What does a penetration test cost?
It depends on scope — number of roles, endpoints, environments and the depth of verification. The estimator on this site gives a range in about a minute, and a lead assessor reviews every estimate before a written proposal goes out.
How long does it take?
Most web application tests are one to three weeks of testing, with a draft report within five business days of the last test day. Audits run three to six weeks; readiness programmes two to four months.
What does the process look like?
Scope, test, fix, verify. We agree scope and rules of engagement in writing, test with daily check-ins and immediate escalation of anything critical, deliver the report with a walkthrough, then retest your fixes.
Do you need access to our source code?
Not for a standard test. For grey-box testing we need accounts for each role and any API documentation. Source access lets us go deeper and is required for a secure code review.
Do you test in production?
Only if you want us to, within agreed windows and rate limits. A production-like staging environment is preferred. Destructive and denial-of-service testing never happens without explicit written approval.
Can we share the report with customers?
Share the summary letter. It confirms scope, dates, methodology and the status of findings at retest, without handing an attacker a map. The full report stays with your team and auditors.
Can you issue our SOC 2 report or ISO 27001 certificate?
No. SOC 2 reports are issued by licensed CPA firms and ISO 27001 certificates by accredited certification bodies. We get you ready for both, and work alongside your chosen auditor.
Which framework should we start with?
The one your customers or regulators ask for. If nobody has asked yet, the CIS Controls v8.1 Implementation Group 1 is the best practical starting line, and NIST CSF 2.0 is the best way to explain your position to leadership.
Do you use automated scanners?
Yes, as a starting point for coverage. They never replace manual testing, and a scanner export is never the deliverable. Most of the serious findings in our reports are things no scanner flags.
Are you independent of the tools you recommend?
Yes. We do not resell security products or take referral fees, so a recommendation to buy something is never how we get paid.
How do we start?
Run the estimator for a range, or send a note and we will set up a scoping call. Either reaches a tester, not a sales team.