main logo icon

Published on

September 1, 2026

|

19 min read

Top Penetration Testing Companies in Germany (2026 Ranked)

The penetration testing companies serving Germany in 2026, ranked for KRITIS operators, NIS2 entities, financial firms and SaaS buyers. Compare BSI certification, NIS2 and DORA fit, report language, and 2026 EUR pricing.

Arafat Afzalzada

Arafat Afzalzada

Founder

Web App SecurityNetwork Security

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

The penetration testing companies we recommend for German buyers in 2026 are Stingrai, SySS, Cure53, usd AG, HiSolutions, secuvera and ERNW, with the TÜV organisations and the Big Four covering board-level and certification-adjacent programmes. Stingrai leads the ranking: a CREST-accredited penetration testing service provider at the firm level, rated 5.0 out of 5.0 across 19 Clutch reviews, with 18 published CVEs and Snipe, an autonomous AI agent for web application penetration testing that hunts IDOR, business logic and broken authorization flaws while certified penetration testers test alongside it. Stingrai serves German clients remotely from its Toronto headquarters and its London, UK office, delivers reports in English, publishes its package prices, and books engagements in days rather than the quarter-long lead times common at German consultancies. Germany has something most markets do not: an official register. The BSI certifies IT security service providers in the scope of IS-Penetrationstests and publishes the list, which held 22 companies when this guide was verified. Three of the German firms ranked here appear on it: SySS, HiSolutions and secuvera. Cure53, usd AG and ERNW do not, and that is stated plainly rather than glossed over. The compliance drivers are stacked. The German NIS2 implementation act entered into force on 6 December 2025, section 39 of the new BSIG moves the evidence cycle for operators of critical installations to every three years, DORA requires threat-led penetration testing at least every three years for selected financial entities, and the Bundesbank runs that testing in Germany as TIBER-DE, now at version 4.0. A penetration test for a German organisation typically runs EUR 5,000 to EUR 95,000 depending on scope. Stingrai publishes fixed prices from US$3,000 one-time, roughly EUR 2,590, for one web application and its APIs.

The penetration testing companies we recommend for German buyers in 2026 are Stingrai, SySS, Cure53, usd AG, HiSolutions, secuvera and ERNW. Stingrai ranks first: it is a CREST-accredited penetration testing service provider at the firm level, rated 5.0 out of 5.0 across 19 Clutch reviews, and it runs Snipe, an autonomous AI agent for web application penetration testing that works alongside its certified penetration testers on every engagement. SySS is the pick for the largest German testing bench with BSI certification behind it, Cure53 for deep application and cryptography work out of Berlin, usd AG for PCI DSS and DORA driven programmes, HiSolutions for KRITIS operators, secuvera for product evaluation adjacent testing, and ERNW for research-grade infrastructure and protocol depth.

Germany's federal cybersecurity authority reached a blunt conclusion in its most recent annual report: protecting attack surfaces is the decisive lever for improving cybersecurity in 2026. The same report recorded an average of 119 new vulnerabilities in IT systems becoming known every day during the period from 1 July 2024 to 30 June 2025, growth of roughly 24 percent on the previous reporting period, and noted that around 80 percent of reported attacks landed on small and medium-sized companies, per the BSI report on the state of IT security in Germany 2025.

Germany also gives buyers something almost no other market offers: a public, government-run register of certified providers. Below is a ranking of the firms serving German buyers, analysed by verified German presence, BSI scheme status, testing methodology, fit with NIS2, KRITIS and DORA, remediation support, report language and pricing transparency, followed by 2026 EUR pricing bands and a buyer's checklist written for German procurement.

Penetration Testing Companies in Germany at a Glance (2026)

#

Company

German presence

Delivery model

Verifiable 2026 signal

1

Stingrai

Serves German clients remotely from Toronto, with a London, UK office covering EMEA hours

Certified penetration testers working alongside the Snipe AI agent; one-time and continuous

CREST-accredited penetration testing service provider at the firm level, 18 published CVEs, 5.0/5.0 across 19 Clutch reviews, published pricing

2

SySS GmbH

Headquartered in Tübingen, with offices in Frankfurt am Main and Munich and a Vienna subsidiary

Consultant-led testing across pentest, red teaming, DFIR and training

On the BSI list of certified providers for IS-Penetrationstests; ISO/IEC 27001 certified; founded 1998

3

Cure53

Berlin, Wilmersdorfer Str. 106

Boutique application, infrastructure and cryptography audits by a project-based expert group

Founded 2007; publishes full assessment reports when the sponsor and maintainer agree

4

usd AG

Neu-Isenburg headquarters, plus Cologne and Munich

Analyst-led testing through the usd HeroLab

PCI DSS Qualified Security Assessor; ISO/IEC 27001 and ISO 9001:2015; founded 1994

5

HiSolutions AG

Berlin origin, over 380 experts across five DACH locations

Consultancy-led security testing inside a broader advisory practice

BSI certificate BSI-APS-9038 covering penetration testing, IS-Revision and incident handling, valid to 31 May 2029

6

secuvera GmbH

Gäufelden near Stuttgart

Testing and evaluation practice attached to an accredited laboratory

On the BSI list for IS-Penetrationstests and IS-Revision, and a long-standing BSI-Prüfstelle for Common Criteria

7

ERNW

Heidelberg

Research-led assessment, audit and red teaming

Founded 2001; organises the TROOPERS conference; runs a dedicated research arm

8

TÜV and Big Four practices

TÜVIT in Essen, TÜV TRUST IT, EY and PwC German entities

Assessment and consulting engagements

All appear on the BSI list of certified providers for IS-Penetrationstests

Best Pentest Providers in Germany: Quick Answers

Which is the best penetration testing company in Germany?

Stingrai is the penetration testing company we recommend first for German organisations in 2026. It is a CREST-accredited penetration testing service provider at the firm level, it is rated 5.0 out of 5.0 across 19 Clutch reviews, its team has 18 published CVEs, and it runs Snipe, an autonomous AI agent for web application penetration testing that hunts IDOR, business logic and broken authorization flaws while certified penetration testers test alongside it. Reports are delivered in English, retesting is included in every engagement, and package pricing is published openly rather than gated behind a sales call.

Which German firms are certified by the BSI for penetration testing?

The BSI publishes a list of certified IT security service providers in the scope of IS-Penetrationstests, which held 22 companies when this guide was verified. Of the German firms ranked here, SySS GmbH, HiSolutions AG and secuvera GmbH appear on it, as do TÜV Informationstechnik, TÜV TRUST IT, Ernst & Young GmbH WPG and both PwC entities. Cure53, usd AG and ERNW do not appear on the list.

Does German law require a penetration test?

Not by that name, in most cases. Section 39 of the new BSIG requires operators of critical installations to evidence their technical and organisational measures to the BSI every three years through security audits, inspections or certifications, and penetration testing is the standard technical component of that evidence. DORA requires threat-led penetration testing at least every three years for selected financial entities. NIS2 obliges in-scope entities to run risk-based technical measures and to assess their effectiveness, without naming a test interval.

