Four distinct product families, transparent commercial routes and an indicative builder before technical scoping.
Trusted experience
Independent expertise organisations rely on.
Recognised organisations trust Pentesys for practical guidance, clear evidence and independently accredited security testing.
01Certification readinessFoundationCyber Essentials and Cyber Essentials Plus preparation, certification support and managed readiness.+
Cyber Essentials
Build the evidence and controls needed for assessment.
Readiness and evidence review
Prioritised remediation plan
Guidance through assessment
Clear next steps if gaps remain
i
What’s included?
Pentesys reviews the organisation boundary, questionnaire evidence and core technical controls, then provides practical actions and support through assessment.
Cyber Essentials Plus
Prepare for the independently verified technical assessment.
Technical pre-assessment
Device and control sampling
Remediation workshop
Assessment preparation pack
i
What’s included?
Preparation for hands-on technical assessment, including agreed sampling, control checks, evidence readiness and remediation guidance.
M
Foundation Managed
Keep evidence and readiness moving throughout the year.
Scheduled readiness checks
Advice sessions and action tracking
Maintained evidence status
Renewal planning
i
What’s included?
Ongoing support to maintain readiness between assessments and avoid a last-minute evidence exercise.
Build your Foundation route
Match support to your organisation.
02External attack surface management (EASM)ExposeContinuous visibility of what is publicly exposed, what has changed and what needs attention.+
Continuous CTEM visibility
Find the assets attackers can see.
Expose continuously discovers internet-facing assets, monitors change, prioritises weaknesses and supports remediation through the Pentesys Portal.
Continuous discovery and change monitoring
Prioritised exposure and vulnerability findings
Threat and leaked-credential visibility
Portal access and actionable reporting
i
What’s included?
Continuous external discovery, exposure and vulnerability monitoring, change alerts, threat context, leaked-credential visibility and prioritised findings.
What is a root domain?
The main registered address owned by your organisation—for example, pentesys.com. Addresses such as portal.pentesys.com and api.pentesys.com are subdomains beneath it.
What is an internet-facing asset?
Anything reachable from the public internet, such as a website, application, API, VPN gateway, mail service, cloud service, public IP address or development environment.
Estimate your Expose coverage
Before you build a test
Choose how you want to buy.
The right route depends on whether you need a single answer now or continuing assurance as your environment changes.
i
What’s included?
Who it suits: A compliance deadline, customer request, procurement requirement or specific change needing independent assurance.
i
What’s included?
Who it suits: Teams concerned that their environment will change after a point-in-time test or new public assets may appear unnoticed.
i
What’s included?
Who it suits: Changing, regulated or high-trust organisations that need continuing evidence rather than isolated reports.
Expose and Annual CTEM routes create a 12-month contract. Human inspections are scheduled through the year; scope can be increased through the Portal at any time and reduced for the next term at renewal. Agreements renew automatically unless cancelled with at least 30 days’ notice.
“Clear, prioritised actions built around real-world attack scenarios—not another generic report.”
CREST accreditedHuman expertise where judgement matters.
One platformScope, findings, remediation and evidence together.
03Penetration testing and continuous validationValidateAI-assisted or Human CREST testing of applications, APIs, networks, cloud and code.+
TYPICAL STARTING POINTS
Which looks most like your service?
Choose an example to load its indicative scope, then refine the bands and testing method below.
Public content and enquiry journeys
Brochure website
A public marketing website with a CMS, contact forms and no authenticated customer area.
Public pages and forms
CMS-facing behaviour
Core enquiry journeys
Common web security controls
Application plus documented API
Simple SaaS service
A straightforward SaaS product with user authentication, one main role and a documented API.
Registration and login
Authenticated application journeys
Up to 25 documented API endpoints
Basic role and session controls
Login, account data and payment journeys
Customer portal with payments
A customer-facing service with account recovery, sensitive profile data, payment flows and a larger API.
Login and account recovery
Customer and profile journeys
Payment and checkout flows
Up to 50 documented API endpoints
Choose scope components
Enter the number of coverage bands required. For example, enter 1 for up to 25 API endpoints, 2 for 26–50 or 3 for 51–75. Every change updates scope effort and price immediately.
Web application
i
What’s included?
