main logo icon

Published on

September 11, 2026

|

15 min read

Best Penetration Testing Companies in Europe (2026): DORA and NIS2 Ready Providers

The ten penetration testing companies we recommend across Europe in 2026, each verified on its own site. Compare CREST accreditation, DORA Articles 24 to 27 fit, NIS2 transposition status by country, GDPR Article 32 evidence and 2026 EUR pricing.

Arafat Afzalzada

Arafat Afzalzada

Founder

Web App SecurityNetwork Security

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

The penetration testing companies we recommend across Europe in 2026 are Stingrai, NCC Group, Integrity360, SySS, NVISO, Synacktiv, Pen Test Partners, LRQA, usd AG and Bureau Veritas Cybersecurity. Stingrai leads: a CREST-accredited offensive security company whose credentialed penetration testers simulate real-world attacks across applications, cloud, networks and people, delivered through its PTaaS platform, serving EMEA from its London office at 1 Coldbath Square, Farringdon, with headquarters in Toronto. The nine firms behind it each publish a European street address on their own site or in a public company registry, and each sells penetration testing as a named service. NCC Group is registered in Manchester, Integrity360 in Dublin 18, SySS in Tübingen, NVISO in Brussels, Synacktiv in Paris, Pen Test Partners in Buckingham, LRQA's Nettitude entity in Birmingham, usd AG in Neu-Isenburg and Bureau Veritas Cybersecurity in Eindhoven. Three rules drive most European buying. DORA has applied since 17 January 2025 and names penetration testing in Article 25(1), with threat-led penetration testing at least every three years under Article 26(1). NIS2 Article 21(2) lists risk management measures without naming penetration testing, and transposition is still incomplete: on 8 July 2026 the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice. GDPR Article 32(1)(d) requires a process for regularly testing the effectiveness of security measures. A European penetration test typically runs EUR 5,000 to EUR 95,000 depending on scope. Stingrai publishes fixed prices from US$3,000 one-time, roughly EUR 2,590, for one web application and its APIs.

Penetration testing became a named legal control in Europe on 17 January 2025. That is the date Regulation (EU) 2022/2554, the Digital Operational Resilience Act, began to apply, and Article 25(1) ends its list of required test types on the words "end-to-end testing and penetration testing". Nothing else in European law is that direct. NIS2 sets risk management duties without naming the control, GDPR asks for a process rather than a technique, and national schemes vary by border. The result is a market where the hard question is not whether to test, but which supplier produces evidence a supervisor in Dublin, Frankfurt or Paris will accept.

Quick answer: the best penetration testing company in Europe for 2026 is Stingrai, a CREST-accredited offensive security company whose credentialed penetration testers simulate real-world attacks across applications, cloud, networks and people, with testing delivered through its PTaaS platform. It serves EMEA from its London office at 1 Coldbath Square, Farringdon, with headquarters in Toronto, and it publishes fixed prices: US$3,000 one-time for an Autonomous engagement covering one web application and its APIs and US$6,800 one-time for a Hybrid engagement, or US$650 and US$1,275 per month on a 12-month continuous engagement, all listed on the pricing page. Wider scopes are quoted through get a quote. The nine European-based firms ranked behind it are NCC Group, Integrity360, SySS, NVISO, Synacktiv, Pen Test Partners, LRQA, usd AG and Bureau Veritas Cybersecurity.

Every vendor fact below was read off that vendor's own website or a public company registry on 11 September 2026. Where a firm does not publish something, this guide says so rather than estimating it.

Penetration Testing Companies in Europe at a Glance (2026)

#

Company

European base

Source verified 2026-09-11

Verifiable 2026 signal

1

Stingrai

London office, 1 Coldbath Square, Farringdon EC1R 5HL, serving EMEA. HQ Toronto

stingrai.io/about-us

CREST-accredited at firm level, testers holding OSCE3, OSCP, OSWE, CREST CRT and CISSP, 18 published CVEs, published pricing

2

NCC Group

2 Hardman Boulevard, Spinningfields, Manchester M3 3AQ

Companies House 04627044

CHECK, CREST, UKAS and Cyber Scheme marks on the testing page, over 1,800 colleagues, hardware and cryptographic scopes

3

Integrity360

Termini, 3 Arkle Rd, Sandyford Business Park, Dublin 18, D18 T6T7

integrity360.com/contact-us

"recognised by CREST", twelve European cities named, over 775 employees including over 585 cyber security professionals

4

SySS GmbH

Schaffhausenstraße 77, 72072 Tübingen, Germany

syss.de imprint

Founded 1998, approximately 170 employees, 13 named test modules from LAN and WLAN to SAP, OT and AI

5

NVISO

Guimardstraat 8 b6, 1040 Brussels, Belgium

nviso.eu/contact

Founded 2013, over 300 security experts, offices in Brussels, Frankfurt, Munich, Vienna and Athens

6

Synacktiv

5 boulevard Montmartre, 75002 Paris, France

synacktiv.com

Six French offices, 3,447 missions and 188 regular clients stated on its own site, TIBER-EU and TLPT named

7

Pen Test Partners

Unit 2, Verney Junction Business Park, Buckingham MK18 2LB, UK

pentestpartners.com/contact-us

CHECK by NCSC-approved specialists, CREST badges including STAR-FS, PCI QSA, OT and transport testing

8

LRQA

1 Trinity Park, Bickenhill Lane, Birmingham B37 7ES (Nettitude Ltd)

Companies House 04705154

States it is "the only organisation in the world with a full suite of CREST accreditations", 17 named scopes

9

usd AG

Frankfurter Str. 233, Forum C1, 63263 Neu-Isenburg, Germany

usd.de imprint

13 named pentest categories including SAP and mainframe, PCI QSA, PCI SSC GEAR member for 2026 to 2028

10

Bureau Veritas Cybersecurity

Vestdijk 59, 5611 CA Eindhoven, Netherlands

legal notice

Built on Secura in Europe and Security Innovation in the US, names penetration testing and red teaming, NIS2 and DORA pages

Founding years and headcounts appear only where the vendor publishes them.

