External Infrastructure & Cloud Security Assessment
Independent assessment of your external-facing network and cloud configuration, tested against NIST SP 800-115 and CIS Benchmarks. Up to 20 external IPs/hosts, one cloud environment (AWS/Azure/GCP), IAM misconfigurations, perimeter services. Signed Attestation Letter and one free retest included.
Quick Answer
Independent security assessment of your external-facing infrastructure and one cloud environment. Scope: up to 20 external IPs/hosts, AWS/Azure/GCP configuration review, IAM misconfigurations, perimeter services (mail, DNS, VPN). Network testing follows NIST SP 800-115; cloud configuration review follows CIS Benchmarks for the relevant provider. Combines automated discovery with manual validation of high-severity findings, delivered as an executive summary plus detailed technical report with CVSS v3.1 severity scoring and a prioritised remediation plan. One free retest of critical/high findings within 30 days is included at no extra cost. This is a network/cloud-perimeter assessment, not a web-application penetration test — for testing a web app or API itself, see our other four Penetration Testing tiers.
Why You Need This
Web application penetration testing (our other four tiers, from €539) covers your application code and API surface — it does not cover the external network perimeter or your cloud provider's configuration. Misconfigured cloud IAM roles, exposed management ports, weak perimeter services, and unpatched external hosts are a distinct and common source of real breaches, and most compliance frameworks that require "regular security testing" expect this surface to be tested too, not just the application layer.
This is the right fit when you need evidence of external network/cloud testing for GDPR Article 32, ISO 27001 Annex A.8.8/A.8.20, or NIS2 Article 21, when your last external network assessment is more than 12 months old, or when a customer's vendor security questionnaire asks specifically about infrastructure/cloud testing rather than application testing.
What this is not: it does not cover internal network testing (assumed-breach, Active Directory attack paths) or web-application exploitation — those require a different scope and are quoted individually on request.
Who Requires This From You
- GDPR Article 32 — Regular testing of the effectiveness of technical measures
- ISO/IEC 27001:2022 Annex A.8.8 — Management of technical vulnerabilities
- ISO/IEC 27001:2022 Annex A.8.20 — Network security
- NIS2 Article 21 — Cybersecurity risk-management measures
What You Get
Methodology
- External network testing aligned with NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment)
- Cloud configuration review aligned with CIS Benchmarks for AWS, Azure, and GCP
- Every finding scored with CVSS v3.1 for consistent, auditor-recognised severity
Assessment scope
- Up to 20 external IPs/hosts
- One cloud environment configuration review (AWS, Azure, or GCP)
- IAM misconfiguration review
- Perimeter services (mail, DNS, VPN)
Deliverables
- Executive summary for leadership (risk overview, business impact)
- Technical report with evidence, CVSS v3.1 severity scoring
- Prioritised remediation roadmap with effort estimates
- Signed Attestation Letter
- One free retest of critical and high findings within 30 days
What Happens If You Don't
Our Process
Reviewed by

Is This the Right Assessment for You?
You should choose this tier if…
- You need to test your external network perimeter, not a web application
- Your AWS, Azure, or GCP configuration has never had an independent review
- Your ISO 27001 auditor needs Annex A.8.20 (Network security) evidence, separate from A.8.8
- Your GDPR Article 32 risk assessment needs to cover infrastructure, not just the application layer
- NIS2 Article 21 requires cybersecurity risk-management measures spanning your network, not only your app
- You've already had a web-app VA or pentest but never had the external network or cloud config tested
Common scenarios
"Our auditor flagged that we have evidence for A.8.8 but nothing for A.8.20 — network security. We need something specific to the network layer."
"We moved our infrastructure to AWS and have never had the configuration independently reviewed. We don't know what we don't know."
"Our underwriter's questionnaire now asks specifically about external network testing, not just application testing."
"We found an exposed admin panel ourselves. We want an independent check before something worse happens."
What buyers search for that leads here
Buyers who reach this page typically searched: "external network penetration test", "cloud security assessment", "AWS configuration review", "CIS Benchmark audit", or "ISO 27001 A.8.20 evidence".
