main logo icon

Published on

September 5, 2026

|

16 min read

Best Penetration Testing Companies in Ireland (2026): Dublin, Cork and Remote Providers

The penetration testing companies serving Ireland in 2026, ranked for Dublin and Cork buyers. Compare verified Irish presence, DORA Articles 24 to 27 fit, NIS2 transposition status, GDPR Article 32 evidence and 2026 EUR pricing.

Arafat Afzalzada

Arafat Afzalzada

Founder

Web App SecurityNetwork Security

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

The penetration testing companies we recommend for Irish buyers in 2026 are Stingrai, Integrity360, Edgescan, CommSec, Smarttech247 and PFH Technology Group. Stingrai leads the ranking: a CREST-accredited penetration testing service provider at the firm level, rated 5.0 out of 5.0 across 19 Clutch reviews, running Snipe, an autonomous AI agent for web application penetration testing that works alongside certified penetration testers, with retesting included in every engagement and package pricing published openly. It serves Irish clients remotely from its Toronto headquarters and its London office, which shares Ireland's time zone. The five Irish-based firms behind it each publish an Irish street address on their own contact pages and each productizes penetration testing as a named service. Integrity360 runs its head office in Sandyford, Dublin 18. Edgescan, founded in 2017, works from Northwest Business Park in Dublin 15. CommSec works from the LINC Building at TU Dublin in Blanchardstown. Smarttech247 lists Cork first among its offices. PFH Technology Group holds offices in Dublin, Cork and Galway. Three rules drive most Irish buying. DORA has applied since 17 January 2025 and names penetration testing directly in Article 25(1), with threat-led penetration testing at least every three years under Article 26(1) for entities the Central Bank of Ireland identifies. NIS2 is not yet transposed in Ireland. GDPR Article 32(1)(d) requires a process for regularly testing the effectiveness of security measures, without naming penetration testing. A penetration test for an Irish organisation typically runs EUR 5,000 to EUR 95,000 depending on scope. Stingrai publishes fixed prices from US$3,000 one-time, roughly EUR 2,590, for one web application and its APIs.

The penetration testing companies we recommend for Irish buyers in 2026 are Stingrai, Integrity360, Edgescan, CommSec, Smarttech247 and PFH Technology Group. Stingrai ranks first: it is a CREST-accredited penetration testing service provider at the firm level, rated 5.0 out of 5.0 across 19 Clutch reviews, and it runs Snipe, an autonomous AI agent for web application penetration testing that works alongside its certified penetration testers on every engagement. The five Irish-based firms behind it each publish a street address in Ireland on their own contact page and each sells penetration testing as a named service, which is the cleanest way to separate a real Irish provider from a location landing page.

Ireland's data protection regulator recorded 6,521 valid personal data breach notifications in 2025, a 16 percent decrease on 2024, while new cases from individuals rose 45 percent to 16,160, according to the Data Protection Commission's 2025 Annual Report. Almost half of those breaches came from correspondence sent to the wrong recipient, which is a process failure rather than an exploit. The technical half of the problem is where testing earns its budget, and in 2026 an Irish financial entity has a regulation that names the control outright.

Below is a ranking of the firms serving Ireland's financial entities, SaaS companies, public bodies and multinational subsidiaries, analysed by verified Irish presence, testing depth, independent accreditation, fit with DORA and GDPR Article 32, remediation support and pricing transparency. We also include 2026 EUR pricing benchmarks and a buyer's checklist.

Penetration Testing Companies in Ireland at a Glance (2026)

#

Company

Irish presence

Founded

Verifiable 2026 signal

1

Stingrai

Serves Irish clients remotely from Toronto, with a London office in Ireland's time zone

2021

CREST-accredited penetration testing service provider at the firm level, 5.0/5.0 across 19 Clutch reviews, published pricing

2

Integrity360

Head office at Termini, 3 Arkle Road, Sandyford Business Park, Dublin 18, D18 T6T7

Not published

Recognised by CREST, states 775+ employees and 585+ dedicated cyber security professionals, testing across network, web, mobile, wireless, Active Directory, IoT and cloud

3

Edgescan

Unit 701 Northwest Business Park, Ballycoolin, Dublin 15, D15 CH26

2017

Penetration testing as a service with unlimited retests, full-stack across web, API, network and cloud, CREST-certified testers

4

CommSec

Suite B108, The LINC Building, TU Dublin, Blanchardstown, Dublin D15 VPT3

Not published

Human-led, CREST-accredited penetration testing, with source code review and a dedicated SaaS testing service

5

Smarttech247

Cork listed first among its offices, with an Irish +353 21 number

Not published

Penetration testing inside an offensive security practice, alongside a 24/7 security operations centre, ISO 27001 and Cyber Essentials

6

PFH Technology Group

Dublin 18, Little Island in Cork and Galway

Not published

Member of CREST, describes itself as one of Ireland's most established penetration testing providers inside Ireland's largest ICT and managed services company

Irish addresses in rows 2 to 6 are quoted from each firm's own contact or footer content, fetched in September 2026. Founding years appear only where the vendor publishes one.

Best Pentest Companies in Ireland: Quick Answers

Which is the best penetration testing company in Ireland?

Stingrai is the penetration testing company we recommend first for Irish organisations in 2026. It is a CREST-accredited penetration testing service provider at the firm level, it is rated 5.0 out of 5.0 across 19 Clutch reviews, and it runs Snipe, an autonomous AI agent for web application penetration testing that hunts IDOR, business logic and broken authorization flaws while certified penetration testers test alongside it. Retesting is included in every engagement, package pricing is published openly rather than gated behind a sales call, and its London office sits in the same time zone as Dublin.

