Decision guide · Penetration Testing
Choosing a pentest vendor: TLPT, red team, classical pentest
Pentests are not a homogeneous market. TLPT, red-team operations, web-app pentest, cloud pentest, hardware pentest, social engineering and adversary simulation are different disciplines.
TL;DR
Define the discipline first, then pick the vendor. TLPT needs TIBER-EU experience, red team needs an own C2 capability.
Who owns this decision
CISO is owner. Compliance and Audit in the steering group for TLPT.
Key criteria to weight
Discipline specialisation
TLPT vendors are not necessarily good web-app testers and vice versa.
Tester qualification
OSCP, OSEP, CRT, GIAC GXPN, GCFA. Minimum filters, not gold standard.
Methodology
TIBER-EU, NIST 800-115, OWASP WSTG, MITRE ATT&CK.
EU sovereignty and data handling
Findings must not flow to US platforms.
Escalation and confidentiality path
On critical findings the communication path must be clear.
Report depth and reproducibility
PoC per finding, reproduction steps, business-language risk rating.
Step-by-step decision flow
- 1
Scope and discipline
What exactly is to be tested? Web app, cloud, internal network, AD, red team, TLPT?
- 2
Vendor longlist per discipline
TLPT: NCC Group, WithSecure, KPMG, Deloitte, EY, Mandiant. Web app / cloud: Cure53, SySS, secunet, NVISO, Bishop Fox. DACH: cirosec, ERNW, Compass Security.
- 3
Methodology review
Which methodology does the vendor run? Which tools, reporting structure, re-test clauses?
- 4
Contract clauses
Confidentiality, data sovereignty, GDPR Art. 28 DPA, re-test inclusion, findings ownership.
- 5
Memo, commission, test, report
Decision memo with vendor pick plus engagement letter plus testing window.
Compliance note
DORA Art. 24-27 (TLPT every 3 years), NIS2 Art. 21 (f), ISO 27001 A.12.7 and A.18.2, BAIT BTO 5.
Common pitfalls
- !Web app pentest is commissioned but a red team use case is meant. Wrong methodology.
- !TLPT without TIBER-EU experience. BaFin does not accept that.
- !Findings land in US SaaS platforms without EU DPA.
- !Re-test not fixed in the contract. Later upcharge.
FAQ
What exactly is TLPT?
Threat-Led Penetration Testing under DORA Art. 26-27. Methodologically aligned with TIBER-EU. Threat-intel-driven scenarios, tests in production, strict tester/customer separation. Mandatory at least every 3 years for significant financial entities.
What does a pentest cost?
Web app pentest 8-25 k EUR. Cloud pentest 15-40 k EUR. Red team 60-200 k EUR. TLPT 200-700 k EUR plus internal effort.
How often must one pentest?
Web apps: every major release, at least yearly. Cloud: annually. AD / internal network: annually. Red team: every 1-2 years. TLPT: at least every 3 years.
Related decision guides
Compliance
How to reach NIS2 readiness as a mid-market or enterprise operator
Compliance
How to reach DORA readiness as a financial entity
Compliance
ISO 27001:2022 recertification: a structured migration and renewal guide
Security
How to choose an EDR or XDR platform in 2026
Security
How to choose an IAM, IGA and PAM stack
Related comparisons
DecisionOS vs Excel and slide decks
Spreadsheets work until the second stakeholder shows up.
DecisionOS vs RFP tools
RFP tools automate Q&A. DecisionOS runs the decision.
DecisionOS vs procurement suites
Procurement suites execute the purchase. DecisionOS makes the decision.
DecisionOS vs Notion
Notion stores knowledge. DecisionOS produces decisions.
DecisionOS vs Confluence
Confluence is a wiki. DecisionOS is a decision record.
Relevant industries
Banken & Finanzdienstleister
Banken entscheiden unter DORA, MaRisk, BAIT gleichzeitig. DecisionOS liefert das Memo, das alle drei Prüfer akzeptieren.
Versicherungen
Versicherer entscheiden unter DORA + Solvency II + VAIT gleichzeitig. Ein Memo-Format für alle drei.
Energieversorger
Energieversorger: KRITIS + IT-SiG 2.0 + NIS2 + branchenspezifische Sicherheit. Memo muss vor BSI und BNetzA bestehen.
Telekommunikation
Telko entscheidet unter NIS2 + TKG §165 + BSI-Sicherheitskatalog gleichzeitig. Ein Memo, das alle Prüfer akzeptieren.
Manufacturing & Industrial
Manufacturing is a NIS2 important entity. OT security and supply-chain diligence are mandatory. The decision memo is the audit standard.
