Offensive Security · Pentesting · Web · API · Infrastructure · AD · Cloud ENS HIGH · ISO 27001

Pentesting: think like an attacker.
Close real gaps.

Automated scanning is not a pentest. We deliver penetration testing with manual validation, controlled exploitation, and actionable reporting including a remediation plan and re-test.

Reference practices: OWASP Web Security Testing Guide (WSTG) and PTES to structure scoping, execution, reporting and closure.

Definition

What is a penetration test?

A penetration test is an authorised, simulated attack against your systems to find out how far someone would actually get. The difference between a pentest and a vulnerability scan is the difference between a list of doors that might be unlocked and somebody pushing each one to see which ones give, what is behind them, and in what order to fix them.

That distinction matters because a scanner cannot chain. It will flag three findings as «medium» without noticing that, combined, they lead from a public sign-up form to the customer database. A tester chains, and that full path is what turns a report into a decision: what gets fixed on Monday and what can wait for the quarter.

Most of the work we are asked for in English is web application and API testing, which is also where the chaining tends to happen: an authorisation flaw in one endpoint plus a predictable identifier in another is rarely critical on paper and frequently critical in practice.

This page covers the service. If what you want is the discipline itself — the phases, the standards and how a test is actually run — we go into it properly in what penetration testing is, its types and methodology.

Terminology

Pentest, ethical hacking, red team

These get used interchangeably and they are not the same exercise. A pentest has a defined scope and looks for as many exploitable findings as it can inside it. Ethical hacking is the umbrella term for testing systems with permission, and covers the pentest along with other engagements. A red team exercise is narrower in objective and broader in method: it picks a goal, stays quiet, and measures whether your defenders notice.

Choosing the wrong one is expensive. A red team against an organisation with no detection capability tells you what you already know. If you are unsure, start with the pentest.

We cover the umbrella in ethical hacking, adversary simulation in red team, and the comparison in pentest vs red team vs BAS.

Scope & deliverables

What should a good pentest quote include?

This is the question we get asked most often in English, and it is a good one, because two quotes for «a web application pentest» can differ by a factor of four and both be honest. What separates them is what is written down before the work starts.

What has to be in the scope

  • Countable units, not adjectives. How many applications, how many API endpoints, how many user roles, how many IP addresses. «The web platform» is not a scope.
  • Knowledge level. Black, grey or white box, and whether credentials are provided. Testing an authenticated area without accounts wastes days proving you cannot log in.
  • Environment. Production or a staging copy, and how faithful that copy is. A staging environment with sanitised data hides whole classes of finding.
  • Explicit exclusions. Denial of service, social engineering, third-party systems you do not own. Written down, not assumed.
  • Assumptions. The ones that, if wrong, change the price. Stated up front rather than discovered in week two.

What you should receive

  • Proof of exploit, not just a CVSS score. A finding without evidence is an opinion. Screenshots, requests, the exact steps to reproduce it.
  • Remediation your engineers can act on. Not «implement input validation», but which parameter, which endpoint, and what a correct fix looks like in your stack.
  • Prioritisation by real impact, with the chains made explicit — the three «mediums» that together are a critical.
  • An executive summary that survives a board meeting and a technical report that survives an auditor. They are different documents and both should be in the price.
  • Retest. See below — this is the one people forget to ask about.

Is the retest included?

Ask this before you sign, because it is where quotes quietly diverge. A pentest without a retest leaves the job half done: you have a list of problems and no record that any of them were solved. It is also the first thing an auditor looks for when deciding whether the exercise was real or decorative — an ISO 27001 auditor accepts a closed finding, not a reported one.

At Hard2bit the retest is included. We verify the fixes, and the closure record is part of the deliverable rather than something you chase afterwards.

Frequency

How often should you run a penetration test?

Our recommendation, and it is a recommendation rather than a legal obligation, is annually as a floor, plus whenever something material changes. Two different clocks are running here, and confusing them is what leads organisations to buy an annual test that does not protect them, or skip one they needed.

The security clock

This one is not set by the calendar but by your own rate of change. A pentest photographs a system as it was on the day. The next morning you deploy, change a firewall rule or onboard a supplier, and the photograph starts to age.

So the useful question is not «how many months has it been?» but «how much has my attack surface changed since the last one?». A team shipping weekly ages its report far faster than one running a stable estate, even though the calendar says the same thing to both.

Five triggers matter more than the date: a new application or API exposed to the internet, a cloud migration or architectural change, an acquisition that hands you a network you do not know, an incident — yours or a peer's — and a supplier gaining privileged access. Any one of them justifies a test even if the last report is three months old.

