Applications
Web / API Pentest
Simple public app, authenticated app, REST/GraphQL APIs, complex business logic.
from €1,490
One-off · VAT not included
View web packs →Automated scanning is not a pentest. We deliver penetration testing with manual validation, controlled exploitation, and actionable reporting including a remediation plan and re-test.
Reference practices: OWASP Web Security Testing Guide (WSTG) and PTES to structure scoping, execution, reporting and closure.
Definition
A penetration test is an authorised, simulated attack against your systems to find out how far someone would actually get. The difference between a pentest and a vulnerability scan is the difference between a list of doors that might be unlocked and somebody pushing each one to see which ones give, what is behind them, and in what order to fix them.
That distinction matters because a scanner cannot chain. It will flag three findings as «medium» without noticing that, combined, they lead from a public sign-up form to the customer database. A tester chains, and that full path is what turns a report into a decision: what gets fixed on Monday and what can wait for the quarter.
Most of the work we are asked for in English is web application and API testing, which is also where the chaining tends to happen: an authorisation flaw in one endpoint plus a predictable identifier in another is rarely critical on paper and frequently critical in practice.
This page covers the service. If what you want is the discipline itself — the phases, the standards and how a test is actually run — we go into it properly in what penetration testing is, its types and methodology.
Terminology
These get used interchangeably and they are not the same exercise. A pentest has a defined scope and looks for as many exploitable findings as it can inside it. Ethical hacking is the umbrella term for testing systems with permission, and covers the pentest along with other engagements. A red team exercise is narrower in objective and broader in method: it picks a goal, stays quiet, and measures whether your defenders notice.
Choosing the wrong one is expensive. A red team against an organisation with no detection capability tells you what you already know. If you are unsure, start with the pentest.
We cover the umbrella in ethical hacking, adversary simulation in red team, and the comparison in pentest vs red team vs BAS.
Scope & deliverables
This is the question we get asked most often in English, and it is a good one, because two quotes for «a web application pentest» can differ by a factor of four and both be honest. What separates them is what is written down before the work starts.
Ask this before you sign, because it is where quotes quietly diverge. A pentest without a retest leaves the job half done: you have a list of problems and no record that any of them were solved. It is also the first thing an auditor looks for when deciding whether the exercise was real or decorative — an ISO 27001 auditor accepts a closed finding, not a reported one.
At Hard2bit the retest is included. We verify the fixes, and the closure record is part of the deliverable rather than something you chase afterwards.
Frequency
Our recommendation, and it is a recommendation rather than a legal obligation, is annually as a floor, plus whenever something material changes. Two different clocks are running here, and confusing them is what leads organisations to buy an annual test that does not protect them, or skip one they needed.
This one is not set by the calendar but by your own rate of change. A pentest photographs a system as it was on the day. The next morning you deploy, change a firewall rule or onboard a supplier, and the photograph starts to age.
So the useful question is not «how many months has it been?» but «how much has my attack surface changed since the last one?». A team shipping weekly ages its report far faster than one running a stable estate, even though the calendar says the same thing to both.
Five triggers matter more than the date: a new application or API exposed to the internet, a cloud migration or architectural change, an acquisition that hands you a network you do not know, an incident — yours or a peer's — and a supplier gaining privileged access. Any one of them justifies a test even if the last report is three months old.
Between pentests, what holds the line is not waiting for the next one: it is continuous vulnerability management. The pentest validates and prioritises; continuous scanning watches. Substituting one for the other is the most common mistake we see.