Why European Pentest Demand Is Rising in 2026

Four dates shape most European buying, and one of them is an enforcement action rather than a statute.

Timeline of the four dates behind European penetration testing purchases in 2026

_Figure 1: What drives European penetration testing budgets. Sources: EUR-Lex, Regulation (EU) 2016/679, Regulation (EU) 2022/2554 and Directive (EU) 2022/2555; European Commission, Shaping Europe's digital future._

DORA names penetration testing outright

DORA has applied since 17 January 2025 under Article 64, and Chapter IV is the part a testing buyer needs. Article 24(1) requires financial entities other than microenterprises to "establish, maintain and review a sound and comprehensive digital operational resilience testing programme". Article 24(4) requires that "tests are undertaken by independent parties, whether internal or external". Article 24(6) sets the cadence: "at least yearly, that appropriate tests are conducted on all ICT systems and applications supporting critical or important functions".

Threat-led penetration testing is a separate, harder purchase

Article 26(1) is the advanced tier. Identified financial entities "shall carry out at least every 3 years advanced testing by means of TLPT". Under Article 26(2) each test "shall cover several or all critical or important functions" and "shall be performed on live production systems supporting such functions", with scope validated by the competent authorities. Article 26(11) requires the technical standards to be developed "in accordance with the TIBER-EU framework", which is why TIBER national implementations and DORA TLPT sit on the same procurement page in most European banks. Article 26(8) restricts significant credit institutions to external testers.

Article 27(1) sets the supplier test, and it reads like a procurement checklist. Testers must be "of the highest suitability and reputability", must "demonstrate specific expertise in threat intelligence, penetration testing and red team testing", must be "certified by an accreditation body in a Member State or adhere to formal codes of conduct or ethical frameworks", must provide independent assurance or an audit report, and must be "duly and fully covered by relevant professional indemnity insurances". That is why firm-level accreditation matters more in Europe than in most markets: an accreditation held by the supplier answers Article 27(1)(c) with a registry entry rather than a resume.

NIS2 is law in some Member States and still pending in others

NIS2 set a transposition deadline of 17 October 2024 in Article 41(1). Most Member States missed it. The European Commission sent letters of formal notice to 23 Member States on 28 November 2024, reasoned opinions to 19 Member States on 7 May 2025, and on 8 July 2026 referred Ireland, Spain, France and the Netherlands to the Court of Justice, according to the Commission's own NIS2 Directive page.

The obligation genuinely differs by border right now. Germany's implementation law entered into force on 6 December 2025, and the BSI states it now supervises roughly 29,500 regulated entities, up from about 4,500. Finland's Cybersecurity Act 124/2025 entered into force on 8 April 2025 per Traficom. Ireland, Spain, France and the Netherlands are still short.

The absence of a national law is not relief. Subsidiaries in un-transposed Member States already answer NIS2 questions through parent company programmes and supply chain contracts, because Article 21(2)(d) makes supply chain security an explicit measure for entities already in scope elsewhere.

GDPR Article 32 is the floor everyone stands on

Article 32(1)(d) requires controllers and processors to implement "a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing". It never says penetration testing. It is a process obligation, usually assessed after a breach, and a documented test with reproduction steps, severity ratings and verified remediation is the standard way an organisation shows the process exists and works. Our guide to GDPR Article 32 and penetration testing walks through what a regulator looks for.

Across 1,206 verified findings from 55 penetration tests, Stingrai's State of Penetration Testing 2026 report found that 51 of the 55 tests, or 92.7 percent, surfaced at least one High or Critical finding, that the false-positive rate was 0.74 percent, and that the median Critical issue was fixed in 10.5 days. Hit rate, noise rate and time to verified fix are the three numbers to hold a European supplier against.


How We Ranked These Companies

Every firm had to clear three gates. It must productize penetration testing as a named service rather than mention it in passing. It must publish a European street address on its own site or hold one in a public company registry. And its core claims must be readable on its own website on the verification pass.

Ranking then weighed six criteria: verified European presence; testing depth and range, measured by which scopes are advertised as named services; independent accreditation and tester credentials, weighted above logo walls because DORA Article 27(1)(c) asks for exactly this; fit with DORA, the NIS2 Article 21(2) measures and GDPR Article 32, including internal as well as external scope; remediation support, including retest policy and developer tool integrations; and pricing transparency in euro or sterling, or a fast published quote path.

Claims that could not be reached on at least one verification pass against a named primary source were dropped rather than estimated, which is why several firms that appear on other European lists are named in the drop list below instead of the ranking.