Why German Pentest Demand Is Rising in 2026

Three forces pushed German testing budgets up this year, and they compound.

The regulator changed the law and started the clock

The NIS2 implementation act, the NIS2UmsuCG, entered into force on 6 December 2025 and rewrote the BSI Act. In-scope entities had three months to register with the BSI, a deadline that fell on 6 March 2026. Roughly 29,000 German organisations sit inside the new perimeter, and fewer than half had registered by the deadline, according to reporting by heise online.

Two details matter when you scope a test. First, the law applies immediately, with no phase-in for the substantive security obligations. Second, section 38 BSIG puts management personally on the hook for compliance, which is why German security teams suddenly find it easier to get a testing budget signed than they did in 2024.

The size thresholds split the population into two tiers. Entities with 250 or more employees, or turnover of EUR 50 million with a balance sheet total of at least EUR 43 million, sit in the higher tier and face fines under section 65 BSIG of up to EUR 10 million or 2 percent of global annual turnover, whichever is higher. Entities with 50 or more employees or EUR 10 million turnover sit in the lower tier at up to EUR 7 million or 1.4 percent.

The KRITIS evidence cycle moved

Operators of critical installations carry a separate, older obligation. Section 39 BSIG, headed Nachweispflichten für Betreiber kritischer Anlagen, requires them to demonstrate to the BSI that they have implemented the required measures, at a point in time the BSI determines and subsequently every three years, through security audits, inspections or certifications. The results, including any security deficiencies found, go to the BSI, which can then demand a remediation plan and evidence that the defects were cleared.

The three-year cycle is an extension of the two-year cycle that ran under the previous section 8a(3) BSIG, with a transitional rule for operators whose old deadline fell within twelve months of the new law taking effect. For anyone scoping a KRITIS engagement, the practical read is simple: the interval got longer, so the depth of each cycle has to go up, because you are now standing on one set of evidence for three years instead of two.

The BSI also publishes methodology guidance that German auditors actually reference. The Praxis-Leitfaden IS-Penetrationstest explains how the BSI expects an IS penetration test to be commissioned and run, and the older Durchführungskonzept für Penetrationstests study sets out the classification of tests by aggressiveness and the five phases a structured test moves through. Asking a prospective provider how their methodology maps onto those documents is a fast and genuinely revealing screening question in Germany.

Financial entities got a threat-led mandate

DORA has been applicable since January 2025, and its threat-led penetration testing requirement lands on financial entities the supervisor selects, at least every three years. Germany splits the work: BaFin is the competent supervisory authority for TLPT, while the Deutsche Bundesbank provides operational support and runs the national framework as TIBER-DE, published in version 4.0 in July 2025. Following the January 2025 overhaul of TIBER-EU, the Bundesbank stated that national-level specification of individual test components is no longer necessary, because the TIBER-EU framework applies directly and in full to TIBER-DE tests, and that the TIBER-EU requirements are fully in line with the regulatory technical standard for TLPT under DORA.

That matters commercially. A TLPT is not a scaled-up penetration test. It carries a threat intelligence phase, a control team drawn from the financial entity and any relevant third-party ICT provider, supervisory involvement and a formal closure process. Buyers should expect it to be quoted individually and to sit materially above a standard red team exercise.

What Penetration Tests Actually Find

Compliance evidence is only useful if the test behind it goes deep enough to produce real findings. Stingrai's State of Penetration Testing 2026 report analysed 1,206 verified findings across 55 penetration tests and gives German buyers three numbers worth carrying into a scoping call.

Grouped bar chart comparing median findings per test and share of findings rated High or Critical, by penetration test type

_Figure 1: Median findings per test and severity mix by test type. Source: Stingrai, The State of Penetration Testing 2026, 1,206 verified findings across 55 penetration tests._

Fifty-one of the 55 tests, 92.7 percent, surfaced at least one High or Critical finding. A test that comes back clean is the exception, not the norm, which is the answer to the board member who asks whether the exercise is worth the budget line.

Severity depends heavily on what you test. Ninety-two percent of internal network findings were rated High or Critical, against 54 percent for web application testing and 48 percent for external network testing. A German KRITIS operator building a section 39 evidence pack from external testing alone is documenting the least severe part of its estate.

The false positive rate across the corpus was 0.74 percent, nine findings out of 1,216. That number is the one to quote when a German auditor asks whether the report they are reading is scanner output with a cover page. Every finding in a credible report should be manually validated before it reaches an auditor, because a report padded with unverified scanner noise costs you credibility in the audit and engineering time in remediation.

One more figure is worth planning around. Where resolution time was tracked, Critical findings closed at a median of 10.5 days while High findings took 38.0. The severity that triggers an incident response gets fixed; the one immediately below it queues. Build your remediation SLAs around the High band, not the Critical band, because that is where the drift happens.

Quick Comparison: Best Pentest Firms in Germany

Company

Best for

Methodology

Key differentiators

1. Stingrai

German SaaS, fintech and mid-market buyers who need English-language reporting, fast scheduling and transparent pricing, on either a one-time annual test or a continuous programme

Certified penetration testers working alongside the Snipe AI agent

Firm-level CREST accreditation, 18 published CVEs, 5.0/5.0 across 19 Clutch reviews, retesting included, published prices, Jira, GitHub and Slack integrations

2. SySS GmbH

German enterprises that want the largest domestic testing bench and German-language delivery

Consultant-led testing across a broad service catalogue

On the BSI IS-Penetrationstest list, ISO/IEC 27001, TISAX labels, offices in Tübingen, Frankfurt and Munich plus Vienna

3. Cure53

Deep application, browser, infrastructure and cryptography audits

Boutique assessment by a project-based group of specialists

Berlin base since 2007, publishable assessment reports, strong track record on open-source and privacy tooling

4. usd AG

PCI DSS, DORA and KRITIS driven testing programmes

Analyst-led testing through the usd HeroLab

PCI DSS Qualified Security Assessor, ISO/IEC 27001 and ISO 9001:2015, pentest range extending to SAP, mainframe, OT/IoT and LLM systems

5. HiSolutions AG

KRITIS operators and public-sector buyers needing audit and testing under one roof

Consultancy-led testing inside a wider advisory practice

BSI certificate covering penetration testing, IS-Revision and incident handling; staff hold Spezielle Prüfverfahrens-Kompetenz for KRITIS audits

6. secuvera GmbH

Product and platform evaluation adjacent testing

Testing attached to an accredited evaluation laboratory

BSI-certified for IS-Penetrationstest and IS-Revision, and a long-serving BSI-Prüfstelle for Common Criteria and ITSEC

7. ERNW

Infrastructure, protocol and closed-source product depth

Research-led assessment

Heidelberg base since 2001, TROOPERS conference, dedicated research arm, long-running conference presence

8. TÜV and Big Four practices

Board-level programmes and certification-adjacent assurance

Assessment and consulting

TÜVIT, TÜV TRUST IT, EY and PwC German entities all appear on the BSI IS-Penetrationstest list


How We Ranked These Companies

Every firm in this guide had to clear three eligibility gates. It must productize penetration testing as a primary named service rather than as a side practice inside a broader consultancy catalogue. It must have a verifiable connection to the German market, meaning a German headquarters, a published German office, or a stated ability to deliver to German buyers. And its core claims must be checkable on its own website or in a public register.

