Penetration Testing as a Service (PTaaS) · Pricing guide

Cobalt.io Pricing, Explained

Cobalt.io does not publish prices. Its pricing page describes a credit-based model and three service tiers, and everything else is "get a quote". This guide explains how the credit system works, what third-party procurement data reports companies actually pay, and how to budget for a Cobalt pentest program in 2026.

Last verified: 2026-07-13

Cobalt.io pricing at a glance

Pricing modelCredit-based: annual credit packages, consumed per engagement. No public price list.
What a credit isCobalt defines one credit as the equivalent of 8 hours of offensive security testing (AI-assisted plus human testers).
Reported credit priceProcurement platforms (e.g. Vendr) commonly report around $1,800 per credit; your quote depends on volume and tier.
Typical engagementA standard web app pentest is commonly reported at 10 to 20 credits, i.e. roughly $18,000 to $36,000 at reported credit prices.
TiersStandard, Premium, and Enterprise: they differ in start speed (3 / 2 / 1 business days) and credit rollover terms.
RetestingUnlimited on-demand retesting is included during the contract term.

How the Credit Model Works

Cobalt sells annual credit packages rather than per-test prices. Each engagement (a web app pentest, an API assessment, a mobile test) consumes a number of credits scoped in advance, with one credit defined as roughly 8 hours of testing effort. Credits are bought up front for the contract year, can be topped up mid-year, and expire based on your tier's rollover terms rather than carrying over indefinitely.

The practical consequence: you are budgeting for a testing program, not a test. If you only need one compliance pentest a year, the annual-package structure means you are still negotiating a yearly commitment, which is why smaller teams often find the entry cost higher than a one-off engagement from a boutique firm.

What Companies Actually Pay

Because Cobalt publishes no numbers, the best public signal is procurement data. Vendr and similar buyer platforms report credit prices around $1,800, typical annual spend between $15,000 and $40,000 for mid-sized programs, and packages scaling well past $100,000 for enterprise continuous-testing programs. Reports also mention an entry-level "Pentest Essentials" offering in the low thousands per month.

Scope drives the credit count: user roles, API surface, and application complexity all add credits. A simple marketing site might scope at the minimum; a multi-tenant SaaS with several roles and integrations can easily double or triple the credit estimate. Always get the credit scoping in writing before comparing quotes.

Costs to Watch For

Three things commonly surprise buyers. First, unused credits: rollover is limited by tier, so credits you do not consume within the terms are lost value. Second, scope creep between quote and kickoff: a re-scope mid-contract consumes more credits than planned. Third, the annual commitment itself: the model rewards teams that test continuously and penalizes teams that only need occasional tests.

Cobalt Cost in Context (2026)

Reported figures for a typical web application pentest, compared with category benchmarks. Quote-based figures are third-party estimates, not vendor list prices.

OptionTypical costModel
Cobalt.io (reported)~$18,000–$36,000 per web app pentest (10–20 credits)Annual credit packages
Traditional consultancy$5,000–$30,000 per web app pentestPer engagement
XBOW (published)$4,000–$8,000 per testPer test
PenetrifyFrom $100/month, unlimited retestsFlat subscription

Cobalt figures from procurement platforms (Vendr) and buyer reports; Cobalt does not publish prices. Consultancy range reflects commonly cited 2026 industry surveys. Last verified July 2026.

The Subscription Alternative

Cobalt's credit model prices human testing time: more testing means more credits means more budget. Penetrify prices the platform instead: autonomous AI pentests of your web apps and APIs run on every deploy at a flat subscription from $100/month, with retests included. For the reported price of a single 10-credit Cobalt engagement you can run Penetrify for years, and many teams pair it with a periodic human engagement for depth where it matters.

The bottom line

Cobalt.io is a mature PTaaS with a genuinely flexible delivery model, and the credit system works well for organizations that run several human-led tests a year and can commit annually. Budget realistically: reported pricing puts a single web app engagement in the high four to five figures and meaningful programs at $15,000 to $40,000+ per year. If what you need is continuous coverage rather than scheduled human engagements, a flat-rate autonomous platform covers the cadence at a fraction of that.

Frequently asked questions

How much does a Cobalt.io pentest cost?

Cobalt does not publish prices. Procurement data commonly reports around $1,800 per credit, with a standard web application pentest scoped at 10 to 20 credits, so roughly $18,000 to $36,000. Your quote depends on scope, tier, and negotiated volume.

What is a Cobalt credit?

Cobalt defines one credit as the equivalent of 8 hours of offensive security testing, delivered through a combination of AI-assisted tooling and vetted human testers. Engagements are scoped in credits, and credits are sold in annual packages.

Does Cobalt.io have a free trial or entry-level plan?

There is no free trial. Buyer reports mention an entry-level "Pentest Essentials" offering in the low thousands per month, but the core product is sold as annual credit packages with a quote.

Is Cobalt.io worth it compared to a traditional pentest firm?

If you test several times a year, the platform workflow (faster starts, structured findings, included retesting) is a real advantage over ad-hoc consultancy engagements at a similar per-test price. For a single annual compliance test, a fixed-price boutique engagement or an autonomous platform is usually cheaper.

Full comparison: Penetrify vs. Cobalt.io

More pricing guides