Here it pays to be precise, because a lot of comfortable claims circulate. Read against the actual text of each framework, the picture is more nuanced than the marketing:
That is not leniency, it is where the burden sits. An ISO 27001 auditor will not ask for «the annual pentest». They will ask how you arrived at that frequency and what evidence supports the decision. Without that reasoning written down, a test every twelve months is worth about as much as none.
| Framework | Sets a pentest cadence? | What it actually says |
|---|---|---|
| PCI DSS v4.0.1 | Yes, and it is the strictest. For everyone in scope. | Internal and external penetration testing at least every 12 months and after significant changes (11.4.2 and 11.4.3). Where segmentation isolates the cardholder data environment, it must be verified every 12 months — and every 6 for service providers (11.4.5 and 11.4.6). Plus internal and external vulnerability scans every 3 months (11.3.1 and 11.3.2). |
| DORA | Yes, but only for TLPT and only for designated entities. | Article 24(6) requires appropriate tests at least once a year on all ICT systems supporting critical or important functions. Note the wording: «appropriate tests». Penetration testing is one of the techniques listed in Article 25 — alongside vulnerability assessments, source code review and scenario-based testing — not an annual obligation in itself. Threat-led penetration testing (TLPT) does run at least every 3 years, with the competent authority able to adjust the frequency. Microenterprises and entities under the simplified framework are excluded. |
| NIS2 | No. You set it and you defend it. | Article 21 of the directive requires policies and procedures to assess the effectiveness of the measures, without naming penetration testing or setting a frequency. Implementing Regulation (EU) 2024/2690 — which sets the technical requirements for DNS, cloud, data centre, CDN, managed service and managed security service providers — devotes a section to security testing (6.5) to say, explicitly, that each entity determines «the need, scope, frequency and type of security testing» from its own risk assessment. |
| ISO 27001:2022 | No. Your customers ask before your auditor does. | It requires internal audits at planned intervals (clause 9.2) and technical vulnerability management, but does not mandate penetration testing or fix a cadence. In practice it appears in customer due-diligence questionnaires long before it appears in an audit finding. |
| ENS Spain, RD 311/2022 | No. It sets the audit cadence, which is a different thing. | Relevant if you sell to the Spanish public sector or supply someone who does. It requires a regular security audit at least every two years (art. 31); BASIC category is met by self-assessment, MEDIUM and HIGH require a certification audit (art. 38). The text sets no frequency for penetration testing. |
Indicative only, not legal advice. Checked against the text of PCI DSS v4.0.1, Regulation (EU) 2022/2554, Directive (EU) 2022/2555 with its Implementing Regulation (EU) 2024/2690, ISO/IEC 27001:2022, and Spanish Royal Decree 311/2022 as published in the BOE. Actual applicability depends on your role, size and national transposition.
Real coverage across web, APIs, infrastructure, Active Directory and cloud—focused on impact and closure.
OWASP Top 10, access control, auth, sessions, SSRF, insecure deserialization, etc.
Authorization (BOLA/IDOR), rate-limits, JWT/OAuth, enumeration and abuse-cases.
Perimeter exposure, services, configuration and compromise paths.
Lateral movement, segmentation, credentials and privilege escalation.
Misconfigurations, delegation, Kerberos, paths to DA, controls and hardening.
IAM, storage, secret sprawl, networking, workloads, containers and serverless.
Web & APIs
OWASP-driven testing, business logic, authentication (SSO/JWT/OAuth), authorization, SSRF, IDOR/BOLA, etc. We prioritize real impact and exploitability.
Infrastructure & AD
External/internal exposure, privilege escalation, AD misconfigurations, compromise paths, segmentation checks and actionable evidence for hardening.
Cloud
IAM review, exposed storage, credentials/secrets, escalation paths, containers and serverless. Focus on business risk.
Fix Verification
Executive + technical reporting, prioritized backlog, practical recommendations, and re-validation to confirm closures.
Full cycle: scoping, execution, evidence, remediation plan and re-test.
OWASP WSTG and PTES help keep testing and reporting consistent across engagements.
Define objectives, assets, exclusions, windows and safety thresholds. Agree reporting cadence and escalation channels for critical findings.
Map the real attack surface (external/internal), authentication flows, roles, integrations and dependencies to identify compromise paths.
Validate findings with expert judgment to minimize false positives. Chain vulnerabilities when relevant to demonstrate real impact with evidence.
Executive and technical reporting: severity, impact, PoC, evidence, quick wins and a remediation plan by team/owner.
Re-validate prioritized findings to confirm fixes and update evidence—ideal for audits and compliance programs.
