Penetration Testing as a Service (PTaaS) · Pricing guide
Cobalt.io Pricing, Explained
Cobalt.io does not publish prices. Its pricing page describes a credit-based model and three service tiers, and everything else is "get a quote". This guide explains how the credit system works, what third-party procurement data reports companies actually pay, and how to budget for a Cobalt pentest program in 2026.
Last verified: 2026-07-13
Cobalt.io pricing at a glance
How the Credit Model Works
Cobalt sells annual credit packages rather than per-test prices. Each engagement (a web app pentest, an API assessment, a mobile test) consumes a number of credits scoped in advance, with one credit defined as roughly 8 hours of testing effort. Credits are bought up front for the contract year, can be topped up mid-year, and expire based on your tier's rollover terms rather than carrying over indefinitely.
The practical consequence: you are budgeting for a testing program, not a test. If you only need one compliance pentest a year, the annual-package structure means you are still negotiating a yearly commitment, which is why smaller teams often find the entry cost higher than a one-off engagement from a boutique firm.
What Companies Actually Pay
Because Cobalt publishes no numbers, the best public signal is procurement data. Vendr and similar buyer platforms report credit prices around $1,800, typical annual spend between $15,000 and $40,000 for mid-sized programs, and packages scaling well past $100,000 for enterprise continuous-testing programs. Reports also mention an entry-level "Pentest Essentials" offering in the low thousands per month.
Scope drives the credit count: user roles, API surface, and application complexity all add credits. A simple marketing site might scope at the minimum; a multi-tenant SaaS with several roles and integrations can easily double or triple the credit estimate. Always get the credit scoping in writing before comparing quotes.
Costs to Watch For
Three things commonly surprise buyers. First, unused credits: rollover is limited by tier, so credits you do not consume within the terms are lost value. Second, scope creep between quote and kickoff: a re-scope mid-contract consumes more credits than planned. Third, the annual commitment itself: the model rewards teams that test continuously and penalizes teams that only need occasional tests.
Cobalt Cost in Context (2026)
Reported figures for a typical web application pentest, compared with category benchmarks. Quote-based figures are third-party estimates, not vendor list prices.
| Option | Typical cost | Model |
|---|---|---|
| Cobalt.io (reported) | ~$18,000–$36,000 per web app pentest (10–20 credits) | Annual credit packages |
| Traditional consultancy | $5,000–$30,000 per web app pentest | Per engagement |
| XBOW (published) | $4,000–$8,000 per test | Per test |
| Penetrify | From $100/month, unlimited retests | Flat subscription |
Cobalt figures from procurement platforms (Vendr) and buyer reports; Cobalt does not publish prices. Consultancy range reflects commonly cited 2026 industry surveys. Last verified July 2026.
The Subscription Alternative
Cobalt's credit model prices human testing time: more testing means more credits means more budget. Penetrify prices the platform instead: autonomous AI pentests of your web apps and APIs run on every deploy at a flat subscription from $100/month, with retests included. For the reported price of a single 10-credit Cobalt engagement you can run Penetrify for years, and many teams pair it with a periodic human engagement for depth where it matters.
The bottom line
Cobalt.io is a mature PTaaS with a genuinely flexible delivery model, and the credit system works well for organizations that run several human-led tests a year and can commit annually. Budget realistically: reported pricing puts a single web app engagement in the high four to five figures and meaningful programs at $15,000 to $40,000+ per year. If what you need is continuous coverage rather than scheduled human engagements, a flat-rate autonomous platform covers the cadence at a fraction of that.
Frequently asked questions
How much does a Cobalt.io pentest cost?
Cobalt does not publish prices. Procurement data commonly reports around $1,800 per credit, with a standard web application pentest scoped at 10 to 20 credits, so roughly $18,000 to $36,000. Your quote depends on scope, tier, and negotiated volume.
What is a Cobalt credit?
Cobalt defines one credit as the equivalent of 8 hours of offensive security testing, delivered through a combination of AI-assisted tooling and vetted human testers. Engagements are scoped in credits, and credits are sold in annual packages.
Does Cobalt.io have a free trial or entry-level plan?
There is no free trial. Buyer reports mention an entry-level "Pentest Essentials" offering in the low thousands per month, but the core product is sold as annual credit packages with a quote.
Is Cobalt.io worth it compared to a traditional pentest firm?
If you test several times a year, the platform workflow (faster starts, structured findings, included retesting) is a real advantage over ad-hoc consultancy engagements at a similar per-test price. For a single annual compliance test, a fixed-price boutique engagement or an autonomous platform is usually cheaper.