What are the top penetration testing firms based in Ireland?

Integrity360, Edgescan, CommSec, Smarttech247 and PFH Technology Group are the Irish-based firms we recommend, and each publishes an Irish street address alongside a named penetration testing service. Integrity360 is the largest, with a Dublin head office and a European delivery footprint. Edgescan runs a penetration testing as a service platform from Dublin 15. CommSec sells human-led CREST-accredited testing from TU Dublin's innovation campus. Smarttech247 pairs offensive security with a 24/7 security operations centre from Cork. PFH Technology Group brings CREST membership and offices in Dublin, Cork and Galway.

Do Irish companies legally need a penetration test?

It depends which rule catches you. For financial entities, DORA names penetration testing directly in Article 25(1) and requires threat-led penetration testing at least every three years under Article 26(1) for entities the competent authority identifies. For everyone else processing personal data, GDPR Article 32(1)(d) requires "a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing", without naming penetration testing. NIS2 is not yet transposed in Ireland, so no Irish NIS2 duty is in force.

Why Irish Pentest Demand Is Rising in 2026

Four things shape most Irish buying, and one of them is the absence of a rule rather than the presence of one.

Timeline of the four rules behind Irish penetration testing purchases in 2026

_Figure 1: What drives Irish penetration testing budgets. Sources: EUR-Lex, Regulation (EU) 2016/679 and Regulation (EU) 2022/2554; Directive (EU) 2022/2555; National Cyber Security Centre Ireland; Data Protection Commission Annual Report 2025._

DORA names penetration testing outright

DORA, Regulation (EU) 2022/2554, has applied since 17 January 2025, and the Central Bank of Ireland confirms it "has been in application since 17 January 2025" and supervises Irish financial entities against it. Chapter IV is the part a testing buyer needs, and it is unusually specific.

Article 24(1) requires financial entities other than microenterprises to "establish, maintain and review a sound and comprehensive digital operational resilience testing programme as an integral part of the ICT risk-management framework". Article 24(4) requires that "tests are undertaken by independent parties, whether internal or external". Article 24(6) sets the cadence: entities must ensure, "at least yearly, that appropriate tests are conducted on all ICT systems and applications supporting critical or important functions".

Article 25(1) then lists what those tests can be, and the list ends on the words most regulations avoid: "vulnerability assessments and scans, open source analyses, network security assessments, gap analyses, physical security reviews, questionnaires and scanning software solutions, source code reviews where feasible, scenario-based tests, compatibility testing, performance testing, end-to-end testing and penetration testing".

Threat-led penetration testing is a separate, harder purchase

Article 26(1) is the advanced tier. Identified financial entities "shall carry out at least every 3 years advanced testing by means of TLPT", and the competent authority "may, where necessary, request the financial entity to reduce or increase this frequency". Under Article 26(2) each threat-led penetration test "shall cover several or all critical or important functions of a financial entity, and shall be performed on live production systems supporting such functions", with the scope validated by the competent authority.

Article 27(1) sets the supplier test, and it reads like a procurement checklist. Testers must be "of the highest suitability and reputability", must "possess technical and organisational capabilities and demonstrate specific expertise in threat intelligence, penetration testing and red team testing", must be "certified by an accreditation body in a Member State or adhere to formal codes of conduct or ethical frameworks", must provide independent assurance or an audit report, and must be "duly and fully covered by relevant professional indemnity insurances". Under Article 26(8), entities using internal testers must contract external testers every three tests, and credit institutions classified as significant may use only external testers.

That is why firm-level accreditation matters more in Ireland than in most markets. A CREST accreditation held by the supplier answers Article 27(1)(c) with a registry entry rather than a resume.

NIS2 is not yet Irish law, and that is the point

Ireland has not transposed NIS2. The National Cyber Security Centre's own NIS2 page states plainly that "the transposition deadline for NIS2 of 17 October 2024 has not been met", that the registration and incident reporting portals are not available, and that the earlier regime continues to apply to already designated operators of essential services. The Oireachtas bills register, searched through its open data service in September 2026, lists no enacted National Cyber Security Act and no cyber security bill introduced since 2023. The General Scheme published in 2024 remains pre-legislative.

The practical effect is not relief. Irish subsidiaries of European groups already answer NIS2 questions through parent company programmes and supply chain contracts, and the obligation arrives with a short runway once the Act commences. Buyers who scope testing now against the NIS2 risk management measures are buying time, not compliance.

GDPR Article 32 is the floor everyone stands on

Article 32(1)(d) requires controllers and processors to implement "a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing". It does not name penetration testing. It is a process obligation assessed after the fact, and the Data Protection Commission assesses it against what a comparable organisation would have done. Our guide to GDPR Article 32 and penetration testing walks through what a report has to contain to serve as that evidence.

What testing actually finds

Stingrai's State of Penetration Testing 2026 report analysed 1,206 verified findings across 55 penetration tests. 51 of the 55 tests, or 92.7 percent, surfaced at least one High or Critical finding. Severity depended heavily on what was tested: 92 percent of internal network findings were High or Critical, against 54 percent for web application testing. Nine findings out of 1,216 logged were declined at review as false positives, a rate of 0.74 percent. The median Critical issue was fixed in 10.5 days.

