The main difference is that an OWASP Top 10 report is compact and technical for your development team, while an NCSC report is more comprehensive and suited to audits and certification processes. Which type you receive depends on the pentest package and your compliance requirements.
What is an OWASP Top 10 report?
An OWASP Top 10 report is based on the OWASP Top 10 Application Security Risks (version 2025) from the Open Worldwide Application Security Project. This internationally used list identifies the ten most important security risks for web applications and is periodically updated by security experts worldwide.
The report is compact, technical and aimed at developers. Findings are mapped to OWASP categories such as Broken Access Control, Cryptographic Failures, Injection and Security Misconfiguration. Your development team can start immediately with concrete remediation instructions per finding.
When suitable: for quick security checks, agile development teams that want to address vulnerabilities per sprint, and organizations without formal audit requirements.
What is an NCSC report?
An NCSC report is based on the ICT Security Guidelines for Web Applications (version 2025) from the Dutch National Cyber Security Centre (NCSC), the national authority for cybersecurity under the Ministry of Justice and Security. These guidelines provide a structured framework for securely developing, managing and offering web applications.
The report is more comprehensive than an OWASP report and includes not only a management summary but also a detailed overview of all assessed components, including those that produced no vulnerabilities. This makes the report directly usable for auditors who want to see full coverage rather than only findings.
When suitable: for compliance audits such as DigiD (Logius framework v4.0), ISO 27001 certification, NEN 7510 (healthcare), NIS2 accountability, MedMij and assurance reports (Third Party Memorandum, TPM).
Which report you receive with each package
- Basic Scan. Concise technical report based on OWASP Top 10.
- Quick Pentest. Technical pentest report based on OWASP Top 10.
- Expert Pentest. Report based on OWASP Top 10 and NCSC guidelines, with compliance mapping.
- Extensive Pentest. Comprehensive report including NCSC guidelines, MIAUW, PCI DSS, MedMij and Azure Security Benchmark where relevant.
View the packages page for complete details.
Other frameworks we use
In addition to OWASP Top 10 and NCSC, our pentesters also work with other international standards where relevant to your scope:
- OWASP ASVS. Application Security Verification Standard for structured security verification.
- OWASP Mobile Top 10 and MASVS. Specifically for mobile apps.
- OWASP API Security Top 10. For REST and GraphQL APIs.
- MITRE ATT&CK. For mapping identified vulnerabilities to real-world attack techniques.
- MIAUW. Methodology for Information Security Research with Audit Value, used within the Dutch government-wide framework agreement for government pentests.
- PCI DSS. For organizations handling card payments.
Not sure which report fits your compliance requirements? Contact us for a complimentary scoping conversation, or read our FAQ on compliance conformity.
Nederlands