The value of pentesting is not “the report”—it’s faster decisions and remediation. We deliver clear evidence, an actionable backlog, and re-testing to verify fixes.
Reproducible details, impact, traces, endpoints, parameters, screenshots and concrete recommendations.
Domain-level summary, top risks, exposure, quick wins and remediation roadmap.
List by criticality/exposure, suggested owner, dependencies and verification steps (re-test).
Workshop with your engineers and stakeholders to align on fixes and prevent regressions.
Common real-world paths: broken access control, injection, crypto misuse, SSRF, insecure design— validated manually to reduce noise and false positives.
We combine automation with expert manual validation and remediation-oriented reporting to help teams close findings.
Plans & pricing
Unlike automated scans or web-only pentests, we assess real exposure from the Internet and from a controlled internal position, identifying attack paths, weak configurations, exploitable vulnerabilities and remediation priorities. All packs include retest and explanation workshop.
Professional manual + automated pentesting, not a SaaS platform scan. Every engagement is executed by a senior engineer using OWASP, OSSTMM and CVSS methodologies. Key difference vs automated SaaS platforms (from €149/scan): human analyst, context, real exploitability validation and an audit-grade report — not a script-generated PDF.
Applications
Simple public app, authenticated app, REST/GraphQL APIs, complex business logic.
from €1,490
One-off · VAT not included
View web packs →Perimeter
Internet-exposed surface: public IPs, services, VPN, firewalls, panels, insecure configurations.
from €2,500
Up to 25 IPs / 50 services
See details →Internal network
Realistic scenario: attacker with internal access (standard user or VPN). Active Directory, lateral movement.
from €2,900
Essential to Advanced (AD)
View internal packs →Combined
Most requested pack: external perimeter + coordinated internal scenario, single report, joint workshop.
from €4,900
One-off · VAT not included
Request proposal →Provider's operating framework
We execute pentesting inside our own ISMS audited at ENS HIGH category and ISO/IEC 27001:2022, plus four additional ISOs (22301, 20000-1, 9001, 14001). Documented rules of engagement, evidence custody and traceability usable by clients subject to NIS2, DORA or ENS in their own audit. The ENS HIGH certification belongs to Hard2bit as a provider; it does not replace the client's own certification.
Plan details
Prices excluding VAT. Retest and explanation workshop included in all packs. Multi-site, operational-impact scenarios or complex cloud (multi-account AWS/Azure/GCP) sized in proposal.
| Pack | Scope | Mode | Includes | Price |
|---|---|---|---|---|
| Pentest Web Essential | 1 simple app / bounded URL | Black / grey box | Manual + automated testing, technical report, executive summary, retest and explanation workshop included. | from €1,490 |
| Pentest Web/API Advanced | Authenticated app · API · complex logic | Grey / white box | Deep manual validation, roles, business logic, REST/GraphQL APIs. Retest and workshop included. | from €3,900 |
| External Perimeter Pentest | Up to 25 public IPs / 50 services | Black box | Internet-exposed surface: public IPs, VPN, firewalls, portals, vulnerable versions. Retest and workshop included. | from €2,500 |
| Internal Pentest Essential | Up to 50 assets / 1-2 VLANs | Grey box (standard user / VPN) | Discovery, internal services, segmentation, shared resources, credential exposure and basic escalation paths. Retest and workshop included. | from €2,900 |
| Internal Pentest Advanced | AD, multiple VLANs, deeper testing | Grey box (realistic scenario) | Active Directory, lateral movement, privilege escalation in depth. Up to 100-150 assets / 3-5 VLANs. Retest and workshop included. | from €5,900 |
| External + Internal Pentest Top | Bounded combined scope | Coordinated external + internal | External perimeter + realistic internal scenario, single report, joint workshop. Most popular pack. Retest and workshop included. | from €4,900 |
| Audit-Ready Pentest (ENS/ISO) | For ENS / ISO 27001 certification | Adapted to regulatory scope | Technical + executive report + remediation plan + auditable evidence aligned with ENS / ISO 27001. Retest and workshop included. | from €5,500 |
| Red Team / Adversary Simulation | Realistic adversary emulation | Custom | Advanced threat actor simulation with contractual objectives (impact-based), MITRE ATT&CK TTPs. No fixed public price. | Custom |
All prices are shown excluding VAT. The applicable VAT will be added on the invoice according to current regulations. Indicative "from" amounts; final terms — scope, sizing, timelines, rules of engagement and contractual conditions — will be set out in the signed commercial proposal.
