Penetration testing and security assessments for applications and IT infrastructure
Dutch pentesting partner since 2012 OSCP-certified ethical hackers with CCV Keurmerk Pentesten certification and ISO 27001:2022. Trusted by 500+ organizations.
Manual testing by experts Our ethical hackers use the same methods as real attackers. Four-eyes principle with peer review on every finding.
For DigiD, NIS2, ISO 27001 and DORA Pentests for web apps, networks, cloud, OT, APIs and mobile apps. Compliant with OWASP, PCI DSS, NEN 7510, GDPR and NCSC guidelines.
Response within 1 business day Complimentary scoping conversation. Quotation within 3 business days. Data stays in Europe. Reporting directly usable for your auditor.
Why choose DongIT
Nine reasons why 500+ organizations trust us with their pentesting and security assessments.
Manual testing by experts
Predominantly manual assessment by OSCP, OSWE, OSEP and OSED-certified ethical hackers. We find business logic flaws and context-specific risks that scanners systematically miss.
Four-eyes principle
Every pentest is performed by a minimum of two ethical hackers, with peer review on every finding. More perspectives lead to higher-quality reports and more discovered vulnerabilities.
CCV Keurmerk Pentesten
Officially certified per the requirements of the Dutch Centre for Crime Prevention and Safety (CCV). Demonstrable proof of quality for your auditor, DPO and supervisory authority.
ISO 27001:2022 certified
We have been ISO 27001-certified since 2015. We know first-hand what external auditors expect and deliver reporting that aligns directly with their requirements.
Compliance mapping
Reporting directly usable for DigiD audits (Logius v4.0), NIS2, DORA, NEN 7510, GDPR and PCI DSS. Findings explicitly linked to the controls of your framework.
Security Reporter platform
Reporting via our self-developed platform. Direct contact with the pentester per finding, exports for your development team and compliance mapping in one environment.
Technology independent
Experience with virtually every framework and tech stack: web apps, mobile apps, APIs (REST, GraphQL), cloud (Azure, AWS, GCP), Kubernetes, OT systems and network infrastructure.
Flexible testing methods
Black-box, grey-box and white-box testing. Time-boxed or budget-boxed based on your preference. From one-off pentests to periodic assessments and retests.
Web Security Scan Trustmark
Display the Web Security Scan Trustmark logo on your website as proof of your commitment to security and customer trust. Available after a successfully completed pentest.
Strengthen the security of your applications and IT infrastructure
Detect and remediate vulnerabilities in your web applications, networks, cloud environments and APIs before attackers do. Every pentest is tailored to your technology, goals and compliance requirements, with concrete recommendations your development team can implement directly.
Response within 1 business day, quotation within 3 business days.
Why organizations choose to have a pentest performed
An upcoming audit, a client asking for demonstrable security, an incident at a competitor, or new legislation such as NIS2 and DORA. Six concrete reasons why 500+ organizations ask us to test their applications and infrastructure:
Find vulnerabilities before attackers do
Ethical hackers approach your systems the way real attackers do, with the same techniques and creativity. We find vulnerabilities that scanners systematically miss: business logic flaws, IDOR patterns, multi-tenant leakage and creative exploit chains.
Meet concrete deadlines
The Dutch Cybersecurity Act (NIS2) has been in effect since 15 August 2026, with fines up to €10 million. DORA requires annual testing for financial entities since 17 January 2025. DigiD audits are mandatory annually. Our pentests deliver the reporting that your supervisory authority expects.
Prevent financial damage and fines
GDPR fines up to 4% of annual revenue, NIS2 fines up to €10 million and remediation costs that often run ten times higher than the investment in prevention. A pentest is the most cost-effective form of risk management.
Give customers and partners confidence
Customers and partners increasingly ask for demonstrable security: from SMB clients expecting a trustmark to enterprise buyers performing formal TPRM assessments. A recent pentest report, supplemented with the Web Security Scan Trustmark on your website, strengthens your position in commercial engagements.
Strengthen your commercial position
Cybersecurity has become a selling point, from SMB proposals to enterprise tenders. Organizations that can demonstrate regular testing by a CCV-certified party score higher with procurement, cyber insurers and risk departments. A concrete advantage in both commercial engagements and insurance renewals.
Protect reputation and customer trust
A cyber incident is one of the most costly business events your organization can experience: customer churn, media attention, contract losses and operational disruption. For SMBs an incident can be existential. For enterprises it means reputational damage toward shareholders and supervisory authorities. Preventive pentests demonstrably reduce impact and detection time.
Development and security expertise under one roof
DongIT combines deep pentesting expertise with a background in software development. Since 2012 we have worked with the tech stacks your teams use: from Node.js, .NET and Java to React, Kubernetes and cloud-native architectures (Azure, AWS, GCP). Our remediation guidance includes concrete code examples your development team can apply directly, instead of abstract lists of risks.

Manual and automated testing
Our pentests go beyond standard security scans. Where automated tools find known vulnerabilities, our OSCP-certified ethical hackers discover what scanners systematically miss: business logic flaws, IDOR patterns, race conditions and creative exploit chains. Four-eyes principle with peer review on every finding ensures the highest report quality.

Proven attack techniques from the field
As specialized ethical hackers we use the same techniques, tools and tactics that real attackers deploy daily. We actively track the threat landscape, MITRE ATT&CK frameworks and new attack vectors. This realistic approach shows not only where you are vulnerable, but also how your detection and response capabilities perform during an actual incident.
Nederlands