Buy a scanner run for a list, an audit for a person who reads the code and proves each finding, and a penetration test before launch if the app handles sensitive data, privileged actions or money, or when a customer or auditor asks in writing. Web application security testing services come in 4 kinds: those three plus managed security.

This page is the buying guide inside production hardening: which kind of outside help to pay for, and when. Every firm I name below is an example of a kind, described from its own public page. None of them is ranked, recommended or linked.

What you are actually buying from web application security testing services

Web application security testing services are four different products: a scanner run, where software checks known patterns and nobody reads the code; an audit, where a person reads the code and verifies each finding; a penetration test, where a person attacks the running app inside an agreed scope; and managed security, a subscription that watches.

Whatever a listing calls it, security testing for web applications, or web app security testing bought as a service, lands in one of those four rows. In my reading, a web app security test sold on its own is most often the scanner or the penetration test, and web application vulnerability testing is usually the scanner row with a person reading the output.

Three other guides on this site already sort these kinds by the question each one answers and what it proves: the AI app security audit guide, whose five-row table also maps the audit and assessment names onto the kinds, the code audit service comparison, and the scanner comparison linked in the scanner section below. I don’t re-map those names here. This page sorts the same market a different way: by who sells it, and by who fixes what they find.

The table is my own categorization of the market, not a quote from any seller.

Kind of sellerWho reads the codeWhat you get backWho fixes
A scanner or tool vendorNobody; software checks known patternsA findings exportYou
An audit or code review firmA person reads the code and configuration and verifies each findingA report with evidence for each findingSometimes the firm, when the agreement says so
A penetration testing firmNot usually; a person attacks the running app inside an agreed, written scopeA report with severity ratings, often with a retestYou
Managed securityNobody reads your code; a subscription watches, filters and alertsAlerts and reportsThe provider responds to the threats it detects on what it watches; fixing your app’s code stays yours

Each row has its own guide. What each scanner proves is in website security check, and comparing the tools themselves is a separate job: choosing a web application testing tool. How an audit is run is its own subject, the web application security audit, and the version for an app built with AI tools is the vibe coding security audit page. The test itself, with its scope document and rules of engagement, is web application penetration testing. Managed security gets its own section next.

Web application security companies, vendors and solutions providers often sell more than one row, in my reading. Bridewell’s own site, for one, lists penetration testing services and managed security services beside its cybersecurity audit. So before you compare two quotes, ask each web application security testing company which row its quote buys. I’d put a web application security consultant, and anyone selling website security audit services, in the audit row, sold by the hour or as a fixed job. Web application security services, and application security services as a whole, come down to these four rows. The company-wide audit is a different purchase again, and it has its own section below.

Security as a service and managed security: the enterprise words, and what they mean for one app

Security as a service is security run by an outside provider and paid for as a subscription, with the provider’s tools and people watching, filtering and alerting across a company’s systems. For one web app it shrinks to edge protection from the host, an error tracker and an uptime check. Fixing the app’s code stays a separate job.

That is my plain-words definition, and it answers what security as a service means when the term turns up in a quote. Security-as-a-service providers run the tools from their own cloud, which is why the same thing is described as security as a service in cloud computing, and some sell it as IT security as a service. Cyber security managed services and managed security solutions are the same model with a team of people attached. Managed application security is that idea pointed at applications rather than laptops and networks.

For one app, the working equivalents are smaller. The host’s edge protection does the filtering; what each host includes, and on which plan, is a separate question: how to set up a web application firewall. An error tracker and an uptime check do the watching, set up as logging and monitoring for a small SaaS.

Small business managed security, in my reading, fits a company with many devices and staff accounts to watch. It becomes a requirement when a customer contract or a regulator asks for round-the-clock monitoring. Security vendors and cyber security solution providers sell one or more of the four rows above, so the same question applies to them: which row does this quote buy?

Cyber security audit services: what the firms that sell them audit

Cyber security audit services, as the four firms named here describe them, check a company’s security controls, processes and systems, often against a framework such as NIST, SOC 2 or ISO 27001. That is a different purchase from testing one web app. Coverage is agreed per engagement, so your app is in only if the written scope names it.

