APTSecurity Management

What Is Penetration Testing as a Service?

Cody D. Martin//Updated August 9, 2026

Penetration testing as a service delivers testing on a subscription rather than as a one off project, with findings appearing in a platform as they are found, retesting included, and coverage continuing between engagements. It suits teams that ship often. It is oversold to teams that do not.

Penetration testing as a service, or PTaaS, delivers testing as an ongoing subscription rather than a one off project. The findings appear in a platform as they are discovered, retesting is included, and some form of coverage continues between engagements.

That is the definition. What matters more is whether it suits you, because the term gets applied to two quite different things.

The two things called PTaaS

A delivery model. Real testers, doing real testing, with the results delivered continuously through a platform instead of arriving as a PDF at the end. Retests are included rather than quoted separately. This is genuinely useful.

A scanner with a subscription. Automated scanning, a dashboard, and a light human review of the output. Sold at testing prices. This is not the same product and the difference is not always obvious from the marketing.

The question that separates them: who found this, and can they explain how they exploited it? A finding that cannot be traced to a person who reproduced it came from a scanner.

What the model is good at

Retesting without a purchase order. In a project model, verifying a fix means a new engagement, which means procurement, which means the fix sits unverified for a quarter. Under a subscription it is part of what you already bought.

Findings arriving when they are found. A critical issue discovered on day two of a two week engagement should not wait twelve days for a report. Continuous delivery is the single most practical advantage of the model.

Coverage between tests. Attack surface monitoring catching the staging host that got a public IP in March, rather than in next year’s test.

A relationship with the tester. Someone who already understands your architecture starts the second engagement well ahead of where a stranger would.

Where it is oversold

If you ship twice a year and your architecture is stable, you are paying a subscription for a service you use once. An annual project test plus a cheap continuous monitoring tool is usually better value.

If the platform is the product rather than the delivery mechanism, you are buying a dashboard. Ask what happens if you want the same testers next year.

What auditors accept

SOC 2 and PCI DSS auditors care about scope, methodology, dates and evidence of remediation. A PTaaS report satisfies them if it contains those things.

They are not impressed by the delivery model, and some will ask more questions about a platform report than a traditional one, because continuous testing makes “within the last twelve months” harder to point at. Make sure your provider issues a point in time attestation you can hand over.

How to decide

Buy the subscription model if you ship frequently, want retests included, and want a tester who knows your systems.

Buy a project test if your architecture is stable, you need a report for an audit, and you would rather spend the difference on fixing what it finds.

Either way, ask to see a sample report first. The report is the deliverable and everything else is process.

  • PTaaS
  • penetration testing
  • SOC 2
  • vendor selection

More on offensive