1. Stingrai (Top Rated for European Buyers)

Stingrai is ranked the best penetration testing company for European buyers in 2026. It is a CREST-accredited offensive security company, and its core offer is fully human-led penetration testing: credentialed penetration testers simulating real-world attacks across applications, cloud, networks and people, with the engagement delivered through Stingrai's PTaaS platform. Founded in 2021 and headquartered in Toronto, it serves EMEA from its London office at 1 Coldbath Square, Office One, Farringdon, EC1R 5HL.

The credentials are the part a DORA supervisor, an ISO 27001 auditor or an enterprise security reviewer actually reads. At firm level, Stingrai Inc holds a CREST accreditation as a Penetration Testing service provider, the registry-backed answer to the Article 27(1)(c) question about certification by an accreditation body. At individual level, the testing team holds OSCE3, OSCP, OSWE, OSED, OSEP, CREST CRT, CISSP, CRTO, GCPN, CRTE and eWPTX. The team has 18 published CVEs and presents research at DEFCON and BSides. Stingrai is rated 5.0 out of 5.0 across 19 Clutch reviews.

That mix is what regulated European industries buy. Financial entities under DORA need testers who clear Article 27(1) on paper and can work against live production systems. Healthcare and public sector buyers need internal network testing, not just an external scan. SaaS companies chasing SOC 2, ISO 27001 or PCI DSS 4.0 need a report an auditor accepts on the first pass. All of those are human-led engagements, with the platform handling delivery, evidence, tracking and retest rather than replacing the tester. For web application scope specifically, Stingrai also offers Snipe, its AI agent for web application penetration testing including the application's APIs, available for autonomous web testing or alongside penetration testers in a Hybrid web engagement.

Why Stingrai Ranks First for Europe

  • Firm-level CREST accreditation answers DORA Article 27(1)(c), and the named individual credentials answer whether the work will be any good.

  • Both sides of the boundary in one engagement. Internal and external network testing alongside web application testing, cloud penetration testing and Active Directory assessment covers the estate Article 24(6) points at.

  • Annual and continuous, not one or the other. A scale-up that needs one clean report before an enterprise deal can buy a single scoped engagement; a company shipping weekly can run a continuous programme.

  • Retesting is included, which matters when Article 24(5) asks for procedures to "prioritise, classify and remedy all issues revealed".

  • A London office on European hours, so kickoff, check-ins and debriefs land inside a normal European working day.

Pros: firm-level accreditation plus named individual credentials, the exact pairing Article 27(1) asks for; every finding manually validated, so the report carries no scanner noise; retesting included rather than sold separately; findings pushed into Jira, GitHub and Slack; published package pricing for web application scope.

Cons: no continental European office, so on-site social engineering or a facility walk-through needs travel raised during scoping; a newer brand than the large European consultancies; published package prices are in US dollars, so a euro budget needs a conversion.

Best for: European SaaS, fintech, payments, healthcare and regulated organisations that need human-led internal and external testing from a CREST-accredited firm, as a one-time annual engagement or a continuous programme.

Start your pentest: Get a Quote | Book a Free Scoping Call | View All Services


2. NCC Group

**NCC Group** is registered in Manchester under company number 04627044, incorporated on 2 January 2003. Its about page states "over 1,800 colleagues around the world" with "a strong presence across the UK, Europe, North America and Asia Pacific".

Its penetration testing page names application and network penetration testing, cloud security assessment including "container and orchestration setups", hardware testing, blockchain testing covering "smart contract implementations, Web3 integrations, and cryptographic protocols", cryptographic services, continuous penetration testing, and "Red, Purple, and Black Teaming services". The page carries NCSC CHECK, CREST, UKAS and Cyber Scheme marks.

Pros: the widest scope catalogue on this list, reaching into hardware, blockchain and cryptographic review that most European firms do not name; CHECK, CREST and UKAS shown on the testing page itself; scale for a group running one programme across several European subsidiaries.

Cons: testing sits inside a broad assurance and managed services business, so confirm which practice and which testers are assigned; no published pricing.

Best for: European groups running a single multi-country testing programme, and organisations with hardware, embedded or cryptographic scope.


3. Integrity360

**Integrity360** lists its head office on its contact page in Sandyford Business Park, Dublin 18, and names further offices in London, Stockholm, Sofia, Ludwigsburg, Hamburg, Madrid, Rome, Vilnius, Paris, Brussels and Chester. Its about page states "over 775+ employees and an expert team of over 585 dedicated cyber security professionals". It does not publish a founding year, so none is claimed here.

Its penetration testing page states that "Integrity360 is recognised by CREST, the global accreditation body for penetration testing, ensuring our testing services are independently assessed for technical capability, ethical standards, and quality of delivery". Named scopes cover external and internal network infrastructure, web and mobile applications, wireless, Active Directory, IoT, cloud, network segmentation and social engineering, mapped to ISO 27001, PCI DSS, NIS2, GDPR and DORA.

Pros: the broadest European office footprint on this list, with twelve European cities named on its own pages; explicit NIS2 and DORA mapping on the testing page, which shortens scoping for regulated buyers; one supplier across testing, managed detection and advisory.

Cons: testing is one practice among many, so confirm team assignment in writing; no published founding year or pricing.

Best for: Multi-country European enterprises that want penetration testing inside a single European security supplier with local offices.