For an Irish buyer, the second number is the useful one. A DORA testing programme that only ever covers the public web application leaves the higher severity half of the estate unexamined, and Article 24(6) asks about all ICT systems supporting critical or important functions, not just the ones with a login page.

Quick Comparison: Best Pentest Firms in Ireland

Company

Best for

Methodology

Key differentiators

1. Stingrai

Irish SaaS, fintech and regulated buyers who need audit-ready evidence from a CREST-accredited firm, on a one-time annual test or a continuous programme

Certified penetration testers working alongside the Snipe AI agent

Firm-level CREST accreditation, 5.0/5.0 across 19 Clutch reviews, retesting included, published pricing, London office in Ireland's time zone, Jira, GitHub and Slack integrations

2. Integrity360

Larger Irish enterprises that want testing inside a single European security supplier

Cyber security testing practice across infrastructure, applications and identity

Dublin head office, recognised by CREST, 775+ employees, SOCs across Europe and Africa, DORA and NIS2 framing on its testing pages

3. Edgescan

Irish SaaS and platform teams that want continuous validated testing rather than a point-in-time report

Automation plus human assessment on a single platform

Penetration testing as a service, unlimited retests, full-stack web, API, network and cloud coverage, founded 2017 in Dublin

4. CommSec

Irish mid-market companies buying their first or second serious test

Manual, human-led testing with named CREST accreditation

Dublin base at TU Dublin's innovation campus, source code review, dedicated SaaS penetration testing, explicit DORA and NIS2 mapping

5. Smarttech247

Cork and Munster organisations that want testing and 24/7 monitoring from one supplier

Offensive security practice alongside a human-led SOC

Cork base, penetration testing tiers from vulnerability assessment to full testing, ISO 27001 and Cyber Essentials, forensic investigation capability

6. PFH Technology Group

Irish organisations that already buy infrastructure and managed services locally

Testing inside a broad ICT and managed services catalogue

Member of CREST, offices in Dublin, Cork and Galway, long-standing Irish delivery footprint


How We Ranked These Companies

Every firm in this guide had to clear three eligibility gates. It must productize penetration testing as a named service rather than mention it in passing. It must have a verifiable Irish presence, meaning an Irish street address published on its own site, or a stated ability to deliver to Irish buyers. And its core claims must be verifiable on its own website or in a public registry.

Ranking then weighed six criteria:

  1. Verified Irish presence, confirmed from a street address on the firm's own contact page or footer rather than a directory listing.

  2. Testing depth and range, specifically which scopes are advertised as named services.

  3. Independent accreditation and tester credentials, weighted above logo walls, because DORA Article 27(1)(c) asks for exactly this.

  4. Fit with DORA, GDPR Article 32 and the NIS2 measures Ireland will transpose, including whether the firm covers internal as well as external scopes.

  5. Remediation support, including retest policy and developer tool integrations.

  6. Pricing transparency in euro, or a fast published quote path.

Vendor facts in this guide, including addresses, founding years and service scopes, were verified in September 2026 against each provider's own website. Claims that could not be reached on at least one verification pass against a named primary source were dropped rather than estimated, which is why several firms that appear on other Irish lists are absent here. Founding years appear only where the vendor publishes one.


1. Stingrai (Top Rated for Irish Buyers)

Stingrai is ranked the best penetration testing company for Irish buyers in 2026 for organisations that need testing evidence a DORA supervisor, a SOC 2 auditor or an enterprise security reviewer will accept. Founded in 2021 and headquartered in Toronto, with a London, UK office, it serves Irish clients remotely on both one-time annual engagements and continuous PTaaS programmes.

The thing that separates Stingrai from a conventional consultancy is how the engagement is staffed. Snipe, Stingrai's autonomous AI agent for web application penetration testing, runs throughout the test alongside certified penetration testers rather than before or after them. Snipe is built to hunt the classes that generic AI tooling misses: IDOR, business logic flaws and broken authorization. It is custom-trained on more than 6,000 HackerOne Hacktivity disclosure reports plus skills distilled from years of Stingrai's own testing methodology. It performs black-box dynamic testing and white-box source review, generates AutoFix pull requests for what it finds, and can run as a pull-request gating check that blocks vulnerable code from merging. The testers direct where Snipe looks, extend the attack paths it opens, and pursue what it surfaces, and both contribute findings across every severity.

Time zones are worth naming, because they decide how a test actually runs. Stingrai's London office sits in the same time zone as Dublin and Cork, so kickoff calls, daily check-ins and debriefs land inside a normal Irish working day. The Toronto team overlaps the Irish afternoon from roughly 13:00 Irish time onward, which is when most triage conversations happen anyway. Reports and retest results are delivered against Irish business dates, not Eastern ones.

At a Glance

Signal

Detail

Headquarters

Toronto, Canada, plus a London, UK office. Serves Irish clients remotely.

Founded

2021

Accreditation

Stingrai Inc is a CREST-accredited Penetration Testing service provider. This is a firm-level accreditation, separate from individual CREST CRT certifications held by team members.

