September 6, 2026 · 9 min read · Aizhan Azhybaeva

Acunetix Pricing 2026: Real Costs, Tiers & What Drives Your Quote

Acunetix pricing is quote-based in 2026. Reported entry cost is around $7,000/year for 5 targets on per-FQDN licensing. Full tier breakdown, cost drivers, alternatives.

Acunetix Pricing 2026: Real Costs, Tiers & What Drives Your Quote

The short answer: Acunetix pricing is quote-based in 2026 and Invicti publishes no rate card, but the most reliable public reference point is roughly USD 7,000 per year for 5 targets, with reported entry deals landing between USD 4,500 and USD 7,000. Licensing is per FQDN with a 5-target minimum, normally on a 2-year subscription paid annually, and the effective Acunetix cost per target drops sharply with volume. Anyone quoting you a firm number without knowing your target count is guessing. The rest of this post explains the tiers, what actually moves your quote, the subdomain trap that catches most buyers, and the alternatives worth pricing against it.

If you are still deciding between paid and free, read Acunetix vs OWASP ZAP. If you want the sibling-product angle, we cover it in Acunetix vs Invicti, and for the whole scanner field see the DAST tools comparison.

Acunetix pricing 2026 at a glance

TierReported annual costTargetsSold as
Acunetix StandardQuote-based, entry ~$4,500-$7,0005, 10, 20 target bundlesSingle-instance scanner
Acunetix PremiumQuote-based, ~$7,000-$37,000+Scales past 20Multi-user, CI/CD, ticketing
Invicti Enterprise (ex Acunetix 360)Quote-based, ~$30,000+50+ typicalPlatform: on-prem, SCA, ASPM

Two caveats before you use that table in a budget. First, every figure in it is a reported or marketplace number, not a vendor list price - Acunetix genuinely does not publish one. Second, tier naming is a mess in the wild: Invicti sells Standard and Premium, older material refers to Acunetix 360, and several review sites label the same lineup Essentials, Professional, and Ultimate. Match the SKU on your quote to the capability list, not to the name.

Acunetix Standard

Acunetix Standard is the single-instance scanner aimed at penetration testers and small AppSec teams. It sells in target bundles of 5, 10, and 20, ships the core proof-based DAST engine and standard API scanning, and is the cheapest way into the product. Past 20 websites you are pushed up to Premium. This is the tier that produces the commonly quoted Acunetix cost of around USD 7,000 a year for a handful of applications.

Acunetix Premium

Acunetix Premium adds multiple user accounts, higher and effectively unbounded target counts, CI/CD pipeline integrations, and issue-tracker connections so findings land in Jira rather than a PDF. This is where most mid-market buyers end up, and where the price becomes genuinely open-ended: reported deployments run from around USD 7,000 for a small estate up to the mid five figures once you are covering 25 or more applications across multiple environments.

Invicti Enterprise, the tier people search as “Acunetix 360 price”

If you are searching for an Acunetix 360 price, you are searching for a name that no longer maps cleanly to a SKU. Acunetix 360 was the DevSecOps and enterprise tier; after the Netsparker and Acunetix consolidation under Invicti Security, that capability is sold as Invicti Enterprise. Reported figures put it around USD 30,000-37,000 per year for roughly 50 targets, rising with on-prem or air-gapped deployment, bundled SCA, ASPM, AcuSensor IAST, and enterprise support. It uses the same proof-based scan engine as Acunetix, so you are paying for governance and platform, not better detection.

What actually drives your Acunetix quote

This is the part that matters more than any tier table, because the same tier can produce wildly different invoices.

  • FQDN target count. Acunetix licenses per fully qualified domain name. This is where most of the cost lives, and it scales down: reported effective rates run around USD 1,400 per target at 5 targets and around USD 740 per target at 50, roughly a 47% per-unit improvement for buying ten times as much.
  • The subdomain multiplication trap. app.example.com, staging.example.com, and api.example.com are three licensed targets, not one application. Teams that scope by “number of products” and then discover they scan three environments each end up at triple their budgeted number. Count hostnames, not apps, before you ask for a quote.
  • User seats. Standard is single-user by design. Once more than one person needs to log in, triage, and pull reports, you are on Premium and seats become a line item.
  • Support and onboarding. SLA-backed response times, dedicated onboarding, and premium support tiers are priced separately from the core licence. Professional services are typically sold in blocks of hours that do not roll over.
  • Contract length. The minimum is normally a 2-year subscription with annual payment, and the discounting lives in term length - resellers report meaningful reductions in the effective annual rate for 24 and 36 month commitments. That is real money, but it is also a target lock: you generally cannot swap which applications are licensed mid-term.

