Pentest pricing and plans

Pentesting by certified ethical hackers. DongIT holds the CCV Keurmerk Pentesten certification.
Which plan would you like to view?

Tap a plan to view its details and price.

Basic Scan €1,480excl. VATRequest Basic Scan
Quick Pentest €2,960excl. VATRequest quote
Extensive Pentest from€7,200excl. VATRequest quote
Best suited for
Best suited for — More information
Examples of applications and situations suited to this plan.
  • Semi-automated vulnerability scan based on the OWASP Top 10
  • Concise insight into common vulnerabilities
  • Ideal during the early phase of a development project
  • Quick security check for SMB organizations
  • Compact pentest with fixed pricing
  • Also suitable for a focused assessment of your external attack surface
  • Periodic security checks for web applications
  • Simple informational applications with limited scope
  • Comprehensive pentest for complex applications, APIs and network infrastructure
  • In-depth insight into your current security posture
  • Compliance audits and TPM engagements
  • Reporting for MIAUW, NIS2, ISO 27001, NEN 7510, DigiD, PCI DSS, MedMij and GDPR
  • DigiD pentests for more extensive environments, aligned with the applicable Logius framework
Reporting
Reporting — More information
You receive the findings through our Security Reporter platform. The content and depth of the report depend on the plan.

Concise technical scan report with findings, risk assessments and remediation advice.

Technical pentest report with findings, risk assessments and remediation advice.

Comprehensive pentest report with management summary, technical findings, remediation advice and mapping to the agreed standards and guidelines.

Lead time
Lead time — More information
Indicative lead time from intake to delivery of the report. We agree the exact schedule with you in advance.

1 week

1-2 weeks

2-4 weeks

Manual testing by certified pentesters
Manual testing by certified pentesters — More information
The stars indicate the level of manual testing included in the plan. The Basic Scan includes a limited manual check; the pentest plans provide more extensive investigation.
AI-assisted analysis, manually validated
AI-assisted analysis, manually validated — More information
We use AI as a supporting tool where appropriate. A pentester checks every finding and determines the final risk assessment.
Automated vulnerability scan and port scan
Automated vulnerability scan and port scan — More information
We start with an automated scan using tools such as Nessus and Nmap. It identifies exposed services and known vulnerabilities to inform manual testing.
Testing for current vulnerabilities
Testing for current vulnerabilities — More information
We draw on known vulnerabilities (CVEs), the OWASP Top 10 and attack techniques from sources such as NCSC-NL and MITRE ATT&CK. Our pentesters follow emerging vulnerabilities and attack methods.
Review by a second pentester
Review by a second pentester — More information
A second experienced pentester reviews the findings, assesses whether they can be exploited and helps filter out false positives.
Direct contact with your pentester
Direct contact with your pentester — More information
Use the Security Reporter platform to ask technical questions, discuss findings and follow progress. You communicate directly with your pentester.
Reporting via Security Reporter
Reporting via Security Reporter — More information
View and export findings through the platform developed by DongIT. It supports team collaboration and integrations with development tools.
Final report discussion
Final report discussion — More information
A brief discussion of the findings with a pentester is included (less than 30 minutes).
AI and LLM application pentesting (optional module)
AI and LLM application pentesting (optional module) — More information
Separately priced module available with the Expert Pentest and Extensive Pentest. Testing covers areas such as prompt injection, data exposure, authorisation, tool use, agent permissions and model integrations. We confirm the price after discussing the scope.
Internal scanning sensor (when required)
Internal scanning sensor (when required) — More information
A physical or virtual scanning sensor lets us test systems inside your network or cloud environment. It is included when needed with the Expert Pentest and Extensive Pentest, and available on request with the Quick Pentest.
Web Security Scan logo
Web Security Scan logo — More information
Use the Web Security Scan logo to show that your web application has been tested. See the logo page for the conditions of use.

Not sure which plan is right for you?

We will discuss what you need tested and help you choose a suitable plan. The advice call is free, with no obligation.

What determines the price of your pentest?

The price of a pentest depends on four factors: the scope of the assessment, technical complexity, the risk profile, and your reporting needs and applicable standards. More user roles, integrations and environments generally require more investigation. Together, we determine the coverage needed and which plan is suitable.

Scope of the test

The number of applications, IP addresses, APIs and user roles defines the scope of the test. An application with two roles and no integrations generally requires less investigation than a platform with ten roles and multiple integrations. We also test whether users can perform actions beyond the permissions of their role.

Technical complexity

Integrations, login processes and functions such as ordering and payment require targeted manual testing. Automated scans help identify known vulnerabilities, but investigating business process abuse also requires an understanding of how your application works. We therefore test how components interact and which actions users can perform. More complex scenarios require more testing time.

Risk profile and coverage

We tailor coverage to the risk profile of your application or environment. Components handling sensitive data or with serious consequences if compromised receive extra attention. By identifying risks together in advance, we focus testing on the most important attack scenarios. The depth of testing required helps determine how much investigation time is needed.

Reporting and standards

We agree in advance which standards and reporting requirements apply to your application, network or other environment. For compliance engagements, we map findings to the applicable framework and make clear what was tested. Additional coverage or evidence requirements may require more testing and reporting time. That is why we discuss them before testing begins.

What is included?

The Quick Pentest, Expert Pentest and Extensive Pentest include:

  • Manual testing by certified ethical hackers at DongIT, a pentest company holding the CCV Keurmerk Pentesten and ISO 27001 certifications
  • Review of findings by a second pentester
  • Reporting through our Security Reporter platform, with online access and PDF and CSV exports
  • Notification of critical findings through the platform, followed up by phone

When is the price confirmed?

