Penetration testing for defense
These 8 penetration testing providers say they work with defense. Most SOC 2 and ISO audits expect a recent penetration test, and any of these providers say they can run one.
Updated 1 Oct 2026. How we research- Firms listed (of penetration testing providers)
- 8
- Published prices
- $1,000 to $15,000 · ₹150,000 to ₹800,000 2 firms, each linked to its source
- Checked in an official register
- 1 of 8
FiltersClear all
Fortreum2 verifiedAudit firm- Starting price
- Not published
- Legal entity
- Not stated
- Accreditations
- Verified
Bright DefenseNot yet checkedConsultant, United States- Starting price
- From $1,000
- Legal entity
- Not stated
- Accreditations
- Not stated
Echelon Risk + CyberNot yet checkedConsultant- Starting price
- Not published
- Legal entity
- Not stated
- Accreditations
- Not stated
- ISSPL Limited (IRQS)Not yet checkedCertification body, India. Signs as ISSPL Limited
- Starting price
- From $3,000
- Legal entity
- Firm states
- Accreditations
- Firm states
PericuloNot yet checkedConsultant, United Kingdom- Starting price
- Not published
- Legal entity
- Not stated
- Accreditations
- Firm states
SeisoNot yet checkedConsultant, United States- Starting price
- Not published
- Legal entity
- Not stated
- Accreditations
- Firm states
- Trava SecurityNot yet checkedConsultant, United States
- Starting price
- Not published
- Legal entity
- Not stated
- Accreditations
- Firm states
WorkstreetNot yet checkedConsultant- Starting price
- Not published
- Legal entity
- Not stated
- Accreditations
- Not stated
No firms match these filters. Clear all filters
How to choose a penetration testing provider
Check what is in scope (web app, API, cloud, mobile), who does the testing, and whether the report is acceptable to your auditor. Ask about re-testing after you fix findings.
Some providers are firms with testers on staff and some are platforms that match you with testers. Both can work, so ask who is accountable for the report.
Do I need a penetration test for SOC 2?
It is not strictly required, but many auditors and customers expect a recent one.
What does CREST accredited mean?
CREST is a body that accredits penetration testing companies. We show it only when the firm states it or a register confirms it.
How is this list ordered?
By the sort you choose. The default is the number of verified credentials, then alphabetical. Payment never changes the order, and a Featured slot is shown apart from the results and labelled as paid.