🛡️ Pentest from €539 · Compliance from €89. See All Services →
Optimum Web
Already Have a Quote?

Already have a quote? Let's check it against published prices.

Quick Answer

Tell us your scope — not the other firm's quote — and we'll price it against our published rates within one business day. We do not ask you to send the other proposal itself; scope parameters belong to you, and that document usually carries a confidentiality clause. There are three possible answers: our price is lower, their price is fair for the scope, or you need a firm we're not (CREST-accredited, TLPT-capable, or MASA-authorised) — and we'll say which, plainly.

Why You Are Probably Comparing

If a SOC 2 or ISO 27001 auditor sent you here, there's a structural reason they gave you a shortlist instead of one name: a firm that both performs your penetration test and later audits its results loses independence. So auditors point to two or three testing firms and let you choose. Comparing prices and scope across a shortlist is normal, expected practice — not a sign you're being difficult, and not a sign you distrust either firm.

What We Need From You

Six scope parameters — what's being tested, how many roles, authentication method, API surface, size, and what prompted the engagement — plus, optionally, what you were quoted, so we can tell you how it compares.

We do not need, and do not ask for, the other firm's proposal document. There's no file upload on this page — that's deliberate, not an oversight.

Free, no obligation. Reply within one business day. No file upload — we only need the scope above.

What You Get Back

A price against our published grid, a short breakdown of what the scope you described justifies (and where it looks over- or under-scoped relative to what you described), an indicative delivery timeline, and what's included in the deliverable. No obligation, and no file needed from you to get it.

Three Possible Answers

1. Our price is lower

We'll show our number against our published grid and explain exactly what's included, so you can compare like for like.

2. Their price is fair

If your scope includes something we don't do at that price point — internal network, red team, mobile client — we'll say the quote looks reasonable for what it covers.

3. You need someone else

If your contract specifically names CREST, DORA TLPT, or MASA validation, we're not the right firm — we'll tell you that directly and take no fee for saying so.

If their quote is fair, we will tell you it is fair. That answer costs us nothing and saves you a week.

Our Published Prices

TierPrice (EUR, excl. VAT)Delivery
Web App Vulnerability Assessment
SEC-PENT-01
€5395 business days
Focused Web App Penetration Test
SEC-PENT-02
from €1,8001.5–2 weeks
Standard Web App + API Penetration Test
SEC-PENT-03
from €4,500~3 weeks
Enterprise SaaS Penetration Test
SEC-PENT-04
from €8,0004–5 weeks
AI Red Team Pentest (add-on)
OW-AIS-10
+ €99010–14 business days

Want an instant number instead of waiting a business day? Try the Pentest Cost Calculator.

How Scope Drives Price

What you're testing

A marketing site, a single logged-in app, an app with an API, a multi-tenant SaaS platform, or a mobile app + backend — each has a very different attack surface.

Roles behind the login

Each additional role (admin, standard user, guest, partner) is tested separately, and cross-role access is where most real findings come from.

Authentication complexity

Email/password is cheap to test. SSO/OAuth and especially SAML/MFA/custom flows have to be exercised end to end.

API surface

REST, GraphQL, and webhooks each add dedicated test time — including undocumented endpoints.

Application size

Distinct screens plus API endpoints. More surface area means more manual testing hours.

What prompted the engagement

A customer questionnaire, SOC 2/ISO 27001 audit, or NIS2/DORA/CRA readiness can require a fuller penetration test even where the raw scope looks small.

What We Do Not Do

Internal network penetration testing
Full red team / adversary simulation engagements
DORA Article 26–27 Threat-Led Penetration Testing (TLPT)
Google Play MASA validation — only App Defense Alliance-authorised labs can issue this
Mobile application (iOS/Android client) penetration testing — we test the backend and API behind it instead
CREST-accredited testing — Moldova currently has no local CREST accreditation path

Frequently Asked Questions

Do I need to send you the other company's proposal?+
No — please don't. Most commercial proposals carry a confidentiality clause, and asking you to forward one would put you in an awkward position and us at legal risk. We only need the scope parameters (what's being tested, roles, auth, API, size, and why), which belong to you as the buyer, not to the firm that quoted you.
Is this free?+
Yes, with no obligation. We compare your scope against our published prices and reply with a written breakdown — you decide what to do with it.
How fast will I hear back?+
Within one business day, by email, from a person — not an automated quote.
Will you tell me if their price is fair?+
Yes. If the scope justifies their number, we say so directly. That answer costs us nothing to give and can save you a week of back-and-forth.
What if I need CREST accreditation?+
Tell us in the comment field. We are not a CREST-accredited firm — Moldova currently has no local CREST accreditation path — and if your contract specifically names CREST, we'll say so plainly rather than take the engagement anyway.
Will you contact me repeatedly afterwards?+
No. You get one reply with the comparison. If you want to talk further, the reply includes how to reach us — we won't chase you.

Ready to Compare?

Free, one business day, no file upload required.

Compare Your Quote