Get a penetration test

Overview of all our penetration testing services and methodologies

When do you need a pentest?

Preparing for a compliance audit (ISO 27001, NIS2, DigiD, GDPR or NEN 7510)? Do enterprise clients require demonstrable security of your application? Rolling out a new architecture and want to be certain it goes live safely? Or has your board asked for demonstrable cyber resilience? In all these situations a pentest, also known as a penetration test or ethical hacking engagement, is the most concrete instrument at your disposal.

We perform pentests for Dutch and European organizations in sectors including healthcare, financial services, government, industry and enterprise SaaS. Our approach is manual and context-aware. All findings are reported via our own Security Reporter platform, and data stays in Europe.

Our pentests are CCV Keurmerk-accredited and performed by OSCP, OSWE and OSEP-certified ethical hackers. DongIT is ISO 27001:2022-certified itself.

Trusted by 500+ organizations

Since 2012 we have worked with a wide range of organizations. From software vendors and hosting providers to hospitals, banks, municipalities and grid operators. For every type of organization we deliver pentests aligned with their architecture, threat model and customer expectations.

IT and software

SaaS vendors, web application builders and hosting providers have their platforms tested to demonstrate security to their own customers.

Healthcare

Hospitals, care institutions and healthcare IT vendors rely on our NEN 7510 mapping and experience with EHR integrations such as HL7 and FHIR.

Government

Municipalities, executive agencies, provinces and water boards choose us for BIO2, DigiD and Suwinet engagements.

Financial sector

Banks, insurers and payment institutions engage us for DORA reporting and preparation for TIBER-EU.

Industry

Manufacturing, transport companies and logistics providers with critical production environments and OT/ICS infrastructure under NIS2.

Education

Universities, colleges, cultural institutions and civil society organizations with sensitive research data, membership administration or public information.

Retail

Webshops, retail platforms and e-commerce organizations with substantial customer databases, payment flows and PCI DSS requirements.

Media

Publishers, content platforms, telecom providers and digital infrastructure vendors with high availability and privacy requirements.

Professional services

Consulting, accountancy and legal firms handling confidential client data who want to demonstrate security to their clients.

What makes our pentests different?

Automated scanners find known vulnerabilities. Our pentesters find what scanners cannot see: business logic flaws, tenant separation issues, complex race conditions, IDOR patterns, cross-tenant leakage and the creative exploit chains real attackers actually use.

By testing in a targeted, context-aware way within the engagement scope, we do more than identify vulnerabilities in isolation. We chain them together for deeper insights that only emerge when experienced people piece the puzzle together. Read more about the benefits of manual testing.

CCV Keurmerk Pentesten

Four eyes on every finding. Every pentest is delivered under our four-eyes principle: minimum of two testers involved per engagement, with peer review on every finding. For supervisory authorities (DNB, AFM, IGJ, Dutch Data Protection Authority) and auditors, this practice combined with the CCV Keurmerk Pentesten accreditation is an additional quality indicator that strengthens your compliance reporting. As an ISO 27001:2022-certified organization ourselves, we know how an audit works from the inside.

Our penetration testing services

We offer pentests for every layer of your digital infrastructure. Choose the service that fits your scope or let us advise you during the scoping conversation on what suits your situation best.

Web application pentest

Pentesting for web applications, APIs and SPAs based on OWASP ASVS. Focus on business logic, authentication and multi-tenant separation.

Network and cloud pentest

External and internal network pentesting including Azure, AWS, M365 and Entra ID. Assumed breach scenarios and Active Directory testing.

OT security pentest

Pentesting for PLCs, SCADA and industrial networks aligned with IEC 62443 and the Purdue model. Without disruption of production continuity.

Phishing and awareness

Controlled phishing simulations and awareness measurements. Suitable for NIS2 reporting and cultural change.

Source code review

Manual code audit for secure coding, business logic and cryptographic implementations. Complements black-box pentesting.

Vulnerability scan

Automated scanning as a supplement to periodic pentesting. For continuous monitoring between assessments.

Our process from scope to report

Transparent, predictable and without surprises. Six steps from the first conversation to the final report. We always align our reporting with the compliance framework that is relevant to you.

Intake

Complimentary conversation to map out your architecture, threat model and compliance goals. No obligation.

Complimentary, 45 to 60 minutes

Tailored quotation

You receive a concrete proposal with scope, methodology, planning and investment. Fixed price, no hidden costs.

