A full pentest every month. Evidence that stays current.

Professional runs the same autonomous pentest as a one-time engagement, every month. Each run re-tests your open findings, proves what changed, and refreshes your certificate. €995 per app per month, half the per-pentest price of a one-time engagement.

Start continuous testing See pricing
Certificate refreshed on every clean run One full pentest per run Re-tests: Fixed, Regressed, New €995 per app / month, cancel anytime

Why the interval is the decision

Three published numbers set the shape of the problem. None of them are ours.

31%
of breaches now start with vulnerability exploitation, up from 20%
43 days
median time to patch a known-exploited vulnerability, up from 32, with 60% to 70% still open a week after disclosure
26%
of known-exploited vulnerabilities are fully remediated, down from 38%, with median time to patch up to 43 days

What a pentest settles is not whether a new CVE landed, that is patching. It is whether the application you actually shipped can be made to do something it should not, and whether the fix you shipped last month held. Both change every time you deploy. The evidence, and what this argument does not rest on.

A pentest proves a moment. Your product moves on.

Every deploy, dependency bump, and config change lands after your last pentest. Professional keeps the proof as current as the product.

Evidence stays current

An annual report proves last year's build. A monthly run proves the application you are shipping now.

Fixes get verified

Each run re-tests every open finding and marks it Fixed, Regressed, or New. You see whether a fix held, not whether someone remembered to re-check it.

Certificate stays fresh

A clean run refreshes your shareable certificate, so the proof you show customers and procurement is weeks old, not a year old.

Questionnaires unblocked

Enterprise security questionnaires ask for recent testing. With a current report on file, the answer is a download, not a six-week project.

What a Professional run does

  1. Full pentest. The same engine as a one-time engagement: reconnaissance, real exploitation, and independent verification of every finding, aligned with OWASP Top 10, OWASP API Security Top 10, and the OWASP Web Security Testing Guide. Results in 24 hours.
  2. Re-test of open findings. Everything still open from previous runs is tested again and marked Fixed, Regressed, or New, so remediation progress is measured, not assumed.
  3. Updated reports. Compliance-ready reports refresh with every run: current evidence for ISO 27001, SOC 2, NIS2, and DORA's Article 24 and 25 testing requirements, including penetration testing.
  4. Certificate and alerts. A run with no high or critical findings refreshes your shareable public certificate. New or regressed findings trigger an alert.

Run it when you are ready, or set a monthly schedule. Billing is per app, monthly via Stripe. Cancel anytime.

One-time pentest or Professional

One-time pentestProfessional
Price per pentest€1,995€995
CadenceOnce, on demandEvery month, per app
Open findingsFree retest of a fixed finding, triggered by youRe-tested on every run: Fixed, Regressed, New
CertificateIssued on a clean resultRefreshed after each clean run
CommitmentOne charge, no auto-renewalMonthly, cancel anytime
Best forAnnual audit evidence, a point-in-time checkTeams that ship faster than an annual test can prove

Honest math: twelve months of Professional is €11,940 per app. If one pentest a year for the audit file is all you need, the €1,995 one-time pentest is the cheaper choice. Professional is for products that change faster than an annual test can prove.

What the rules actually say about frequency

No EU regulation prescribes a monthly pentest. Three of them require something more demanding: test regularly, justify the interval yourself, and test again when things change.

Cyber Resilience Act
Annex I, Part II, point 3

Manufacturers must "apply effective and regular tests and reviews of the security of the product with digital elements", for the whole support period rather than once at launch. The CRA does not name penetration testing and sets no interval; it makes regular a legal obligation.

NIS2 implementing regulation
(EU) 2024/2690, Annex 6.5.1 and 6.5.2(a)

In-scope entities must apply a documented security testing policy, and must establish "the need, scope, frequency and type of security tests" from their own risk assessment, documenting the type, scope, time and results of each. The burden of justifying a cadence sits with you.

DORA
(EU) 2022/2554, Art. 24(6) and Art. 25

Appropriate testing at least yearly on ICT systems supporting critical or important functions, with penetration testing named among the appropriate tests. For central securities depositories and central counterparties, Art. 25(2) triggers on a change, not a calendar: vulnerability assessments before any deployment or redeployment.

Every Professional run produces compliance-ready reports you can put in an evidence pack, refreshed monthly rather than annually. Attack Surface monitoring supports a testing programme; it never satisfies a testing requirement, because only a pentest actually tests.

Watch exposure weekly, prove it monthly

The free Attack Surface shows what is publicly visible on your domain: subdomains, TLS, headers, open ports. It observes what is exposed; it never tests. With a SQUR account, your scopes are re-checked weekly and you are alerted when new exposure appears.

The scan shows what's exposed. Only a pentest proves what's exploitable, because only a pentest actually tests. Professional closes that loop every month.

See your exposure free in 60 seconds

Common questions

How does billing work?

Stripe, monthly, per app. No lock-in: cancel anytime and the subscription simply stops at the end of the period.

Do runs start automatically?

Your choice: trigger each monthly pentest when you are ready, for example after a release, or set a monthly schedule and let it run.

We have several apps.

Professional is priced per app. For a portfolio, request a quote or look at bulk credits and Enterprise on the pricing page.

Does it cover compliance?

Every run produces compliance-ready reports structured to support ISO 27001, SOC 2, NIS2, and DORA's Article 24 and 25 testing evidence, including penetration testing, refreshed monthly instead of annually.

Start continuous testing

Create a free account to see a ready-made demo pentest with a full sample report, then put your first app on a monthly cadence. No scoping calls.

Start continuous testing Get a quote