Penetration testing for e-commerce
These 10 penetration testing providers say they work with e-commerce. Most SOC 2 and ISO audits expect a recent penetration test, and any of these providers say they can run one.
Updated 1 Oct 2026. How we research- Firms listed (of penetration testing providers)
- 10
- Published prices
- $2,500 to $15,000 1 firm, each linked to its source
- Checked in an official register
- 3 of 10
FiltersClear all
- AARC-3601 verifiedAudit firm, United States
- Starting price
- Not published
- Legal entity
- Not stated
- Accreditations
- Verified
Drummond Group1 verifiedAudit firm, United States- Starting price
- Not published
- Legal entity
- Not stated
- Accreditations
- Verified
- VISTA InfoSec1 verifiedConsultant, India
- Starting price
- Not published
- Legal entity
- Not stated
- Accreditations
- Verified
AgencyNot yet checkedConsultant- Starting price
- From $2,500
- Legal entity
- Not stated
- Accreditations
- Not stated
Cybertryzub Infosec Private LimitedNot yet checkedCertification body, India. Signs as Cybertryzub Infosec Private Limited- Starting price
- Not published
- Legal entity
- Firm states
- Accreditations
- Firm states
FinAudit CPANot yet checkedAudit firm, United States- Starting price
- Not published
- Legal entity
- Not stated
- Accreditations
- Firm states
HackerOneNot yet checkedPentest platform- Starting price
- Not published
- Legal entity
- Not stated
- Accreditations
- Firm states
Kaamel TechnologyNot yet checkedConsultant, United States- Starting price
- Not published
- Legal entity
- Not stated
- Accreditations
- Not stated
SeisoNot yet checkedConsultant, United States- Starting price
- Not published
- Legal entity
- Not stated
- Accreditations
- Firm states
Wattlecorp Cybersecurity LabsNot yet checkedConsultant- Starting price
- Not published
- Legal entity
- Not stated
- Accreditations
- Firm states
No firms match these filters. Clear all filters
How to choose a penetration testing provider
Check what is in scope (web app, API, cloud, mobile), who does the testing, and whether the report is acceptable to your auditor. Ask about re-testing after you fix findings.
Some providers are firms with testers on staff and some are platforms that match you with testers. Both can work, so ask who is accountable for the report.
Do I need a penetration test for SOC 2?
It is not strictly required, but many auditors and customers expect a recent one.
What does CREST accredited mean?
CREST is a body that accredits penetration testing companies. We show it only when the firm states it or a register confirms it.
How is this list ordered?
By the sort you choose. The default is the number of verified credentials, then alphabetical. Payment never changes the order, and a Featured slot is shown apart from the results and labelled as paid.