Product vs service
If you need a passive external snapshot of your domain, our SaaS scanner gives it in 60 seconds. If you need to validate whether weaknesses are exploitable and get audit-grade evidence, the professional pentest is the right fit. They're not substitutes: the Scanner is usually the previous step.
| Feature | Hard2bit Scanner | Professional Pentest |
|---|---|---|
| Model | Self-service SaaS | Professional service executed by senior engineer |
| Analysis | Passive, public domain | Active, manual + automated, with controlled exploitation |
| Exploitability validation | No (signals) | Yes (real proof with evidence) |
| Methodologies | Own checks | OWASP, OSSTMM, OWISAM, OpenSAMM, CVSS |
| Active Directory | Not applicable | Yes, in Internal Advanced packs |
| Executive + technical report | PDF report | Technical + executive report + workshop |
| Post-remediation retest | No | Included in all packs |
| Audit evidence (ENS/ISO) | PDF report | Full evidence + remediation plan |
| Indicative price | Free · from €19/mo | from €1,490 |
Scope and exclusions
The following exclusions can be contracted separately or combined with other Hard2bit services (red team, vulnerability management, digital forensics). Making them explicit avoids misunderstandings and sizes the engagement correctly.
Pentesting is the parent practice; each technical discipline has its own methodology, auditor profile and deliverable. If your scope is very specific, start from the dedicated page to understand expectations, timelines and price.
Web application audit
OWASP WSTG + ASVS L2/L3. Identity, logic, data, integrations. Suitable for PCI DSS and ENS High.
View →
API security audit
OWASP API Top 10 2023: BOLA, BOPLA, BFLA, rate-limit. REST, GraphQL, gRPC.
View →
Source code security audit
SAST + SCA + secrets + manual review. Logic, cryptography, IaC, supply chain.
View →
Non-human identities (NHI)
Tokens, secrets, service accounts, OAuth apps. Full governance programme.
View →
Systems hardening
CIS Benchmarks · DISA STIG · Microsoft Baselines. As code + drift monitoring.
View →
DevSecOps
Security built into CI/CD. Shift-left, policy as code, artefact signing.
Deploy DevSecOps →
AI agents & MCP audit
Adversarial red teaming on LLMs and MCP servers: prompt injection, tool poisoning, jailbreaks. OWASP LLM + EU AI Act.
Audit AI agent →
It depends on scope. A web/API pentest typically takes 5–15 days; infrastructure/AD can take 2–4 weeks. We adjust by criticality, number of assets and complexity.
Yes. We include evidence and traceability, plus an executive summary that supports audits and frameworks like NIS2/DORA/ENS/ISO 27001.
Less noise, more impact: manual validation, business logic analysis, vulnerability chaining when relevant, and an actionable backlog with re-test.
Yes. We can work jointly to validate detections (use cases, alerts) and improve rules and response workflows.
Yes. We regularly work with organizations in Madrid and across Spain. When it makes sense, we coordinate on-site sessions for kick-off, findings review or final handover with the client's team. See the dedicated pentesting in Madrid page for the local angle.
Yes. We deliver pentesting to companies operating in Barcelona and across Catalonia, with the same methodology and deliverables we apply to regulated clients nationwide. See the dedicated pentesting in Barcelona page for the local angle and Catalan-language blocks.
Concepts from our cybersecurity glossary that connect directly with this service.
We scope properly, test with evidence, and deliver an actionable backlog with re-testing to verify closure.
Talk to a specialistBefore you leave…
Quick 15-minute assessment and we'll tell you what to prioritise first: Microsoft 365, pentesting, vulnerability management, SOC, DORA, NIS2, ENS or ISO 27001.
No spam. Reply within 24h.