Between pentests, what holds the line is not waiting for the next one: it is continuous vulnerability management. The pentest validates and prioritises; continuous scanning watches. Substituting one for the other is the most common mistake we see.

The compliance clock

Here it pays to be precise, because a lot of comfortable claims circulate. Read against the actual text of each framework, the picture is more nuanced than the marketing:

  • Only PCI DSS imposes a general pentest cadence on everyone in its scope.
  • DORA imposes one, but a narrow one: it applies to threat-led testing and only to designated entities. Its annual obligation is for «appropriate tests», not for a pentest specifically.
  • NIS2, ISO 27001 and Spain's ENS set none. They ask you to assess the effectiveness of your measures and leave you to justify how and how often.

That is not leniency, it is where the burden sits. An ISO 27001 auditor will not ask for «the annual pentest». They will ask how you arrived at that frequency and what evidence supports the decision. Without that reasoning written down, a test every twelve months is worth about as much as none.

Framework Sets a pentest cadence? What it actually says
PCI DSS v4.0.1 Yes, and it is the strictest. For everyone in scope. Internal and external penetration testing at least every 12 months and after significant changes (11.4.2 and 11.4.3). Where segmentation isolates the cardholder data environment, it must be verified every 12 months — and every 6 for service providers (11.4.5 and 11.4.6). Plus internal and external vulnerability scans every 3 months (11.3.1 and 11.3.2).
DORA Yes, but only for TLPT and only for designated entities. Article 24(6) requires appropriate tests at least once a year on all ICT systems supporting critical or important functions. Note the wording: «appropriate tests». Penetration testing is one of the techniques listed in Article 25 — alongside vulnerability assessments, source code review and scenario-based testing — not an annual obligation in itself. Threat-led penetration testing (TLPT) does run at least every 3 years, with the competent authority able to adjust the frequency. Microenterprises and entities under the simplified framework are excluded.
NIS2 No. You set it and you defend it. Article 21 of the directive requires policies and procedures to assess the effectiveness of the measures, without naming penetration testing or setting a frequency. Implementing Regulation (EU) 2024/2690 — which sets the technical requirements for DNS, cloud, data centre, CDN, managed service and managed security service providers — devotes a section to security testing (6.5) to say, explicitly, that each entity determines «the need, scope, frequency and type of security testing» from its own risk assessment.
ISO 27001:2022 No. Your customers ask before your auditor does. It requires internal audits at planned intervals (clause 9.2) and technical vulnerability management, but does not mandate penetration testing or fix a cadence. In practice it appears in customer due-diligence questionnaires long before it appears in an audit finding.
ENS
Spain, RD 311/2022
No. It sets the audit cadence, which is a different thing. Relevant if you sell to the Spanish public sector or supply someone who does. It requires a regular security audit at least every two years (art. 31); BASIC category is met by self-assessment, MEDIUM and HIGH require a certification audit (art. 38). The text sets no frequency for penetration testing.

Indicative only, not legal advice. Checked against the text of PCI DSS v4.0.1, Regulation (EU) 2022/2554, Directive (EU) 2022/2555 with its Implementing Regulation (EU) 2024/2690, ISO/IEC 27001:2022, and Spanish Royal Decree 311/2022 as published in the BOE. Actual applicability depends on your role, size and national transposition.

The most requested penetration tests

Real coverage across web, APIs, infrastructure, Active Directory and cloud—focused on impact and closure.

Web App Pentest

OWASP Top 10, access control, auth, sessions, SSRF, insecure deserialization, etc.

API Security Testing

Authorization (BOLA/IDOR), rate-limits, JWT/OAuth, enumeration and abuse-cases.

External Infrastructure

Perimeter exposure, services, configuration and compromise paths.

Internal Infrastructure

Lateral movement, segmentation, credentials and privilege escalation.

Active Directory

Misconfigurations, delegation, Kerberos, paths to DA, controls and hardening.

Cloud

IAM, storage, secret sprawl, networking, workloads, containers and serverless.

Web & APIs

Web Application & API Penetration Testing

OWASP-driven testing, business logic, authentication (SSO/JWT/OAuth), authorization, SSRF, IDOR/BOLA, etc. We prioritize real impact and exploitability.

OWASP WSTG API Security Business Logic

Infrastructure & AD

Network / Infrastructure & Active Directory Assessments

External/internal exposure, privilege escalation, AD misconfigurations, compromise paths, segmentation checks and actionable evidence for hardening.

External/Internal Privilege Esc. AD Assessment

Cloud

Cloud Pentesting & Security Posture Review (AWS/Azure/GCP)

IAM review, exposed storage, credentials/secrets, escalation paths, containers and serverless. Focus on business risk.