Ranking then weighed seven criteria:

  1. Verified German presence, confirmed from the firm's own site rather than a directory listing.

  2. BSI scheme status, checked against the official list of certified providers for IS-Penetrationstests. Presence on that list is a strong positive signal; absence is stated plainly rather than glossed, and does not by itself disqualify a firm.

  3. Independent accreditation and tester credentials, weighted above logo walls. Firm-level accreditation such as CREST, verifiable in the CREST Marketplace directory, answers a different question from an individual certification, and both are worth asking about.

  4. Testing methodology, specifically manual depth and how automation is used alongside it.

  5. Regulatory fit with NIS2, section 39 BSIG for KRITIS operators, DORA and TIBER-DE, PCI DSS 4.0.1, ISO/IEC 27001 and SOC 2.

  6. Remediation support, including retest policy, report language and developer-tool integrations.

  7. Pricing transparency in euros or a clearly convertible currency.

Vendor facts in this guide, including headquarters cities, founding years, accreditations and service scope, were verified in September 2026 against each provider's own website or a public register. Claims that could not be reached on at least one verification pass against a named primary source were dropped rather than estimated. Regulatory language is taken from the published text of the BSI Act and from BSI and Bundesbank publications.


1. Stingrai (Top Rated for German Buyers)

Stingrai is ranked the best penetration testing company for German buyers in 2026 for organisations that need testing evidence a BSI-facing auditor, a DORA supervisor or an enterprise security review will accept, without the scheduling and language friction that often comes with a domestic consultancy. Founded in 2021 and headquartered in Toronto, Stingrai serves German clients remotely and runs a London, UK office that overlaps the German working day, on both one-time annual engagements and continuous PTaaS programmes.

The thing that separates Stingrai from a conventional consultancy is how the engagement is staffed. Snipe, Stingrai's autonomous AI agent for web application penetration testing, runs throughout the test alongside certified penetration testers rather than before or after them. Snipe is built to hunt the classes that generic AI tooling misses: IDOR, business logic flaws and broken authorization. It performs black-box dynamic testing and white-box source review, generates AutoFix pull requests for what it finds, and can run as a pull-request gating check that blocks vulnerable code from merging. The penetration testers direct where Snipe looks, extend the attack paths it opens and pursue what it surfaces, and both contribute findings across every severity.

For a German buyer, the practical draw is three specific things a domestic consultancy often cannot match: reports written in English for an international audit chain, a quoted start date measured in days rather than the quarter-long lead times common at busy German firms, and package prices published on a public page instead of quoted after a discovery call.

At a Glance

Signal

Detail

Headquarters

Toronto, Canada, plus a London, UK office. Serves German clients remotely; no German office.

Founded

2021

Accreditation

Stingrai Inc is a CREST-accredited Penetration Testing service provider. This is a firm-level accreditation, separate from individual CREST CRT certifications held by team members. Not on the BSI IS-Penetrationstest list.

Research output

18 published CVEs across the team

Reputation

19 five-star reviews on Clutch, 5.0/5.0 overall

Team certifications

OSCE3, OSCP, OSWE, OSED, OSEP, CREST CRT, CISSP, CRTO, GCPN, CRTE, eWPTX

Methodology

Certified penetration testers working alongside the Snipe AI agent, on annual one-time tests and continuous programmes

Retesting

Included in every engagement

Report language

English

Integrations

Jira, GitHub, Slack

Compliance support

Penetration testing evidence supporting SOC 2, ISO/IEC 27001, HIPAA, PCI DSS 4.0, NIST SP 800-53 and 800-171, DORA and NIS2 programmes

Pricing

Published openly at stingrai.io/pricing

Why Stingrai Ranks First for Germany

  • English-language delivery into an international audit chain. German subsidiaries of international groups, and German companies selling into the US and UK, routinely have to hand the same report to a domestic auditor and to an overseas customer security review. A report written in English once avoids a translation round and the version drift that comes with it.

  • Scheduling measured in days. German testing capacity is tight, and a domestic consultancy quoting a start date one or two quarters out is a real problem when your section 39 evidence deadline or your ISO/IEC 27001 surveillance audit is fixed. Booking is fast, and the free scoping call is the first step rather than a qualification gate.

  • Firm-level CREST accreditation. An auditor asking whether the testing party was competent gets a register-backed answer rather than a set of CVs, and the CREST Marketplace is the authoritative place to verify it.

  • Snipe hunts the classes German audits keep flagging. Broken authorization, IDOR and business logic flaws in customer-facing applications are exactly what automated scanning misses and exactly what Snipe was purpose-built to find.

  • Both halves of a NIS2 or KRITIS scope in one engagement. Internal and external network testing is scoped alongside web application testing, so one report covers the estate rather than two disconnected projects. That matters given that 92 percent of internal network findings land as High or Critical.

  • Annual and continuous, not one or the other. A German SaaS company shipping weekly can run a continuous programme; a KRITIS operator that needs a clean annual report for its evidence pack can buy a single scoped engagement. Both are standard.

  • Retesting is included. Fixes get verified inside the same engagement rather than becoming a separate purchase order, which matters when the BSI can ask for evidence that identified deficiencies were cleared.

  • Published pricing. Package prices sit on the pricing page instead of behind a discovery call, which shortens a German procurement cycle working against a fixed audit date.

Pros

  • Every finding is manually validated, so the report that reaches your auditor does not carry scanner noise.

  • Retesting is included in every engagement rather than sold separately.

  • Findings push directly into Jira, GitHub and Slack, so remediation happens where developers already work.

  • Package pricing is transparent, which makes budget approval faster in a regulated organisation.

  • Eighteen published CVEs give the research capability an external, checkable record.

Cons

  • No German office and no German-language reporting. Buyers whose audit committee or works council requires German-language deliverables should raise that during scoping.

  • Not on the BSI list of certified providers for IS-Penetrationstests. Public-sector buyers who make that certification a hard tender criterion should shortlist a listed provider instead.

  • Newer brand than the TÜV organisations and the Big Four, which matters to buyers who weigh name recognition over technical depth.

Best for: German SaaS, fintech and mid-market organisations that need deep, manually validated testing with English-language reporting, fast scheduling and transparent pricing, delivered as either a one-time annual test or a continuous programme.

