Pentera pioneered automated security validation, and it's a genuinely capable platform, but its go-to-market is enterprise-only. Pricing is quote-based, publicly reported deals run from roughly $35,000 to over $100,000 a year, and it's sold as an annual subscription with no distinct SKU for the EU/DORA-scoped mid-market. That combination sends a specific kind of buyer looking for alternatives: EU financial entities and their ICT providers who need a DORA pentest under Articles 24 and 25, on a real budget, without an enterprise sales cycle. For the full head-to-head, see our SQUR vs Pentera comparison.
This isn't a "best pentesting tool" ranking. It's a narrower list: which Pentera alternatives make sense if you're an EU company preparing DORA Article 24 evidence, or otherwise care about EU data residency. We checked each vendor's own public pricing, EU presence, and DORA-specific messaging as of September 2026. Where a vendor doesn't publish a number, we say so instead of guessing.
Pentera alternatives at a glance
| Tool | Starting price | EU-based | DORA-specific positioning | Best for |
|---|---|---|---|---|
| SQUR Recommended | €1,995 flat | Yes: EU data residency (GCP Brussels) | Built for DORA Article 24 | EU financial entities needing a fixed-price, 24-hour DORA pentest under Articles 24 and 25 |
| Aikido Security | Platform $350–$1,050/mo + pentest from $4,000 (waived on no high/critical findings) | Yes: Ghent, Belgium | Dedicated DORA/NIS2/CRA compliance page | Teams that want a full SAST+SCA+DAST+pentest platform from an EU vendor |
| Escape.tech | Not publicly disclosed | Paris-based; EU data residency not confirmed publicly | DORA referenced in content marketing, no dedicated compliance SKU | API-heavy teams wanting a French/EU vendor mid-pivot to agentic pentesting |
| SelfHack | Not publicly listed (usage-based) | Yes: Helsinki, Finland | No explicit DORA messaging found | Early-stage EU teams comfortable with an early-stage vendor |
| Horizon3.ai | Not publicly disclosed (enterprise, quote-based) | No: US-founded; EMEA expansion funded, no EU entity confirmed | VP publicly calls DORA's 3-year TLPT cycle "out of date" | Large enterprises wanting continuous validation at scale |
| Terra Security | Not publicly disclosed (enterprise) | No: Tel Aviv-founded, no EU residency claim found | None found | Enterprises wanting human-governed continuous PTaaS with AWS Partner credentials |
| Novee | Not publicly disclosed | No: Tel Aviv/New York only, no EU presence found | None found | Enterprises already evaluating Novee's named customers for AI-native web app testing |
| Ridge Security | $399–$2,999 (credit-based, PurpleRidge 3.0) | No EU presence confirmed | None found | Price-sensitive SMBs without an EU-compliance requirement |
1. SQUR: built for DORA Article 24, not the whole rulebook
SQUR runs a fully autonomous, AI-driven penetration test benchmarked at 87.5% (91 of 104) issue coverage against an 85% average for human testers on the same target set. Reports are delivered in 24 hours, at a fixed €1,995 per test, with all testing infrastructure and data processing kept inside the EU (GCP Brussels). SQUR is built to produce DORA Article 24 evidence: the ICT third-party risk pentest requirement most financial entities and their critical ICT providers face, not the separate, much heavier Article 26 TLPT program, which SQUR does not claim to cover. Reference customers include Gameforge, bitExpert, and Codeligence, alongside a research collaboration with KASTEL@KIT.
2. Aikido Security: the EU platform play
Aikido raised a $60M Series B in January 2026 at a $1B valuation, based in Ghent, Belgium. Unlike most vendors on this list, Aikido publishes a dedicated "European Cybersecurity Platform Built for EU Compliance" page covering GDPR, NIS2, DORA, and the CRA in one place. Its own pricing is public too: the platform runs $350–$1,050/month, with pentest engagements starting from $4,000, waived entirely if the test turns up no high or critical findings. That's a genuinely EU-native, compliance-literate alternative, though it's priced and packaged as a broader AppSec platform (SAST, SCA, DAST, plus pentest) rather than a single fixed-price pentest.