The Basic Scan and Quick Pentest have the fixed prices shown in the table. For the Expert Pentest, Extensive Pentest and tailored assessments, we first discuss what you need tested in a free scoping call. You then receive a quotation with the final price before testing begins.

The Quick, Expert and Extensive Pentest are performed and reported in accordance with the quality requirements of the CCV Keurmerk Pentesten certification scheme. The Basic Scan is not a pentest and is not covered by this certification: it combines an automated scan with a limited manual check. The stars in the comparison table indicate the different levels of manual testing.

Frequently asked questions about pentest costs

More about choosing a plan, additional costs and how we work.

What does a web application pentest cost?

The Quick Pentest costs €2,960 excluding VAT and is intended for a straightforward web application with a limited scope. For applications with multiple user roles, APIs or integrations, the Expert Pentest from €5,040 excluding VAT is usually a better fit. We confirm the final price after discussing the scope with you. Read about web application pentesting and pentesting mobile apps and APIs.

What does a network or cloud pentest cost?

The Expert Pentest from €5,040 excluding VAT is usually the starting point for a network or cloud pentest. For more complex infrastructure, such as multiple network segments or cloud environments, the Extensive Pentest from €7,200 excluding VAT is a better fit. We confirm the final price once we have agreed the scope with you. Read about our network and cloud pentests.

Can the Quick Pentest assess my external attack surface?

Yes. The Quick Pentest at €2,960 excluding VAT can be used for a focused assessment of your external attack surface. Within the agreed scope, we identify subdomains, publicly accessible IP addresses, services and identifiable software versions. Our pentesters then perform targeted manual testing for potential vulnerabilities and assess the risks. The assessment therefore goes beyond an inventory or automated scan.

We agree in advance which domains and IP ranges are in scope and which manual tests we will perform. This is one possible use of the Quick Pentest, not an additional assessment included by default alongside a web application pentest. If a broader scope or more in-depth testing is needed, we discuss a suitable plan and its price before testing begins.

Which plan fits a DigiD, NIS2 or ISO 27001 assessment?

For a compact DigiD environment, the Expert Pentest from €5,040 excluding VAT may be suitable. For more extensive environments, such as those with multiple applications or complex integrations, we offer the Extensive Pentest from €7,200 excluding VAT. With either plan, we align the DigiD pentest with the applicable Logius framework and the evidence your auditor needs. We agree which plan fits the scope, risk profile and reporting requirements in advance, then confirm the final price.

For NIS2 and ISO 27001 assessments, we offer the Extensive Pentest from €7,200 excluding VAT. The report includes a management summary and maps findings to relevant standards and controls. We discuss the systems to be tested and the reporting requirements in advance.

Can I request a plan directly without a quotation?

You can request the Basic Scan and Quick Pentest directly at the fixed plan price. We then confirm what we will test and when. For the Expert Pentest, Extensive Pentest and tailored assessments, we first discuss your requirements and scope in a free call. You receive a quotation within three business days of that conversation.

What if a pentest does not fit my budget?

Then we reverse the approach. Normally, we first determine the scope based on what needs to be tested, and the price follows from that. If your budget is fixed, we time-box the assessment: we agree on the available testing time and focus it on the highest-risk areas. We document what falls outside that coverage in the report, so you know what has not yet been tested.

Why is the Basic Scan cheaper than a pentest?

The Basic Scan costs €1,480 excluding VAT and is a vulnerability scan with a limited manual check. This requires less manual investigation than a pentest. The Quick Pentest costs €2,960 excluding VAT and includes manual testing of a straightforward web application, including user permissions and business logic. A Basic Scan is therefore a different type of assessment, not a lower-priced pentest plan.

Does a white box pentest cost extra?

No. We do not charge extra for a white box pentest. With this approach, our pentesters receive relevant information in advance, such as credentials, source code and documentation. This helps them use their time more effectively, investigate more and reduce blind spots. That is why we generally recommend a white box pentest.

The price depends on the scope, complexity and required coverage of the assessment, not on providing this information. A full source code review is a separate service. Read about black box, grey box and white box testing.

What does a retest cost?

A retest is not included in the plan price. It checks whether previously identified vulnerabilities have been fixed. The price depends on the number of findings that need to be tested again. We discuss the cost when delivering the pentest report.

Is red teaming part of a plan?

No. Red teaming is a separate, tailored assessment with its own quotation. We simulate a realistic attack on your organisation and agree the objectives and scope with you in advance.

What does an AI or LLM application pentest cost?

Testing AI and LLM applications is a separately priced module available with the Expert Pentest and Extensive Pentest. The cost depends on the number of models and interfaces, connected data sources and tools, user roles and AI agent permissions. The abuse scenarios to be investigated also affect the price. Discuss your AI application with us; we provide a quotation after a free scoping call.

Do you use AI in pentesting, and what does that mean for the cost?

Yes. We use AI selectively to improve the quality of our testing, not to replace experienced pentesters. This requires expert direction: the right instructions, technical context and a critical assessment of the results. Our pentesters check every finding and determine the final risk assessment. Manual testing and review by a second pentester remain part of our approach.

AI therefore does not automatically make a pentest cheaper. The price depends on the scope, complexity and required depth of testing.

Need a tailored pentest?

Need to test multiple environments or meet specific testing and reporting requirements? We will discuss what you need and prepare a tailored quotation. You receive a response within one business day and a quotation within three business days of the scoping call.