Network, web and mobile application penetration testing, code security audits (SAST, DAST, IAST), red, blue and purple teaming, vulnerability management and advanced APT attack simulations.
Penetration testing pricing and scope
Penetration testing pricing depends mainly on scope - the number of applications, IP addresses or features to check - and on the test type: black box (no prior knowledge), grey box (partial knowledge, usually the most cost-effective) or white box (full code access). Methodology (OWASP, PTES), team certifications (OSCP, CREST) and whether a retest after remediation is included also affect the price. Ask about lead time too: the test itself usually runs from a few days to a couple of weeks, but experienced teams are booked weeks ahead, so the start date often matters more than the day rate. Ask providers to quote per scope rather than a flat rate; quotes can differ several times over.
When to buy these services
- You are deploying a new application or a significant change and want it verified before production.
- A client, tender or standard (ISO 27001, PCI-DSS, NIS2) requires periodic security testing.
- You want to know your real resilience to attack, not just compliance with a checklist.
- After an incident you need independent confirmation that the vulnerability is actually closed.
How to choose a provider
- Scope and methodology (for example OWASP, PTES) and the type of test: black, grey or white box.
- Team qualifications and certifications, plus sample reports so you can judge the depth of findings.
- Whether retesting after remediation is included, and on what terms.
- How findings are prioritised by business risk rather than raw severity counts.
Company directory
Offensive security specialist delivering penetration testing, application and cloud security assessments and red teaming for large organisations in regulated sectors.
Offensive security and intelligence provider combining penetration testing, red teaming, threat and geopolitical intelligence, leak monitoring and vulnerability management.
Cybersecurity integrator and advisor delivering NIS2 audits, vCISO services, penetration testing, SOC outsourcing and security awareness programmes.
IT company running a cybersecurity centre with SOC and CSIRT teams, providing incident monitoring and response, IT audits and penetration testing.
CERT/CSIRT specialist offering SOC outsourcing, security audits against ISO 27001 and Poland's National Cybersecurity System, response team build-outs, malware analysis and penetration testing.
Cybersecurity firm offering penetration testing, red teaming and OSINT alongside NIS2 and DORA audits, including Threat-Led Penetration Testing for financial institutions.
Distributor of IT security technology (ESET, Stormshield) providing audits, deployments and technical training, including penetration tests and security policy work.
IT security firm formed by merging Securelex and DeCode9, delivering penetration testing, code audits, systems monitoring and security incident management.
Managed IT and cybersecurity provider covering infrastructure, networks, Microsoft 365, backup, penetration testing, phishing simulations and incident response.
Cybersecurity and data protection firm running penetration tests of web, mobile and embedded applications, source code review, ISO 27001 and 22301 audits and DevSecOps support, also as PTaaS.
Offense-driven security firm delivering penetration testing, attack simulations, IT security audits and incident response, backed by its own testing and awareness platforms.
State-owned telecom operator providing end-to-end cybersecurity services, from network protection and EDR through advanced SOC monitoring to penetration testing.
Showing 12 of 29 companies. Use the filters to narrow the results.
Does your company work in Penetration Testing & Audits?
Join the directory for free and reach organisations actively looking for providers in this category.
Looking for a vetted penetration testing & audits provider in Poland? Send us your requirements and we will point you to the right companies.
Is this your company profile? Submit a company to this category
Frequently asked questions
Short answers for teams planning to buy services in this category.
A scan automatically detects known weaknesses. A penetration test adds a human who chains findings together, bypasses controls and shows the real business impact - which a scanner cannot do.
At least annually, and additionally after significant changes to the application or infrastructure. Many standards and clients expect exactly that cadence.
A well-scoped test should not. Agree the window, the intensity and which techniques are excluded in advance, and run destructive scenarios against a staging environment.