SEE MATPROOF ON YOUR STACK — BOOK A 30-MINUTE DEMO

Penetration Testing Services: How to Choose, and When to Choose Someone Else

Most pages like this one tell you every buyer should pick the vendor who wrote the page. This one does not. Matproof Sentinel is an AI penetration testing platform. It runs ten agents and a ValidatorAgent that stamps every finding VALIDATED, UNVERIFIED or FALSE_POSITIVE. It has no human penetration tester behind it, and Matproof holds no CREST membership, no NCSC CHECK approval and no FedRAMP 3PAO accreditation. That rules us out of some work, and we would rather tell you now than after you have paid. Below: which requirement actually applies to you, what to ask any provider, and where a platform beats a consultancy.

MW
Written by Malte Wagenbach
Founder of Matproof Security. Specialized in AI-driven penetration testing and EU compliance (DORA, NIS2, ISO 27001, SOC 2).
Last reviewed: 19 August 2026

Choosing a provider: five questions that decide it

Start with the contract, not the vendor. Read your customer's security schedule, your tender documents and your regulator's text before you shop, because they usually name the answer. If a scheme is named, buy from someone accredited under that scheme and stop reading comparison pages. If nothing is named, you are free to choose on merit, and merit comes down to five questions. First: does the provider prove each finding, or forward scanner output? A finding without proof wastes your engineers' time. Second: does the report map to the controls your auditor checks, or must you translate it? Third: how current will the evidence be? The NCSC is blunt that a penetration test validates known issues on the day of the test, and notes that a year or more often passes between tests. Fourth: is the re-test after remediation in the price, or billed again? This single question moves budgets more than any other. Fifth: can you get a price without a sales call? Most cannot publish one, because they price by day against a custom scope. That is a fair reason, but it still costs you weeks. Match the answer to the job. A platform is the right buy for web, API and external testing that has to run all year. A human team is the right buy for social engineering, physical entry, red teaming, and anything that needs a person to improvise.

  • Read the contract first. If it names CREST, CHECK, CBEST, ASSURE or a 3PAO, that decides your shortlist before merit does.
  • Ask for proof of exploit per finding. Scanner output dressed up as a pentest is the most common way buyers get short-changed.
  • Ask whether the report maps to your framework. An unmapped technical PDF is homework, not evidence.
  • Ask whether the re-test is included. Many firms bill it a second time, and it is rarely in the headline price.
  • Ask about lead time. Weeks of scheduling means the report describes a build you have already replaced.
  • Check who does the work and what they hold. Certificates sit with people, not with the company logo.
  • Check insurance. A test is a controlled attack on live systems. Ask what covers you if something breaks.

What Matproof Sentinel covers

  • Recon: nmap, amass and httpx map the attack surface before anything is probed.
  • Web: OWASP Top 10 coverage with nuclei, sqlmap and OWASP ZAP.
  • API: REST and GraphQL against the OWASP API Security Top 10.
  • Infrastructure: exposed services, edge devices, TLS and DNS with testssl.sh.
  • Cloud: configuration and IAM checks with Prowler, on Growth and above.
  • Mobile: iOS and Android packages with MobSF, on Growth and above.
  • Source code and supply chain: Semgrep, Gitleaks and Trivy read the repositories you connect.
  • Validation: a ValidatorAgent re-runs every finding and stamps it VALIDATED, UNVERIFIED or FALSE_POSITIVE.
  • Reporting: PDF, JSON and SARIF 2.1.0, mapped to ISO 27001, SOC 2, NIS2, DORA, PCI DSS and HIPAA controls.
  • Domain ownership is confirmed by DNS TXT or an HTTP file challenge before any traffic is sent.

Sample finding

Info

The honest comparison, both ways

A traditional firm gives you a named tester, an accreditation you can show a customer, and the ability to improvise against your business logic. It also gives you a scoping call, a wait of weeks, a report describing one day, and often a second invoice for the re-test. A platform gives you a price up front, a report in about half an hour, testing that runs all year, and machine-readable output your pipeline can consume. It does not give you a human, an accreditation, social engineering or zero-day research. Neither is better in the abstract. They answer different questions. 'Can I show a client a signed report from an accredited firm' is one question. 'Is the build I shipped this morning clean' is a different one.

Fix: Work out which question you are being asked, and by whom. If it comes from a procurement team, a tender or a regulator naming a scheme, buy the accreditation. If it comes from your own engineers or an auditor asking for evidence across a period, buy continuous testing. If both are being asked, buy both: one accredited engagement a year for the signature, continuous automated testing for the evidence in between. That is what most mature teams end up doing, and it usually costs less than two annual engagements.