Worked examples: what teams actually pay

These are reported real-world shapes rather than vendor quotes, so treat them as budgeting anchors and nothing more.

ScenarioTargetsReported annual cost
Small team, 5 apps, cloud only5 FQDNs~$7,000
Mid-market, 25 apps across 3 environments~75 FQDNs~$60,000-$86,000 with premium support
Enterprise, 100+ apps, regulated100+ FQDNsQuote only, six figures realistic

The middle row is the one worth staring at. Twenty-five applications sounds like a modest programme, but multiply by dev, staging, and production and you are licensing seventy-five targets. That single scoping decision is the difference between a five-figure and a low-six-figure line item, and it is entirely within your control - scan production plus one pre-production environment rather than all three, or consolidate test environments behind fewer hostnames.

Acunetix cost versus the alternatives

Here is the honest comparison, including the tools that publish their prices.

Tool2026 priceModelTrade-off
AcunetixQuote, ~$7,000+/yrPer FQDN, 5 minimumLow-noise proof-based scanning, no free tier
Invicti EnterpriseQuote, ~$30,000+/yrPer target, platformSame engine plus governance, SCA, ASPM
Burp Suite Professional$499/user/yrPer seat, publishedManual testing workbench, not unattended DAST
Burp Suite DASTQuote, ~$6,000-$200,000+/yrPer app plus usersDirect enterprise DAST competitor
OWASP ZAPFree (Apache 2.0)Open sourceSame core coverage, you pay in triage time
Nessus Professional$4,790/yrPer instance, publishedNetwork CVE scanning, different job

Two comparisons are worth making explicitly. Against Burp Suite Professional at $499 per user per year, Acunetix looks expensive, but they are not substitutes: Burp Pro is a per-seat manual workbench, Acunetix is per-application unattended scanning. We break down the seat maths in Burp Suite pricing 2026. Against OWASP ZAP, which is free, the trade is licence money versus operator time - ZAP matches Acunetix on core OWASP Top 10 detection classes and hands you more false positives to filter, which is a real cost that just does not appear on an invoice.

When Acunetix is worth the quote

Pay for it without agonising when:

  • You scan many applications continuously and triage time is your bottleneck. Proof-based scanning auto-verifies a large share of findings, and at 20 or more applications that saved triage genuinely outruns the licence.
  • You answer to auditors under CBUAE, DFSA, VARA, or ISO 27001 and need scan evidence with a supported commercial vendor behind it. “We use the free one and tuned it ourselves” is a harder conversation than it should be.
  • You need SPA and JavaScript-heavy crawling that open-source crawlers handle less reliably, or AcuSensor IAST coverage on a supported runtime.

Skip it when you have fewer than five applications, no CI/CD scanning requirement, and someone on the team who can run and tune ZAP. Below that threshold the 5-target minimum means you are buying capacity you will not use.

Get a quote, and what to ask for

Because there is no published price, the quote conversation is the pricing. Go in with:

  1. An exact FQDN count, environments included, so the number you get is the number you pay.
  2. A clear position on term length - if you are willing to commit for 24 or 36 months, say so, because that is where the discount is.
  3. Written confirmation of what support tier is bundled versus priced separately.
  4. Confirmation of whether licensed targets can be changed mid-term. Usually they cannot, and that matters if your estate churns.

Treat every figure in this post, and every figure on any comparison site, as indicative. Marketplace listings, reseller pages, and review aggregators all lag actual contract terms, and regional pricing differs.

Where the scanner licence stops mattering

The uncomfortable part. Acunetix, Invicti, Burp DAST, and ZAP are all automated scanners, and automated scanning finds roughly 40% of what a manual web application penetration test finds. Proof-based scanning is genuinely good at the pattern-detectable classes: injection, cross-site scripting, misconfiguration, exposed data, known-vulnerable components. It is weak or blind on precisely the flaws that cause the worst incidents:

  • Broken access control - no scanner knows that user A should not be able to read user B’s invoice. A human tester proves it in ten minutes.
  • Business-logic flaws - price manipulation, workflow bypass, abuse of a legitimate feature. No signature exists for these.
  • Chained exploits - three low-severity findings that combine into account takeover, which a scanner faithfully reports as three unrelated notes.

That is why the licence question is often the wrong question. When you engage a penetration testing firm, you do not buy Acunetix, or ZAP, or a per-FQDN subscription - the firm brings its own tooling and, more to the point, the human judgment that turns raw findings into proven, exploited, business-impact reports. Your USD 7,000 buys a scanner; a pentest buys the 60% the scanner cannot reach.