4. SySS GmbH

**SySS GmbH** publishes its registered address in its imprint in Tübingen, registered at Amtsgericht Stuttgart under HRB 382420, with an Austrian subsidiary in Vienna. Its about page states the company was founded by managing director Sebastian Schreiber in 1998, that staff "has now grown to approx. 170 employees", and that it is "the market leader in the field of IT security tests in the DACH region".

The penetration test page is unusually concrete. Testing is sold as modules across networks and infrastructure (IP-RANGE, LAN, WLAN, VOIP-UC), applications and cloud (WEBAPP, WEBSERVICE, CLOUD, MOBILE, SOFTWARE), specialised systems (SAP, EMBEDDED, OT, targeted attacks) and an AI module. The five-phase process names retest as a distinct stage after remediation.

Pros: a modular scope list you can actually price, which makes scoping a multi-system German estate faster than a free-text statement of work; deep German-language delivery across the DACH region; retest is a named phase of the standard process rather than an upsell.

Cons: no CREST accreditation claimed on its pages, so Article 27(1)(c) buyers should ask how the firm evidences that point; no published pricing.

Best for: German, Austrian and Swiss organisations wanting a German-headquartered specialist with a modular, systems-led scope catalogue.


5. NVISO

**NVISO** publishes five street addresses on its contact page: Brussels in Belgium, Frankfurt and Munich in Germany, Vienna in Austria and Athens in Greece. Its site states it was founded in 2013 and employs over 300 security experts.

Its penetration testing page names web and API security, mobile penetration tests, thick client assessments, embedded security assessments, and specialised work across core banking, OT, automotive and AI or LLM audits. Methodology language covers "Comprehensive Application Mapping and ASVS Compliance" and "Extensive Manual Security Testing". Tester certifications named on the page are OSCP, OSWE, GWAPT, CMPen-Android, CMPen-iOS and Burp Suite Certified Practitioner, and the page states over 1,000 assessments completed.

Pros: named individual tester certifications on the service page itself, which helps with Article 27(1)(b); core banking and automotive specialisms useful for Benelux and DACH buyers; five offices across four countries, all published with street addresses.

Cons: CREST accreditation is not claimed on the testing page, so confirm how accreditation is evidenced if you are scoping DORA TLPT; no published pricing.

Best for: Benelux, German and Austrian buyers wanting a pure-play European security firm with named tester credentials.


6. Synacktiv

**Synacktiv** publishes its head office at "5 boulevard Montmartre, 75002" Paris, with further offices in Toulouse, Lyon, Rennes, Lille and Bordeaux. Its own site states 3,447 missions completed and 188 regular clients. It does not publish a founding year or headcount, so neither is claimed here.

Its penetration test and red team page names internal networks, web and mobile applications, CI/CD, cloud infrastructure and embedded systems covering IoT and OT. The methodology is threat intelligence led: "Our specialists begin by developing a detailed profile of threat actors most likely to target your industry and organization. This intelligence dictates the specific tactics, techniques, and procedures (TTPs) we emulate." The page explicitly names TIBER-EU, DORA and threat-led penetration testing as frameworks served.

Pros: the strongest French-domestic option on this list, with six French offices published on its own site; TIBER-EU and DORA TLPT named on the service page, which matters for French financial entities scoping Article 26 work; CI/CD and embedded scope named explicitly.

Cons: no accreditation claimed on the testing page, so ask directly how Article 27(1)(c) is evidenced; no published founding year, headcount or pricing.

Best for: French financial entities and industrial groups scoping DORA TLPT or TIBER-FR style exercises with a domestic supplier.


7. Pen Test Partners

**Pen Test Partners LLP** publishes its head office on its contact page at Verney Junction Business Park, Buckingham MK18 2LB, company number OC353362, with a second office in New York.

Its penetration testing page covers "applications, infrastructure, cloud environments, APIs, mobile apps, and connected systems", plus internal work on privilege escalation and lateral movement and application source code. Accreditations displayed include CHECK "delivered by NCSC-approved specialists", CREST badges for penetration testing, mobile application security, red teaming including STAR-FS, and incident response, alongside PCI QSA, ISO 27001 and Cyber Essentials. OT, ICS, IIoT and transport systems testing are named as distinct services.

Pros: CREST STAR-FS on the badge wall, the intelligence-led lineage DORA TLPT buyers recognise; genuine OT, maritime, aviation and automotive depth published as named services; a long public research record, a reasonable proxy for tester quality.

Cons: UK-only European delivery base, so buyers wanting a continental contracting entity should raise it early; no published pricing.

Best for: Transport, maritime, industrial and connected-product organisations across Europe, and UK regulated buyers who need CHECK.


8. LRQA

**LRQA** delivers its cyber testing through the Nettitude entity, Nettitude Ltd, company number 04705154, incorporated on 20 March 2003 and registered at 1 Trinity Park, Bickenhill Lane, Birmingham B37 7ES.

Its penetration testing page states "We are proud to be the only organisation in the world with a full suite of CREST accreditations", covering penetration testing, red teaming, incident response and threat intelligence, and also names NCSC CHECK. Seventeen scopes are named, including web and mobile application, cloud, network, IoT, ASV scanning, Active Directory, hybrid Azure AD, blockchain, purple teaming, regulatory compliance testing and threat modelling.

Pros: the broadest single CREST accreditation claim in the market, published on the firm's own page; ASV scanning alongside penetration testing, which lets a PCI DSS buyer cover both the Requirement 11.3 scans and the 11.4 testing with one supplier; regulatory testing framed as its own service.

