Skip to main content
PortSwigger logo
Risk & ComplianceEstablished · 20 yrs on market

Burp Suite

Web security testing toolkit and automated DAST scanning used by security professionals worldwide

By PortSwigger · HQ Knutsford, UK · 4.8/5 Value-Position score (estimate)

Positioning guardrails

Best for

  • Penetration testers and security consultants doing hands-on testing of web applications
  • AppSec and vulnerability management teams that need unlimited automated DAST scanning across a portfolio
  • DevOps and engineering teams embedding CI-driven DAST scanning before release
  • Security upskilling through the free Web Security Academy and community labs

Ideal size: 10–500 people · Security-mature organisation with a dedicated AppSec, pentest or DevSecOps function

Not for

  • Teams without security specialists that want a fully managed compliance platform
  • Buyers who need published, self-serve list pricing without going through sales
  • Organisations looking for a broad GRC or policy-management suite instead of testing tooling
  • Non-technical stakeholders expecting one-click dashboards with no configuration

Value metrics scorecard

Time-to-Value

2–4 weeks for first production scan

~30 days to first production value

Total Cost of Ownership

On request

Editions are split by use case (hands-on testing, scalable automated scanning, CI-driven scanning). The pricing page routes buyers to a demo or quote rather than publishing list prices.

Implementation Friction

3/5

Engineering + admin effort required

Value-Position score

4.8

out of 5 · model estimate

Full cost breakdown

Mandatory implementation fee

None

Seat tiers

Not listed

Add-on costs

  • None

Company & support

Who is behind Burp Suite, and how your team gets help once it is live.

Company

Founded
Not recorded
Headquarters
Knutsford, UK

How you get support

  • PhoneNot listed
  • EmailPlan not stated
  • Live chatNot listed
  • Support portal / ticketsPlan not stated
  • Community forumAll plans
  • Help centre / docsAll plans
  • Dedicated account managerNot listed
  • In person / on-siteNot listed
Hours
Not recorded
Response time
Not stated

Technical support and a Customer Happiness team are reached by email, and the support centre hosts documentation for both desktop and DAST editions. No phone support line is offered.

“Not listed” means the vendor’s public pages don’t mention that channel, not that it is unavailable. Ask about it during evaluation.

Market position

Where Burp Suite sits against its closest alternatives. Pick any two of cost, speed, friction and buyer score, and up to 9 companies to compare.

Quadrant view

Typical annual cost × Time-to-value

$0/yr$1/yr27d29d30d31d33dAnnual TCO ← betterDays to value better →Quick & CheapQuick & PriceySlow & CheapSlow & PriceyBurp SuiteVeracodeRelativityOneSardineSalt SecurityConvera

The lines cross at the median of the solutions shown, so about half sit on each side of each line.

Burp Suite is outlined. Click any dot to open its dossier.

Companies on the chart 6 / 10

  • Burp Suite
  • Veracode
  • RelativityOne
  • Sardine
  • Salt Security
  • Convera
Add or change companies

Up to 10 companies including Burp Suite. Listed closest first.

Stack fit signal

Compatibility with standard B2B ecosystems.

MCPNot supported

No supported MCP path today, so it cannot be driven from an AI client.

SalesforceNot supported
AWSNot supported
SnowflakeNot supported
HubSpotNot supported
Google WorkspaceNot supported
Microsoft 365Not supported
SAPNot supported
SlackNot supported

AI & MCP readiness

What Burp Suite ships in AI, and what it asks of your ecosystem.

We haven’t recorded AI capabilities for Burp Suite yet. Nothing here means unverified — not absent.

Compliance attestations

SOC 2 — not heldISO 27001 — not heldGDPR — not heldHIPAA — not heldFedRAMP — not heldISO 42001 — not heldIAPP AIGP* — not held

* IAPP AIGP certifies individuals, not products. It means named staff hold the credential — not that the platform does.

Bottom line

Burp Suite is PortSwigger's web application security testing toolkit, used for over 20 years by pentesters and AppSec teams. Desktop editions cover hands-on manual testing; Burp Suite DAST adds unlimited, CI-driven automated scanning. PortSwigger reports 90,000+ practitioners and 15,000+ organisations in 170 countries, and a 4.8 rating on G2. Buying is quote-based rather than self-serve list pricing, and the compliance page positions Burp as an input to PCI DSS, HIPAA and GDPR programmes rather than a compliance system of record.

Frequently asked questions

What does Burp Suite cost and how do we buy it?

PortSwigger's pricing page routes buyers by use case rather than publishing list prices: hands-on manual testing, scalable automated scanning, and CI-driven scanning for developers. Licensing is handled through sales, so expect a quote and a demo request. Free web security training and community resources sit alongside the paid editions.

How quickly can a team get value from Burp Suite?

Individual testers become productive quickly because the desktop editions are point-and-click rather than code-driven, and customers describe a short learning curve. Larger DAST deployments take longer because they involve installation, target configuration and scan scheduling, so budget two to four weeks for a first production scan of a real application portfolio.

How does Burp Suite fit our compliance obligations?

The compliance page positions Burp Suite as an input to PCI DSS, HIPAA, NIST 800-53, OWASP Top 10 and GDPR work: scheduled scanning, reporting and reduced pentest effort give assessors evidence of continuous testing. It is not a GRC system of record and does not itself certify or manage compliance.

What support is included?

Technical support and a Customer Happiness team are reached by email, and a support centre holds documentation for both desktop and DAST editions. There is no support phone line; the contact page directs callers to email instead.

Can we run automated scanning in CI/CD and at enterprise scale?

Yes. PortSwigger positions Burp Suite DAST for AppSec and DevOps teams with unlimited automated scanning, CI-driven scanning before release, and deployment to a Kubernetes cluster, so scans can be scheduled or triggered by pipeline events.