If you have been running Acunetix and want to know what it missed, a web application pentest from pentest.ae delivers exploited findings and a remediation-ready report, not scanner output - and there is no per-target licence for you to buy. Book a free scope call.

Before you sign a two-year scanner contract, price a real test.

A licence renewal is a rounding error next to a breach. Our fixed-scope penetration test finds what proof-based scanning cannot - human-verified, exploit-chained, and documented for CBUAE, DFSA, and ISO 27001 auditors.

Get a fixed-scope quote

Disclaimer

This article is published for informational purposes. Acunetix does not publish list pricing. Every figure here is drawn from public marketplace listings, reseller pages, and third-party review sites at the time of writing, and may not reflect current contract terms, regional pricing, volume discounts, promotional rates, or negotiated terms. Obtain a current quote directly from Invicti Security before any procurement decision. Acunetix, Acunetix 360, AcuSensor, Invicti, Netsparker, Burp Suite, Nessus, and OWASP ZAP are trademarks of their respective owners; pentest.ae is not affiliated with, endorsed by, or sponsored by Invicti Security, PortSwigger, Tenable, or the OWASP Foundation. Mentions are nominative and descriptive only.

Frequently Asked Questions

How much does Acunetix cost in 2026?

Acunetix pricing is quote-based - Invicti publishes no rate card, so any number you see online is a reported or marketplace figure rather than a list price. The most commonly cited reference point is the AWS Marketplace listing for Acunetix Online Premium at around USD 7,000 per year for 5 targets. Third-party review sites report an entry band of roughly USD 4,500-7,000 per year for a small target count, mid-market deployments in the tens of thousands, and enterprise scanning quoted individually. Licensing is per FQDN with a 5-target minimum, normally on a 2-year subscription paid annually.

What is the Acunetix 360 price?

There is no published Acunetix 360 price, and the name itself is now legacy. Acunetix 360 was the DevSecOps and enterprise tier of the line, and after the Netsparker and Acunetix consolidation under Invicti Security that capability is quoted as Invicti Enterprise. Reported figures for that enterprise tier start around USD 30,000-37,000 per year for roughly 50 targets and climb from there with on-prem deployment, SCA, ASPM, and support add-ons. If a reseller quotes you a fixed 'Acunetix 360' number, ask which current SKU it maps to before you sign.

What are the Acunetix tiers?

Invicti currently sells Acunetix as Standard and Premium, with the enterprise capability sitting in Invicti Enterprise (historically marketed as Acunetix 360). Standard is the single-instance scanner aimed at pentesters and small teams, sold in target bundles of 5, 10, and 20. Premium adds multiple users, larger target counts, and CI/CD and ticketing integrations. Be aware that third-party review sites label the tiers Essentials, Professional, and Ultimate, which is a stale or reseller-specific naming - always confirm the SKU name against your actual quote.

What drives the cost of an Acunetix licence?

Four things. First and biggest is the number of FQDN targets - every domain, subdomain, and separately addressed API host counts as its own licensed target, so a staging and dev environment triples the count for the same application. Second, user seats on Premium and above. Third, support and onboarding tier, which is priced separately from the core licence. Fourth, contract length - multi-year commitments are where the discounting lives, with 24 and 36 month terms reported to cut the effective annual rate substantially.

Is Acunetix cheaper than Invicti or Burp Suite?

Acunetix is the cheaper of the two Invicti Security products because it is the standalone scanner rather than the enterprise platform - same proof-based engine, less packaging. Against Burp Suite Professional at $499 per user per year it is not close on sticker price, but they are different tools: Burp Pro is a manual testing workbench sold per seat, while Acunetix is unattended automated scanning sold per application. If your requirement is genuinely free automated scanning, OWASP ZAP is free under Apache 2.0 and covers the same core OWASP Top 10 classes with more triage effort on your side.

Is there a free version of Acunetix?

No. Acunetix has no free tier and no community edition, and the minimum commercial purchase is 5 targets. Trials and demos are arranged through the sales team rather than self-service download. If you need zero-cost automated web scanning, the realistic options are OWASP ZAP for full DAST coverage and Nuclei for templated checks - both free, both requiring you to spend operator time where Acunetix spends your licence budget.

Find It Before They Do

Book a free 30-minute security discovery call with our AI Security experts in Dubai, UAE. We identify your highest-risk AI attack vectors - actionable findings in days.

Talk to an Expert