Pentera pioneered automated security validation, and it's a genuinely capable platform, but its go-to-market is enterprise-only. Pricing is quote-based, publicly reported deals run from roughly $35,000 to over $100,000 a year, and it's sold as an annual subscription with no distinct SKU for the EU/DORA-scoped mid-market. That combination sends a specific kind of buyer looking for alternatives: EU financial entities and their ICT providers who need a DORA pentest under Articles 24 and 25, on a real budget, without an enterprise sales cycle. For the full head-to-head, see our SQUR vs Pentera comparison.

This isn't a "best pentesting tool" ranking. It's a narrower list: which Pentera alternatives make sense if you're an EU company preparing DORA Article 24 evidence, or otherwise care about EU data residency. We checked each vendor's own public pricing, EU presence, and DORA-specific messaging as of September 2026. Where a vendor doesn't publish a number, we say so instead of guessing.

Pentera alternatives at a glance

Tool Starting price EU-based DORA-specific positioning Best for
SQUR Recommended €1,995 flat Yes: EU data residency (GCP Brussels) Built for DORA Article 24 EU financial entities needing a fixed-price, 24-hour DORA pentest under Articles 24 and 25
Aikido Security Platform $350–$1,050/mo + pentest from $4,000 (waived on no high/critical findings) Yes: Ghent, Belgium Dedicated DORA/NIS2/CRA compliance page Teams that want a full SAST+SCA+DAST+pentest platform from an EU vendor
Escape.tech Not publicly disclosed Paris-based; EU data residency not confirmed publicly DORA referenced in content marketing, no dedicated compliance SKU API-heavy teams wanting a French/EU vendor mid-pivot to agentic pentesting
SelfHack Not publicly listed (usage-based) Yes: Helsinki, Finland No explicit DORA messaging found Early-stage EU teams comfortable with an early-stage vendor
Horizon3.ai Not publicly disclosed (enterprise, quote-based) No: US-founded; EMEA expansion funded, no EU entity confirmed VP publicly calls DORA's 3-year TLPT cycle "out of date" Large enterprises wanting continuous validation at scale
Terra Security Not publicly disclosed (enterprise) No: Tel Aviv-founded, no EU residency claim found None found Enterprises wanting human-governed continuous PTaaS with AWS Partner credentials
Novee Not publicly disclosed No: Tel Aviv/New York only, no EU presence found None found Enterprises already evaluating Novee's named customers for AI-native web app testing
Ridge Security $399–$2,999 (credit-based, PurpleRidge 3.0) No EU presence confirmed None found Price-sensitive SMBs without an EU-compliance requirement

1. SQUR: built for DORA Article 24, not the whole rulebook

SQUR runs a fully autonomous, AI-driven penetration test benchmarked at 87.5% (91 of 104) issue coverage against an 85% average for human testers on the same target set. Reports are delivered in 24 hours, at a fixed €1,995 per test, with all testing infrastructure and data processing kept inside the EU (GCP Brussels). SQUR is built to produce DORA Article 24 evidence: the ICT third-party risk pentest requirement most financial entities and their critical ICT providers face, not the separate, much heavier Article 26 TLPT program, which SQUR does not claim to cover. Reference customers include Gameforge, bitExpert, and Codeligence, alongside a research collaboration with KASTEL@KIT.

2. Aikido Security: the EU platform play

Aikido raised a $60M Series B in January 2026 at a $1B valuation, based in Ghent, Belgium. Unlike most vendors on this list, Aikido publishes a dedicated "European Cybersecurity Platform Built for EU Compliance" page covering GDPR, NIS2, DORA, and the CRA in one place. Its own pricing is public too: the platform runs $350–$1,050/month, with pentest engagements starting from $4,000, waived entirely if the test turns up no high or critical findings. That's a genuinely EU-native, compliance-literate alternative, though it's priced and packaged as a broader AppSec platform (SAST, SCA, DAST, plus pentest) rather than a single fixed-price pentest.

3. Escape.tech: Paris-based, mid-pivot

Escape.tech raised a €15.4M (about $18M) Series A in March 2026 and is based in Paris. It started as an API-native DAST product and is now repositioning toward "agentic pentesting." Its content marketing frames DORA as a reason API security testing has become a regulatory expectation, but Escape does not publish a specific price or a dedicated DORA compliance SKU: its own copy describes cost only as "a fraction of traditional pentesting," with no number attached.

4. SelfHack: the Nordic early-stage option

SelfHack is a Helsinki-based, ECSO-labeled vendor with no confirmed institutional funding round as of September 2026, making it the smallest and earliest-stage company on this list. Its reports map to ISO 27001, NIS2, SOC2, and GDPR Article 32, but we found no explicit DORA messaging on its site, unlike Aikido, Escape.tech, or Pentera itself.

5. Horizon3.ai: enterprise scale, and a public DORA critique

Horizon3.ai closed a $250M Series E in August 2026, tripling its valuation past $2B and serving 7,000+ organizations on its NodeZero platform. Some of that funding is earmarked for EMEA expansion, but Horizon3 remains a US-founded company with no confirmed EU entity or data-residency commitment yet. Notably, one of its own VPs has publicly argued that DORA's 3-year TLPT testing cycle is "out of date," a critique of the regulation rather than a claim of fit with it.

6. Terra Security: enterprise PTaaS, no EU angle

Terra Security has raised $38M total, is based in Tel Aviv, and became the first AWS Partner with the Autonomous Security Validation competency. It holds SOC2 and CREST credentials and positions itself for continuous, human-governed PTaaS at enterprise scale, but we found no EU-residency claim or DORA-specific messaging on its site.

7. Novee: well-funded, but no EU presence

Novee has raised $51.5M total and is generally available with named enterprise customers including UiPath and HiBob. It operates out of Tel Aviv and New York only. We found no EU office, EU data-residency claim, or DORA messaging anywhere in its public materials, making it the least EU-relevant option on this list despite its funding and customer base.

8. Ridge Security: cheapest self-serve entry, no compliance framing

Ridge Security's PurpleRidge 3.0, launched at RSAC 2026, runs on a credit-based pricing model from $399 to $2,999, the lowest published entry point of any vendor here. It's a general-purpose autonomous testing product, though, and we found no EU or DORA-specific positioning on either ridgesecurity.ai or purpleridge.ai as of September 2026.

Where Pentera itself fits

Pentera remains a capable, well-funded platform: over $250M raised, a valuation above $1B, and 1,200+ reported customers. Its own pricing, per publicly reported deals, runs from roughly $35,000 to over $100,000 a year, sold as an annual subscription with no distinct EU/DORA-scoped SKU. For teams that need that scale and budget, Pentera is a reasonable choice, and our full comparison is at SQUR vs Pentera. For teams that need a single, fixed-price DORA pentest under Articles 24 and 25 without an enterprise sales cycle, the alternatives above are the more direct fit.

Bottom line

If EU data residency and a DORA Article 24 evidence trail are non-negotiable and you want a fixed price with no sales call, SQUR (€1,995, 24 hours, GCP Brussels) and Aikido Security (EU-founded, with a dedicated DORA/NIS2/CRA page) are the two vendors on this list that say so explicitly, in public, with a number attached. Escape.tech and SelfHack are EU-based but haven't published DORA-specific pricing or messaging yet. Horizon3.ai, Terra Security, Novee, and Ridge Security are worth evaluating on their own merits (scale, platform depth, or price), but none of them currently make an EU-residency or DORA-fit claim, so budget time to verify that directly with the vendor if it matters for your engagement.