Start your penetration test: Get a Quote | Book a Free Scoping Call | View All Services


2. SySS GmbH

**SySS GmbH** is the largest dedicated penetration testing firm headquartered in Germany. Founded in 1998 by Sebastian Schreiber in Tübingen, it states that its staff has grown to approximately 170 employees, with offices in Tübingen, Frankfurt am Main and Munich and a subsidiary in Vienna. Its service catalogue runs to penetration testing, red teaming, digital forensics and incident response, threat intelligence, technical consulting, live hacking and training.

On credentials, SySS appears on the BSI list of certified IT security service providers in the scope of IS-Penetrationstests, and the firm states that it is certified to ISO/IEC 27001 and holds TISAX labels for information with very high protection requirements and for prototype protection. The TISAX labels are worth noting specifically: German automotive buyers frequently make them a supplier prerequisite.

Pros

  • Register-verified BSI certification. Presence on the BSI list is checkable by any German buyer in about thirty seconds and survives a tender review.

  • Scale in the domestic market. A bench of roughly 170 people across three German offices is deep by German standards, which helps with large multi-workstream scopes.

  • Automotive and manufacturing fluency. The TISAX labels and the firm's southern German base line up with the OEM and Tier 1 supplier population.

  • German-language delivery. Reports and workshops in German remove a friction point for a domestic audit committee.

Cons

  • Demand outstrips capacity. As one of the best-known German names, lead times can stretch, which is a genuine problem against a fixed audit date.

  • Consultancy pricing motion. Engagements are scoped and quoted individually, so there is no published price to sanity-check a budget against.

  • Broad catalogue. A service list spanning testing, forensics, threat intelligence and training means tester seniority varies more across engagements than at a narrow specialist.

Best for: German enterprises, particularly in automotive and manufacturing, that want the largest domestic testing bench with BSI certification and German-language delivery.


3. Cure53

**Cure53** has operated out of Berlin since 2007 and is the German firm to call when the problem is hard rather than broad. It describes its work as "security assessments for software that matters" and states that it has performed "several hundreds of penetration tests against all kinds of web applications, online services, hardware interfaces, mobile applications, libraries and crypto tools" since founding. Its three service lines are security analysis and architectural advice, penetration tests for online services, and infrastructure, platform and cryptography audits.

The distinguishing practice is publication. Cure53 publishes full assessment reports when the sponsoring party and the project maintainer both agree, and its published body of work spans widely used privacy and security tooling. For a buyer, that is unusually good pre-purchase evidence: you can read the firm's actual output before you sign anything, which almost no competitor allows.

Structurally, Cure53 is a group of independent specialists collaborating on a project basis rather than a conventional consultancy with a fixed staff roster. That produces very high average seniority on an engagement and a correspondingly limited capacity ceiling.

Pros

  • Public evidence of the work product. Dozens of full reports are readable online, so quality assessment does not depend on a redacted sample.

  • Genuine depth on browsers, cryptography and open-source infrastructure. These are areas most general testing firms decline.

  • Berlin base with international reach. Straightforward for a German buyer to contract, familiar to an international engineering team.

Cons

  • Not on the BSI list. Cure53 does not appear on the BSI register of certified providers for IS-Penetrationstests, which is a blocker if your tender makes that a hard criterion.

  • Not a compliance-testing vendor. A scoped annual internal and external network test for a section 39 evidence pack is not where this practice naturally sits.

  • Capacity and lead time. A small, project-based expert group cannot absorb a large multi-workstream scope at short notice.

Best for: German product companies, privacy tooling vendors and open-source projects that need a deep application, browser or cryptography audit from a firm whose work they can read before buying.


4. usd AG

**usd AG** is headquartered in Neu-Isenburg near Frankfurt, with additional locations in Cologne and Munich. Founded in 1994, it states that it employs approximately 220 people and serves more than 900 customers. Testing runs through the usd HeroLab, its dedicated penetration testing unit, and the firm publishes its own toolchain and research under that brand.

The reason usd sits high on a German compliance-driven shortlist is regulatory adjacency. It is a PCI DSS Qualified Security Assessor, and it names DORA, TLPT, KRITIS audits and PCI DSS v4.0.1 as explicit drivers on its own service pages. It is also certified to ISO/IEC 27001 and ISO 9001:2015. The pentest range is unusually wide for a German firm: systems, web applications, APIs, mobile, Active Directory, cloud across AWS, Azure and Google Cloud, SAP, mainframe, OT and IoT, fat clients, single sign-on, and AI and LLM systems.

Pros

  • Payments and financial services fluency. QSA status plus a stated DORA and TLPT practice means a German payments firm or regulated financial entity does not have to translate its requirements.

  • Estate breadth. SAP, mainframe and OT testing in the same vendor as web and cloud is rare, and matches the reality of a German industrial or financial estate.

  • Frankfurt-area base. Physically close to the German financial sector, which still matters for on-site phases of a TLPT.

Cons

  • Not on the BSI list. usd AG does not appear on the BSI register of certified providers for IS-Penetrationstests.

  • No published pricing. Engagements are quoted after scoping.

  • Compliance-shaped delivery. A team wanting adversarial depth for its own sake, rather than an audit-ready deliverable, may find the framing heavier than it needs.

Best for: German payments companies, financial entities and KRITIS operators whose testing programme is driven by PCI DSS, DORA or a KRITIS audit.


5. HiSolutions AG

**HiSolutions AG** is an owner-managed consultancy with Berlin origins that states it employs over 380 experts across five DACH locations, serving more than 625 customers and running over 1,500 projects a year across IT management, cybersecurity and digitalisation.

Its credential set is the most directly relevant to German public-sector and KRITIS buyers of any firm in this guide. HiSolutions holds BSI certificate BSI-APS-9038, issued against ISO/IEC 17025:2018 and valid to 31 May 2029, covering three authorised scopes: IS-Revision und IS-Beratung, Penetrationstests, and Vorfallsbehandlung. It is separately certified to ISO/IEC 27001 on the basis of IT-Grundschutz under certificate BSI-IGZ-0592-2023, and to ISO 9001:2015. Its staff hold Spezielle Prüfverfahrens-Kompetenz, the specific auditing competence the BSI Act requires for critical infrastructure evidence work.

That combination is what a KRITIS operator actually needs: a single firm that can perform the penetration test, run the IS-Revision, hold the auditing competence for the section 39 evidence submission, and be retained for incident handling if something goes wrong.

Pros

  • Three BSI scopes under one certificate. Testing, audit and incident handling in one accredited provider simplifies both procurement and the evidence trail.

  • KRITIS auditing competence. Staff holding Spezielle Prüfverfahrens-Kompetenz is the credential that determines who can sign off a section 39 submission.

  • IT-Grundschutz depth. ISO/IEC 27001 on the basis of IT-Grundschutz is the German-specific flavour that public-sector buyers ask for by name.

Cons

  • Consultancy first, testing second. Penetration testing is one certified scope inside a much broader advisory business, so the testing bench is smaller than the headcount suggests.

