Annual or biannual, scheduled in advance | Continuous or repeated cycles within the subscription |
| Findings delivery | Report at the end of the test window | Findings published as they are confirmed |
| Retesting | Normally billed separately | Commonly included, often unlimited |
| Workflow integration | Manual — someone transcribes the PDF | Ticketing, chat, webhook and API integrations |
| Human testing | Central to the engagement | Varies enormously by vendor and tier |
| Best suited to | Bespoke, complex or one-off scopes | Recurring assurance on a known, changing estate |
How a PTaaS engagement actually runs
The mechanics are more standardised than marketing suggests. Almost every platform follows the same five stages, and the differences between vendors show up in how much of each stage is automated.
- Scoping and authorisation — you declare the targets and prove you control them, usually by DNS record, file upload or a portal-side ownership check. Testing anything you have not verified is both a contractual and a legal problem.
- Discovery — the platform enumerates what is actually reachable on the targets you declared: hosts, subdomains, ports, endpoints, APIs, authentication surfaces.
- Testing — automated checks run continuously; human testers work in cycles against the parts automation cannot judge, such as authorisation logic, business-flow abuse and chained weaknesses.
- Triage and reporting — confirmed findings are severity-rated with reproduction steps and remediation guidance, then routed to whoever owns the fix.
- Retesting — you mark a finding fixed and request verification. This is the stage that produces the evidence auditors and enterprise buyers actually want.
The question that separates real PTaaS from a scanner with a portal
Vendors use the same three letters for very different products. Some PTaaS platforms are primarily an automated engine with a human review layer; others are a testing team with a platform attached. Both can be the right purchase — but they are not interchangeable, and the price difference is rarely the honest signal.
Ask exactly four things and the category sorts itself out. How many hours of human testing are included, and how often? Which classes of finding does the automated engine explicitly not attempt? Is retesting unlimited or capped? And what does the platform produce that an auditor will accept as evidence?
A vendor whose answer to the first question is 'our engine covers that' is selling continuous vulnerability scanning. That is a legitimate and often sensible product — it is simply a different one, and the distinction matters because automation is strong at known-vulnerability detection and weak at reasoning about whether your permission model can be abused.
What PTaaS does not solve
Subscription testing is bounded by its scope. Because pricing is typically per target, the commercial incentive is to declare fewer targets — which is precisely how the forgotten staging server escapes assurance. Attack-surface discovery is the counterweight, and not every PTaaS platform includes it.
It also does not remove the need for specialist engagements. Complex business-logic testing, a hardware or embedded product, a large bespoke internal estate, a red-team exercise measuring your detection and response — these remain scoped consulting work. PTaaS is the standing assurance layer underneath them, not a replacement.
Finally, no platform makes you compliant. Frameworks require that testing happens, that findings are risk-assessed and that remediation is tracked. A PTaaS subscription produces excellent evidence for all three, but the obligation stays with you.
Who PTaaS genuinely suits
The model pays off fastest for organisations with a moderate, changing internet-facing estate and no in-house penetration testers: SaaS companies answering enterprise security questionnaires, regulated small businesses, and managed IT providers who need to show continuous assurance across a client base.
It suits large enterprises less as a whole-programme answer and more as one layer. Where a mature security function already runs validation and red-teaming, PTaaS tends to cover the perimeter continuously so specialist capacity can be spent elsewhere.
If you have no asset inventory at all, start earlier in the chain. Testing a list you cannot vouch for produces confident reports about the wrong systems.
FAQ
No. Automated penetration testing describes what does the work; PTaaS describes how the service is sold and delivered. Some PTaaS platforms are heavily automated, others include substantial human testing. Always ask how many human testing hours the subscription includes.
For many organisations it replaces the routine annual perimeter test, because it covers the same surface more often and produces the same evidence. It does not replace scoped specialist engagements such as complex business-logic testing or a red-team exercise.
Usually as an annual subscription tied to a number of targets, assets or applications, with tiers that vary by testing depth and by how much human testing is included. Vendors selling to enterprise frequently publish no price at all and quote per environment.
Auditors want evidence that testing occurred, that findings were risk-assessed, and that remediation was tracked and verified. Platform reports plus retest records generally serve that purpose well. Neither the report nor the tool grants certification.
Automated findings typically appear within hours of a scan cycle. Human-verified findings appear when a tester confirms them, which depends on the vendor's testing cadence — this is worth pinning down contractually rather than assuming continuous means instant.
Most PTaaS platforms include continuous scanning as their automated layer, so a separate external scanner is often redundant. Internal, endpoint and container scanning are frequently out of scope, and those remain your responsibility.
A verified inventory of the assets you want covered, proof of ownership for each, a named owner for remediation, and a decision about where findings should land — a ticket queue, a chat channel, or both.
This guide is deliberately vendor-neutral. When you are ready to evaluate products, these are the TTML pages that continue the topic.
Our reviews are based on vendor documentation, publicly available product information, independent testing where available, and ongoing editorial updates. We do not sell rankings. Where a page carries affiliate links we may earn a commission at no additional cost to you, and that relationship never changes the conclusion — see our affiliate disclosure and review methodology.
- Last reviewed
- Reviewed by
- The Tool Money Lab Editorial Team — independent software research
- Evidence sources
- Vendor Documentation · Official Pricing Pages · Public Standards Documentation (OWASP, NIST SP 800-115)
Stay Ahead of AI
Receive our weekly Intelligence Brief. Independent AI reviews, comparisons, new tools and practical recommendations delivered every Friday.
- ✓ New AI tools
- ✓ Honest reviews
- ✓ Best AI deals
- ✓ New comparisons
- ✓ Industry trends
- ✓ No spam.