From secure development to cybersecurity experts
Founded in 2012, DongIT started as a web development company with a strong focus on security by design: developing applications that are secure and privacy-sensitive from the ground up. That perspective shaped everything that followed. Those who understand how to build IT systems securely also know how to test them effectively for vulnerabilities.
Today DongIT is a trusted cybersecurity partner in two ways. As a penetration testing service, we are trusted by 500+ organizations across government, healthcare, financial services, software vendors and enterprise IT. As the developer of the Security Reporter platform, we serve leading cybersecurity teams worldwide including those at ABN AMRO, ASML, the European Central Bank, EY, Orange Cyberdefense, Capgemini and Telenor.
Want to know how secure your IT environment really is? Contact us for a complimentary scoping conversation.
Guaranteed quality: CCV Keurmerk Pentesten and ISO 27001
DongIT is certified under the CCV Keurmerk Pentesten, the Dutch national standard for high-quality penetration testing issued by the Centre for Crime Prevention and Safety. This certification guarantees that our methods meet the highest requirements for quality, integrity and transparency.
- Certified pentesters holding OSCP, OSWE, OSEP, OSED, CRTO, CISSP and CISA
- Comprehensive and realistic pentests based on internationally recognized methodologies (OWASP, NCSC, MITRE ATT&CK)
- Four-eyes principle: every finding is peer-reviewed by a second ethical hacker, ensuring higher-quality reports and more discovered vulnerabilities
DongIT itself has been ISO 27001-certified since 2025, assessed against the international standard ISO/IEC 27001:2022. Our information security management system is independently audited, so we know first-hand what external auditors expect and deliver reporting that aligns directly with their requirements.

Certified security experts
Our ethical hackers are among the most highly qualified professionals in the Netherlands. They hold extensive hands-on experience and internationally recognized cybersecurity certifications:
- OSCP, Offensive Security Certified Professional
- OSWE, Offensive Security Web Expert
- OSEP, Offensive Security Experienced Pentester
- OSED, Offensive Security Exploit Developer
- CRTO, Certified Red Team Operator
- CISSP, Certified Information Systems Security Professional
- CISA, Certified Information Systems Auditor
- eCPPTv2, eLearnSecurity Certified Professional Penetration Tester
Combining deep technical expertise with real-world experience, we do more than identify vulnerabilities: we provide concrete remediation guidance your team can apply directly. Every finding comes with code-level advice via our self-developed Security Reporter platform.
Our expertise in the media
Our security experts regularly share their knowledge and research in the media. Nieuwsuur, a leading Dutch investigative news programme, interviewed DongIT about vulnerabilities in the security of web applications used by dozens of Dutch municipalities.
Why choose DongIT
- In-depth technical expertise. We go beyond surface-level testing. Our specialists assess security at the architecture, configuration and code level, uncovering risks that standard assessments miss.
- Certified security professionals. Every pentest is performed by experienced ethical hackers with recognized top-tier certifications. They combine current threat intelligence with real-world experience.
- Compliance-focused reporting. Every organization is different. We align our security assessments with your IT environment, business processes and regulatory framework, including DigiD, NIS2, ISO 27001, DORA, NEN 7510 and PCI DSS.
- CCV-certified and independent. Independent quality assurance and a transparent testing methodology you can trust.
- Actionable reporting. Every finding includes risk rating, prioritization and concrete remediation guidance for both technical teams and management.
- A long-term security partner. Beyond delivering a report, we support retesting, remediation programmes, secure development and strategic security advice.
Ready to strengthen your cybersecurity? Contact us for a complimentary scoping conversation and discover how we can help.
Nederlands
