Web pentest and NIS2 audit
Web penetration testing, black box or white box, and the technical side of a NIS2 audit, run by an OSWE-certified consultant. OWASP and PTES method, prioritized report, re-test included.
Black-box Web Pentest
Black-box web penetration test, no access to the code. The exact position of an external attacker.
No access, no account, no blueprint: exactly the position of an attacker discovering your application from the internet.
- Entry point
- €2,250 (5-day engagement)
- Best for
- An exposed web application nobody has actually attacked yet.
White-box Web Pentest
The code tells the truth. We read it line by line.
Source code, test accounts and architecture diagram on the table: the review reaches the business logic, where a black box stops.
- Entry point
- €3,000 (5-day engagement)
- Best for
- An application whose business logic carries most of the risk.
NIS2 Audit, technical side
Evidence that your NIS2 measures hold. Not another binder, a real test and the deliverables that go with it.
The technical scope only: effectiveness evidence for article 21.2 (f), a coverage matrix, a remediation plan. No governance work, and no NIS2 certificate, that does not exist.
- Entry point
- €2,250 (5-day engagement)
- Best for
- An entity in scope of NIS2 that has to demonstrate its measures work.
Net amounts. VAT not applicable (art. 293 B of the French tax code).
Between two engagements, the surface keeps moving
A penetration test describes a single moment. A domain registered the following week is not in it. That is what both platforms watch continuously.