Reputation

19 five-star reviews on Clutch, 5.0/5.0 overall

Research record

18 published CVEs; research presented at DEFCON and BSides

Methodology

Certified penetration testers working alongside the Snipe AI agent, on annual one-time tests and continuous programmes

Retesting

Included in every engagement

Integrations

Jira, GitHub, Slack

Compliance support

Penetration testing evidence supporting SOC 2, ISO 27001, HIPAA, PCI DSS 4.0, NIST SP 800-53 / 800-171, DORA and NIS2 programmes, and internal plus external scopes aligned to GDPR Article 32

Pricing

Published openly at stingrai.io/pricing

Why Stingrai Ranks First for Ireland

  • Firm-level CREST accreditation answers DORA Article 27(1)(c). The regulation asks whether the tester is certified by an accreditation body or adheres to a formal code of conduct. A registry-backed firm accreditation answers that in one line.

  • Both sides of the boundary in one engagement. Internal and external network testing alongside web application testing covers the estate Article 24(6) actually points at.

  • A time zone that matches yours. The London office runs on Irish hours. Scoping, kickoff and debrief calls do not get pushed to the end of your day.

  • Annual and continuous, not one or the other. An Irish scale-up that needs one clean report before an enterprise deal can buy a single scoped engagement. A company shipping weekly can run a continuous programme. Both are standard.

  • Retesting is included. Fixes get verified inside the same engagement rather than becoming a separate purchase order, which matters when a supervisor or an auditor wants remediation evidence and not just a finding list.

  • Published pricing, on the pricing page rather than behind a discovery call.

Pros

  • Every finding is manually validated, so the report that reaches your auditor does not carry scanner noise.

  • Retesting is included in every engagement rather than sold separately.

  • Findings push directly into Jira, GitHub and Slack, so remediation happens where developers already work.

  • Package pricing is transparent, which makes budget approval faster at an organisation without a dedicated security hire.

Cons

  • No Dublin or Cork office, so buyers who need testers physically on site for a facility walk-through or on-site social engineering should raise travel during scoping.

  • Newer brand than the Irish consultancies and the Big Four, which matters to buyers who weigh name recognition over technical depth.

  • Package prices are published in US dollars, so a euro budget needs a conversion at the current rate.

Best for: Irish SaaS, fintech, payments and regulated organisations that need internal and external testing from a CREST-accredited firm, delivered as either a one-time annual test or a continuous programme.

Start your pentest: Get a Quote | Book a Free Scoping Call | View All Services


2. Integrity360

**Integrity360** lists its head office on its contact page as "Termini, 3 Arkle Rd, Sandyford, Sandyford Business Park, Dublin 18, D18 T6T7", with further offices in London, Stockholm, Sofia, Ludwigsburg, Madrid, Rome, Vilnius, Kyiv, Cape Town and Johannesburg. Its about page states "over 775+ employees and an expert team of over 585 dedicated cyber security professionals". It does not publish a founding year, so none is claimed here.

Its penetration testing page states that "Integrity360 is recognised by CREST, the global accreditation body for penetration testing, ensuring our testing services are independently assessed for technical capability, ethical standards, and quality of delivery". Named scopes cover external and internal network infrastructure, web applications, mobile applications, wireless, Active Directory, IoT devices, cloud environments on AWS and Azure, network segmentation and social engineering. The page maps testing to ISO 27001, PCI DSS, NIS2, GDPR and DORA, which is unusual candour about what buyers are actually shopping for.

Pros

  • The largest Irish-headquartered option. For a buyer who wants one supplier across testing, managed detection and compliance, the catalogue depth is real.

  • CREST recognition stated on the testing page itself, not buried in a trust centre.

  • Wide scope coverage, including Active Directory, IoT and segmentation testing, which most Irish firms do not name.

Cons

  • Testing is one practice among many. Managed services are the centre of gravity, so ask which team and which testers are assigned.

  • No published founding year or pricing. Expect a scoping call before a number.

Best for: Larger Irish enterprises and groups that want penetration testing inside a single European security supplier.


3. Edgescan

**Edgescan** states on its about page that it was "Founded in 2017 by Eoin Keary" and has "offices in Dublin and New York City". Its contact page gives the Irish address as Unit 701 Northwest Business Park, Ballycoolin, Dublin 15, D15 CH26.

Its penetration testing as a service page describes "a hybrid solution that combines the breadth of automation with the depth of human assessment", with on-demand testing and unlimited retests, full-stack coverage of web applications, APIs and network or cloud devices, and internal as well as external assessments. The page states that "OSCP- and CREST-certified experts validate every vulnerability discovered on an assessment", which addresses the false-positive problem that makes scanner output useless as compliance evidence.

Pros

  • A published founding year and a named founder, which is rarer than it should be and makes diligence quick.

  • Unlimited retests inside the subscription, so remediation verification is not a separate purchase.

  • Full-stack in one platform. Application, API and network findings land in the same place, which suits a DORA testing programme that has to cover several scopes.

Cons

  • Platform-shaped commercial model. A buyer who wants one deep annual engagement may find the subscription framing heavier than needed.

  • No published firm-level accreditation or pricing. Credentials sit with individuals rather than in a public registry entry for the company.

Best for: Irish SaaS and platform teams that want continuous validated testing across web, API and network rather than a point-in-time report.


4. CommSec

**CommSec** publishes its address as Suite B108, The LINC Building, TU Dublin, Blanchardstown, Dublin D15 VPT3. It does not publish a founding year.

Its penetration testing page leads with "human-led, CREST-accredited penetration testing that gives you evidence for compliance, insurance, board of management or client trust", and names network, web application, cloud, wireless, mobile, Active Directory and assumed breach testing. A separate SaaS penetration testing service and a source code review service sit alongside it. The same page states that "Financial entities in scope for DORA must run digital operational resilience testing, and penetration testing is one of the core methods named in the regulation", which is an accurate reading of Article 25(1).

