🛡️ Pentest from €539 · Compliance from €89. See All Services →
Optimum Web
Penetration Testing Services

Audit-Grade Security Validation — From €539 to €12,000 · 5 clearly-defined tiers

From €539 to €12,000 · 5 clearly-defined tiers, plus an AI Red Team add-on

Quick Answer

Optimum delivers independent penetration testing across five clearly-defined tiers — from automated Vulnerability Assessment (€539, 5 business days) to Enterprise SaaS Penetration Test (€8,000–12,000, 4–5 weeks), including an External Infrastructure & Cloud Security Assessment (€699, 8 business days) — plus a separate AI Red Team add-on (€990+) for AI/LLM applications. All engagements produce a formal report with CVSS v3.1 vectors, CWE classification, and a signed Attestation Letter accepted as evidence for ISO 27001 Annex A.8.29, SOC 2 CC4.1/CC7.1, and cyber insurance underwriter requirements. Methodology aligned with OWASP WSTG v4.2, OWASP Top 10:2025, and OWASP API Security Top 10 (2023).

Why Penetration Testing is No Longer Optional

Regulatory pressure. ISO/IEC 27001:2022 Annex A.8.29 explicitly requires regular external security testing as evidence. SOC 2 auditors flag missing pen test reports under CC4.1 and CC7.1. GDPR Article 32 names "regular testing, assessing and evaluating the effectiveness of technical and organisational measures" as a required security measure.

Procurement pressure. Enterprise prospects increasingly demand pen test reports during vendor security review before signing contracts. Without recent, independent testing evidence, deals stall in procurement legal review for weeks — or fail entirely.

Insurance pressure. Cyber insurance underwriters now require pen test evidence before quoting favourable rates. Companies without recent pen test reports are declined coverage or rated up by 200–400% premium.

Who Requires This From You

  • ISO/IEC 27001:2022 auditors — Annex A.8.29 evidence requirement
  • SOC 2 auditors — Trust Services Criteria CC4.1, CC7.1, CC7.2
  • Enterprise vendor security reviews — vendor risk assessment standard
  • Cyber insurance underwriters — AIG, Hiscox, Beazley, Chubb, Travelers
  • GDPR Article 32 — appropriate technical and organisational measures
  • NIS2 Directive Article 21 — risk management measures for in-scope EU entities
  • PCI DSS 4.0 Requirement 11.4 — for organisations handling cardholder data

Methodology and Standards

OWASP WSTG v4.2
Operational testing basis
OWASP Top 10:2025
Current vulnerability classification
OWASP API Security Top 10 (2023)
REST API surface coverage
OWASP ASVS v4.0.3 Level 2
Verification benchmark
PTES
Penetration Testing Execution Standard
NIST SP 800-115
Evidence handling, reproducibility
CVSS v3.1
Severity scoring with full vector strings
CWE
Weakness classification

Our Process

1
Scoping call
30–60 min to confirm assets, authorisation, and escalation contacts.
2
NDA + Rules of Engagement
Written authorisation before any testing begins.
3
Access provisioned
Test credentials, IP whitelisting, monitoring setup.
4
Active testing
Manual + automated, 70/30 ratio. Daily updates. Critical findings escalated in 4h.
5
Report + Attestation
CVSS-scored findings, remediation guidance, signed Attestation.
6
Optional retest
Included Tier 3+. Validates remediations, delta report.

Optimum's penetration testing services are used by SaaS, fintech, and mid-market companies across the United Kingdom, Germany, Netherlands, Switzerland, France, Austria, and the United States. Penetration testing UK companies rely on, delivered remotely from our Chișinău (Moldova IT Park) office under UK/EU GDPR-compliant DPAs. Fixed-price SaaS penetration testing, web application penetration testing, and API penetration testing — with no surprise invoices.

Frequently Asked Questions

Will this be accepted as evidence by an ISO 27001 auditor?

Yes — our deliverables include the elements ISO 27001 auditors look for under Annex A.8.29 and A.8.8: independent testing, recognised methodology (OWASP, PTES, NIST), structured CVSS-scored findings, documented scope, signed Rules of Engagement, and signed Attestation Letter. We recommend confirming the specific scope with your auditor before engagement.

Are you CREST-accredited?

We are not a CREST-member firm. CREST currently has no local accreditation path in Moldova. We build credibility through OWASP-aligned methodology, named-tester accountability, ISO/IEC 27001-aligned controls (certification in progress, Q4 2026), and audit-grade reporting. If a customer specifically requires CREST membership, we will flag that upfront.

