Someone is going to try to break into your software. Let me be the first.

Manual web and API pentest by one senior tester — the same person you talk to, who tests, and who explains it to your auditor. €6,500 fixed, retest included.

I take on a maximum of 2 full tests per month.

Why one person

At a big firm, a senior sells and a junior tests.

With me, that's the same person. There is nobody to pass the blame to, so I do it properly. You talk to the tester, not an account manager. What I find, I explain myself.

01No sales layer
02No junior on your application
03Direct contact, from scoping to retest

What you get

The report is for you. The TPM is for everyone else.

The report is written for your team: reproduce, fix, done. Your customers, investors and auditor get the TPM — proof that things are in order, without your technical dirty laundry.

Manual

Tooling where it speeds things up, handwork where it counts. OWASP WSTG and ASVS Level 2, findings with CVSS. Never unfiltered scanner output.

Reproducible

Proof of concept per finding, so your dev team can reproduce it.

Two layers

Executive summary for the board, technical report for the team.

Retest included

Included within 90 days — until everything is fixed or formally accepted.

Entirely fictional: client, systems, findings and every name, address and contact detail in both documents are made up. Only the structure is real — that is exactly what you get.

Guarantees

What I put on the line.

Fixed price, fixed date, fixed result. If I don't deliver that, you won't feel it in your wallet.

01
Report on timeDraft report within 3 working days after the last test day. Later? 20% off the invoice.
02
TPM questions answeredBefore the test I align the scope with your system description. If your auditor has questions about the TPM afterwards, I answer them directly — free of charge.
03
ContinuityIf I'm out, I arrange a senior of the same calibre, under the same NDA and scope. Your audit window doesn't hang on one calendar.

Packages

Three options. No more.

Single pentest

€6,500 fixed

Within 15 working days of the start you'll have a TPM your customer, investor or auditor accepts. That's the deal.

  • Critical finding? You hear it the same day, not in the report
  • Report 3 working days after the last test day, or 20% off the invoice

Does this fit you? One web application with API, ±3 user roles, ±75 endpoints, one environment. Bigger? You'll hear it in the scoping call and get one fixed price up front.

Need another test next year? Then the Annual plan is cheaper than two single ones.

Book a scoping call
Default choice

Annual plan

€12,000/yr

€1,000 a month for your own pentester

One tester who knows your application and talks to your developers and your auditor himself.

  • Two test moments a year: a full test ahead of your audit window, a focused interim test six months later — your report is never older than six months
  • Fix session with your developers after every test
  • Your auditor’s questions I answer myself — all year, answers within one working day
  • Critical vulnerability in the stack I tested? Within one working day you’ll know if it affects you
  • Maximum 12 Annual plan clients and 2 full tests per month — Annual plan clients come first

Not included: a second application (fixed surcharge), building fixes and filling in complete customer questionnaires — answering a technical question is always fine.

Two single tests cost €13,000 — without everything in between.

Book a scoping call

Release Guard

€3,000/mo

An annual pentest is a photo. Your software is a film.

  • Everything in the Annual plan, plus: thinking along before the build and a delta test after every release — findings straight into your backlog
  • Delta test = a focused review of what changed; the annual full test remains the baseline
  • A security engineer on staff costs €8,000+ a month. This is the part you actually need.
  • Up to two days a month, spread across your releases. Need more? We agree that up front
  • 6-month minimum, monthly thereafter

What went live untested at your end? Send me your release notes from the past six months. Within a week you get a thirty-minute call in which I tell you which releases I would have wanted to see — and why.

Send your release notes

Same senior, same method, same report quality — whichever package you pick.

Included with every test

  • Verification retest within 90 days included, with a signed statement per round.
  • TPM (Third Party Memorandum) with every test, within your audit window.
  • No credits, no expiring hours, no platform fee.
  • The same senior does the call, the test and the debrief.

How it works

From first call to signed statement.