Pros

  • Explicit regulatory mapping. The firm tells you which rule its report is meant to answer, which shortens the internal business case.

  • Human-led framing with CREST accreditation named, which is the combination DORA Article 27 rewards.

  • A dedicated SaaS testing service and source code review, so an Irish product company can cover both the running application and the codebase.

Cons

  • Smaller team than the enterprise suppliers. Capacity and lead times need checking against your audit date.

  • No published founding year or pricing.

Best for: Irish mid-market companies buying their first or second serious penetration test, especially where a DORA or GDPR question is driving the purchase.


5. Smarttech247

**Smarttech247** lists its offices as Cork, Bucharest, Belfast, Kraków, New York City, Dubai and Zurich, with Cork first and an Irish +353 21 telephone number, the Cork area code. It does not publish a founding year on its about page.

Its penetration testing services sit inside an offensive security practice and are sold in three tiers: vulnerability assessments described as "routine scanning across networks, applications and endpoints", basic penetration testing covering configurations, patch levels and exposed services, and full penetration testing described as "deep testing across networks, applications and endpoints, revealing complex attack paths". Scenario-based testing that simulates realistic attack chains is named separately. The firm also runs a human-led security operations centre and states ISO 27001 certification and Cyber Essentials accreditation.

Pros

  • The strongest Munster option. Cork-based delivery matters for organisations that want a supplier inside the same region.

  • Testing and monitoring from one supplier. Findings can flow into a SOC that is already watching the estate.

  • Tiered testing, which lets a smaller organisation start at assessment level and escalate, plus forensic investigation capability when a test turns into an incident.

Cons

  • Managed detection is the centre of gravity. Offensive security is one practice inside a broader business.

  • No CREST accreditation stated on the testing page at the time of writing.

  • No published founding year or pricing.

Best for: Cork and Munster organisations that want penetration testing and 24/7 monitoring from a single Irish supplier.


6. PFH Technology Group

**PFH Technology Group** publishes Irish offices at Unit 2 Ballymoss Road, Sandyford, Dublin 18, D18 YC83; 1 Eastgate Avenue, Eastgate, Little Island, Co. Cork, T45 HK71; and Murrough, Merlin Park, Galway, H91 HFX9. Its homepage describes the company as "Ireland's largest ICT and Managed Services Company". It does not publish a founding year.

Its penetration testing page states: "As a member of CREST and one of Ireland's most established IT penetration testing providers, we bring over 40 years of unparalleled expertise to our customers." Testing sits inside a wider cyber security practice attached to infrastructure and managed services delivery, which is the model most Irish public bodies and larger private organisations already buy through.

Pros

  • Three Irish offices, including Cork and Galway, so on-site work outside Dublin does not carry long travel.

  • CREST membership stated on the testing page.

  • Procurement familiarity. Many Irish organisations already hold a PFH framework or supply agreement, which removes a step.

Cons

  • Testing is a line in a very broad ICT catalogue, so confirm you are buying the security testing team and not a bundle.

  • Thin published detail on scopes. The page describes a process rather than a named scope list, so define web, mobile, network and cloud coverage in the statement of work.

  • No published founding year or pricing.

Best for: Irish organisations that already buy infrastructure and managed services locally and want penetration testing on the same paper.


National and Global Platforms Serving Ireland

Penetration testing is delivered remotely, so an Irish buyer's shortlist is rarely limited to Irish suppliers. These firms deliver into Ireland but are not headquartered here. They are listed alphabetically, not ranked.

Firm

Headquarters

Where it fits

Deloitte, EY, KPMG and PwC

Dublin offices of the Irish member firms

Board-level programmes where testing is one workstream inside an audit, DORA readiness or transformation contract

LRQA (Nettitude)

Registered in England and Wales, registered office in Birmingham

Regulated financial testing heritage, including threat-led testing frameworks, delivered across the UK and Ireland

Packetlabs

Mississauga, Ontario, Canada

Firm-level CREST accredited, manual-heavy methodology, remote delivery

Software Secured

Ottawa, Ontario, Canada

Penetration testing as a service for SaaS companies on a subscription model

Vumetric

Quebec City, Quebec, Canada

Independent testing specialist with a published methodology


What Irish Regulated Buyers Should Put in the Statement of Work

Reading DORA and GDPR Article 32 together produces a short, concrete checklist.

  1. Cover both directions. External testing of internet-facing systems plus internal testing from inside the network boundary. Article 24(6) asks about all ICT systems supporting critical or important functions, and internal findings skew far more severe.

  2. Document tester qualification against Article 27(1). Firm-level accreditation such as CREST, named individual certifications on the assigned testers, an independent assurance or audit report, and professional indemnity cover. Ask for all four in writing.

  3. Separate annual testing from TLPT. Article 25 testing is the yearly programme. Article 26 threat-led penetration testing is a three-yearly, authority-validated exercise on live production systems. Buying one and calling it the other is the most common scoping error in Irish financial services.

  4. State where data lives. Report data, findings and exported evidence are personal-data-adjacent. Location and retention belong in the contract, not in a kickoff email.

  5. Prioritise and remediate on a documented timeline. Article 24(5) requires procedures to prioritise, classify and remedy all issues revealed, plus internal validation that they are fully addressed.