What's the difference between Vulnerability Assessment (€539) and Focused Pentest (€1,800)?

Vulnerability Assessment combines automated scanning with manual validation of high-severity findings only. Focused Pentest is a real manual penetration test — all findings are exploited where safely possible, business logic flaws are tested, authorisation is challenged. VA is sufficient where regulation accepts "regular vulnerability testing"; Pentest is required where regulation specifies "penetration test".

Do you sign DPAs and NDAs?

Yes. Mutual NDA is signed before any technical disclosure. DPA is signed where personal data is in scope. We are GDPR processor-ready under signed DPAs for EU and UK clients (UK GDPR compliant, EU Standard Contractual Clauses available).

What is your typical lead time?

Subject to current engagement load, active testing typically starts 3–4 weeks after Statement of Work signature. For urgent engagements (compliance deadlines, contract negotiations), we can frequently accommodate faster starts.

Where is testing performed?

All testing is performed by named, employed Optimum engineers from our Chișinău office. We do not subcontract. All target-facing traffic originates from a single, pre-disclosed source IP address. Reports and evidence are stored on encrypted Optimum infrastructure.

How much does a penetration test cost?

Our penetration tests are fixed price: Vulnerability Assessment €539, External Infrastructure & Cloud Security Assessment €699, Focused Web App Pentest from €1,800, Standard SaaS + API Pentest from €4,500, Enterprise SaaS Pentest from €8,000. UK CREST firms charge £3,000–18,000 for equivalent scope. We deliver the same methodology at 60–80% lower cost.

How is Optimum cheaper than CREST firms?

Our engineers are based in Chișinău, Moldova — senior security expertise at Eastern European salary levels. Same OWASP WSTG v4.2 methodology, CVSS v3.1 scoring, and audit-grade Attestation Letters. We pass the entire saving to you.

Which penetration testing tier do I need?

VA (€539): compliance baseline, ISO 27001 A.8.8, vendor questionnaires. Focused Pentest (€1,800): single web app, ISO 27001 A.8.29, cyber insurance, enterprise deals. Standard Pentest (€4,500): multi-tenant SaaS, REST APIs, SOC 2, ISO 27001 full ISMS. Enterprise (€8,000+): fintech/healthtech/regulated SaaS, cloud surface, DORA, PCI DSS Level 1. Need your external network perimeter or cloud configuration tested instead of a web app? See our External Infrastructure & Cloud Security Assessment (€699). Testing an AI/LLM application? Add our AI Red Team Pentest (€990+) on top of whichever tier fits your app's non-AI surface.

What OWASP methodology is used?

Web application testing follows OWASP WSTG v4.2 (all test categories). API testing follows OWASP API Security Top 10 (2023 edition). AI security follows OWASP LLM Top 10:2025. Findings are scored with CVSS v3.1 vectors and CWE classification.

What is included in a penetration test report?

All reports include: executive summary, methodology description, scope confirmation, detailed findings (CVSS v3.1 vector, CWE ID, evidence screenshots, reproduction steps, business impact), remediation recommendations, and signed Attestation Letter confirming the engagement was conducted. Standard and Enterprise tiers include a remediation retest.

Do you include remediation retest?

Remediation retest is included as standard in Tier 3 (Standard Web App + API, €4,500+) and Tier 4 (Enterprise SaaS, €8,000+). For Tier 1 (VA) and Tier 2 (Focused Pentest), one round of clarification questions is included and retest can be added as a paid add-on: +€200 for VA, +€500 for Focused Pentest.

What compliance frameworks does the report satisfy?

Our pentest reports are designed to satisfy: ISO 27001:2022 Annex A.8.8 and A.8.29, SOC 2 CC4.1 and CC7.1, PCI DSS v4.0.1 Requirement 11.4, DORA Article 24-25 general resilience testing, GDPR Article 32 technical measures, and cyber insurance underwriter questionnaires (AIG, Hiscox, Beazley, Chubb).

How do you scope a penetration test?

Scope is agreed in writing before any testing begins via a Rules of Engagement document. You specify: URLs/domains in scope, user roles to test (unauthenticated, standard user, admin), testing window (business hours/24-7), rate limiting constraints, and out-of-scope systems. Scoping call is free.

Ready to Start?

Order Without Payment — Get Invoice

Submit your details and we will send a scoped invoice within 4 hours. No commitment until you confirm the SoW.

PayPal · SSL Senior only 14-day warranty SEC-PENT-HUB