Four firms whose own audit pages appear in Google’s results for these searches on 17 September 2026 show what the purchase covers: Atlant Security, Bridewell and BD Emerson on “cyber security audit services”, BD Emerson also on “security audit company”, and ScienceSoft on “information security audit services”. Each is quoted from its own page, in no particular order:

  • Atlant Security: “We audit 20 NIST 800-53 domains across your live environment, close what is blocking you, and hand you the evidence they are asking for.”
  • Bridewell, on its cybersecurity audit page: “A cybersecurity audit is a comprehensive assessment of your digital infrastructure, including how effectively its systems, data, and security processes are protected against threats.”
  • BD Emerson, on its cybersecurity and IT security audit services page: “We test against SOC 2, HIPAA, GDPR, ISO 27001, and NIST, examine your people, processes, and technology, and report findings ranked by severity with the evidence behind each one.”
  • ScienceSoft, on its IT security audit services page: “IT security audit is the verification of a company’s security policies, procedures, and technical controls against an applicable security framework, standard, or regulation.”

Astra’s list of cyber security audit companies shows up in the same results. It is a list, so I don’t use it as a source for what any firm audits.

For a small SaaS, an information security audit service delivers this same company audit, and the firm agrees what it will cover before it starts. ScienceSoft’s first audit step is “Planning and scoping”, where it decides “Audit coverage (what controls will be audited)”, and BD Emerson “scopes each engagement to the systems that store or process regulated data”. So whether your web app, its code and its hosting account are inside the audit depends on the written scope. The exact question to put to any cyber security audit firm about that is the first question in the questions section below.

The label on the seller tells you little. The same company audit is also sold as security auditing services, and a security audit company, one of the cyber security assessment companies or a firm calling itself an IT security audit company can all be selling it, so read the scope rather than the name. What a security assessor’s report should contain is a separate question, not covered here. Some security auditing companies sell it to startups too: Atlant Security describes its Essentials Audit as a “Focused audit for startups and small teams”. When a startup needs one is the timing question further down.

What it costs

Security testing prices follow who does the work, not the tool. On the pricing pages checked here, scanners charge a plan price that grows with assets or targets, billed monthly or yearly; the penetration test seller sells testing credits in annual packages; the managed security seller charges per endpoint per month; the audit firm agrees a fixed price in writing.

How much a security audit costs, or a security assessment, depends first on which of the four kinds you are buying. The table names one or two sellers per kind as examples, with every basis and figure as that seller’s own public page states it.

KindSeller named as the sourcePrice basisPublished figureDate checked
ScannerPentest-Tools.com”price varies by asset count and billing cycle”; monthly or yearly billing (“Pay only 10 months” on yearly)NetSec from $95/month, WebNetSec from $140/month, Pentest Suite from $190/month, each “with 5 assets”; a Free edition is listed2026-09-27
ScannerIntruder”a base fee plus a small fee-per-target”, billed monthly or annuallyCloud plan at the page’s default of 5 infrastructure targets and no web apps: $299 a month billed monthly, or $239 a month billed annually ($2,870 a year); the Free plan lists web apps as “Not included”2026-09-27
AuditAtlant Security”Fixed price agreed in writing”, per engagementEssentials Audit from $5,000 per engagement (up to 50 employees); Comprehensive Audit from $12,000 (up to 500 employees); Enterprise Audit from $25,000 (500+ employees)2026-09-27
Penetration testCobaltCredits “sold in annual packages”; one credit is “the equivalent of 8 hours of offensive security testing”, delivered through “a combination of AI-powered automation and human expertise”; the NCSC says the effort is “usually given in terms of resource days”Not stated on Cobalt’s page (each tier is “get a quote”)2026-09-27
Managed securityHuntressManaged EDR, per endpoint per month; the price “does not include deployment, integration, or the day-to-day operational and portal management that Huntress Partners can provide""Example pricing for 100 endpoints”: $7.99 a month per endpoint2026-09-27

Prices checked 27 September 2026 on each seller’s public page, in US dollars. Intruder’s page picks its currency from the visitor’s country, so a visitor outside the US may see another currency.

The managed security row is also the short answer to how much an MSSP usually costs: Huntress quotes its example price per endpoint per month, and says its per-unit rate goes down as volume goes up. The penetration test row has no figure because Cobalt’s pricing page states none.

The size of the scope moves these prices. The NCSC’s penetration testing guidance says that when testers identify systems or components outside the testing scope that could affect the systems in scope, they may suggest a change to the scope, which is likely to alter testing time frames and cost, or recommend recording the exclusion as a limitation on testing. In my reading, two other things move the price: whether fixes and a retest are included, and who the report is for.

