Your platform flagged the control. This is what closes it.
Vanta, Drata, Secureframe and the rest automate evidence collection right up to the point where a control needs an independent human test. That's where the automation stops and someone has to buy something.
Quick Answer
Compliance platforms do not perform penetration tests. They flag the control, then route you to a third-party testing firm and store the report as evidence. Optimum is one of those firms. Fixed prices from €539 to €12,000, published in full, with CVSS v3.1 findings, CWE classification, retest, and a signed attestation letter your auditor can review.
Where we fit
Four steps. Only one of them is ours, and it's the one your platform can't do for you.
Control is flagged
Evidence is missing for the control that requires independent security testing. The task appears in your dashboard.
We test and report
Scoped in writing, tested manually, findings scored with CVSS v3.1 and classified by CWE.
You upload the artefact
Report plus signed attestation letter go into your platform against the control. We hand over files, not integrations.
Auditor reviews
The auditor accepts or asks questions. The report is written for that conversation, not for marketing.
What exactly does your control need?
Pick your framework and your platform.
A vulnerability scan alone is rarely accepted here — the control speaks to evaluating effectiveness, which is what manual testing evidences.
What your platform does, and what it does not
A misunderstanding worth clearing up
Clicking "request a pentest" inside a compliance platform doesn't buy a test from the platform. It opens a contract with an outside testing firm the platform has onboarded. The platform facilitates and stores the evidence; the methodology, the depth and the quality of the report belong to the testing firm, not the platform.
What that means for you
- —You're choosing a testing firm either way, inside the marketplace or outside it.
- —Quotes in these marketplaces vary widely for the same scope.
- —Our prices are published in full, so you can compare before you talk to anyone.
- —You keep the report. It's yours to hand to any auditor, customer, or underwriter.
Published prices
The full catalogue, in public, no scoping call required to see a number.
| ID | Service | Price | Typical fit |
|---|---|---|---|
| SEC-PENT-01 | Web App Vulnerability Assessment | €539 | Baseline, small target, tight deadline |
| SEC-PENT-02 | Focused Web App Penetration Test | From €1,800 | First SOC 2 or ISO 27001 cycle |
| SEC-PENT-03 | Standard Web App + API Pentest | From €4,500 | Multiple roles, real API surface |
| SEC-PENT-04 | Enterprise SaaS Penetration Test | From €8,000–€12,000 | Multi-tenant, regulated, enterprise buyers |
| OW-AIS-10 | AI Red Team Pentest | €990 | LLM features, prompt injection, agents |
How we compare to the firms usually recommended
These five are the providers most often named in "best pentest for Vanta" round-ups. Every figure below is the vendor's own published price — where a vendor doesn't publish one, that's what the row says.
| Provider | Published price | Accreditation | Usual fit |
|---|---|---|---|
| Optimum Web (EU) | €539 – €12,000, full list public | OWASP WSTG methodology · Not CREST-accredited · ISO 27001 in progress (Q4 2026) | Seed to Series B SaaS on a fixed budget |
| Software Secured | Not published | Not CREST-accredited | Growth-stage SaaS, first SOC 2 cycles |
| Cobalt.io | Credit-based, not published | CREST | Teams that must start within 24 hours |
| NetSPI | Not published | CREST, 3PAO | Mid-market and enterprise programmes |
| Bishop Fox | Not published | CREST | Complex authorisation, elevated risk |
| Coalfire | Not published | Accredited assessor | Multi-framework, regulated enterprise |
If your buyer's contract names CREST specifically, use a CREST-accredited firm. We'll say that on the scoping call, not after the invoice.
How to scope a SOC 2 pentest
1. Define the SOC 2 system boundary
Which applications, environments and data stores are actually in scope for the audit period — not your entire infrastructure.
2. Map the external attack surface
Domains, subdomains, APIs, admin panels and third-party integrations reachable from outside your network.
3. Define the worst credible compromise
Data access, admin privileges, or cross-tenant leakage — the scenario that determines depth of testing, not just breadth.
What we are, and what we are not
We are
We are not
Questions we actually get
Will your report be accepted in Vanta, Drata, or Secureframe?+
Do you integrate with the platform?+
Is a €539 Vulnerability Assessment enough for SOC 2?+
How fast can you start?+
Do you sign NDAs and DPAs?+
Are you CREST accredited?+
Is a remediation retest included?+
Which compliance platforms do you work alongside?+
Have the artefact ready before your auditor asks
Published prices from €539 · CVSS v3.1 findings · signed attestation letter
This page describes how we work alongside compliance platforms — it does not claim partner status with Vanta, Drata, Secureframe, Sprinto, or Thoropass.