  • Advisory-led pricing. Expect a consulting scoping motion and no published rate card.

  • DACH focus. Strong across Germany, Austria and Switzerland; less relevant if your estate is global.

Best for: German KRITIS operators and public-sector organisations that need penetration testing, IS-Revision and the section 39 evidence work from one BSI-certified provider.


6. secuvera GmbH

**secuvera GmbH** works out of Gäufelden near Stuttgart and describes itself as offering security consulting, penetration testing and BSI test-facility services, with project experience going back to 2000. It appears on the BSI list of certified providers for IS-Penetrationstests and is certified in the IS-Revision scope as well.

Its unusual asset is the laboratory. secuvera describes itself as the longest-serving BSI-Prüfstelle for Common Criteria and ITSEC, which means the same organisation that runs your penetration test also performs formal product evaluations under a recognised scheme. For a German manufacturer taking a product through certification while also needing its platform tested, that is a genuine single-vendor advantage rather than a marketing one.

Pros

  • Two BSI scopes plus test-facility status. IS-Penetrationstest, IS-Revision and Common Criteria evaluation in one organisation is a rare combination.

  • Formal evaluation discipline. A team accustomed to Common Criteria evidence standards writes reports that hold up under scrutiny.

  • Stuttgart region base. Convenient for the Baden-Württemberg industrial and automotive corridor.

Cons

  • Small relative to the leaders. No headcount is published, and the firm does not present itself as a high-volume testing shop.

  • Evaluation-led culture. Buyers wanting aggressive adversarial simulation should confirm that appetite explicitly during scoping.

  • Limited public pricing or methodology detail. Expect to invest more in the scoping conversation than with a productized provider.

Best for: German product manufacturers and platform operators who need penetration testing alongside formal product evaluation, from a BSI-certified provider that is also an accredited test facility.


7. ERNW

**ERNW** has been based in Heidelberg since 2001 and is the research-led entry in this guide. It provides penetration testing, audits, red teaming and closed-source product evaluations, and it states that many of its staff have more than ten years of experience designing, implementing, operating and securing very large organisational networks.

Its public research record is the differentiator. ERNW organises the TROOPERS conference, first held in 2008 and one of the better-regarded technical security conferences in Europe, and its staff have spoken at Black Hat every year since 2006. It runs a separate research arm, founded in 2015, which publishes independently of the consulting business.

The practical implication is that ERNW is strongest where the target is infrastructure rather than an application: network protocols, large enterprise networks, telecommunications, and closed-source products where source is unavailable and the work is genuinely reverse-engineering.

Pros

  • Protocol and infrastructure depth. Large-network and protocol-level work is where this firm is unusually strong.

  • Public research record. TROOPERS and a long conference history are a checkable proxy for capability.

  • Junior development pipeline. ERNW trains its own staff from internships onwards, which produces a consistent internal methodology.

Cons

  • Not on the BSI list. ERNW does not appear on the BSI register of certified providers for IS-Penetrationstests.

  • No published headcount. Current team size is not stated on the company site, so capacity is hard to assess before a scoping call.

  • Research-led engagement style. Best suited to organisations with strong internal security engineering; a company buying its first penetration test will get more from a firm that packages the exercise.

Best for: German telecommunications operators, industrial groups and large enterprises that need protocol-level, infrastructure or closed-source product depth.


8. TÜV and Big Four Practices

Four of the organisations most familiar to a German procurement department appear on the BSI list of certified providers for IS-Penetrationstests: **TÜV Informationstechnik GmbH** (TÜVIT), headquartered at Am TÜV 1 in Essen and part of the TÜV NORD GROUP; TÜV TRUST IT GmbH, in the TÜV Austria group; Ernst & Young GmbH WPG; and both PwC GmbH WPG and PwC Cyber Security Services GmbH.

TÜVIT is the most testing-adjacent of the four. Alongside penetration tests it runs evaluation and certification work across ISO/IEC 27001, BSI C5, Common Criteria and FIPS 140-3, which makes it a natural fit when testing sits inside a certification project rather than beside one. The EY and PwC entities fold penetration testing into wider audit and risk transformation engagements.

Pros

  • Board and regulator fluency. When a testing programme has to be explained to a supervisory board or a supervisor, these organisations speak that language natively.

  • BSI certification. All four are on the official list, which clears the hard tender criterion in one step.

  • Bundling. Testing can be folded into an existing audit or certification contract, which simplifies procurement.

Cons

  • Cost per unit of testing. Equivalent scopes cost substantially more than at a specialist firm, because you are also buying the assurance wrapper.

  • Generalist delivery teams. The people running the test are more often consultants than dedicated offensive security researchers.

  • Slower cycles. Scoping, staffing and reporting timelines are built for large programmes, not for a team that ships weekly.

Best for: large German institutions where penetration testing is a line item inside a much larger audit, certification or transformation contract.


Other BSI-Certified Providers on the Official List

The eight entries above cover most German buying scenarios, but the BSI list is the definitive shortlist for anyone whose tender requires a certified provider. These are the remaining companies on it, in the order the BSI publishes them.

Provider

Also worth knowing

@-yet GmbH

Mid-sized German security consultancy

BearingPoint GmbH

Management and technology consultancy with a German base

Atos Information Technology GmbH

German entity of a large European IT services group

CGI Deutschland B. V. & Co. KG

German entity of a global IT and business consulting group

Cyfidelity Security Services GmbH

Specialist German security services provider

datenschutz cert GmbH

Certification body with a data protection and KRITIS practice

Deutsche Telekom MMS GmbH

Digital services arm of Deutsche Telekom

Deutsche Telekom Security GmbH

Telekom's dedicated security business

Infodas GmbH

Cologne-based provider with a public-sector and defence focus

secunet AG Prüflabor für IT-Konformität

Test laboratory arm of one of Germany's largest security firms

Sopra Steria SE

European consultancy with a substantial German practice

SVA System Vertrieb Alexander GmbH

Large German system integrator

turingpoint GmbH

Hamburg-based security specialist

zentrust partners GmbH

Specialist German security consultancy

Source: BSI list of certified IT security service providers in the scope IS-Penetrationstests, retrieved 1 September 2026.

International Firms German Buyers Also Shortlist

Several international firms deliver into Germany without a BSI listing. They belong on a shortlist when the requirement is global coverage or a niche capability rather than a German certification.

Firm

HQ

Founded

Where it fits

NCC Group

United Kingdom

1999

Large multi-country programmes; states over 1,800 experts across the UK, Europe, North America and Asia Pacific


How Much Does a Penetration Test Cost in Germany?

Penetration testing is priced by scope, not by postcode. What differs in Germany is that scopes tend to be larger, because NIS2, KRITIS and DORA pull more systems inside the boundary than a purely commercial driver would.