Cost by kind for an app built with AI tools is on the AI app security audit page linked above, and I won’t repeat that table here. Published code review prices by seller are in source code review services. The day-rate arithmetic of a small pen test belongs to the affordable pen test guide linked in the penetration test section below.

The Production Hardening Sprint covers one codebase and runs for 10 working days. Formal third-party certifications and independent audit opinions are separate from the sprint deliverables.

When to pick each

Whatever a startup security company calls its offer, a security audit for startups resolves to one of the five choices below. Companies that do security audits for startups may sell more than one of them, and so may any app security service for startups, so ask which one a quote buys.

A scanner run

A scanner run fits a first look and a repeating outside check, on a free tier where the seller offers one, as long as you know the free tier’s limits. Pentest-Tools.com’s Free edition marks “DAST scanning (beyond OWASP Top 10)” as limited and does not include “Authenticated web app scans (incl. AI-assisted authentication)”, which its WebNetSec and Pentest Suite plans include. Intruder’s Free plan lists “Weekly external vulnerability scans” and marks web apps “Not included”, so its web app scanning starts on a paid plan such as Cloud, which lists “Web app & API testing”. My reading of those two plan tables: a free scan of a web app sees the logged-out outside and nothing behind the login.

Using a scanner to test web app security gets you a list. Web server security testing (headers, TLS, exposed software versions) is the outside view a scanner has, and what a free online checker sees and cannot see is in the website security check guide linked above. Buying a vulnerability scan service or a vulnerability scanning platform is buying this row.

A scanner run does not fit as the answer to “is it secure?”, in my reading, because the list needs a person to work out which findings the app can actually reach. When a scanner should hand off to an audit or a pentest is covered in vibe coding security scanners compared, and why scanner output and verified findings diverge is on the vibe coding audit page linked above.

In one app I audited, a health-data API, the scanner output was led by denial-of-service and request-smuggling alerts that looked like the front door. They arrived only under an AI library used in offline export scripts; the live web server never loaded them. The lesson I take from it: a scanner’s list says what is in the dependency tree, and only a person can say which of it the running app ever loads.

An audit with fixes

An audit with fixes fits an app built with AI tools that is about to take paying customers, with a security questionnaire on the way and one codebase to read. It does not fit an estate of many services owned by different teams. What comes back is a report with evidence for each finding, and fixes only when the agreement says so. Whether the auditor should also do the fixing, and why to keep the two as separate agreements, is answered on the AI app security audit page linked above; code review sold as a service is the code review page linked in the cost section.

A penetration test

The pen test guide on this site gives the rule: “commission an authorized penetration test before exposure when the app will handle sensitive data, privileged actions, or money. Otherwise, you usually need one only when a customer contract, security questionnaire, or auditor asks for it in writing”. The same do I need a pen test guide covers when a pentest is the right call over a code review, what to ask pentest vendors and the written authorization every test needs, and I don’t restate any of it here.

My working rule for when it does not fit: a penetration test is not the first thing to buy for an app nobody has read, so a code review comes first and the test follows. The pen test guide also says a source and workflow review “can expose intended behavior and high-risk paths before the test challenges them in the deployed environment”. What comes back is a report of what a tester could do inside the agreed scope.

Buying one on a small budget, and whether pentesting is illegal, are covered in affordable penetration testing. The standards route, when a framework is what the customer really wants, is SOC 2 compliance consultants.

Managed security

Managed security fits when a contract requires round-the-clock monitoring, or when there are many services and devices to watch. It does not fit one app with one developer: the subscription watches, and fixing the app’s code stays with whoever maintains it. What comes back, in my reading, is alerts, reports and the provider’s response to threats on what it watches, not changes to your code.

Do it yourself, hire someone, or both, and when

The DIY security audit vs hiring choice is mostly a question of timing. Start yourself with an application security checklist. For how to do a security audit of a website on your own, the website security check guide linked in the first section has the steps, and for an app built with AI tools the seven free checks on the AI app security audit page come first; neither is repeated here.

My working rule is to hire before the first paying customer, the first real users’ data or the first security questionnaire, whichever comes first. That is the best time to hire a security audit for a small team. It agrees with the outside-review signals on the AI app security audit page and with the pen test guide’s rule quoted above, and I don’t restate either.

