🛡️ Pentest from €539 · Compliance from €89. See All Services →
Optimum Web
Partners

Your platform flagged the control. This is what closes it.

Vanta, Drata, Secureframe and the rest automate evidence collection right up to the point where a control needs an independent human test. That's where the automation stops and someone has to buy something.

Quick Answer

Compliance platforms do not perform penetration tests. They flag the control, then route you to a third-party testing firm and store the report as evidence. Optimum is one of those firms. Fixed prices from €539 to €12,000, published in full, with CVSS v3.1 findings, CWE classification, retest, and a signed attestation letter your auditor can review.

Where we fit

Four steps. Only one of them is ours, and it's the one your platform can't do for you.

Step 01
Your platform

Control is flagged

Evidence is missing for the control that requires independent security testing. The task appears in your dashboard.

Step 02
Optimum

We test and report

Scoped in writing, tested manually, findings scored with CVSS v3.1 and classified by CWE.

Step 03
You

You upload the artefact

Report plus signed attestation letter go into your platform against the control. We hand over files, not integrations.

Step 04
Your auditor

Auditor reviews

The auditor accepts or asks questions. The report is written for that conversation, not for marketing.

See full tier pricing and timelines for compliance-driven pentests

What exactly does your control need?

Pick your framework and your platform.

Framework
Platform
Control
CC4.1 and CC7.1
What it asks for
Evidence that controls are evaluated for effectiveness, and that vulnerabilities are detected and remediated.
What we deliver
Penetration test report with CVSS v3.1 findings, CWE classification, remediation guidance, retest result, signed attestation letter.
What you upload to Vanta
Report PDF and attestation letter, attached to the flagged control.

A vulnerability scan alone is rarely accepted here — the control speaks to evaluating effectiveness, which is what manual testing evidences.

What your platform does, and what it does not

A misunderstanding worth clearing up

Clicking "request a pentest" inside a compliance platform doesn't buy a test from the platform. It opens a contract with an outside testing firm the platform has onboarded. The platform facilitates and stores the evidence; the methodology, the depth and the quality of the report belong to the testing firm, not the platform.

What that means for you

  • You're choosing a testing firm either way, inside the marketplace or outside it.
  • Quotes in these marketplaces vary widely for the same scope.
  • Our prices are published in full, so you can compare before you talk to anyone.
  • You keep the report. It's yours to hand to any auditor, customer, or underwriter.

Published prices

The full catalogue, in public, no scoping call required to see a number.

IDServicePriceTypical fit
SEC-PENT-01Web App Vulnerability Assessment€539Baseline, small target, tight deadline
SEC-PENT-02Focused Web App Penetration TestFrom €1,800First SOC 2 or ISO 27001 cycle
SEC-PENT-03Standard Web App + API PentestFrom €4,500Multiple roles, real API surface
SEC-PENT-04Enterprise SaaS Penetration TestFrom €8,000–€12,000Multi-tenant, regulated, enterprise buyers
OW-AIS-10AI Red Team Pentest€990LLM features, prompt injection, agents

How we compare to the firms usually recommended

These five are the providers most often named in "best pentest for Vanta" round-ups. Every figure below is the vendor's own published price — where a vendor doesn't publish one, that's what the row says.

ProviderPublished priceAccreditationUsual fit
Optimum Web (EU)€539 – €12,000, full list publicOWASP WSTG methodology · Not CREST-accredited · ISO 27001 in progress (Q4 2026)Seed to Series B SaaS on a fixed budget
Software SecuredNot publishedNot CREST-accreditedGrowth-stage SaaS, first SOC 2 cycles
Cobalt.ioCredit-based, not publishedCRESTTeams that must start within 24 hours
NetSPINot publishedCREST, 3PAOMid-market and enterprise programmes
Bishop FoxNot publishedCRESTComplex authorisation, elevated risk
CoalfireNot publishedAccredited assessorMulti-framework, regulated enterprise

If your buyer's contract names CREST specifically, use a CREST-accredited firm. We'll say that on the scoping call, not after the invoice.

How to scope a SOC 2 pentest

1. Define the SOC 2 system boundary

Which applications, environments and data stores are actually in scope for the audit period — not your entire infrastructure.

2. Map the external attack surface

Domains, subdomains, APIs, admin panels and third-party integrations reachable from outside your network.

3. Define the worst credible compromise

Data access, admin privileges, or cross-tenant leakage — the scenario that determines depth of testing, not just breadth.

Use the calculator to turn this into a price

What we are, and what we are not

We are

Senior-only testers — no juniors on engagements
OWASP WSTG methodology, CVSS v3.1 scoring, and CWE classification on every finding
Signed attestation letters written for auditor review
Remediation retest included as standard from the Standard tier (€4,500+) upward; available as a paid add-on on Vulnerability Assessment and Focused tiers
A GDPR data processor — DPA and Standard Contractual Clauses available, mutual NDA before technical disclosure
EU-based — Chișinău, Moldova IT Park

We are not

Integrated with any platform — we hand over files, you upload them
CREST-accredited — Moldova currently has no local CREST accreditation path
ISO 27001 certified yet — certification is in progress, targeted for Q4 2026
A provider of Threat-Led Penetration Testing (TLPT) under DORA Article 26
Your auditor — we produce evidence, the auditor decides whether it satisfies the control

Questions we actually get

Will your report be accepted in Vanta, Drata, or Secureframe?+
The platform stores the file; the auditor accepts it. Our reports are structured for auditor review — scope, methodology, findings with CVSS v3.1 and CWE, remediation status, retest result, and a signed attestation letter. If your auditor has a specific format requirement, tell us before we start and we'll meet it.
Do you integrate with the platform?+
No. We deliver the report and the attestation letter as files, and you attach them to the control yourself. We don't have a live API integration or a commercial partnership with any compliance automation platform.
Is a €539 Vulnerability Assessment enough for SOC 2?+
Usually not. A Vulnerability Assessment gives you a scored baseline, but where an auditor or an enterprise customer asks for independent penetration testing, they mean manual testing. Start at €1,800 (Focused Web App Penetration Test) if the flagged control is the reason you're here.
How fast can you start?+
Scoping call, written scope, then testing. Delivery ranges from 5 business days (Vulnerability Assessment) to 4–5 weeks (Enterprise SaaS) — exact timelines are on each tier's page.
Do you sign NDAs and DPAs?+
Yes. A mutual NDA before any technical disclosure, and a DPA with Standard Contractual Clauses as a GDPR processor.
Are you CREST accredited?+
No. We are not a CREST-member firm — Moldova, where we're based, currently has no local CREST accreditation path. If your buyer's contract specifically names CREST, use a CREST-accredited firm; we'll say so on the scoping call, not after the invoice.
Is a remediation retest included?+
Standard Web App + API Pentest (€4,500+) and Enterprise SaaS Pentest include a remediation retest as standard. Vulnerability Assessment and Focused Web App Pentest offer retest as a paid add-on (+€200 and +€500 respectively).
Which compliance platforms do you work alongside?+
Vanta, Drata, Secureframe, Sprinto, Thoropass, and others — we don't have a commercial partnership with any of them at this time. This page explains how the handoff works, not an integration.

Have the artefact ready before your auditor asks

Published prices from €539 · CVSS v3.1 findings · signed attestation letter

This page describes how we work alongside compliance platforms — it does not claim partner status with Vanta, Drata, Secureframe, Sprinto, or Thoropass.