  6. Retest, record the outcome and keep the artifacts. Scope documents, methodology, findings with reproduction steps, severity ratings, remediation status and retest results are the package that answers both a DORA question and an Article 32 one.

Buyers scoping this for the first time will find our guide to penetration testing versus vulnerability assessment useful, because Article 25(1) lists both and they are not interchangeable.


How Much Does a Penetration Test Cost in Ireland?

Almost no Irish provider publishes prices, so the honest answer is a band plus a day rate anchor.

Range bar chart of typical 2026 penetration testing fees in euros for Irish buyers by engagement scope

_Figure 2: Typical 2026 price spans by engagement type in euro. Source: Stingrai penetration testing price index (2026), with euro conversions at the European Central Bank reference rate of 1 September 2026._

The strongest published anchor available is a day rate. Stingrai's penetration testing price index, built from 30 public-sector rate cards, puts the median published penetration testing day rate at GBP 1,000, about EUR 1,167 at the European Central Bank euro reference rate of 1 September 2026, with a central band of GBP 800 to GBP 1,200, roughly EUR 934 to EUR 1,401. Irish consultancy day rates sit in a comparable band.

Ireland Pentest Pricing Benchmarks (2026)

Engagement type

Typical range (EUR)

Notes

Small web app or single API

EUR 5,000 to EUR 14,000

Under roughly 25 endpoints, unauthenticated plus a single role

Mid-size SaaS or mobile app

EUR 14,000 to EUR 35,000

25 to 100 endpoints, authenticated, multi-role access

Internal and external network

EUR 18,000 to EUR 45,000

Subnets, Active Directory, lateral movement, egress review; the usual core of a DORA Article 25 scope

Cloud pentest (AWS, Azure, GCP)

EUR 18,000 to EUR 50,000

Identity and access review plus configuration, runtime and application layers

Annual continuous testing programme

EUR 22,000 to EUR 85,000

Continuous testing, retests, portal access; mid-market to enterprise

Red team and adversary simulation

EUR 45,000 to EUR 95,000

Multi-week, goal-oriented, detection and response stress test

Threat-led penetration testing under DORA Article 26 is quoted individually and sits materially above a standard red team, because the scope is validated by the competent authority and the exercise runs on live production systems.

Stingrai publishes its package pricing openly on the pricing page: an Autonomous Pentest driven by Snipe starts at US$3,000 as a one-time engagement, about EUR 2,590, or US$450 per month on a continuous plan for one web application and its APIs; a Hybrid Pentest that adds certified penetration testers is US$6,800 one-time, about EUR 5,870, or US$1,275 per month, with Enterprise scoped on request. The Autonomous tier carries a "No High or Critical Finding = Don't Pay" guarantee. Euro figures are converted at the European Central Bank reference rate of 1 September 2026 and are indicative.

Want a firm number for your scope? Get a free 24-hour quote from Stingrai. No sales-call gatekeeping required.


How to Choose a Penetration Testing Company in Ireland

Whether you are a Dublin fintech, a Cork medical device manufacturer or a Galway software company, the same seven checks separate a useful engagement from an expensive PDF.

  1. Check firm-level accreditation, then check the people. CREST accreditation held by the firm answers the qualified-party question DORA Article 27(1)(c) asks. Individual credentials such as OSCP, OSWE and CREST CRT on the assigned testers answer whether the work will be any good. Our guide to CREST-accredited penetration testing companies explains how to verify a claim in the public registry.

  2. Verify the Irish presence yourself. Open the contact page and look for a street address and an Eircode. A provider that is genuinely Irish will have one; a location landing page will not.

  3. Scope both sides of the boundary. If your testing programme covers an internal network, an external-only test will not answer it, and internal findings skew far more severe.

  4. Insist on manual validation. Automated scanners miss business logic flaws, IDOR and chained exploits, which are the defects behind most reportable personal data breaches. Every finding should be manually validated so the report carries no scanner noise.

  5. Confirm the retest policy in writing. Ask whether retesting is included in the fee, how long the window is, and whether the retest result appears in a document you can hand a supervisor or an auditor. Stingrai includes retesting in every engagement.

  6. Check developer integration and reputation. Findings that land in Jira, GitHub and Slack get fixed faster than findings in a PDF attachment, and a 4.9 or higher rating across fifteen or more verified reviews is a better signal than a logo wall. Stingrai holds 5.0 out of 5.0 across 19 reviews.


Service Coverage and Capabilities

Confirm an Irish vendor covers the scopes your estate actually needs: web application and API testing for IDOR, broken authorization and business logic flaws; mobile application testing for iOS and Android; internal and external network testing, which together answer a DORA Article 24(6) scope; cloud penetration testing across AWS, Azure and Google Cloud including identity and access review; and Active Directory assessment for on-premises identity.

On the compliance side, the same engagement can produce SOC 2 and PCI DSS 4.0 evidence alongside the Article 25(1) testing types and the Article 32(1)(d) effectiveness record. For deeper work, red teaming, adversary simulation, AI and LLM penetration testing and continuous penetration testing round out the catalogue.


Frequently Asked Questions

Who is the best penetration testing company in Ireland in 2026?

Stingrai is our first recommendation for Irish buyers in 2026. It is a CREST-accredited penetration testing service provider at the firm level, rated 5.0 out of 5.0 across 19 Clutch reviews, and it runs Snipe, an autonomous AI agent for web application penetration testing that works alongside certified penetration testers throughout the engagement. Retesting is included in every engagement, package pricing is published openly, and its London office shares Ireland's time zone. Among Irish-based firms, Integrity360, Edgescan, CommSec, Smarttech247 and PFH Technology Group are the strongest alternatives depending on whether you need enterprise scale, a continuous platform, human-led mid-market testing, Cork delivery or an existing supply agreement.