To hire someone to secure your app, or to outsource web app security as a whole, is to buy the audit row with fixes. The two website security audit best practices I hold to are a scope in writing and a retest after the fixes. Who to hire for which part of the work is in fractional CTO vs agency, and the whole launch list is the go live checklist.

Questions to ask before you pay

These six questions tell you which kind you are being sold. The detailed questions for each kind are on their own pages (an audit’s on the code audit service page, a pentest’s on the pen test guide, a code review’s on the code review page, all linked above), and I don’t repeat them.

  1. 01 Does the written scope name my app, its code, its database and its hosting account, or only the company's systems? A company audit can leave the app out entirely, so you want all four named.
  2. 02 Will a person read the code, and who? If nobody does, it is a scanner run whatever it is called; you want a named reviewer and evidence for each finding. As an example of what verified can mean, here is the standard I hold my own audits to: the held-out validation run produced 0 cry-wolf false positives (findings reported that were not real) across 10 apps, recall of 1.0 against human-verified ground truth, and 10 out of 10 correct N/A gating (checks that did not apply, marked as not applicable). The deep-audit corpus of 11 apps I audited survived 36 independent re-verify runs across the 12 pillars with zero regressions and zero new false positives. The recall is counted on confirmed findings, and both results are checks of my own June and July 2026 audits of a selected set of apps: a measure of the method, not a rate for AI-built apps.
  3. 03 Will anyone attack the running app, and against which written scope? The right answer is a named tester and a scope document you have signed; how a small scope is written down is in the penetration testing guide linked above.
  4. 04 Who fixes what is found, and is that a separate agreement? A clear answer says who fixes, by when, and what proves each fix is done.
  5. 05 Does anyone keep checking after the report? Managed security watches round the clock, and a scanner plan can re-scan on a schedule: Intruder's plans list weekly external scans and custom scan schedules. An audit or penetration test report is a point in time, so if the answer is nobody, plan your own re-check.
  6. 06 What does the website security audit report look like, and who is it for: you, your developer, or a customer's security team? A seller who can show you a redacted sample has answered it.

What a good report contains, and how to judge one you are handed, is covered in penetration test report format.

Ask how findings are ranked, because volume alone tells you little: my audits of 21 third-party apps produced 958 confirmed findings, about 46 per app, and only 58 of those 958 were critical, about 6 percent. Those audits covered the 11 third-party public vibe-coded apps I audited exhaustively across all 12 pillars and 10 disjoint third-party apps held out and audited blind, in June and July 2026. They are a selected set of audited apps, not a random sample, and not a rate for every app built with AI tools.

Where the sprint fits

Sprint deliverable 3.7, OWASP Top 10 review, is verified this way: deliver category-level results and supporting test evidence, with justified non-applicable cases identified. Sprint deliverable 3.10, targeted external penetration testing, is verified this way: record the five surfaces, authorized tests, findings, fixes, and retest outcomes. I perform this targeted test. The targeted security tests cover the five priority attack surfaces documented in the report, and the package also includes an OWASP review and a controls checklist with evidence. Certifications and audit opinions stay outside it, as the cost section says.

Common questions about buying security testing

What is web application security testing?

Web application security testing is any check, by a person or a program, that tries to make a web app do what it should not: show data to the wrong user, accept a forged request, or break its own rules. Sellers package it in the four ways the first table on this page sorts.

How much does a security consultant cost?

Techem Group’s cybersecurity consultant pricing guide, published in March 2026, says to “Expect $150 – $400 per hour for experienced cybersecurity consultants in the US market”, and that “Gulf region consultants typically range $100–$250 per hour”. Those are that firm’s figures for those markets. A fixed-price audit is quoted per engagement instead, as the cost table above shows.

What are the three main types of security assessments?

In this page’s terms, the three main types of security assessments are a vulnerability scan, a code audit and a penetration test: an automated check, a reviewer who reads the source, and a tester who tries to break in to the live app. Managed security is the fourth row of the first table, but it watches systems over time rather than assessing them once.

Is cybersecurity considered SaaS?

Some of it is. Security sold as a subscription from the provider’s cloud is called security as a service, and here that covers managed security and the hosted scanners, which are priced per month or per year. Audits and penetration tests are priced per engagement or in testing credits, with people doing the work. So part of cyber security is sold as software and part as a service with people behind it, the split the first table draws.