Testing for one web application, one environment, up to 10 core user journeys and two authenticated roles. Each selected band includes prioritised findings and practical remediation guidance.
One web application and up to 10 user journeys per band.
API / web services
i
What’s included?
Testing of documented APIs and web services. Each selected band covers up to 25 endpoints and includes prioritised findings and remediation guidance.
Up to 25 documented endpoints per band. Enter 1 for 1–25, 2 for 26–50, and so on.
External network
i
What’s included?
Testing of internet-facing network services. Each selected band covers up to 25 public IP addresses and includes prioritised findings and remediation guidance.
Up to 25 public IP addresses per band. Enter 1 for 1–25, 2 for 26–50, and so on.
Internal network
i
What’s included?
Consultant-led testing for the agreed internal network. Each selected band covers up to 50 devices and assesses exploitable weaknesses, access paths and control effectiveness.
Human CREST testing onlyUp to 50 devices per band. Enter 1 for 1–50, 2 for 51–100, and so on. Human-led only.
Mobile application
i
What’s included?
Testing of one iOS or Android application. Each selected band covers one application on one platform and includes prioritised findings and remediation guidance.
One iOS or Android application on one platform per band.
Cloud Security Review
i
What’s included?
A security review of one cloud account or subscription, covering the agreed identity, configuration and exposure controls with prioritised findings and practical remediation guidance.
One Azure, AWS or Google Cloud account or subscription per band.
Social engineering
i
What’s included?
An authorised social-engineering assessment. Each selected band covers up to 25 recipients. Scenarios, safeguards, exclusions and success criteria are agreed before delivery.
Human CREST testing onlyUp to 25 recipients per band. Enter 1 for 1–25, 2 for 26–50, and so on. Human-led only.
Wireless security
i
What’s included?
A consultant-led wireless security assessment for one physical site per selected band, covering agreed networks, authentication controls and exposure paths.
Human CREST testing onlyOne physical site per band. Human-led only.
Code review / SAST
i
What’s included?
A source-code security review covering up to 50,000 lines per selected band, with prioritised findings mapped to affected code and practical remediation guidance.
Up to 50,000 lines of supplied source code per band.
Every Validate scope includes
Agreed technical scope and rules of engagement
Executive and technical reporting
Prioritised remediation guidance
One retest of reported findings within 60 days
Closure statement
04Red teaming and purple teamingAdversarySafely test whether realistic attackers can achieve agreed objectives—and whether your team can detect and respond.+
TYPICAL STARTING POINTS
Choose the level of challenge.
Choose the closest organisation profile, then refine the objectives below.
ORGANISATION PROFILE
Growing organisation
A focused exercise for a growing business that wants to understand whether a realistic initial foothold could reach sensitive information.
ORGANISATION PROFILE
Established mid-market
A broader exercise for an established organisation with Active Directory, a security team and business-critical data.
ORGANISATION PROFILE
Larger or regulated organisation
A deeper exercise spanning supply-chain and identity controls, cloud privilege, detection and incident response.
Choose objectives
Each objective carries configurable effort. Your price is calculated from the objectives selected.
Every Adversary scope includes
Formal rules of engagement
Agreed escalation and safety controls
Executive and technical reporting
Detection and control observations
Facilitated debrief
Common Questions
Useful answers before you request a quote.
Is this a formal quotation?+
No. The calculator provides an indicative value. Pentesys checks the selected scope, assumptions and testing method before issuing a formal quotation.
What does one coverage band mean?+
Each product explains its band beside the quantity field. For example, one API band covers up to 25 documented endpoints; two covers 26–50.
When should I choose Human CREST testing?+
Choose Human CREST testing where expert judgement, business logic, chained attack paths or independent CREST-led assurance are important. The scoping call will confirm the proportionate method.
Is there a separate setup or onboarding charge?+
No. The calculator prices the product packs and objectives you select; there is no separate standing setup charge.
Which options create an annual contract?+
Standalone is a one-off engagement. Standalone plus Expose CTEM and the Annual CTEM assurance programme create a 12-month agreement, as explained in the commercial-route section.
Indicative quotation
Get a copy of your quote.
Send your selected scope to Pentesys. We’ll check it and prepare a presentable quotation within four working hours.