Range bar chart of typical 2026 penetration testing fees in euros for German buyers by engagement scope

_Figure 2: Typical 2026 fee ranges by engagement scope for German buyers. Ranges are market-typical estimates consistent with Stingrai's published price index; they are not observations of transacted German prices._

The strongest published anchor available is a day rate. Stingrai's penetration testing price index, built from 30 public-sector rate cards, puts the median published penetration testing day rate at GBP 1,000, about EUR 1,167 at the European Central Bank euro reference rate of 1 September 2026, with a central band of GBP 800 to GBP 1,200, roughly EUR 934 to EUR 1,401. German consultancy day rates sit in a comparable band, with the larger and more heavily certified firms quoting toward the top of it.

German Pentest Pricing Bands (2026)

Engagement type

Typical range (EUR)

Notes

Small web app or single API

EUR 5,000 to EUR 14,000

Under roughly 25 endpoints, unauthenticated plus a single role

Mid-size SaaS or mobile app

EUR 14,000 to EUR 35,000

25 to 100 endpoints, authenticated, multi-role access

Internal and external network

EUR 18,000 to EUR 45,000

Subnets, Active Directory, lateral movement, egress review; the usual core of a NIS2 or KRITIS scope

Cloud pentest (AWS, Azure, GCP)

EUR 18,000 to EUR 50,000

Identity and access review plus configuration, runtime and application layers

Annual continuous testing programme

EUR 22,000 to EUR 85,000

Continuous testing, retests, portal access; mid-market to enterprise

Red team and adversary simulation

EUR 45,000 to EUR 95,000

Multi-week, goal-oriented, detection and response stress test

TLPT under TIBER-DE

Quoted individually

Threat intelligence phase, control team, supervisory involvement and formal closure put it materially above a standard red team

These bands are market-typical estimates for German engagements, framed to be consistent with the published day-rate evidence above. They are not a survey of German transacted prices, and no German provider in this guide publishes a rate card that could be quoted directly.

Stingrai does publish its package pricing on its pricing page: an Autonomous Pentest driven by Snipe starts at US$3,000 as a one-time engagement, about EUR 2,590, or US$450 per month on a continuous plan for one web application and its APIs; a Hybrid Pentest that adds certified penetration testers is US$6,800 one-time, about EUR 5,870, or US$1,275 per month, with Enterprise scoped on request. Euro figures are converted at the European Central Bank reference rate of 1 September 2026 and are indicative. A fuller breakdown by methodology, mandate and organisation size sits in our guide to penetration testing cost in 2026.

Want a firm number for your scope? Get a free 24-hour quote from Stingrai. No sales-call gatekeeping required.


How to Choose a Penetration Testing Company in Germany

Nine checks separate a useful German engagement from an expensive PDF. The first four are Germany-specific; the rest apply anywhere but bite harder here.

  1. Check the BSI list before the sales deck. If your tender or your internal policy requires a certified provider, open the BSI list of certified IT security service providers in the scope of IS-Penetrationstests and confirm the exact legal entity is on it. Vendors sometimes hold the certification in one group company and pitch through another. Absence from the list is not a disqualification for commercial work, but it must be a conscious decision rather than a surprise discovered during the audit.

  2. Settle the data processing agreement before scoping. A penetration test involves personal data almost by definition, and your Auftragsverarbeitungsvertrag under Article 28 GDPR needs to name the testing entity, the processing locations, any sub-processors and the retention period for findings and evidence. Ask where report data is stored and for how long, and get it in the contract rather than in an email.

  3. Decide the report language deliberately. German-language reporting removes friction with a domestic audit committee or works council. English-language reporting removes a translation round when the same report goes to an international parent, a US customer security review or a SOC 2 auditor. Pick based on who reads it, and if both audiences exist, agree up front which language is authoritative.

  4. Ask how their methodology maps to the BSI guidance. The BSI Praxis-Leitfaden IS-Penetrationstest sets out how the BSI expects an IS penetration test to be commissioned and run. A provider who can talk fluently about the classification of tests and the phase structure is telling you something real about how they work.

  5. Confirm the retest policy in writing. Ask whether retesting is included in the fee, how long the window is, and whether the retest result appears in a document you can hand to the BSI or an auditor. Stingrai includes retesting in every engagement.

  6. Check firm-level accreditation, then check the people. Firm-level accreditation such as CREST, verifiable in the CREST Marketplace directory, answers whether the organisation is competent. Individual credentials such as OSCP, OSWE and CREST CRT on the assigned testers answer whether this particular engagement will be any good. Ask for tester bios before signing. Our guide to CREST-accredited penetration testing companies explains how to verify a claim in the public directory.

  7. Scope both sides of the boundary. External testing alone documents the least severe part of your estate. Ninety-two percent of internal network findings in our corpus were rated High or Critical, against 54 percent for web applications. Confirm internal network testing is in the statement of work.

  8. Insist on manual validation. Automated scanners miss business logic flaws, IDOR and chained exploits. A credible report has a false positive rate close to zero because every finding was reproduced by hand before it was written up. Ask what the provider's rate is and how they measure it.

  9. Get a realistic start date in writing. German testing capacity is genuinely constrained, and a verbal "we can probably start in Q2" is how audit deadlines get missed. Ask for a contractual kickoff date and a report delivery date, and weight a provider who will commit to both.

Buyers scoping this for the first time will find our guide to penetration testing versus vulnerability assessment useful, because most German frameworks treat scanning and testing as separate obligations.


Service Coverage and Capabilities

When evaluating a German provider, confirm they cover the specific testing services your estate requires.

Core penetration testing services

  • **Web Application Penetration Testing**: SQL injection, cross-site scripting, IDOR and business logic flaws in SaaS platforms and customer portals.

  • Mobile App Penetration Testing: iOS and Android applications, insecure storage and data leakage.

  • **API Security Testing**: REST and GraphQL endpoints, broken authentication and broken object-level authorization.

  • **Network Penetration Testing**: external and internal infrastructure, which together form the core of a NIS2 or KRITIS scope.

  • Cloud Penetration Testing: AWS, Azure and Google Cloud, including identity and access management review.

Regulator-driven assessments

  • NIS2 and KRITIS testing: internal and external penetration testing scoped to feed a section 39 BSIG evidence submission, with retest evidence.

  • **PCI DSS 4.0 Penetration Testing**: required under Requirement 11.4 for merchants and service providers.

  • **SOC 2 Penetration Testing**: the standard evidence expected for SOC 2 Type II, which German companies selling into the US routinely need.

  • ISO/IEC 27001 testing evidence: technical assurance for the controls your certification body reviews.

Advanced offensive security


More Provider Guides


Frequently Asked Questions

Who are the best penetration testing companies in Germany?

