Plans and pricing

Transparent pricing for pentesting by OSCP-certified ethical hackers
Basic Scan €1480.00excl. VATRequest Basic Scan
Quick Pentest €2960.00excl. VATRequest quote
Extensive Pentest from€7200.00excl. VATRequest quote
Test Best Suited For ?
Examples of situations best-fitted to specific test approach.
  • Semi-automated vulnerability scans against OWASP Top 10
  • Concise insight into common vulnerabilities
  • Ideal during the early phase of a development project
  • Quick security check for SMB organizations
  • Compact pentest with fixed pricing
  • Technical insight into your current security posture
  • Periodic security checks for web applications
  • Simple informational applications with limited scope
  • Comprehensive pentest for complex applications, APIs and network infrastructure
  • Complete insight into your current security posture
  • Compliance audits and TPM engagements
  • Compatible with MIAUW, NIS2, ISO 27001, NEN 7510, DigiD, PCI DSS, MedMij and GDPR
  • DigiD assessments per Logius framework v4.0
Type of Report ?
Research findings and output from security tools are reported and presented in professional reports, created with our own Security Reporter platform (https://securityreporter.app).

Concise technical report based on OWASP Top 10

Technical pentest report based on OWASP Top 10

Comprehensive report with management summary and compliance mapping (OWASP Top 10, NCSC, MIAUW, PCI DSS, MedMij and Azure Security Benchmark)

Delivery time ?
Indicative delivery time from intake to final report. Exact scheduling is aligned during the scoping conversation.

1 week

1-2 weeks

2-4 weeks

Manual Testing by Certified Pentesters ?
Degree of manual testing and research methods used by our certified ethical hackers (OSCP, OSWE, OSWP, eCPPT, CISSP, CISA).
Automated vulnerability scan and port scan ?
Automatic scan with industry-standard tools (Nessus, Nmap) as the first testing phase. Detects all open services, unpatched versions and known CVEs before manual testing begins.
Detection of current vulnerabilities ?
All testing methods are aligned with the latest OWASP Top 10 (2021), current CVE database and threat intelligence from NCSC-NL and MITRE ATT&CK. Our pentesters track new exploit techniques and attack vectors weekly.
Four-eyes principle with peer review ?
Every finding is reviewed by a second senior ethical hacker. This peer review filters false positives, verifies exploitability and ensures the report is directly usable for your auditor or development team.
Direct contact with your pentester ?
Direct contact with your pentester through the Security Reporter platform: ask technical questions, discuss findings during the test and monitor progress in real time. No waiting on account managers or tickets, you speak directly with the expert testing your systems.
Reporting via Security Reporter ?
Our reports are delivered through the DongIT-developed Security Reporter platform. Interactive findings, export options, integration with your development tools and support for team collaboration.
Evaluation of Final Report with Pentester ?
A short discussion of the research results with a pentester (<30 minutes is included).
Internal scanning sensor (when required) ?
For internal pentests, we configure a scanning sensor (physical or virtual appliance) on your network to test systems behind firewalls, in isolated subnets or in cloud environments. Standard included with Expert and Extensive pentests, available on request for Quick Pentest.
Trustmark Logo ?
Boost your customer confidence. Receive the Web Security Scan quality label that shows the security level of your web application.

Not sure which package fits your situation?

Our security experts are happy to review with you which package best matches your goal and technology. Complimentary, no obligation and no sales pressure.

Ready to schedule a pentest?

For enterprise engagements, DORA obligations, multi-scope assessments or complex compliance requirements, we prepare a tailored quotation. Response within 1 business day, quotation within 3 business days.