This is a different asset class from our four web-application tiers (from €539). Those test your application code and API surface. This one tests what your application runs on top of: your external network perimeter (up to 20 IPs/hosts) and one cloud environment's configuration (AWS, Azure, or GCP) — the layer where misconfigured IAM roles, exposed management ports, and weak perimeter services live.
Network testing follows NIST SP 800-115 (the standard technical methodology referenced in NIST's own testing guidance); cloud configuration review follows CIS Benchmarks for the relevant provider. We name both explicitly rather than describing the work vaguely, because "what methodology did you use?" is one of the first questions a competent auditor or security-literate buyer will ask.
One free retest of critical and high findings within 30 days is included in the €899 price — unlike our Vulnerability Assessment and Focused Pentest tiers, where retest is a paid add-on (Standard Pentest and above already include remediation retest as standard). If your only goal is confirming a specific fix, that included retest is often the most underused part of this tier.
When to choose a different tier instead
| Signal | Recommended service |
|---|---|
| Web application or API needs testing, not infrastructure | Web App Vulnerability Assessment (€539) |
| Need full manual exploitation of a web app | Focused Web App Pentest (€1,800) |
| Multi-tenant SaaS that already needs API + app testing | Standard Web App + API Pentest (€4,500) |
| AI/LLM-specific attack surface | AI Red Team Pentest (from €990) |
| Unsure whether you need internal or external testing | Internal vs External Testing Explained |
| Need internal network / Active Directory testing | Contact us for individual scope and quote |
Frequently asked questions about this tier
Do I need internal network testing too, or is external enough?
It depends on your requirement. External testing (this tier) covers what an attacker sees from outside your network and cloud provider — the perimeter most compliance frameworks ask about first. Internal testing (assumed-breach, Active Directory attack paths) simulates what happens after an attacker or malicious insider already has a foothold inside your network. Most organisations start with external testing; internal testing becomes relevant once you have sensitive internal systems, a Windows Active Directory domain, or a specific compliance requirement (some NIS2 and DORA scopes) that names internal testing explicitly.
What is NIST SP 800-115?
NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment) is a US National Institute of Standards and Technology publication describing a structured methodology for security testing — planning, discovery, attack, and reporting phases. We align our external network testing process with it because it's a widely recognised, auditor-legible methodology, not because it's a certification we hold.
What is a CIS Benchmark?
CIS Benchmarks are consensus-based configuration hardening guides published by the Center for Internet Security, with a specific benchmark for each major cloud provider (AWS, Azure, GCP) and service. Our cloud configuration review checks your environment against the relevant benchmark's controls — IAM policy, storage permissions, network exposure, logging, and encryption settings.
Does this cover my web application?
No. This assessment covers your external network perimeter and cloud configuration only. For the application or API itself, choose one of our four web-application Penetration Testing tiers (from €539).
How is this different from a CSPM tool like Wiz, Prisma Cloud, or Orca?
CSPM (Cloud Security Posture Management) tools continuously monitor your cloud configuration against benchmark rules and flag drift as it happens — genuinely useful for ongoing visibility. What they don't do is validate findings manually, test your external network perimeter (they're cloud-only), or produce a signed, auditor-recognised deliverable. Think of a CSPM subscription as continuous monitoring and this assessment as the independent, manually-validated checkpoint your auditor or insurer actually asks for — most mature security programmes run both, not one instead of the other.
What exactly does the free retest cover?
One retest of every critical- and high-severity finding from your report, within 30 days of delivery, at no additional cost. You tell us which findings you've remediated; we re-test those specific items and confirm the status. It doesn't cover a full re-assessment of the entire scope.
Can you test more than one cloud provider at once?
One cloud environment (AWS, Azure, or GCP) is included in the €899 price. A second environment, or a multi-cloud setup, is quoted on request — contact us with your architecture and we'll scope it.
Is the retest really included, or is that an upsell?
Genuinely included, no upsell. It's one of the differences between this tier and our Vulnerability Assessment and Standard Pentest tiers, where retest is a separate paid add-on (+€200 and +€500 respectively). We include it here because a network/cloud misconfiguration fix is usually quick to verify, and we'd rather confirm it's actually closed than leave you guessing.