IAM Misconfig Containers

Fix Verification

Remediation Plan + Re-test

Executive + technical reporting, prioritized backlog, practical recommendations, and re-validation to confirm closures.

Backlog Evidence Re-test

Methodology

Full cycle: scoping, execution, evidence, remediation plan and re-test.

OWASP WSTG and PTES help keep testing and reporting consistent across engagements.

Scope & Rules of Engagement (RoE)

Define objectives, assets, exclusions, windows and safety thresholds. Agree reporting cadence and escalation channels for critical findings.

Reconnaissance & threat modeling

Map the real attack surface (external/internal), authentication flows, roles, integrations and dependencies to identify compromise paths.

Execution: manual validation & controlled exploitation

Validate findings with expert judgment to minimize false positives. Chain vulnerabilities when relevant to demonstrate real impact with evidence.

Actionable report + readout session

Executive and technical reporting: severity, impact, PoC, evidence, quick wins and a remediation plan by team/owner.

Re-test & closure evidence

Re-validate prioritized findings to confirm fixes and update evidence—ideal for audits and compliance programs.

Deliverables that drive closure

The value of pentesting is not “the report”—it’s faster decisions and remediation. We deliver clear evidence, an actionable backlog, and re-testing to verify fixes.

Technical report (PoC + evidence)

Reproducible details, impact, traces, endpoints, parameters, screenshots and concrete recommendations.

Executive report (risk & decisions)

Domain-level summary, top risks, exposure, quick wins and remediation roadmap.

Prioritized backlog (actionable)

List by criticality/exposure, suggested owner, dependencies and verification steps (re-test).

Readout session

Workshop with your engineers and stakeholders to align on fixes and prevent regressions.

What we look for “as an attacker”

Common real-world paths: broken access control, injection, crypto misuse, SSRF, insecure design— validated manually to reduce noise and false positives.

Broken Access Control / IDOR CRITICAL
Injection (SQL/NoSQL/OS) CRITICAL
SSRF / Internal pivot HIGH
Auth/JWT/OAuth misuse HIGH
Misconfig + secrets exposure MEDIUM

We combine automation with expert manual validation and remediation-oriented reporting to help teams close findings.

Plans & pricing

Pentesting with transparent "from" pricing

Unlike automated scans or web-only pentests, we assess real exposure from the Internet and from a controlled internal position, identifying attack paths, weak configurations, exploitable vulnerabilities and remediation priorities. All packs include retest and explanation workshop.

Professional manual + automated pentesting, not a SaaS platform scan. Every engagement is executed by a senior engineer using OWASP, OSSTMM and CVSS methodologies. Key difference vs automated SaaS platforms (from €149/scan): human analyst, context, real exploitability validation and an audit-grade report — not a script-generated PDF.

Applications

Web / API Pentest

Simple public app, authenticated app, REST/GraphQL APIs, complex business logic.

from €1,490

One-off · VAT not included

View web packs →

Perimeter

External Pentest

Internet-exposed surface: public IPs, services, VPN, firewalls, panels, insecure configurations.

from €2,500

Up to 25 IPs / 50 services

See details →

Internal network

Internal Pentest

Realistic scenario: attacker with internal access (standard user or VPN). Active Directory, lateral movement.

from €2,900

Essential to Advanced (AD)

View internal packs →
Best seller

Combined

External + Internal

Most requested pack: external perimeter + coordinated internal scenario, single report, joint workshop.

from €4,900

One-off · VAT not included

Request proposal →

Provider's operating framework

We execute pentesting inside our own ISMS audited at ENS HIGH category and ISO/IEC 27001:2022, plus four additional ISOs (22301, 20000-1, 9001, 14001). Documented rules of engagement, evidence custody and traceability usable by clients subject to NIS2, DORA or ENS in their own audit. The ENS HIGH certification belongs to Hard2bit as a provider; it does not replace the client's own certification.

Plan details

8 modalities, indicative "from" pricing

Prices excluding VAT. Retest and explanation workshop included in all packs. Multi-site, operational-impact scenarios or complex cloud (multi-account AWS/Azure/GCP) sized in proposal.