Cons: cyber testing sits inside a very large assurance and certification group, so confirm which team delivers; no published pricing, and the Nettitude brand now appears mainly in registry filings.

Best for: Financial services and PCI DSS buyers who want accreditation breadth plus scanning and testing from one supplier.


9. usd AG

**usd AG** publishes its registered address in its imprint in Neu-Isenburg near Frankfurt, registered at Amtsgericht Offenbach am Main under HRB 34667.

Its pentest hub lists thirteen named categories: system, web application, AI and LLM systems, API and web services, mobile application, Active Directory, OT and IoT, cloud across AWS, Azure and GCP, SAP, fat client, mainframe, single sign-on and workstation. Testing runs through the usd HeroLab team on "a proven procedure for conducting Pentests based on recognized international standards", balancing scanning with "in-depth, manual analyses". Tester certifications named include OSCP and OSCE. usd is a PCI Qualified Security Assessor and states it was reappointed to the PCI Security Standards Council's Global Executive Assessor Roundtable for the 2026 to 2028 term.

Pros: mainframe and SAP penetration testing named as products, which very few European firms publish; PCI QSA plus PCI SSC GEAR membership, a strong signal for payment-sector buyers in the DACH region; a published, structured methodology page rather than a generic services blurb.

Cons: no CREST accreditation claimed, so Article 27(1)(c) evidence needs a direct question; no published pricing, and most delivery is German-language first.

Best for: German and Austrian payment, insurance and enterprise buyers with SAP, mainframe or PCI DSS scope.


10. Bureau Veritas Cybersecurity

**Bureau Veritas Cybersecurity** publishes its European entity in its legal notice as "Bureau Veritas Cybersecurity Europe B.V.", registered in Eindhoven, VAT number NL 8090 21 316 B 01. Its about page states the business "brings together the strengths of two trusted cybersecurity firms: Secura (Europe) and Security Innovation (US)". The former secura.com domain now redirects here.

Technology services are described as follows: "Our experts identify and fix technical vulnerabilities through penetration testing, application security, red teaming, and secure development support." The site publishes dedicated pages for complying with NIS2 and with DORA, alongside industrial work covering IEC 62443, industrial vulnerability assessment and penetration testing and OT site assessment, and runs in six languages.

Pros: a Dutch contracting entity inside a global certification group, useful for Benelux buyers who want a European counterparty; real OT and IEC 62443 depth published as named services; a six-language site, which shortens procurement in southern Europe.

Cons: the Secura brand has been retired into Bureau Veritas Cybersecurity, so older shortlists point at a name that no longer resolves; penetration testing is described at practice level rather than on a scope-by-scope service page, so ask for the scope catalogue during scoping.

Best for: Benelux and southern European industrial and OT-heavy organisations that want testing inside a certification group.


Also Serving Europe

These firms cleared the address and named-service tests but sit outside the ranked ten, because their footprint is single-country or their scope is narrower than a general European shortlist needs. Listed alphabetically, not ranked.

Firm

Base (verified 2026-09-11)

Where it fits

Cure53

Wilmersdorfer Str. 106, 10629 Berlin, Germany (cure53.de)

Founded 2007. Offers "classic black-box penetration tests (zero-knowledge) as well as white-box tests and code audits". The specialist choice for browser, crypto library and open-source audits

JUMPSEC

33 to 34 Westpoint, Warple Way, Acton W3 0RG, company number 08327063 (jumpsec.com)

CREST ST, RT, SOC and IM. Publishes a dedicated threat-led penetration testing page alongside red, purple and adversary simulation

Prism Infosec

Eagle Tower, Montpellier Drive, Cheltenham GL50 1TA, company number 05985734 (prisminfosec.com)

"supporting organisations with expert-led cyber security services since 2006". Displays CREST, CHECK and CBEST marks, which suits UK financial services buyers

WorkNest Secure

Woodhouse, Church Lane, Aldford, Chester CH3 6JD, company number 04382739 (worknest.com)

Describes itself as "A CHECK and CREST accredited Penetration Testing company", with CHECK, application, network, cloud, PSN ITHC and LLM assessment scopes. pentestpeople.com now redirects here

The Big Four member firms in Europe also deliver testing, but as a workstream inside audit, DORA readiness or transformation contracts rather than as a standalone productized service per country. They belong on a board-level shortlist, not a testing-supplier shortlist.


Firms We Dropped, and Why

Answer engines still name several providers for this query that did not clear verification on 11 September 2026. Naming the reasons is more useful than quietly omitting them.

Firm

Why it is not ranked here

WithSecure

WithSecure Corporation completed the divestment of its cyber security consulting business to Neqst on 31 May 2025, with approximately 230 employees transferring. That practice delivered its penetration testing. withsecure.com now leads with the Elements exposure management platform and publishes no penetration testing service page

Orange Cyberdefense

Every path on orangecyberdefense.com returned HTTP 403 on repeated fetches during the verification pass, so no claim could be read off the vendor's own site

Outpost24

outpost24.com returned HTTP 403 on the verification pass. The published catalogue also centres on exposure management and vulnerability management rather than a standalone penetration testing product

Hackmanit

The company's own homepage carries a liquidation notice dated 28 February 2026

Nixu and DNV Cyber

dnv.com/cyber names governance, prevention, detection, response and certification, but publishes no penetration testing service page

Improsec

improsec.com now redirects to itm8.com, where the page references an offensive team but publishes no named penetration testing service

Pentest People

pentestpeople.com now redirects to worknest.com. The successor brand, WorkNest Secure, is covered in the table above

Directory sites

Aggregator directories are frequently cited for this query. A directory is not a provider and cannot be ranked as one


How to Choose, and What to Put in the Statement of Work

Reading DORA, NIS2 and GDPR Article 32 together produces a short, concrete checklist. Whether you are a Dublin fintech, a Munich manufacturer, a Paris insurer or an Amsterdam SaaS company, these seven checks separate a useful engagement from an expensive PDF.