Pricing & Delivery
€899 fixed price — up to 20 external IPs/hosts, one cloud environment. Additional hosts or a second cloud environment quoted on request. Internal network / Active Directory assessment (assumed-breach testing, privilege escalation paths, network segmentation review) is a separate scope with different tooling, quoted individually based on domain size and environment complexity.
Last reviewed: 25 August 2026
Frequently Asked Questions
Is this a penetration test?
No — this is a Security Assessment, the same honesty distinction we make with our €539 Vulnerability Assessment tier. It combines automated discovery with manual validation, not full manual exploitation. If your requirement specifically names "penetration test" for this scope, contact us to scope a manual engagement.
Does this cover my web application too?
No. This assessment covers your external network perimeter and cloud configuration only. For the application/API itself, choose one of our other four Penetration Testing tiers (from €539).
What cloud providers are covered?
AWS, Google Cloud Platform (GCP), and Microsoft Azure. One environment is included in the €899 price; a second is quoted on request.
Do you also test internal networks / Active Directory?
Not as part of this fixed-price assessment. Internal network / Active Directory testing covers assumed-breach scenarios (starting from a compromised low-privilege account), privilege escalation paths to Domain Admin, and network segmentation review between trust zones — a genuinely different scope and toolset from external perimeter testing. It's quoted individually based on domain size and environment complexity; contact us to scope it.
Is the retest really included?
Yes — one retest of critical and high-severity findings within 30 days, at no extra cost.
Are you CREST-accredited?
No — we are not CREST-accredited, and CREST has no accreditation pathway for firms in Moldova, so this reflects jurisdiction rather than testing capability. Even though we are not CREST-accredited, our infrastructure and cloud engagements follow the same OWASP-aligned methodology CREST-accredited testers use, with CVSS v3.1 scoring and CWE classification, plus a signed Attestation Letter for audit and compliance evidence. Because we are not CREST-accredited, if a CREST-member requirement applies to your engagement — typically UK public sector — tell us before scoping and we'll refer a partner firm.
Will testing take down our email, VPN, or other live services?
Denial-of-service techniques are explicitly excluded from scope — we never intentionally degrade or crash a live service. Scan intensity and testing windows are agreed during scoping, and an immediate-stop threshold with a direct emergency contact channel is defined in the Rules of Engagement before testing begins. If a test action unexpectedly affects service availability, we halt immediately and notify you — this is a documented step in our process, not an ad-hoc response.
Do we need to notify our cloud provider or hosting company before testing starts?
It depends on the provider and the type of testing — AWS, Azure, and GCP each publish their own security-testing policies, and some activities (e.g. testing that could resemble a DDoS pattern) require prior notification or approval even when testing your own environment. We check the current policy for your specific provider during scoping and tell you if notification or a pre-approval request is required before we start — we don't assume it isn't needed.
Our infrastructure sits behind Cloudflare (or another CDN/WAF) — what do you actually test?
When a target sits behind a CDN or WAF, the outward-facing scan initially sees the provider's edge infrastructure, not your origin server — so we don't just scan the CDN and call it done. Part of the engagement is identifying whether your real origin IP is discoverable (via DNS history, exposed subdomains, mail server records, or misconfigured services that bypass the CDN) and, where it is, assessing that origin directly. We'll also tell you plainly if the origin can't be located within scope — a WAF in front of an undiscoverable origin is a different risk picture than a WAF in front of a leaky one, and the report reflects which situation you're in rather than treating "behind a CDN" as automatically secure.
We don't know exactly how many external IPs or hosts we have — is that a problem?
No — not knowing your own external footprint is one of the most common reasons to run this assessment, not a barrier to starting it. Asset inventory (enumerating your actual public-facing IPs, subdomains, and hosts) is part of the engagement itself. The €899 price covers up to 20 external IPs/hosts; if the inventory turns up more, we tell you before testing begins and agree a revised scope and price together — you're never billed for overage after the fact.