Professional pentesting packs
Pack Scope Mode Includes Price
Pentest Web Essential 1 simple app / bounded URL Black / grey box Manual + automated testing, technical report, executive summary, retest and explanation workshop included. from €1,490
Pentest Web/API Advanced Authenticated app · API · complex logic Grey / white box Deep manual validation, roles, business logic, REST/GraphQL APIs. Retest and workshop included. from €3,900
External Perimeter Pentest Up to 25 public IPs / 50 services Black box Internet-exposed surface: public IPs, VPN, firewalls, portals, vulnerable versions. Retest and workshop included. from €2,500
Internal Pentest Essential Up to 50 assets / 1-2 VLANs Grey box (standard user / VPN) Discovery, internal services, segmentation, shared resources, credential exposure and basic escalation paths. Retest and workshop included. from €2,900
Internal Pentest Advanced AD, multiple VLANs, deeper testing Grey box (realistic scenario) Active Directory, lateral movement, privilege escalation in depth. Up to 100-150 assets / 3-5 VLANs. Retest and workshop included. from €5,900
External + Internal Pentest Top Bounded combined scope Coordinated external + internal External perimeter + realistic internal scenario, single report, joint workshop. Most popular pack. Retest and workshop included. from €4,900
Audit-Ready Pentest (ENS/ISO) For ENS / ISO 27001 certification Adapted to regulatory scope Technical + executive report + remediation plan + auditable evidence aligned with ENS / ISO 27001. Retest and workshop included. from €5,500
Red Team / Adversary Simulation Realistic adversary emulation Custom Advanced threat actor simulation with contractual objectives (impact-based), MITRE ATT&CK TTPs. No fixed public price. Custom

All prices are shown excluding VAT. The applicable VAT will be added on the invoice according to current regulations. Indicative "from" amounts; final terms — scope, sizing, timelines, rules of engagement and contractual conditions — will be set out in the signed commercial proposal.

Product vs service

Hard2bit Scanner vs Hard2bit Professional Pentest

If you need a passive external snapshot of your domain, our SaaS scanner gives it in 60 seconds. If you need to validate whether weaknesses are exploitable and get audit-grade evidence, the professional pentest is the right fit. They're not substitutes: the Scanner is usually the previous step.

Feature Hard2bit Scanner Professional Pentest
Model Self-service SaaS Professional service executed by senior engineer
Analysis Passive, public domain Active, manual + automated, with controlled exploitation
Exploitability validation No (signals) Yes (real proof with evidence)
Methodologies Own checks OWASP, OSSTMM, OWISAM, OpenSAMM, CVSS
Active Directory Not applicable Yes, in Internal Advanced packs
Executive + technical report PDF report Technical + executive report + workshop
Post-remediation retest No Included in all packs
Audit evidence (ENS/ISO) PDF report Full evidence + remediation plan
Indicative price Free · from €19/mo from €1,490

Scope and exclusions

What the service does not include (by default)

The following exclusions can be contracted separately or combined with other Hard2bit services (red team, vulnerability management, digital forensics). Making them explicit avoids misunderstandings and sizes the engagement correctly.

  • Technical remediation, systems administration or configuration changes (quoted separately).
  • Denial-of-service tests, social engineering, phishing, vishing, smishing and physical testing (separate service under contract).
  • Extensive hardening, deep code review (SAST/DAST/SCA) and mobile pentest (per app) not included by default — complementary services.
  • Pentest on domains or systems without formal owner authorization. All activity requires signed rules of engagement.
  • Scenarios with operational impact or complex cloud (multi-account AWS/Azure/GCP) may require additional sizing.

Frequently asked questions

How long does a pentest take?

It depends on scope. A web/API pentest typically takes 5–15 days; infrastructure/AD can take 2–4 weeks. We adjust by criticality, number of assets and complexity.

Do you provide audit-ready evidence?

Yes. We include evidence and traceability, plus an executive summary that supports audits and frameworks like NIS2/DORA/ENS/ISO 27001.

What makes you different from “commodity” vendors?

Less noise, more impact: manual validation, business logic analysis, vulnerability chaining when relevant, and an actionable backlog with re-test.

Can you coordinate with our SOC/MDR?

Yes. We can work jointly to validate detections (use cases, alerts) and improve rules and response workflows.

Do you offer pentesting in Madrid?

Yes. We regularly work with organizations in Madrid and across Spain. When it makes sense, we coordinate on-site sessions for kick-off, findings review or final handover with the client's team. See the dedicated pentesting in Madrid page for the local angle.

And in Barcelona and the rest of Catalonia?

Yes. We deliver pentesting to companies operating in Barcelona and across Catalonia, with the same methodology and deliverables we apply to regulated clients nationwide. See the dedicated pentesting in Barcelona page for the local angle and Catalan-language blocks.

Concepts from our cybersecurity glossary that connect directly with this service.

Need a pentest that leads to fixes?

We scope properly, test with evidence, and deliver an actionable backlog with re-testing to verify closure.

Talk to a specialist