Within 3 business days

Preparation

We arrange access, set up safety agreements and prepare test environments together with your IT and development teams.

1 to 2 weeks

Execution

Manual testing by at least one certified pentester. Larger engagements use teams of two to three testers with regular progress updates.

5 to 25 business days depending on scope

Report

Delivery via Security Reporter with executive summary, technical findings (CVSS-scored) and remediation guidance.

Within 5 business days after execution

Retest

Once you have resolved vulnerabilities, we validate that the remediation actually works. Time and materials, based on the number and complexity of findings.

Time and materials

Pentest types: black box, gray box or white box?

Which form of pentest works best depends on your objective, threat model and available information. The forms differ mainly in how much prior knowledge, test accounts and background information the tester receives upfront.

The form is determined in consultation with you, based on the situation, requirements and intake process.

  • Black box pentest. Tester has minimal prior knowledge. The most realistic simulation of a real-life hack.
  • Gray box pentest. Tester has partial information such as user accounts.
  • White box pentest. Tester has full insight into all aspects of the system architecture and access to the source code. This produces the most thorough findings.
  • Time-boxed or budget-boxed pentest. Testing where the duration or budget determines when the test ends.

Our methodology: internationally recognized frameworks

An effective pentest goes beyond finding vulnerabilities. It is about insight, impact and actionable remediation. Our approach is based on internationally recognized frameworks, and we actively apply the latest developments, zero-day vulnerabilities and current attack techniques in our security engagements.

  • NIST Cybersecurity Framework. Risk management and best practices for IT security.
  • OWASP Testing Guide and ASVS. Testing web applications against the most critical vulnerabilities.
  • PTES and OSSTMM. Standards for in-depth and structured penetration testing.
  • ISSAF. Assessment framework for systems and networks.
  • IEC 62443. For OT environments and industrial control systems.
  • NCSC guidelines. Dutch best practices for security testing.

What does a pentest cost?

The price depends on scope and complexity. For clearly defined engagements we offer standard packages. For more complex engagements we work with a scoping conversation and a tailored quotation.

  • Quick Pentest, €2,960 excl. VAT
  • Expert Pentest, from €5,040 excl. VAT (most chosen)
  • Extensive Pentest, from €7,200 excl. VAT
  • Enterprise engagements, tailored quotation

Tailored pricing

For every complex engagement we first propose a complimentary scoping conversation. This ensures you know exactly what the investment will be and what to expect.

Frequently asked questions about pentesting

Below are the most frequently asked questions about pentesting. For a complete overview please visit our FAQ page.

What exactly is a pentest?

A pentest, also known as a penetration test or ethical hacking engagement, is a security assessment in which certified ethical hackers test your systems and applications for vulnerabilities. In the same way malicious hackers would. The goal is to identify and fix weaknesses before they can be exploited.

Which pentest do I need?

That depends on what you want to secure. For a web application or SaaS platform, a web application pentest is appropriate. For an organization-wide network security review, a network and cloud pentest. For industrial environments, an OT security pentest. During the scoping conversation we advise which form fits your situation best.

How long does a pentest take?

Active testing time ranges from 16 hours for a small web application to 80 hours or more for a large network or enterprise web app pentest. Total duration from scoping conversation to final report is typically 4 to 8 weeks.

What is the difference between a pentest and a vulnerability scan?

A vulnerability scan is an automated check for known vulnerabilities. A pentest adds manual creativity: our testers chain vulnerabilities together, test business logic and discover issues that scanners systematically miss. For compliance purposes, a pentest is typically the minimum requirement.

How often should I have a pentest performed?

Market standard for organizations under NIS2, ISO 27001 or DigiD is annually. After significant architectural changes an additional test is recommended. For DigiD connections annual pentesting is legally required.

Will a pentest disrupt our production environment?

We prefer to work on acceptance or test environments. Where production testing is necessary, we make strict safety agreements about timing, impact limits and escalation paths. Our testers know how to work without disruption.

What about compliance mapping?

Our reports are always aligned with the compliance framework relevant to you: NIS2 and the Dutch Cybersecurity Act, ISO 27001:2022, DigiD normenkader v4.0, DORA, BIO2, NEN 7510, IEC 62443, GDPR or PCI DSS. Findings are explicitly linked to the relevant controls for your auditor or supervisory authority.

Ready to demonstrate your security?

Preparing for an audit? Meeting client or contract requirements? Rolling out a new application? Response within one business day. Quotation within three business days.