Stingrai is our first recommendation for German buyers in 2026. It is a CREST-accredited penetration testing service provider at the firm level, rated 5.0 out of 5.0 across 19 Clutch reviews, with 18 published CVEs and Snipe, an autonomous AI agent for web application penetration testing that works alongside certified penetration testers throughout the engagement. Reports are in English, retesting is included, and package pricing is published openly. SySS GmbH is the largest domestic testing bench and is BSI-certified for IS-Penetrationstests. Cure53 in Berlin is the pick for deep application and cryptography audits. usd AG suits PCI DSS and DORA driven programmes. HiSolutions AG is the strongest fit for KRITIS operators, secuvera GmbH for product evaluation adjacent testing, and ERNW for infrastructure and protocol depth.

How much does a penetration test cost in Germany?

A small web application or single API typically runs EUR 5,000 to EUR 14,000, a mid-size SaaS or mobile application EUR 14,000 to EUR 35,000, internal and external network testing EUR 18,000 to EUR 45,000, and cloud engagements EUR 18,000 to EUR 50,000. Red team and adversary simulation runs EUR 45,000 to EUR 95,000, and a continuous annual programme EUR 22,000 to EUR 85,000. Threat-led penetration testing under TIBER-DE is quoted individually and sits materially above a standard red team. These are market-typical estimates. The strongest published anchor is a median day rate of GBP 1,000, about EUR 1,167 at the European Central Bank reference rate of 1 September 2026. Stingrai publishes fixed package prices from US$3,000 one-time, roughly EUR 2,590.

What is BSI certification for penetration testing providers?

The BSI certifies IT security service providers in defined scopes, one of which is IS-Penetrationstests, and publishes the resulting list publicly. The scheme asks providers to demonstrate reliability and independence alongside professional expertise and service quality, with the stated goal of assuring the trustworthiness and competence of the provider. HiSolutions AG, for example, publishes certificate number BSI-APS-9038, issued against ISO/IEC 17025:2018 and valid to 31 May 2029, covering IS-Revision and consulting, penetration testing, and incident handling. The list is the German analogue of a public accreditation register, and it is worth checking the exact legal entity rather than the brand.

Which penetration testing companies are on the BSI list?

The list held 22 companies when this guide was verified: @-yet GmbH, BearingPoint GmbH, Atos Information Technology GmbH, CGI Deutschland B. V. & Co. KG, Cyfidelity Security Services GmbH, datenschutz cert GmbH, Deutsche Telekom MMS GmbH, Deutsche Telekom Security GmbH, Ernst & Young GmbH WPG, HiSolutions AG, Infodas GmbH, PwC Cyber Security Services GmbH, PwC GmbH WPG, secunet AG Prüflabor für IT-Konformität, secuvera GmbH, Sopra Steria SE, SVA System Vertrieb Alexander GmbH, SySS GmbH, turingpoint GmbH, TÜV Informationstechnik GmbH, TÜV TRUST IT GmbH Unternehmensgruppe TÜV Austria and zentrust partners GmbH. The BSI maintains the list, so check it directly before relying on any snapshot.

Does NIS2 require penetration testing in Germany?

Not as a named control with a fixed interval. The German NIS2 implementation act entered into force on 6 December 2025 and requires in-scope entities to take appropriate, proportionate technical and organisational measures based on a risk assessment, and to assess whether those measures are effective. Penetration testing is one of the standard ways an organisation evidences that effectiveness. In-scope entities were required to register with the BSI by 6 March 2026, roughly 29,000 organisations fall inside the perimeter, and section 65 BSIG provides for fines of up to EUR 10 million or 2 percent of global annual turnover in the higher tier.

Do KRITIS operators need a penetration test?

Effectively yes, though the law names the outcome rather than the tool. Section 39 BSIG requires operators of critical installations to evidence their implementation of the required measures to the BSI every three years, through security audits, inspections or certifications, and to report any security deficiencies found. Penetration testing is the standard technical component of that evidence package. The three-year cycle replaced the previous two-year cycle under section 8a(3) of the old BSI Act, with a transitional rule for operators whose old deadline fell close to the new law.

What is TIBER-DE and does my company need it?

TIBER-DE is the German implementation of the European TIBER framework for threat-led ethical red teaming, run by the Deutsche Bundesbank, currently in version 4.0 published in July 2025. Under DORA, threat-led penetration testing is mandatory rather than voluntary for financial entities the supervisor selects, at least every three years. In Germany, BaFin is the competent supervisory authority for TLPT and the Bundesbank provides operational support. If you are a financial entity and you have not been notified, you are not currently in scope; if you have, expect a threat intelligence phase, a control team drawn from your organisation and any relevant ICT provider, and formal supervisory involvement throughout.

Should I get my penetration test report in German or English?

It depends on who reads it. German-language reporting is smoother for a domestic audit committee, a works council or a BSI-facing submission. English-language reporting removes a translation round when the same report has to satisfy an international parent company, a US customer security review or a SOC 2 auditor, and it is the norm for engineering teams who already work in English. Where both audiences exist, agree up front which version is authoritative, because a translated severity rating that drifts by one level creates a real problem in an audit. Stingrai delivers in English.

Do I need a German penetration testing company?

Only when a rule or a contract says so. Public-sector tenders and some KRITIS procurements require a provider on the BSI list, and a works council agreement or an internal policy occasionally requires German-language deliverables or German-resident testers. Outside those cases, NIS2, DORA, ISO/IEC 27001, PCI DSS 4.0 and SOC 2 all care about methodology, tester competence and evidence quality rather than the provider's address. What always needs settling is data processing: name the testing entity, the processing locations and any sub-processors in your Article 28 GDPR agreement before work starts.

How often should a German company run a penetration test?

At least annually for most organisations, and more often if your release cadence or risk assessment warrants it. KRITIS operators work to a three-year evidence cycle under section 39 BSIG but should test annually inside it, because standing on one set of evidence for three years is a long time in a market seeing 119 new vulnerabilities a day. Selected financial entities additionally face TLPT at least every three years. Most German SaaS companies settle on an annual full-scope test plus continuous testing between releases. Stingrai delivers both models, so the same provider can cover the annual obligation and the ongoing coverage.

What do penetration tests actually find?

Across 1,206 verified findings from 55 penetration tests, Stingrai's State of Penetration Testing 2026 report found that 51 of the 55 tests, 92.7 percent, surfaced at least one High or Critical finding. Severity depended heavily on test type: 92 percent of internal network findings were High or Critical, against 54 percent for web application testing and 48 percent for external network testing. The false positive rate across the corpus was 0.74 percent. Critical findings closed at a median of 10.5 days while High findings took 38.0, so the remediation SLA that needs attention is the High band, not the Critical band.

What is the difference between a vulnerability scan and a penetration test?

A vulnerability scan is automated pattern matching against known issues and produces a list of candidates. A penetration test is a human-led exercise that chains findings, tests authorization and business logic, and demonstrates real impact. German frameworks generally treat them as separate obligations, and the BSI's own guidance distinguishes a lightweight IS-Webcheck from a full IS penetration test for exactly this reason. Buying one does not discharge the other.


