Independent and free for buyers. We don't do audits. We help you find and compare the firms that do.

Penetration testing for e-commerce

These 10 penetration testing providers say they work with e-commerce. Most SOC 2 and ISO audits expect a recent penetration test, and any of these providers say they can run one.

Updated 1 Oct 2026. How we research
Get 3 to 5 quotes
Firms listed (of penetration testing providers)
10
Published prices
$2,500 to $15,000
1 firm, each linked to its source
Checked in an official register
3 of 10
Filters
Credentials
Price
Works with
Also offers
Region
Firm type
10 matching firms
  • AARC-3601 verified
    Audit firm, United StatesSOC 1SOC 2SOC 3ISO 27001
    Starting price
    Not published
    Legal entity
    Not stated
    Accreditations
    Verified
    Get a quoteProfileChecked 1 Oct 2026
  • Drummond Group logo
    Drummond Group1 verified
    Audit firm, United StatesSOC 2ISO 27001PCI DSSHIPAA
    Starting price
    Not published
    Legal entity
    Not stated
    Accreditations
    Verified
    Get a quoteProfileChecked 1 Oct 2026
  • VISTA InfoSec1 verified
    Consultant, IndiaPCI DSSSOC 2ISO 27001GDPR
    Starting price
    Not published
    Legal entity
    Not stated
    Accreditations
    Verified
    Get a quoteProfileChecked 1 Oct 2026
  • Agency logo
    AgencyNot yet checked
    ConsultantSOC 2ISO 27001GDPRHIPAA
    Starting price
    From $2,500
    Legal entity
    Not stated
    Accreditations
    Not stated
    Get a quoteProfileChecked 1 Oct 2026
  • Cybertryzub Infosec Private Limited logo
    Certification body, India. Signs as Cybertryzub Infosec Private LimitedISO 27001PCI DSSHIPAASOC 2
    Starting price
    Not published
    Legal entity
    Firm states
    Accreditations
    Firm states
    Get a quoteProfileChecked 1 Oct 2026
  • FinAudit CPA logo
    FinAudit CPANot yet checked
    Audit firm, United StatesSOC 1SOC 2SOC 3ISO 27001
    Starting price
    Not published
    Legal entity
    Not stated
    Accreditations
    Firm states
    Get a quoteProfileChecked 1 Oct 2026
  • HackerOne logo
    HackerOneNot yet checked
    Pentest platformSOC 2ISO 27001GDPRDORA
    Starting price
    Not published
    Legal entity
    Not stated
    Accreditations
    Firm states
    Get a quoteProfileChecked 1 Oct 2026
  • Kaamel Technology logo
    Kaamel TechnologyNot yet checked
    Consultant, United StatesSOC 2GDPRHIPAAISO 27001
    Starting price
    Not published
    Legal entity
    Not stated
    Accreditations
    Not stated
    Get a quoteProfileChecked 1 Oct 2026
  • Seiso logo
    SeisoNot yet checked
    Consultant, United StatesISO 27001SOC 2CMMCHIPAA
    Starting price
    Not published
    Legal entity
    Not stated
    Accreditations
    Firm states
    Get a quoteProfileChecked 1 Oct 2026
  • Wattlecorp Cybersecurity Labs logo
    ConsultantDORAISO 27001GDPRPCI DSS
    Starting price
    Not published
    Legal entity
    Not stated
    Accreditations
    Firm states
    Get a quoteProfileChecked 1 Oct 2026

How to choose a penetration testing provider

Check what is in scope (web app, API, cloud, mobile), who does the testing, and whether the report is acceptable to your auditor. Ask about re-testing after you fix findings.

Some providers are firms with testers on staff and some are platforms that match you with testers. Both can work, so ask who is accountable for the report.

Related lists
Do I need a penetration test for SOC 2?

It is not strictly required, but many auditors and customers expect a recent one.

What does CREST accredited mean?

CREST is a body that accredits penetration testing companies. We show it only when the firm states it or a register confirms it.

How is this list ordered?

By the sort you choose. The default is the number of verified credentials, then alphabetical. Payment never changes the order, and a Featured slot is shown apart from the results and labelled as paid.