Someone is going to try to break into your software. Let me be the first.
Manual web and API pentest by one senior tester — the same person you talk to, who tests, and who explains it to your auditor. €6,500 fixed, retest included.
I take on a maximum of 2 full tests per month.
Sound familiar?
Why one person
At a big firm, a senior sells and a junior tests.
With me, that's the same person. There is nobody to pass the blame to, so I do it properly. You talk to the tester, not an account manager. What I find, I explain myself.
What you get
The report is for you. The TPM is for everyone else.
The report is written for your team: reproduce, fix, done. Your customers, investors and auditor get the TPM — proof that things are in order, without your technical dirty laundry.
Tooling where it speeds things up, handwork where it counts. OWASP WSTG and ASVS Level 2, findings with CVSS. Never unfiltered scanner output.
Proof of concept per finding, so your dev team can reproduce it.
Executive summary for the board, technical report for the team.
Included within 90 days — until everything is fixed or formally accepted.
Entirely fictional: client, systems, findings and every name, address and contact detail in both documents are made up. Only the structure is real — that is exactly what you get.
Guarantees
What I put on the line.
Fixed price, fixed date, fixed result. If I don't deliver that, you won't feel it in your wallet.
Packages
Three options. No more.
Single pentest
€6,500 fixed
Within 15 working days of the start you'll have a TPM your customer, investor or auditor accepts. That's the deal.
- Critical finding? You hear it the same day, not in the report
- Report 3 working days after the last test day, or 20% off the invoice
Does this fit you? One web application with API, ±3 user roles, ±75 endpoints, one environment. Bigger? You'll hear it in the scoping call and get one fixed price up front.
Need another test next year? Then the Annual plan is cheaper than two single ones.
Book a scoping callAnnual plan
€12,000/yr
€1,000 a month for your own pentester
One tester who knows your application and talks to your developers and your auditor himself.
- Two test moments a year: a full test ahead of your audit window, a focused interim test six months later — your report is never older than six months
- Fix session with your developers after every test
- Your auditor’s questions I answer myself — all year, answers within one working day
- Critical vulnerability in the stack I tested? Within one working day you’ll know if it affects you
- Maximum 12 Annual plan clients and 2 full tests per month — Annual plan clients come first
Not included: a second application (fixed surcharge), building fixes and filling in complete customer questionnaires — answering a technical question is always fine.
Two single tests cost €13,000 — without everything in between.
Book a scoping callRelease Guard
€3,000/mo
An annual pentest is a photo. Your software is a film.
- Everything in the Annual plan, plus: thinking along before the build and a delta test after every release — findings straight into your backlog
- Delta test = a focused review of what changed; the annual full test remains the baseline
- A security engineer on staff costs €8,000+ a month. This is the part you actually need.
- Up to two days a month, spread across your releases. Need more? We agree that up front
- 6-month minimum, monthly thereafter
What went live untested at your end? Send me your release notes from the past six months. Within a week you get a thirty-minute call in which I tell you which releases I would have wanted to see — and why.
Send your release notesSame senior, same method, same report quality — whichever package you pick.
Included with every test
- Verification retest within 90 days included, with a signed statement per round.
- TPM (Third Party Memorandum) with every test, within your audit window.
- No credits, no expiring hours, no platform fee.
- The same senior does the call, the test and the debrief.
How it works
From first call to signed statement.
Planning
When can I start?
If this is ready today, I could in theory start tomorrow. In practice, signatures and accounts take days to weeks. Want it fast? Have these four ready before the scoping call.
Compliance
Pentest for SOC 2 and ISO 27001.
The scope aligns with your system description. Shipping continuously? Then an annual test plus ongoing verification (Release Guard) is possible — after alignment with your auditor. Handled factually, without drama.
For MSPs and IT partners
Your client asks for a pentest. From now on, you just say yes.
Co-branded: you sell and own the client relationship, I test. The report carries your logo and names CyberScore as the testing party — exactly what your client's auditor wants to see. No investment, no contract, fixed partner price per engagement.
Become a partnerAbout me
17 years of offensive security across government, defence, finance, healthcare and critical infrastructure. CISSP and OSCP+. I work from the Netherlands, fully remote, for the whole EU.
Why there's no name or photo here: I work for government and defence. In that line of work, a small digital footprint isn't modesty, it's professional hygiene. What you don't see here, you get in the scoping call — my name, my certification numbers to verify yourself, my proof of insurance and two clients you can call. Under NDA, before you sign anything.
References
Three tests, three audits passed.
Anonymised at the clients' request. Names and contact details are shared in the scoping call, with their consent.
[±80 endpoints, 3 roles]
[1 critical, 2 high]
[Retest clean after 3 weeks]
[SOC 2 Type II passed]
[±60 endpoints, 2 roles]
[0 critical, 3 high]
[Retest clean after 2 weeks]
[ISO 27001 passed]
[±100 endpoints, 4 roles]
[2 critical, 1 high]
[Retest clean after 4 weeks]
[NIS2 evidence delivered to customer]
FAQ
Frequently asked questions
How do I know you are who you say you are?
In the scoping call, under NDA: name, certification numbers you verify live with ISC2 and OffSec, proof of insurance, Chamber of Commerce extract and two references you can call. Only then do you sign anything.
Isn't a manual pentest just an expensive scanner?
No — though I do use tooling where it speeds things up; the handwork is where it counts. A scanner finds what every scanner finds. I find what goes wrong when someone gives your application days of personal attention: logic flaws, authorisation issues, chains of small issues that add up to one big one. That's where the damage lives.
Why not an automated platform?
Pick the platform if you mainly want lots of endpoints scanned continuously and cheaply. Pick a senior when someone needs to understand your business logic and authorisation — and you need a TPM (Third Party Memorandum) that auditors and enterprise customers accept.
Can I use this report for ISO 27001, SOC 2, NIS2 or DORA?
Yes. The report follows OWASP WSTG and ASVS and contains what an auditor, insurer or customer wants to see: scope, methodology, findings and the reassessment after retest. If you don't fall under NIS2 yourself but received a security questionnaire from a customer, this is usually the evidence they're asking for. And no: NIS2 does not require quarterly pentests — an annual, risk-based assessment is sufficient. Anyone telling you otherwise is overselling.
What if you don't find anything?
Then you get a TPM that proves it. That's exactly the document you want to show customers and auditors. In practice I almost always find something; the question is how serious.
What if I just have a question in between?
Ask it. A reasonable question I'll simply answer, even outside a running engagement, and I won't send an invoice for it. That's how I prefer to work — and how I think about pricing too.
Do you also do network, cloud, TISO or vCISO work?
Yes, for existing clients, on request — TISO roles included. Delta testing lives in Release Guard.
A 30-minute call is enough to know whether this fits.
Prefer email? Send your scope to info@cyberscore.nl — within 24 hours on working days you'll know whether it fits in 5 days and what it costs.
Message sent
Thanks for reaching out. You'll hear from me within 24 hours on working days.
What I'll ask you
- How often do you release to production?
- Who asked for the pentest and what exactly do they want to see?
- Is there a SOC 2, ISO or NIS2 track running, and when is the deadline?
- What happened to the findings from your previous test?
- Who would be my point of contact?