Looking for a penetration test? Fixed-scope engagements for GDPR, NIS2 & DORA.Get a quote today →
Request a Quote
Services · PTaaS

Penetration Testing as a Service

Continuous application security testing with live findings, direct remediation discussion, and an ongoing evidence trail — not a PDF you open once, file away, and hope still reflects reality eleven months later.

At a Glance
Engagement ModelSubscription, Monthly or Quarterly Cycles
Delivery FormatLive Findings Feed, Not a Single Report
Best ForTeams Shipping Continuously
FrameworksGDPR, NIS2, DORA, CRA

A once-a-year PDF stops being true the day your next release ships

A point-in-time pentest tells you what your risk looked like on the day it was run. Everything you ship afterwards — new features, new dependencies, new API endpoints — is untested until the next scheduled engagement, which for most companies is eleven or twelve months away.

What tends to happen with annual testing

  • The report gets filed away, opened again mostly when an auditor asks for it
  • Findings sit in a spreadsheet or ticket queue with no one checking they were actually fixed until the next test cycle
  • A vulnerability introduced in month two isn't caught until month twelve, if the next test even covers that part of the app
  • By the time findings are retested, months have passed since anyone discussed them with the person who tested

Why regulators are moving past this

  • NIS2 (Article 21) expects ongoing risk-management measures, not a single annual assessment
  • DORA's ICT risk management framework (Articles 6–16) is built around continuous monitoring, not a yearly snapshot
  • The Cyber Resilience Act requires handling vulnerabilities throughout the product's lifecycle, not just at release
  • An unresolved finding that sits open for months, undocumented, can itself become the compliance breach an auditor flags — not the original vulnerability

Testing that runs alongside how you actually ship software

Same manually-led methodology as a standard engagement, run continuously instead of once, with findings surfaced as they're confirmed.

01

Onboarding & Baseline

Weeks 1–2

A full manual assessment of your application as it stands today, establishing the baseline every future cycle builds on. This is scoped and run exactly like a standard engagement.

  • Access, roles, and documentation gathered once, reused across every subsequent cycle
02

Continuous Testing Cycles

Ongoing, Monthly or Per Release

Recurring manual testing aligned to your release cadence, targeted at what's changed since the last cycle — new endpoints, new features, new roles — plus a periodic sweep of the application as a whole.

  • Large diffs and codebases triaged with AI-assisted tooling, including Claude Code, to point manual effort at what actually changed
03

Live Findings & Direct Discussion

As Each Finding Is Confirmed

Findings are pushed to your live feed the moment they're manually verified, not held back for a final report. Each one has a direct line to discuss it with the person who found it: confirm intended behavior, ask about severity, or push back before it's marked as real.

  • No waiting weeks for a PDF to find out something critical was sitting open
04

Continuous Validation

As Fixes Ship

Once a fix ships, it's retested and marked verified in the same feed — not scheduled as a separate engagement months later. The record of what was found, discussed, fixed, and confirmed stays intact and exportable.

  • That record is exactly the evidence an auditor asks for under GDPR, NIS2, or DORA

A live feed, not a document you have to go looking for

Every finding is tagged with severity and the specific compliance control it touches, and tracked through to verification. Illustrative example below.

Broken object-level authorization on /api/invoices/{id}
Severity: HighGDPR Art. 32Confirmed 2 days ago
In Remediation
Missing rate limiting on login endpoint
Severity: MediumNIS2 Art. 21Confirmed 9 days ago
Open
Verbose error messages leaking stack traces
Severity: LowISO 27001Fixed 14 days ago
Fixed
Privilege escalation via role parameter tampering
Severity: CriticalDORA Art. 24–25Verified 21 days ago
Fixed & Verified

Illustrative example for format only. Your actual feed reflects your application and your findings.

Everything a point-in-time report gives you, plus the ongoing part

The live programme

  • A live findings feed, updated as issues are confirmed, not batched into a final document
  • Every finding tagged with severity and the exact framework article or control it maps to
  • A direct channel per finding to discuss, validate, or dispute it with the person who tested it
  • Defined response targets for critical and high findings, not "whenever the report ships"
  • Continuous retesting as fixes go out, tracked in the same feed

The audit trail

  • A complete, exportable history of every finding: when it was found, discussed, fixed, and verified
  • Evidence of an ongoing risk-management process, not a single annual snapshot
  • Formatted for direct submission to auditors or enterprise customers under GDPR, NIS2, DORA, or the Cyber Resilience Act
  • No gap between "when we tested" and "what's true right now"

One-off pentest vs. PTaaS

Point-in-Time Pentest
×A single snapshot, valid the day it was tested and steadily less accurate after
×Findings arrive all at once, weeks after testing started
×New features shipped after the test go untested until next year
×Retesting is a separate, scheduled engagement
×Evidence for auditors is a single dated PDF
PTaaS
Testing runs continuously, aligned to your actual release cadence
Findings are live the moment they're confirmed
New features are covered in the next cycle, not next year
Retesting is built into the same ongoing feed
Evidence is a live, exportable history of the whole remediation loop

Both are run manually, by the same team, to the same standard. PTaaS just removes the eleven-month gap where nothing gets checked.

Ready to move off the annual PDF?

Tell us about your application, release cadence, and compliance driver, and you'll get a proposal back covering onboarding and the ongoing cycle.