A full pentest every month. Evidence that stays current.
Professional runs the same autonomous pentest as a one-time engagement, every month. Each run re-tests your open findings, proves what changed, and refreshes your certificate. €995 per app per month, half the per-pentest price of a one-time engagement.
Why the interval is the decision
Three published numbers set the shape of the problem. None of them are ours.
What a pentest settles is not whether a new CVE landed, that is patching. It is whether the application you actually shipped can be made to do something it should not, and whether the fix you shipped last month held. Both change every time you deploy. The evidence, and what this argument does not rest on.
A pentest proves a moment. Your product moves on.
Every deploy, dependency bump, and config change lands after your last pentest. Professional keeps the proof as current as the product.
Evidence stays current
An annual report proves last year's build. A monthly run proves the application you are shipping now.
Fixes get verified
Each run re-tests every open finding and marks it Fixed, Regressed, or New. You see whether a fix held, not whether someone remembered to re-check it.
Certificate stays fresh
A clean run refreshes your shareable certificate, so the proof you show customers and procurement is weeks old, not a year old.
Questionnaires unblocked
Enterprise security questionnaires ask for recent testing. With a current report on file, the answer is a download, not a six-week project.
What a Professional run does
- Full pentest. The same engine as a one-time engagement: reconnaissance, real exploitation, and independent verification of every finding, aligned with OWASP Top 10, OWASP API Security Top 10, and the OWASP Web Security Testing Guide. Results in 24 hours.
- Re-test of open findings. Everything still open from previous runs is tested again and marked Fixed, Regressed, or New, so remediation progress is measured, not assumed.
- Updated reports. Compliance-ready reports refresh with every run: current evidence for ISO 27001, SOC 2, NIS2, and DORA's Article 24 and 25 testing requirements, including penetration testing.
- Certificate and alerts. A run with no high or critical findings refreshes your shareable public certificate. New or regressed findings trigger an alert.
Run it when you are ready, or set a monthly schedule. Billing is per app, monthly via Stripe. Cancel anytime.
One-time pentest or Professional
| One-time pentest | Professional | |
|---|---|---|
| Price per pentest | €1,995 | €995 |
| Cadence | Once, on demand | Every month, per app |
| Open findings | Free retest of a fixed finding, triggered by you | Re-tested on every run: Fixed, Regressed, New |
| Certificate | Issued on a clean result | Refreshed after each clean run |
| Commitment | One charge, no auto-renewal | Monthly, cancel anytime |
| Best for | Annual audit evidence, a point-in-time check | Teams that ship faster than an annual test can prove |
Honest math: twelve months of Professional is €11,940 per app. If one pentest a year for the audit file is all you need, the €1,995 one-time pentest is the cheaper choice. Professional is for products that change faster than an annual test can prove.
What the rules actually say about frequency
No EU regulation prescribes a monthly pentest. Three of them require something more demanding: test regularly, justify the interval yourself, and test again when things change.
Manufacturers must "apply effective and regular tests and reviews of the security of the product with digital elements", for the whole support period rather than once at launch. The CRA does not name penetration testing and sets no interval; it makes regular a legal obligation.
In-scope entities must apply a documented security testing policy, and must establish "the need, scope, frequency and type of security tests" from their own risk assessment, documenting the type, scope, time and results of each. The burden of justifying a cadence sits with you.
Appropriate testing at least yearly on ICT systems supporting critical or important functions, with penetration testing named among the appropriate tests. For central securities depositories and central counterparties, Art. 25(2) triggers on a change, not a calendar: vulnerability assessments before any deployment or redeployment.
Every Professional run produces compliance-ready reports you can put in an evidence pack, refreshed monthly rather than annually. Attack Surface monitoring supports a testing programme; it never satisfies a testing requirement, because only a pentest actually tests.
Watch exposure weekly, prove it monthly
The free Attack Surface shows what is publicly visible on your domain: subdomains, TLS, headers, open ports. It observes what is exposed; it never tests. With a SQUR account, your scopes are re-checked weekly and you are alerted when new exposure appears.
The scan shows what's exposed. Only a pentest proves what's exploitable, because only a pentest actually tests. Professional closes that loop every month.
Common questions
How does billing work?
Stripe, monthly, per app. No lock-in: cancel anytime and the subscription simply stops at the end of the period.
Do runs start automatically?
Your choice: trigger each monthly pentest when you are ready, for example after a release, or set a monthly schedule and let it run.
We have several apps.
Professional is priced per app. For a portfolio, request a quote or look at bulk credits and Enterprise on the pricing page.
Does it cover compliance?
Every run produces compliance-ready reports structured to support ISO 27001, SOC 2, NIS2, and DORA's Article 24 and 25 testing evidence, including penetration testing, refreshed monthly instead of annually.
Start continuous testing
Create a free account to see a ready-made demo pentest with a full sample report, then put your first app on a monthly cadence. No scoping calls.