Reference: NCSC penetration testing guidance (reviewed 10 January 2022) · NCSC CHECK · PCI DSS v4.0 requirement 11.4 · Matproof pricing at matproof.com/pricing

Free scan, Matproof Sentinel, and a traditional firm

Free scanMatproof SentinelTraditional consultancy
Price published before a sales call✓ €149 / €299 / €1,490 / CustomRare
Human penetration tester✗ AI agents only
CREST, CHECK or 3PAO accreditation✗ Matproof holds noneAvailable from accredited firms
Proof of exploit per finding✓ ValidatorAgent re-runs each one
Findings labelled VALIDATED / UNVERIFIED / FALSE_POSITIVE✓ On every finding✗ Usually severity only
Social engineering, phishing, physical entry✗ Out of scope✓ On a red team engagement
Zero-day research✗ Out of scope✓ At the top end
Testing between annual engagements✓ Continuous✗ Point in time
Findings raised in your issue tracker✓ GitHub issues, deduped across re-tests✗ PDF
Machine-readable output✓ SARIF 2.1.0 and JSONUsually PDF only
Published methodn/a✓ docs.matproof.com, including what it will not doVaries

Which requirement actually applies to you

Market: United Kingdom and United States · Figures checked on 19 August 2026. Every row links to the page the number comes from.

ScopePublished priceWhat it coversSource
UK public sector or CNI, systems at OFFICIAL and aboveNCSC CHECK companyNCSC says such systems should be assessed by a CHECK-assured companyNCSC, using a CHECK provider
UK private sector, no contractual demandNo scheme requiredThe NCSC does not tell private organisations to use CHECKNCSC, CHECK penetration testing
UK systemically important financial firms and FMIsCBEST accredited providerBank of England framework, run with the PRA and FCABank of England, CBEST threat intelligence-led assessments implementation guide
UK Cyber Essentials PlusIASME-accredited certification bodyCREST is not the gate. IASME sets the assessor qualificationIASME, Cyber Essentials
Card data environments under PCI DSS v4.0Internal and external test every 12 monthsReq. 11.4.2 and 11.4.3. No certification named. Asks for a qualified party and organizational independencePCI Security Standards Council, PCI DSS v4.0 SAQ D for Merchants
New York covered financial entitiesPenetration test at least annually23 NYCRR 500.5(a)(1), inside and outside the boundary, by a qualified partyNYDFS, Second Amendment to 23 NYCRR Part 500
US defense contractors at CMMC Level 3Penetration test at least annually32 CFR 170.14. Level 1 and Level 2 do not require one32 CFR 170.14, CMMC Level 3 requirements
US federal cloud services under FedRAMPAccredited 3PAO3PAOs are accredited by A2LA against ISO/IEC 17020FedRAMP, penetration test guidance version 3
US healthcare under HIPAANo penetration test required today45 CFR 164.308(a)(8) asks for a periodic evaluation. The word penetration does not appear45 CFR 164.308, HIPAA Security Rule administrative safeguards
SOC 2 auditsNo penetration test required by the frameworkThe Trust Services Criteria do not name it. Auditors and buyers usually ask anywayPCI Security Standards Council, PCI DSS v4.0 SAQ D for Merchants

Read this before you shop. Buyers routinely pay for an accreditation that nothing in their world asks for, and skip the one their contract does ask for. Every row links to the body that runs the scheme.

Sources

  1. NCSC, CHECK penetration testingNo date shown on page
  2. NCSC, using a CHECK providerNo date shown on page
  3. NCSC, penetration testing guidancePublished 8 August 2017, last reviewed 10 January 2022
  4. CRESTNo date shown on page
  5. CREST, CHECK membership requirementsNo date shown on page. States deadlines of 31 March 2025 and 31 March 2026
  6. Bank of England, CBEST threat intelligence-led assessments implementation guideNo date shown on page
  7. IASME, Cyber EssentialsNo date shown on page
  8. PCI Security Standards Council, PCI DSS v4.0 SAQ D for MerchantsPublication date April 2022
  9. NYDFS, Second Amendment to 23 NYCRR Part 500Dated 1 November 2023. Section 500.5 compliance date 1 May 2025
  10. 32 CFR 170.14, CMMC Level 3 requirementsCurrent text as published by Cornell LII
  11. 45 CFR 164.308, HIPAA Security Rule administrative safeguards68 FR 8376 (20 February 2003), amended 78 FR 5694 (25 January 2013)
  12. FedRAMP, penetration test guidance version 3Dated 30 June 2022
  13. A2LA, FedRAMP 3PAO accreditationNo date shown on page
  14. Precursor Security, penetration testing rate cardPage marked updated August 2026
  15. Synack, platform pricingNo date shown on page

Matproof Sentinel pricing (public, no quote required)