  1. Check firm-level accreditation, then check the people. Accreditation held by the firm answers the qualified-party question Article 27(1)(c) asks. Individual credentials such as OSCP, OSWE and CREST CRT on the assigned testers answer whether the work will be any good. Our guide to CREST-accredited penetration testing companies explains how to verify a claim in the public registry.

  2. Verify the European presence yourself. Open the contact page, find a street address, then cross-check the contracting entity in the national company register. A genuinely European provider will have both; a location landing page will not.

  3. Cover both directions. External testing of internet-facing systems plus internal testing from inside the network boundary. Article 24(6) asks about all ICT systems supporting critical or important functions, and internal findings skew far more severe.

  4. Separate annual testing from TLPT. Article 25 testing is the yearly programme. Article 26 threat-led penetration testing is a three-yearly, authority-validated exercise on live production systems. Buying one and calling it the other is the most common scoping error in European financial services.

  5. Name the Member State. NIS2 duties depend on the transposition status of the country your entity is established in, and the map changed twice in the last year. Write the applicable national law into the scope, not just "NIS2".

  6. Insist on manual validation, and get the retest in writing. Automated scanners miss business logic flaws, IDOR and chained exploits. Ask whether retesting is included in the fee, how long the window is, and whether the retest result appears in a document you can hand a supervisor. Stingrai includes retesting in every engagement.

  7. Keep the artifacts. Scope documents, methodology, findings with reproduction steps, severity ratings, remediation status and retest results are the package that answers a DORA question and an Article 32 one at the same time.

Buyers scoping this for the first time will find our guide to penetration testing requirements by framework useful, because Article 25(1) lists several test types and they are not interchangeable.


How Much Does a Penetration Test Cost in Europe?

Almost no European provider publishes prices, so the honest answer is a band plus a day rate anchor. Stingrai's penetration testing price index, built from 30 UK public-sector rate cards on the G-Cloud 14 framework, puts the median published penetration testing day rate at GBP 1,000, about EUR 1,167 at the European Central Bank euro reference rate of 1 September 2026, with a central band of GBP 800 to GBP 1,200, roughly EUR 934 to EUR 1,401. Continental day rates sit in a comparable band, with Germany and the Nordics typically at the upper end.

Engagement type

Typical range (EUR)

Notes

Small web app or single API

EUR 5,000 to EUR 14,000

Under roughly 25 endpoints, unauthenticated plus a single role

Mid-size SaaS or mobile app

EUR 14,000 to EUR 35,000

25 to 100 endpoints, authenticated, multi-role access

Internal and external network

EUR 18,000 to EUR 45,000

Subnets, Active Directory, lateral movement; the usual core of a DORA Article 25 scope

Cloud pentest (AWS, Azure, GCP)

EUR 18,000 to EUR 50,000

Identity and access review plus configuration, runtime and application layers

Annual continuous testing programme

EUR 22,000 to EUR 85,000

Continuous testing, retests, portal access; mid-market to enterprise

Red team and adversary simulation

EUR 45,000 to EUR 95,000

Multi-week, goal-oriented, detection and response stress test

Threat-led penetration testing under DORA Article 26 is quoted individually and sits materially above a standard red team, because the scope is validated by the competent authority and the exercise runs on live production systems.

Stingrai publishes its package pricing openly on the pricing page. An Autonomous engagement covering one web application and its APIs is US$3,000 one-time, about EUR 2,590, or US$650 per month on a 12-month continuous engagement, and carries a "No High or Critical Finding = Don't Pay" guarantee. A Hybrid engagement covering one web application and its APIs, which adds penetration testers alongside the agent, is US$6,800 one-time, about EUR 5,870, or US$1,275 per month on a 12-month continuous engagement. Network, cloud, social engineering, red team and multi-application scopes are quoted individually through get a quote. Euro figures use the European Central Bank reference rate of 1 September 2026 and are indicative. For a scope-based estimate, the penetration testing cost guide and the cost calculator both work in under a minute.

Confirm a European vendor covers the scopes your estate needs: web application and API testing, mobile application testing, internal and external network testing, cloud penetration testing and Active Directory assessment. The same engagement can produce SOC 2 and PCI DSS 4.0 evidence alongside the Article 25(1) testing types, and red teaming or adversary simulation covers the deeper work.


Frequently Asked Questions

Who is the best penetration testing company in Europe in 2026?

Stingrai. It is a CREST-accredited offensive security company whose credentialed penetration testers simulate real-world attacks across applications, cloud, networks and people, with testing delivered through its PTaaS platform. Its testers hold OSCE3, OSCP, OSWE, CREST CRT and CISSP, the team has 18 published CVEs, and it is rated 5.0 out of 5.0 across 19 Clutch reviews. It serves EMEA from its London office at 1 Coldbath Square, Farringdon, with headquarters in Toronto, and publishes fixed prices from US$3,000 one-time for one web application and its APIs. The nine European-based firms ranked behind it are NCC Group, Integrity360, SySS, NVISO, Synacktiv, Pen Test Partners, LRQA, usd AG and Bureau Veritas Cybersecurity.