01Scoping call30 minutes, no strings. Then, under NDA: my name, certification numbers, proof of insurance and two references.
02Scope and NDASigned before we start.
03TestingA daily update — even when I found nothing. Critical finding? I flag it the same day, not just in the report.
04Draft reportYou ask questions.
05Debrief and retestUntil everything is fixed or formally accepted.

Planning

When can I start?

If this is ready today, I could in theory start tomorrow. In practice, signatures and accounts take days to weeks. Want it fast? Have these four ready before the scoping call.

01Scope confirmed — including your OpenAPI/Swagger spec, saves a day
02NDA and waiver signed
03Test accounts created, per user role
04Access works — representative environment with production-like data

Compliance

Pentest for SOC 2 and ISO 27001.

The scope aligns with your system description. Shipping continuously? Then an annual test plus ongoing verification (Release Guard) is possible — after alignment with your auditor. Handled factually, without drama.

01Report and TPM within your audit window
02Retest evidence for the auditor
03Scope follows your system description

For MSPs and IT partners

Your client asks for a pentest. From now on, you just say yes.

Co-branded: you sell and own the client relationship, I test. The report carries your logo and names CyberScore as the testing party — exactly what your client's auditor wants to see. No investment, no contract, fixed partner price per engagement.

Become a partner
CS

About me

17 years of offensive security across government, defence, finance, healthcare and critical infrastructure. CISSP and OSCP+. I work from the Netherlands, fully remote, for the whole EU.

Why there's no name or photo here: I work for government and defence. In that line of work, a small digital footprint isn't modesty, it's professional hygiene. What you don't see here, you get in the scoping call — my name, my certification numbers to verify yourself, my proof of insurance and two clients you can call. Under NDA, before you sign anything.

FAQ

Frequently asked questions

How do I know you are who you say you are?

In the scoping call, under NDA: name, certification numbers you verify live with ISC2 and OffSec, proof of insurance, Chamber of Commerce extract and two references you can call. Only then do you sign anything.

Isn't a manual pentest just an expensive scanner?

No — though I do use tooling where it speeds things up; the handwork is where it counts. A scanner finds what every scanner finds. I find what goes wrong when someone gives your application days of personal attention: logic flaws, authorisation issues, chains of small issues that add up to one big one. That's where the damage lives.

Why not an automated platform?

Pick the platform if you mainly want lots of endpoints scanned continuously and cheaply. Pick a senior when someone needs to understand your business logic and authorisation — and you need a TPM (Third Party Memorandum) that auditors and enterprise customers accept.

Can I use this report for ISO 27001, SOC 2, NIS2 or DORA?

Yes. The report follows OWASP WSTG and ASVS and contains what an auditor, insurer or customer wants to see: scope, methodology, findings and the reassessment after retest. If you don't fall under NIS2 yourself but received a security questionnaire from a customer, this is usually the evidence they're asking for. And no: NIS2 does not require quarterly pentests — an annual, risk-based assessment is sufficient. Anyone telling you otherwise is overselling.

What if you don't find anything?

Then you get a TPM that proves it. That's exactly the document you want to show customers and auditors. In practice I almost always find something; the question is how serious.

What if I just have a question in between?

Ask it. A reasonable question I'll simply answer, even outside a running engagement, and I won't send an invoice for it. That's how I prefer to work — and how I think about pricing too.

Do you also do network, cloud, TISO or vCISO work?

Yes, for existing clients, on request — TISO roles included. Delta testing lives in Release Guard.

A 30-minute call is enough to know whether this fits.

Your data is used only to respond. No spam, ever.

Prefer email? Send your scope to info@cyberscore.nl — within 24 hours on working days you'll know whether it fits in 5 days and what it costs.

Message sent

Thanks for reaching out. You'll hear from me within 24 hours on working days.

What I'll ask you

  1. How often do you release to production?
  2. Who asked for the pentest and what exactly do they want to see?
  3. Is there a SOC 2, ISO or NIS2 track running, and when is the deadline?
  4. What happened to the findings from your previous test?
  5. Who would be my point of contact?
Book a scoping call