Continuous Penetration Testing
Continuous penetration testing that follows every release, not one date a year. Manual verified findings in a live portal. Fixed monthly price.
Continuous penetration testing keeps a human attacker pointed at your systems all year, not for one week in the spring. Between formal engagements your code ships, your infrastructure drifts, and new CVEs land weekly. A once-a-year test is blind to all of it, and this closes that gap.
Why point-in-time testing leaves a gap
The traditional model is simple and increasingly out of step with how software is built. You test once a year, get a report, fix what you can, and the certificate goes in a drawer. Meanwhile you deploy to production several times a week. Every one of those releases can introduce a vulnerability, and none of them are covered until the next annual test, by which point the window has been open for months.
Continuous penetration testing changes the cadence. Instead of a single snapshot, you get testing that follows your release cycle and your changing attack surface, with a human confirming each finding rather than a scanner throwing alerts over the fence.
How continuous testing works with us
The engagement runs as an ongoing relationship rather than a project with a start and end date. We keep a live map of your in-scope assets and re-test on the events that matter: a release, a new host appearing, a relevant CVE, or a scheduled deeper pass.
Baseline assessment
We begin with a full manual penetration test of the scope, the same depth you would expect from a standalone engagement. This establishes the baseline: every known issue found, rated and reported, so continuous testing from then on is watching a known-good state rather than starting blind.
Ongoing surface monitoring
Your external footprint is tracked continuously. When a new subdomain, port, service or application appears, it enters scope and gets looked at by a person, not just fingerprinted by a tool. Shadow IT and forgotten staging environments are exactly the things that get compromised, and they are exactly what an annual test misses.
Release-triggered testing
When you ship a significant change, we test the affected functionality. Authentication changes, new API endpoints, payment flows and permission model changes get manual attention, because those are where a regression becomes a real vulnerability. Smaller changes are covered by lighter checks so the cadence stays practical.
New-threat response
When a serious vulnerability lands in software you run, we check whether your instance is exposed and tell you, rather than leaving you to correlate a news headline with your own asset inventory. That turns a scramble into a short, calm message with a clear answer.
What we test on every cycle
The vulnerability classes do not change just because the cadence does. What changes is that we catch them within days of introduction instead of months later.
Web and API layer
Injection, broken access control and IDOR, authentication and session flaws, SSRF, and business-logic abuse across your applications and their APIs. New endpoints from a release get the same scrutiny as the originals.
Infrastructure and external surface
Exposed management interfaces, misconfigured services, weak TLS, and unpatched software on internet-facing hosts. This is where the continuous surface map earns its cost, because the risky thing is usually the host nobody remembered was public.
Configuration and identity drift
Cloud misconfigurations, over-permissive roles, storage that quietly became public, and credentials that appear in a repository. These drift in over time between formal tests, which is precisely the interval continuous testing is built to cover.
Manual testing with tooling underneath
Continuous does not mean automated-only. Plenty of vendors sell a rebranded vulnerability scanner on a subscription and call it continuous pentesting. We use automation for coverage and speed, to watch the surface and flag candidates, but a certified engineer confirms every finding before it reaches you. You never get a raw scanner dump with a hundred false positives to triage yourself. That is the whole difference between a tool and a test.
Want this tested on your own systems?
Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.
Reporting and the portal
Because the work is ongoing, so is the reporting. Findings appear in a portal as we confirm them, each with a severity, reproduction steps and a fix, and you can track remediation status in one place.
Live findings
No waiting for a quarterly PDF. A confirmed high-severity issue is in front of your team the same day, with everything needed to reproduce and fix it.
Point-in-time reports on demand
When you need a formal report for an auditor, a customer or a board, we generate one from the current state of findings, so your compliance evidence is always a click away rather than a project.
Who runs the testing, and how scope stays honest
The people doing the work are certified offensive engineers, the same testers behind our standalone engagements. A continuous model only works when the person watching your systems understands them, so we keep continuity: the engineer who ran your baseline knows your architecture, your quirks and your risky corners, and that context carries into every cycle. You are not starting from scratch with a new stranger each month.
Keeping scope current
Scope drift is the quiet enemy of continuous testing. Assets get added, environments get spun up for a demo and forgotten, a subsidiary launches something on a subdomain nobody told security about. We reconcile the live surface map against your agreed scope regularly and raise anything new, so testing follows reality rather than a document written a year ago. When something falls out of scope, we say so rather than quietly testing it.