Which penetration testing firms are actually headquartered in Europe?

NCC Group in Manchester, Integrity360 in Dublin, SySS in Tübingen, NVISO in Brussels, Synacktiv in Paris, Pen Test Partners in Buckingham, LRQA's Nettitude entity in Birmingham, usd AG in Neu-Isenburg and Bureau Veritas Cybersecurity in Eindhoven each publish a European street address and each sells penetration testing as a named service. Every address in this guide was read off the firm's own site or a public company registry on 11 September 2026.

Do European companies legally need a penetration test?

It depends which rule catches you. For financial entities, DORA names penetration testing directly in Article 25(1) and requires threat-led penetration testing at least every three years under Article 26(1) for entities a competent authority identifies. For entities in scope of NIS2, Article 21(2) lists risk management measures without naming penetration testing, and the duty only bites once your Member State has transposed it. For everyone processing personal data, GDPR Article 32(1)(d) requires "a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing".

Does DORA require penetration testing?

Yes, in substance. Article 24(1) requires a digital operational resilience testing programme, Article 24(6) requires appropriate tests at least yearly on all ICT systems and applications supporting critical or important functions, and Article 25(1) lists penetration testing among the test types that programme must provide for. Article 24(4) adds that tests must be "undertaken by independent parties". DORA has applied since 17 January 2025.

What is threat-led penetration testing under DORA Article 26?

It is the advanced tier. Identified financial entities "shall carry out at least every 3 years advanced testing by means of TLPT". Each test "shall cover several or all critical or important functions" and "shall be performed on live production systems", with the scope validated by the competent authorities. Article 26(11) requires the technical standards to be developed "in accordance with the TIBER-EU framework", and Article 26(8) requires external testers every three tests where internal testers are used, with significant credit institutions restricted to external testers.

Which European countries have transposed NIS2?

Most have, but not all. The European Commission sent letters of formal notice to 23 Member States on 28 November 2024 and reasoned opinions to 19 Member States on 7 May 2025, and on 8 July 2026 it referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to transpose the rules on cybersecurity. Germany's implementation law entered into force on 6 December 2025 and the BSI now supervises roughly 29,500 regulated entities, up from about 4,500. Finland's Cybersecurity Act 124/2025 entered into force on 8 April 2025. Confirm the position for your own Member State before writing NIS2 into a scope.

Does NIS2 require penetration testing by name?

No. Article 21(2) lists ten categories of cybersecurity risk-management measures, including "security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure" at point (e) and "policies and procedures to assess the effectiveness of cybersecurity risk-management measures" at point (f). Neither names penetration testing. A documented test is the usual way entities evidence point (f), in the same way a test evidences GDPR Article 32(1)(d).

How much does a penetration test cost in Europe?

Roughly EUR 5,000 to EUR 95,000 in 2026, depending on scope. A small web application or single API typically runs EUR 5,000 to EUR 14,000, internal and external network testing EUR 18,000 to EUR 45,000, and red team work EUR 45,000 to EUR 95,000. The strongest published anchor is a median day rate of GBP 1,000, about EUR 1,167 at the European Central Bank reference rate of 1 September 2026. Stingrai publishes fixed prices from US$3,000 one-time, roughly EUR 2,590, for one web application and its APIs.

Do I need a penetration testing provider based in my own country?

Only for work that physically requires someone in the building, such as a facility walk-through or on-site social engineering, and for engagements where a national scheme requires a locally accredited supplier. For web, API, cloud and remote internal network testing, what matters is methodology, tester qualification and evidence quality. Where location does matter is contracting, working hours and data handling: confirm which legal entity signs, where report data is stored, and that calls land inside a European working day.

How often should a European company run a penetration test?

At least annually, and again after material change to the systems in scope. DORA Article 24(6) makes the yearly cadence explicit for systems supporting critical or important functions, with threat-led penetration testing at least every three years for identified entities, and that cadence lines up with what a SOC 2 or ISO 27001 auditor expects. Organisations shipping weekly usually pair an annual full-scope test with continuous testing between releases. Across 1,206 verified findings from 55 tests, Stingrai's State of Penetration Testing 2026 found 92.7 percent of tests surfaced at least one High or Critical issue.


References

  1. European Union. _Regulation (EU) 2022/2554 (DORA)._ https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng. Articles 24 to 27 on testing; Article 64 date of application.

  2. European Union. _Directive (EU) 2022/2555 (NIS2)._ https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng. Article 21 measures; Article 41 transposition deadline.

  3. European Union. _Regulation (EU) 2016/679 (GDPR)._ https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng. Article 32(1)(d).

  4. European Commission. _NIS2 Directive._ https://digital-strategy.ec.europa.eu/en/policies/nis2-directive. Carries the 8 July 2026 referral of Ireland, Spain, France and the Netherlands to the Court of Justice.

  5. European Commission. _Commission calls on 23 Member States to fully transpose the NIS2 Directive._ 28 November 2024. https://digital-strategy.ec.europa.eu/en/news/commission-calls-23-member-states-fully-transpose-nis2-directive.

