We manage your pentest programme end to end - not just the test in the middle.
You have an ISMS and you know your applications and services. We help define testing frequency and structure, execute, support remediation and keep you auditable - from the first plan to the final evidence pack.
Managed pentest programme: calendar, retests, findings management, audit evidence.
Price ranges live on /pentest-kosten, mandatory regulated testing on /dora-tlpt.
- How do we plan testing across the year instead of ordering test by test?
- Who tracks findings and retests?
- Where does the evidence for the next audit come from?
Five steps that repeat every quarter.
Planning
We define test frequency and structure with you: which application, service or system is tested when. A quarterly calendar aligned to release cycles and ISMS planning.
Execution
Senior-led, manual testing against OWASP WSTG, ASVS, MASVS and AISVS - the same depth as a one-off mandate, just recurring and predictable.
Remediation support
Your engineers get access to the operators who found the issue: guidance, follow-up questions, assessment of workarounds, retest readiness.
Findings management
Findings land with CVSS and owner in your risk register or Jira - not in a PDF nobody reopens. Status, deadlines and retests are tracked.
Audit evidence
Consistent evidence across the year: test plan, reports, retest statements and coverage overview - in a form auditors and supervisors accept without rework.
For us, PTaaS does not mean a scanner subscription.
- A managed pentest programme with a fixed calendar and named operators
- Manual depth testing, extended by continuous automated coverage between engagements
- Retests as a planned component, not a renegotiation
- An integration into your ISMS, risk register and ticketing
- One counterpart for planning, delivery, remediation and evidence
- Not a scanner subscription with a dashboard full of unvalidated findings
- Not a crowd model with rotating, unknown testers
- Not a substitute for a red team or a DORA TLPT
- Not a black box: you see scope, methodology and effort per cycle
What a programme covers.
- ▸ Web and API applications including role and tenant separation
- ▸ External perimeter and exposed services
- ▸ Internal networks, Active Directory and Entra ID
- ▸ Cloud configuration, IAM and CI/CD chains
- ▸ Mobile apps and their backends
- ▸ AI and LLM components against OWASP AISVS
Continuous coverage
Between manual cycles we watch the attack surface for change: new hosts, new endpoints, altered auth flows. Relevant changes trigger an assessment impulse instead of waiting for the next quarter.
Operator-validated
No finding reaches your risk register before a senior operator has reproduced and rated it. That keeps the false-positive burden on our side.
A testing programme your auditor accepts without follow-up questions.
Evidence of a structured testing process is a recurring duty under ISO 27001, DORA, NIS2 and TISAX. In a programme that evidence emerges as a by-product of the work: test plan, coverage overview, report per cycle, retest statement and finding status history.
- ▸ Findings with CVSS and owner in the risk register or Jira
- ▸ Recurring test calendar in the annual plan
- ▸ Consistent metrics across application portfolios
- ▸ MITRE ATT&CK mapping for your detection engineering
Test types, methodologies, lifecycle and standards - for CISOs, product security and auditors.
Effort and budget logic per test type live on pentest costs. Mandatory regulated testing under DORA Article 26 runs through DORA TLPT. One-off, project-based tests and all nine test types live on penetration testing.
Request a PTaaS programme.
One form, one point of contact: describe your assets, audit deadlines and preferred cycle, and we reply with a testing calendar, an effort range and the open scoping questions. NDA before any details on request.
Frequent questions about PTaaS
How does PTaaS differ from individual penetration tests?
The test itself is identical - senior-led and manual. The difference sits around it: frequency and sequence are planned for the year, retests are priced in, findings are tracked to closure, and evidence accumulates continuously instead of the week before an audit.
Do you use automation or do humans test?
Both, with a clear division of labour. Automated and AI-assisted coverage runs between engagements and flags changes to the attack surface. Every finding that reaches you has been validated by an operator - unconfirmed scanner hits never enter your risk register.
How many tests does a programme include per year?
That follows from your portfolio and criticality, not from a package name. Four to twelve assessment cycles per year is typical, split across applications, perimeter, cloud and internal systems. Effort is stated in tester-days per cycle.
What does a PTaaS programme cost?
A programme is priced from the same building blocks as individual tests - a web application is indicatively €7,000 - €16,000, an internal AD assessment €12,000 - €24,000. Across the year, planning, retests and evidence work are added; in exchange, per-order scoping rounds disappear.
Does PTaaS satisfy our DORA or NIS2 obligations?
For regular security testing and evidence of a structured testing programme: yes, that is exactly its purpose. A threat-led penetration test under DORA Article 26 is not covered by it - that runs as its own, supervised operation.
Can we start with a single test and move to a programme later?
Yes, that is the most common path. The first test provides the baseline; from there we build the calendar for the following twelve months.
Specialist assessments - which page fits your scope
Entry point: test types, delivery, reporting, price ranges.
Open pageTier 0 assessment: attack paths to Domain Admin, ADCS, hybrid joins.
Open pageSAP-specific assessment: RFC gateway, authorisations, BTP integration.
Open pageCombines the technical test with ISMS / compliance evidence.
Open pageJoint detection work with your SOC instead of a covert operation.
Open pageGoal-oriented, covert attack simulation against people, technology and process.
Open pageDiscuss a programme instead of a single test.
Bring your application portfolio and audit deadlines - we draft the testing calendar for the next twelve months.
Not ready to talk yet? The Scope Check returns exercise type, tester-days and a budget range in two minutes - no email gate.