Rules of engagement
Continuous does not mean unpredictable. We agree the rules once, in writing: which environments are fair game, which checks are considered intrusive and need a window, and who to call if a test ever appears to cause a problem. Those rules travel with the engagement, so your team is never surprised by a test and never has to re-authorize the basics every month.
How continuous testing changes your remediation loop
The real payoff is not just finding issues faster; it is fixing them faster and proving they stay fixed. When a finding lands in the portal the same day it is confirmed, your developers act on it while the relevant code is still fresh in their heads, rather than months later when the author has moved on and the context is gone.
Shorter exposure windows
The metric that matters is how long a vulnerability stays live in production. Annual testing measures that window in months. Continuous testing measures it in days, because the issue is found close to when it was introduced and retested close to when it was fixed. For an internet-facing application, that difference is the difference between a near miss and an incident.
Trend visibility over time
Because the work is ongoing, you can see whether your security is improving. Are the same classes of bug recurring release after release? Is a particular team shipping cleaner code than it did last quarter? The portal turns testing into a signal your engineering leadership can act on, not a once-a-year verdict with no context around it.
Feeding fixes back into your process
When a pattern repeats, the fix is usually upstream of the code. If the same authorization gap appears in three services, the answer is a shared library or a design standard, not three separate patches. We flag those patterns as they emerge and suggest where a guardrail in your pipeline or a check in code review would stop the class of bug at the source. Over a year that turns continuous testing from a safety net into something that measurably raises the baseline quality of what your team ships, which is a return no single annual report can offer.
Compliance and standards
Continuous testing supports frameworks that increasingly expect testing to reflect a changing environment rather than a single annual date. It maps to PCI DSS 4.0 requirement 11.4 for regular penetration testing and to the standard’s emphasis on ongoing security. It evidences the technical-vulnerability management expected under ISO/IEC 27001:2022 Annex A control A.8.8, and the continuous monitoring criteria under SOC 2, particularly CC7.1 and CC7.2. For organizations under DORA or NIS2 across Europe, testing that tracks the real state of systems supports the ongoing risk-management measures those regimes require.
Pricing
Continuous testing is a subscription priced by the size of your attack surface and the depth of coverage: how many applications and hosts are in scope, how often you release, and how much manual testing time each cycle needs. The baseline assessment is usually a one-off at the start, then a monthly plan runs the ongoing work.
| Plan | What’s covered | Cadence | Price |
|---|---|---|---|
| Surface Watch | External attack-surface monitoring, new-CVE checks against your stack, manual verification of flagged issues, portal access | continuous, monthly reporting | from €900/month |
| Active | Surface Watch plus release-triggered manual testing of one or two web apps and their APIs, remediation tracking | continuous + per release | from €1,800/month |
| Advanced | Broader scope, deeper per-release testing, authenticated multi-role coverage, on-demand point-in-time reports | continuous + per release | €3,000–€6,000/month |
| Baseline assessment | Full manual pentest at the start to establish a known-good state (one-off, precedes any plan) | 5–10 working days | from €2,500 |
| Custom / large estate | Many applications or a full environment, scoped to your release cadence after a call | on scoping | custom |
Every plan is fixed-price, quoted after a free 20-minute scoping call, with no hourly surprises and retesting built into the cadence. Get a fixed quote
FAQ
How much does continuous penetration testing cost?
How is this different from a vulnerability scanner subscription?
Do you test after every release?
Can I still get a formal report for an auditor?
Does this satisfy PCI DSS or SOC 2 testing requirements?
How fast do you retest a fix?
What happens when a big new CVE drops?
Will continuous testing disrupt production?
Related services
Teams shipping to production weekly, SaaS businesses whose attack surface changes constantly, and security leaders who know an annual test cannot represent a system that looks different every sprint.
Security you can prove
The same standard on every engagement, big or small.
Evidence, not opinions
Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".
Humans over scanners
Certified engineers find the logic flaws and chained attacks automated tools walk straight past.
Fixed price, free retest
You know the cost up front, and verifying the fix is part of the deal — not a second invoice.
Ready to lock this down?
Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.