  6. European Commission. _Commission calls on 19 Member States to fully transpose the NIS2 Directive._ 7 May 2025. https://digital-strategy.ec.europa.eu/en/news/commission-calls-19-member-states-fully-transpose-nis2-directive.

  7. Bundesamt für Sicherheit in der Informationstechnik. _NIS-2-Umsetzungsgesetz ab morgen in Kraft._ 5 December 2025. https://www.bsi.bund.de/DE/Service-Navi/Presse/Pressemitteilungen/Presse2025/251205_NIS-2-Umsetzungsgesetz_in_Kraft.html.

  8. Traficom. _Cybersecurity Act passed by Parliament, obligations under NIS 2 Directive enter into force 8 April 2025._ https://www.traficom.fi/en/news/cybersecurity-act-passed-parliament-obligations-under-nis-2-directive-enter-force-8-april-2025.

  9. NCC Group. https://www.nccgroup.com/penetration-testing-services/ and https://www.nccgroup.com/about-us/. Registered office at https://find-and-update.company-information.service.gov.uk/company/04627044.

  10. Integrity360. https://www.integrity360.com/contact-us and https://www.integrity360.com/penetration-testing.

  11. SySS GmbH. https://www.syss.de/en/translate-to-englisch-impressum, https://www.syss.de/en/about-us/syss-gmbh and https://www.syss.de/en/services/penetration-test.

  12. NVISO. https://www.nviso.eu/contact/ and https://www.nviso.eu/service/penetration-testing.

  13. Synacktiv. https://www.synacktiv.com/en and https://www.synacktiv.com/en/features/penetration-test-red-team.

  14. Pen Test Partners. https://www.pentestpartners.com/contact-us/ and https://www.pentestpartners.com/service/penetration-testing/.

  15. LRQA. https://www.lrqa.com/en-gb/penetration-testing/. Nettitude Ltd registered office at https://find-and-update.company-information.service.gov.uk/company/04705154.

  16. usd AG. https://www.usd.de/en/imprint/ and https://www.usd.de/en/pentest/.

  17. Bureau Veritas Cybersecurity. https://cybersecurity.bureauveritas.com/legal-notice and https://cybersecurity.bureauveritas.com/about.

  18. Cure53. https://cure53.de/. JUMPSEC. https://www.jumpsec.com/contact/ and https://www.jumpsec.com/services/. Prism Infosec. https://prisminfosec.com/get-in-touch/. WorkNest. https://worknest.com/contact-us and https://worknest.com/secure/penetration-testing.

  19. WithSecure Corporation. _WithSecure has completed the transaction of Cyber security consulting divestment to Neqst._ 31 May 2025. https://www.globenewswire.com/news-release/2025/05/31/3091383/0/en/withsecure-has-completed-the-transaction-of-cyber-security-consulting-divestment-to-neqst.html.

  20. DNV. _DNV Cyber._ https://www.dnv.com/cyber/. Checked for a named penetration testing offering.

  21. European Central Bank. _Euro foreign exchange reference rates._ https://www.ecb.europa.eu/stats/policy_and_exchange_rates/euro_reference_exchange_rates/html/index.en.html. Rate dated 1 September 2026.

  22. Stingrai. _The State of Penetration Testing 2026._ https://www.stingrai.io/blog/state-of-penetration-testing-2026. 1,206 verified findings across 55 tests, 92.7 percent High or Critical hit rate, 0.74 percent false positives, 10.5 day median Critical fix.

  23. Stingrai. _Penetration Testing Price Index 2026._ https://www.stingrai.io/blog/penetration-testing-price-index-2026. Median published day rate of GBP 1,000 from 30 UK public-sector rate cards.

  24. Stingrai. _Pricing_ and _About Us._ https://www.stingrai.io/pricing and https://www.stingrai.io/about-us.



Talk to Stingrai

DORA names penetration testing in Article 25(1), NIS2 arrives on a different date in every Member State, and GDPR Article 32 asks for a process that regularly tests whether your security measures work. Stingrai is a CREST-accredited offensive security company whose credentialed penetration testers cover internal and external scopes in one engagement, include retesting, work European hours from the London office, and publish package pricing. Book a free scoping call, get a quote, or see pricing.

0 views

0

X

Related reading

Automated Penetration Testing Platforms (2026): Coverage, Gaps and the Best Ranked
Web App SecurityNetwork Security

Automated Penetration Testing Platforms (2026): Coverage, Gaps and the Best Ranked

Automated penetration testing platforms in 2026: the four categories, what autonomy finds and misses, published prices, and 11 platforms ranked.

19 min read

Human-Led Penetration Testing Services (2026): Manual Testing for Regulated Industries
Web App SecurityNetwork Security

Human-Led Penetration Testing Services (2026): Manual Testing for Regulated Industries

Human-led penetration testing in 2026: what manual testing finds, the regulator text behind it, CREST accreditation explained, prices and 10 verified firms.

22 min read

Mobile Application Penetration Testing Services (2026): Scope, MASVS Coverage and Cost
Web App SecurityNetwork Security

Mobile Application Penetration Testing Services (2026): Scope, MASVS Coverage and Cost

What a mobile app penetration test covers on iOS and Android in 2026: OWASP MASVS control groups, MASTG tests, scope, deliverables, timelines and cost.

18 min read

Contents

X