3. Escape.tech: Paris-based, mid-pivot
Escape.tech raised a €15.4M (about $18M) Series A in March 2026 and is based in Paris. It started as an API-native DAST product and is now repositioning toward "agentic pentesting." Its content marketing frames DORA as a reason API security testing has become a regulatory expectation, but Escape does not publish a specific price or a dedicated DORA compliance SKU: its own copy describes cost only as "a fraction of traditional pentesting," with no number attached.
4. SelfHack: the Nordic early-stage option
SelfHack is a Helsinki-based, ECSO-labeled vendor with no confirmed institutional funding round as of September 2026, making it the smallest and earliest-stage company on this list. Its reports map to ISO 27001, NIS2, SOC2, and GDPR Article 32, but we found no explicit DORA messaging on its site, unlike Aikido, Escape.tech, or Pentera itself.
5. Horizon3.ai: enterprise scale, and a public DORA critique
Horizon3.ai closed a $250M Series E in August 2026, tripling its valuation past $2B and serving 7,000+ organizations on its NodeZero platform. Some of that funding is earmarked for EMEA expansion, but Horizon3 remains a US-founded company with no confirmed EU entity or data-residency commitment yet. Notably, one of its own VPs has publicly argued that DORA's 3-year TLPT testing cycle is "out of date," a critique of the regulation rather than a claim of fit with it.
6. Terra Security: enterprise PTaaS, no EU angle
Terra Security has raised $38M total, is based in Tel Aviv, and became the first AWS Partner with the Autonomous Security Validation competency. It holds SOC2 and CREST credentials and positions itself for continuous, human-governed PTaaS at enterprise scale, but we found no EU-residency claim or DORA-specific messaging on its site.
7. Novee: well-funded, but no EU presence
Novee has raised $51.5M total and is generally available with named enterprise customers including UiPath and HiBob. It operates out of Tel Aviv and New York only. We found no EU office, EU data-residency claim, or DORA messaging anywhere in its public materials, making it the least EU-relevant option on this list despite its funding and customer base.
8. Ridge Security: cheapest self-serve entry, no compliance framing
Ridge Security's PurpleRidge 3.0, launched at RSAC 2026, runs on a credit-based pricing model from $399 to $2,999, the lowest published entry point of any vendor here. It's a general-purpose autonomous testing product, though, and we found no EU or DORA-specific positioning on either ridgesecurity.ai or purpleridge.ai as of September 2026.
Where Pentera itself fits
Pentera remains a capable, well-funded platform: over $250M raised, a valuation above $1B, and 1,200+ reported customers. Its own pricing, per publicly reported deals, runs from roughly $35,000 to over $100,000 a year, sold as an annual subscription with no distinct EU/DORA-scoped SKU. For teams that need that scale and budget, Pentera is a reasonable choice, and our full comparison is at SQUR vs Pentera. For teams that need a single, fixed-price DORA pentest under Articles 24 and 25 without an enterprise sales cycle, the alternatives above are the more direct fit.
Bottom line
If EU data residency and a DORA Article 24 evidence trail are non-negotiable and you want a fixed price with no sales call, SQUR (€1,995, 24 hours, GCP Brussels) and Aikido Security (EU-founded, with a dedicated DORA/NIS2/CRA page) are the two vendors on this list that say so explicitly, in public, with a number attached. Escape.tech and SelfHack are EU-based but haven't published DORA-specific pricing or messaging yet. Horizon3.ai, Terra Security, Novee, and Ridge Security are worth evaluating on their own merits (scale, platform depth, or price), but none of them currently make an EU-residency or DORA-fit claim, so budget time to verify that directly with the vendor if it matters for your engagement.