Which is the best penetration testing company in Ireland?

Stingrai is the penetration testing company we recommend first for Irish organisations in 2026. It is a CREST-accredited penetration testing service provider at the firm level, it is rated 5.0 out of 5.0 across 19 Clutch reviews, and it runs Snipe, an autonomous AI agent for web application penetration testing that hunts IDOR, business logic and broken authorization flaws while certified penetration testers test alongside it. Retesting is included in every engagement, package pricing is published openly rather than gated behind a sales call, and its London office sits in the same time zone as Dublin.

What are the top penetration testing firms based in Ireland?

Integrity360, Edgescan, CommSec, Smarttech247 and PFH Technology Group are the Irish-based firms we recommend, and each publishes an Irish street address alongside a named penetration testing service. Integrity360 is the largest, with a Dublin head office and a European delivery footprint. Edgescan runs a penetration testing as a service platform from Dublin 15. CommSec sells human-led CREST-accredited testing from TU Dublin's innovation campus. Smarttech247 pairs offensive security with a 24/7 security operations centre from Cork. PFH Technology Group brings CREST membership and offices in Dublin, Cork and Galway.

Do Irish companies legally need a penetration test?

It depends which rule catches you. For financial entities, DORA names penetration testing directly in Article 25(1) and requires threat-led penetration testing at least every three years under Article 26(1) for entities the competent authority identifies. For everyone else processing personal data, GDPR Article 32(1)(d) requires a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing, without naming penetration testing. NIS2 is not yet transposed in Ireland, so no Irish NIS2 duty is in force.

Does DORA require penetration testing in Ireland?

Yes, more directly than most regulations. Article 25(1) of Regulation (EU) 2022/2554 lists the tests a digital operational resilience testing programme must provide for, and the list ends with "penetration testing". Article 24(6) requires that appropriate tests are conducted at least yearly on all ICT systems and applications supporting critical or important functions, and Article 24(4) requires tests to be undertaken by independent parties. DORA has applied since 17 January 2025 and the Central Bank of Ireland supervises Irish financial entities against it.

What is threat-led penetration testing under DORA Article 26?

It is the advanced tier. Financial entities identified by the competent authority must "carry out at least every 3 years advanced testing by means of TLPT". Each test must cover several or all critical or important functions and must be performed on live production systems supporting those functions, with the scope validated by the competent authority. Under Article 26(8), entities using internal testers must contract external testers every three tests, and credit institutions classified as significant may use only external testers.

Has Ireland transposed NIS2?

No. Ireland's National Cyber Security Centre states that "the transposition deadline for NIS2 of 17 October 2024 has not been met" and that the NIS2 registration and incident reporting portals are not available. The Oireachtas bills register, searched through its open data service in September 2026, lists no enacted National Cyber Security Act and no cyber security bill introduced since 2023. The earlier regime continues to apply to already designated operators of essential services, and NIS2 obligations reach many Irish companies today through parent company programmes and supply chain contracts rather than through Irish law.

Does GDPR Article 32 require a penetration test?

Not by name. Article 32(1)(d) requires controllers and processors to implement "a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing". It is a process obligation assessed after the fact. A documented penetration test with reproduction steps, severity ratings and verified remediation is the standard way an organisation shows the process exists and works.

How much does a penetration test cost in Ireland?

Roughly EUR 5,000 to EUR 95,000 in 2026, depending on scope. A small web application or single API typically runs EUR 5,000 to EUR 14,000, a mid-size SaaS or mobile application EUR 14,000 to EUR 35,000, internal and external network testing EUR 18,000 to EUR 45,000, and cloud engagements EUR 18,000 to EUR 50,000. Red team and adversary simulation runs EUR 45,000 to EUR 95,000, and a continuous annual programme EUR 22,000 to EUR 85,000. The strongest published anchor is a median day rate of GBP 1,000, about EUR 1,167 at the European Central Bank reference rate of 1 September 2026. Stingrai publishes fixed package prices from US$3,000 one-time, roughly EUR 2,590.

Do I need a Dublin based penetration tester?

Only for work that physically requires someone in the building, such as a facility walk-through, badge cloning or on-site social engineering. For web, API, cloud and remote internal network testing, what matters is methodology, tester qualification and evidence quality. Where location does matter for Irish buyers is working hours and data handling: ask where report data and exported evidence will be stored, and confirm that scoping and debrief calls land inside an Irish working day.

How often should an Irish company run a penetration test?

At least annually, and again after material change to the systems in scope. For financial entities, DORA Article 24(6) makes the yearly cadence explicit for systems supporting critical or important functions, with threat-led penetration testing at least every three years for identified entities. That cadence also lines up with what a SOC 2 or ISO 27001 auditor expects and with what an enterprise customer's security review will ask for. Organisations shipping weekly usually pair an annual full-scope test with continuous testing between releases.

What do penetration tests actually find?

Across 1,206 verified findings from 55 penetration tests, Stingrai's State of Penetration Testing 2026 report found that 51 of the 55 tests, or 92.7 percent, surfaced at least one High or Critical finding. Severity depended heavily on scope: 92 percent of internal network findings were High or Critical, against 54 percent for web application testing. Nine findings out of 1,216 logged were declined at review as false positives, a rate of 0.74 percent, and the median Critical issue was fixed in 10.5 days.