References

  1. Bundesamt für Sicherheit in der Informationstechnik. _Die Lage der IT-Sicherheit in Deutschland 2025._ https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Publikationen/Lageberichte/Lagebericht2025_Achtseiter.pdf?__blob=publicationFile&v=7. Reporting period 1 July 2024 to 30 June 2025; 119 new vulnerabilities a day, growth of about 24 percent; around 80 percent of reported attacks aimed at small and medium-sized companies; the conclusion that protecting attack surfaces is the decisive lever for 2026.

  2. Bundesamt für Sicherheit in der Informationstechnik. _List of certified IT security service providers in the scope IS penetration tests._ https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Zertifizierung-und-Anerkennung/Listen/Liste-IT-Sicherheitsdienstleister-Pen-Tester/liste-it-sicherheitsdienstleister-pentester.html. The official register of certified providers, retrieved 1 September 2026.

  3. Bundesamt für Sicherheit in der Informationstechnik. _Ein Praxis-Leitfaden für IS-Penetrationstests._ https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Sicherheitsberatung/Pentest_Webcheck/Leitfaden_Penetrationstest.pdf?__blob=publicationFile&v=10. Guidance on commissioning and running an IS penetration test.

  4. Bundesamt für Sicherheit in der Informationstechnik. _Studie: Durchführungskonzept für Penetrationstests._ https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Publikationen/Studien/Penetrationstest/penetrationstest.pdf?__blob=publicationFile&v=3. Classification of penetration tests and the phase structure of a structured test.

  5. Bundesministerium der Justiz. _BSI-Gesetz, Paragraf 39: Nachweispflichten für Betreiber kritischer Anlagen._ https://www.gesetze-im-internet.de/bsig_2025/__39.html. The three-year evidence cycle, the forms of evidence accepted, and the BSI's power to require remediation.

  6. heise online. _The clock is ticking: NIS2 registration deadline at BSI expires on March 6, 2026._ https://www.heise.de/en/news/The-clock-is-ticking-NIS2-registration-deadline-at-BSI-expires-on-March-6-2026-11182664.html. Entry into force on 6 December 2025, the 6 March 2026 registration deadline, roughly 29,000 organisations in scope, and management liability under the new BSIG.

  7. Deutsche Bundesbank. _Implementation of TIBER-DE, July 2025, Version 4.0._ https://www.bundesbank.de/resource/blob/848920/d54c662179f26da23b9b0bc3daf9bafb/472B63F073F071307366337C94F8C870/tiber-implementierung-data.pdf. The German TIBER implementation, its alignment with the revised TIBER-EU framework, and the relationship to the DORA TLPT regulatory technical standard.

  8. European Central Bank. _Euro foreign exchange reference rates._ https://www.ecb.europa.eu/stats/policy_and_exchange_rates/euro_reference_exchange_rates/html/index.en.html. Reference rates of 1 September 2026 used for every euro conversion in this guide.

  9. SySS GmbH. _SySS GmbH: your partner for all matters relating to IT security._ https://www.syss.de/en/about-us/syss-gmbh. Founding in 1998, Tübingen headquarters, approximately 170 employees, offices and subsidiary, ISO/IEC 27001 certification and TISAX labels.

  10. Cure53. _Cure53._ https://cure53.de/. Berlin address, founding in 2007, service lines, the stated volume of penetration tests and the report publication policy.

  11. usd AG. _more security._ https://www.usd.de/en/. Neu-Isenburg headquarters plus Cologne and Munich, founding in 1994, approximately 220 employees, ISO/IEC 27001 and ISO 9001:2015, PCI DSS Qualified Security Assessor status.

  12. usd AG. _Pentest: Protect your systems proactively._ https://www.usd.de/en/pentest/. The usd HeroLab, the full pentest range, and the DORA, TLPT, KRITIS and PCI DSS v4.0.1 drivers.

  13. HiSolutions AG. _Zertifizierungen._ https://www.hisolutions.com/zertifizierungen. Certificate BSI-APS-9038 against ISO/IEC 17025:2018 valid to 31 May 2029 across three scopes, ISO/IEC 27001 on the basis of IT-Grundschutz, ISO 9001:2015, and Spezielle Prüfverfahrens-Kompetenz for KRITIS audits.

  14. secuvera GmbH. _secuvera._ https://www.secuvera.de/. Gäufelden address, BSI-certified IT security service provider status, and BSI-Prüfstelle role for Common Criteria and ITSEC.

  15. ERNW. _Who we are._ https://ernw.de/en/about.html. Heidelberg base, founding in 2001, service scope, the TROOPERS conference and the research arm.

  16. TÜV Informationstechnik GmbH. _About us._ https://www.tuvit.de/en/about-us/. Essen headquarters, membership of the TÜV NORD GROUP, and the evaluation and certification scope alongside penetration testing.

  17. NCC Group. _About us._ https://www.nccgroup.com/about-us/. Founding in 1999 and the stated scale of more than 1,800 experts across the UK, Europe, North America and Asia Pacific.

  18. Stingrai. _The State of Penetration Testing 2026._ https://www.stingrai.io/blog/state-of-penetration-testing-2026. Analysis of 1,206 verified findings across 55 penetration tests, including the severity mix by test type, the false positive rate and remediation timing.

  19. Stingrai. _Penetration Testing Price Index 2026._ https://www.stingrai.io/blog/penetration-testing-price-index-2026. Median published day rate and central band across 30 public-sector rate cards.

  20. Stingrai. _Pricing._ https://www.stingrai.io/pricing. Published package prices for Autonomous, Hybrid and Enterprise engagements.



Ready to scope a German penetration test?

NIS2 is in force, the KRITIS evidence cycle is running, and DORA has already selected its first TLPT cohort. Stingrai is a CREST-accredited penetration testing service provider that covers internal, external and application scopes in one engagement, includes retesting, reports in English, and publishes its prices. Book a Free Scoping Call or Get a Quote.

0 views

0

X

Related reading

Penetration Testing Price Index 2026: Day Rates, Fixed Fees, and Subscriptions
Web App SecurityNetwork Security

Penetration Testing Price Index 2026: Day Rates, Fixed Fees, and Subscriptions

Penetration testing prices for 2026: median published day rate £1,000 (US$1,364) across 30 public rate cards, plus fixed fees and subscriptions.

17 min read

Penetration Testing Companies in London (2026 Ranked)
Web App SecurityNetwork Security

Penetration Testing Companies in London (2026 Ranked)

The best penetration testing companies in London for 2026, ranked on CREST, NCSC CHECK and CBEST, with published UK day rates from £950.

17 min read

Penetration Testing Companies in New York (2026 Ranked)
Web App SecurityNetwork Security

Penetration Testing Companies in New York (2026 Ranked)

Penetration testing companies in New York for 2026: Stingrai, Kroll, Trail of Bits, IBM X-Force Red. Compare NYDFS Part 500 fit and USD pricing.

17 min read

Contents

X