Skip to content
Exploit Labs
Penetration Testing as a Service

We manage your pentest programme end to end - not just the test in the middle.

You have an ISMS and you know your applications and services. We help define testing frequency and structure, execute, support remediation and keep you auditable - from the first plan to the final evidence pack.

What this page is for

Managed pentest programme: calendar, retests, findings management, audit evidence.

Price ranges live on /pentest-kosten, mandatory regulated testing on /dora-tlpt.

  • How do we plan testing across the year instead of ordering test by test?
  • Who tracks findings and retests?
  • Where does the evidence for the next audit come from?
The PTaaS cycle

Five steps that repeat every quarter.

01

Planning

We define test frequency and structure with you: which application, service or system is tested when. A quarterly calendar aligned to release cycles and ISMS planning.

02

Execution

Senior-led, manual testing against OWASP WSTG, ASVS, MASVS and AISVS - the same depth as a one-off mandate, just recurring and predictable.

03

Remediation support

Your engineers get access to the operators who found the issue: guidance, follow-up questions, assessment of workarounds, retest readiness.

04

Findings management

Findings land with CVSS and owner in your risk register or Jira - not in a PDF nobody reopens. Status, deadlines and retests are tracked.

05

Audit evidence

Consistent evidence across the year: test plan, reports, retest statements and coverage overview - in a form auditors and supervisors accept without rework.

Boundaries

For us, PTaaS does not mean a scanner subscription.

What it is
  • A managed pentest programme with a fixed calendar and named operators
  • Manual depth testing, extended by continuous automated coverage between engagements
  • Retests as a planned component, not a renegotiation
  • An integration into your ISMS, risk register and ticketing
  • One counterpart for planning, delivery, remediation and evidence
What it is not
  • Not a scanner subscription with a dashboard full of unvalidated findings
  • Not a crowd model with rotating, unknown testers
  • Not a substitute for a red team or a DORA TLPT
  • Not a black box: you see scope, methodology and effort per cycle
Coverage

What a programme covers.

  • Web and API applications including role and tenant separation
  • External perimeter and exposed services
  • Internal networks, Active Directory and Entra ID
  • Cloud configuration, IAM and CI/CD chains
  • Mobile apps and their backends
  • AI and LLM components against OWASP AISVS
Between engagements

Continuous coverage

Between manual cycles we watch the attack surface for change: new hosts, new endpoints, altered auth flows. Relevant changes trigger an assessment impulse instead of waiting for the next quarter.

Operator-validated

No finding reaches your risk register before a senior operator has reproduced and rated it. That keeps the false-positive burden on our side.

ISMS & evidence

A testing programme your auditor accepts without follow-up questions.

Evidence of a structured testing process is a recurring duty under ISO 27001, DORA, NIS2 and TISAX. In a programme that evidence emerges as a by-product of the work: test plan, coverage overview, report per cycle, retest statement and finding status history.

  • Findings with CVSS and owner in the risk register or Jira
  • Recurring test calendar in the annual plan
  • Consistent metrics across application portfolios
  • MITRE ATT&CK mapping for your detection engineering
Complete guide: penetration testing explained

Test types, methodologies, lifecycle and standards - for CISOs, product security and auditors.

Effort and budget logic per test type live on pentest costs. Mandatory regulated testing under DORA Article 26 runs through DORA TLPT. One-off, project-based tests and all nine test types live on penetration testing.

Enquiry

Request a PTaaS programme.

One form, one point of contact: describe your assets, audit deadlines and preferred cycle, and we reply with a testing calendar, an effort range and the open scoping questions. NDA before any details on request.

PTaaS · Programme enquiry

Request a PTaaS programme

Confidential. Goes straight to a senior operator, never shared with third parties.

FAQ

Frequent questions about PTaaS

How does PTaaS differ from individual penetration tests?

The test itself is identical - senior-led and manual. The difference sits around it: frequency and sequence are planned for the year, retests are priced in, findings are tracked to closure, and evidence accumulates continuously instead of the week before an audit.

Do you use automation or do humans test?

Both, with a clear division of labour. Automated and AI-assisted coverage runs between engagements and flags changes to the attack surface. Every finding that reaches you has been validated by an operator - unconfirmed scanner hits never enter your risk register.

How many tests does a programme include per year?

That follows from your portfolio and criticality, not from a package name. Four to twelve assessment cycles per year is typical, split across applications, perimeter, cloud and internal systems. Effort is stated in tester-days per cycle.

What does a PTaaS programme cost?

A programme is priced from the same building blocks as individual tests - a web application is indicatively €7,000 - €16,000, an internal AD assessment €12,000 - €24,000. Across the year, planning, retests and evidence work are added; in exchange, per-order scoping rounds disappear.

Does PTaaS satisfy our DORA or NIS2 obligations?

For regular security testing and evidence of a structured testing programme: yes, that is exactly its purpose. A threat-led penetration test under DORA Article 26 is not covered by it - that runs as its own, supervised operation.

Can we start with a single test and move to a programme later?

Yes, that is the most common path. The first test provides the baseline; from there we build the calendar for the following twelve months.

Confidential

Discuss a programme instead of a single test.

Bring your application portfolio and audit deadlines - we draft the testing calendar for the next twelve months.

Not ready to talk yet? The Scope Check returns exercise type, tester-days and a budget range in two minutes - no email gate.