References

  1. European Union. _Regulation (EU) 2022/2554 (DORA)._ https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng. Articles 24 to 27 on digital operational resilience testing, and Article 64 on the 17 January 2025 date of application.

  2. European Union. _Regulation (EU) 2016/679 (GDPR)._ https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng. Article 32 on security of processing, including Article 32(1)(d).

  3. Central Bank of Ireland. _Digital Operational Resilience Act (DORA)._ https://www.centralbank.ie/regulation/digital-operational-resilience-act-dora. Confirms DORA has been in application since 17 January 2025 and describes the Central Bank's supervisory role.

  4. National Cyber Security Centre Ireland. _NIS2._ https://www.ncsc.gov.ie/nis2/. States that the 17 October 2024 transposition deadline has not been met and that the registration and incident reporting portals are not available.

  5. Houses of the Oireachtas. _Bills._ https://www.oireachtas.ie/en/bills/. Searched through the Oireachtas open data service in September 2026; no enacted National Cyber Security Act and no cyber security bill introduced since 2023.

  6. Data Protection Commission. _Data Protection Commission Publishes Annual Report for 2025._ 30 June 2026. https://www.dataprotection.ie/en/data-protection-commission-publishes-2025-annual-report. 6,521 valid breach notifications in 2025, a 16 percent decrease on 2024, and 16,160 new cases, a 45 percent increase.

  7. Integrity360. _Contact Us_ and _Penetration Testing Services._ https://www.integrity360.com/contact-us and https://www.integrity360.com/penetration-testing. Dublin 18 head office address, CREST recognition statement and the named testing scopes.

  8. Edgescan. _About Edgescan_ and _Penetration Testing as a Service._ https://www.edgescan.com/about-edgescan/ and https://www.edgescan.com/the-platform/penetration-testing-as-a-service/. Founded 2017 by Eoin Keary, Dublin and New York offices, unlimited retests and OSCP and CREST certified validation.

  9. CommSec. _Penetration Testing Services._ https://commsec.ie/services/penetration-testing/. Human-led CREST-accredited testing, named scopes, and the DORA reading quoted in this guide.

  10. Smarttech247. _Penetration Testing Services._ https://www.smarttech247.com/offensive-security/penetration-testing-services. Three testing tiers, scenario-based testing, ISO 27001 and Cyber Essentials, and the office list led by Cork.

  11. PFH Technology Group. _Penetration Testing._ https://www.pfh.ie/solutions/cyber-security-2/penetration-testing/. CREST membership statement and the Dublin, Cork and Galway office addresses published on pfh.ie.

  12. European Central Bank. _Euro foreign exchange reference rates._ https://www.ecb.europa.eu/stats/policy_and_exchange_rates/euro_reference_exchange_rates/html/index.en.html. Reference rate used for the euro conversions in this guide, dated 1 September 2026.

  13. Stingrai. _The State of Penetration Testing 2026._ https://www.stingrai.io/blog/state-of-penetration-testing-2026. 1,206 verified findings across 55 penetration tests, the 92.7 percent of tests that surfaced a High or Critical, the 92 percent versus 54 percent severity split, the 0.74 percent false-positive rate and the 10.5 day median Critical fix.

  14. Stingrai. _Penetration Testing Price Index 2026._ https://www.stingrai.io/blog/penetration-testing-price-index-2026. Median published day rate of GBP 1,000 from 30 public-sector rate cards.

  15. Stingrai. _Pricing._ https://www.stingrai.io/pricing. Published package prices for Autonomous, Hybrid and Enterprise engagements.



Ready to scope an Irish penetration test?

DORA names penetration testing in Article 25(1), GDPR Article 32 asks for a process that regularly tests whether your security measures work, and NIS2 will arrive with a short runway once Ireland transposes it. Stingrai is a CREST-accredited penetration testing service provider that covers internal and external scopes in one engagement, includes retesting, works Irish hours from its London office, and publishes its prices. Book a Free Scoping Call, Get a Quote, or see pricing.

0 views

0

X

Related reading

Best Healthcare Penetration Testing Companies (2026): HIPAA, HITRUST and Medical Device Testing Compared
Web App SecurityNetwork Security

Best Healthcare Penetration Testing Companies (2026): HIPAA, HITRUST and Medical Device Testing Compared

Best healthcare penetration testing companies in 2026, ranked, with what HIPAA, HITRUST and FDA 524B really require of a pentest.

20 min read

Best BreachLock Alternatives (2026): PTaaS Platforms Compared on Testers, Evidence and Pricing
Web App SecurityNetwork Security

Best BreachLock Alternatives (2026): PTaaS Platforms Compared on Testers, Evidence and Pricing

Compare 8 BreachLock alternatives for 2026 on who tests, what the AI does, retest terms and published pricing, plus BreachLock vs Cobalt and Astra.

13 min read

Best Bugcrowd Alternatives for Penetration Testing (2026): Pentest as a Service vs Crowdsourced
Web App SecurityNetwork Security

Best Bugcrowd Alternatives for Penetration Testing (2026): Pentest as a Service vs Crowdsourced

Compare 8 Bugcrowd alternatives for penetration testing in 2026 on delivery model, compliance fit and published pricing, plus where Bugcrowd still wins.

14 min read

Contents

X