Pentest Single
€149 / run
  • 10 specialised AI agents + ValidatorAgent
  • Web + API + Infra + DNS/TLS coverage
  • Up to 50 target URLs per scan
  • PDF + SARIF 2.1.0 + JSON export
  • SOC 2 / ISO 27001 / DORA / NIS2 mapping
  • Open methodology (docs.matproof.com)
Buy single run
Recommended
Pentest Starter
€299 / mo
  • 3 full Sentinel pentests per month
  • All 10 agents (Web / API / Infra / Source-Code)
  • GitHub App + auto-created GitHub Issues
  • Up to 50 target URLs per scan
  • Remediation-diff metric across re-tests
  • SOC 2 / ISO 27001 / DORA / NIS2 evidence
Start Starter
Pentest Growth
€1,490 / mo
  • 20 Sentinel pentests per month
  • Additional scans at €149 each
  • All 10 agents incl. Cloud (Prowler) + Mobile (MobSF)
  • Continuous schedules — hourly / daily / weekly
  • Authenticated scanning (session cookies, bearer tokens)
  • Webhook delivery + priority support
Start Growth
Pentest Enterprise
Custom
  • Everything in Growth + unlimited targets
  • SupplyChain agent on (Trivy: deps + containers + IaC)
  • SSO / SAML, role-based access
  • Custom compliance mapping (PCI DSS, HIPAA, BaFin MaRisk, NEN 7510)
  • Dedicated success manager + SLA
  • Private deployment options
Book a call

Frequently asked questions about penetration testing services

What should I look for in a penetration testing company?

Five things. Proof of exploit on every finding, not scanner output. A report mapped to the controls your auditor checks. Short lead time and a cadence that matches how often you ship. Re-tests included rather than billed again. A price you can get without a sales call. Before any of that, read your contract: if it names a scheme, that decides your shortlist.

Do I need a CREST-accredited provider?

Only when something asks for it. No UK law requires CREST. CREST is a private accreditation body and a delivery partner for NCSC CHECK, Bank of England CBEST, Cabinet Office GBEST and UK CAA ASSURE. For UK public sector and CNI systems at OFFICIAL and above, the NCSC guidance points to CHECK. If you are not public sector or CNI, the NCSC does not tell you to use CHECK. Your customer's security schedule might, so read it first.

What is the difference between CREST and CHECK?

CHECK is the NCSC's own assurance scheme, and it exists so that public sector and CNI systems are tested by assured companies. CREST is an independent accreditation body that operates internationally and acts as a delivery partner for CHECK and other UK schemes. CHECK is scoped to UK public work. CREST is a market signal that also underpins several regulated schemes.

Is there a US equivalent of CHECK?

Not for general commercial work. The closest is FedRAMP 3PAO accreditation, which applies only to federal cloud services and is granted by A2LA against ISO/IEC 17020. In the US, OSCP, GIAC GPEN and CREST are market signals. No US rule we checked names a certification. PCI DSS asks for a qualified party with organizational independence, and NYDFS asks for a qualified internal or external party.

Does Matproof hold CREST or CHECK?

No. Matproof holds no CREST membership, no NCSC CHECK approval and no FedRAMP 3PAO accreditation, and we employ no human penetration tester. Sentinel is an AI platform: ten agents plus a ValidatorAgent that stamps each finding VALIDATED, UNVERIFIED or FALSE_POSITIVE. If your buyer needs a CREST-signed report for a contract, hire an accredited firm. We would rather say that than sell you the wrong thing.

Are automated penetration testing services credible?

For web applications, APIs and external infrastructure, a platform that proves each finding covers the ground most audits check, and it runs all year rather than once. It is not credible as a substitute for social engineering, physical entry, red teaming or bespoke legacy work, and we do not claim it is. Judge a platform on whether it validates findings and publishes its method. Ours is public at docs.matproof.com, including the list of what it will not do.

Will this help us pass an ISO 27001 or SOC 2 audit?

It gives you evidence, not a pass. Reports map to ISO 27001 A.8.8 and A.8.29, SOC 2 CC4.1 and CC7.1, NIS2 Art. 21 and DORA Art. 24, with proof of exploit, CVSS ratings and re-test verification. Continuous testing also evidences that a programme ran throughout a period, which is what surveillance and Type 2 audits look for. Note that the SOC 2 Trust Services Criteria do not actually name penetration testing. Your auditor's request list is what matters.

Do you provide penetration testing services in the UK and US?

Yes, in the sense that Sentinel is a platform and has no geographic scheduling constraint. Reports map to UK, EU and US frameworks. Pricing is published in euros only: €149 per run, €299 per month, €1,490 per month, and Custom. We do not publish a USD or GBP price list.

Related

Go deeper — related blog articles

When not to buy Matproof Sentinel

Sentinel is an AI penetration testing platform and nothing more. Ten agents test, and a ValidatorAgent re-runs every finding before it ships. There is no human penetration tester behind it, and Matproof holds no accreditation of its own. Several kinds of work are therefore out of our reach, and we will point you elsewhere rather than take the order.

  • No human penetration tester. AI agents find the issues. Another AI agent checks them.
  • No CREST membership, no NCSC CHECK approval, no FedRAMP 3PAO accreditation. We cannot sign a report as an accredited assessor.
  • No social engineering, no phishing simulation, no physical intrusion.
  • No zero-day research and no improvised business-logic red teaming.
  • Buy from an accredited firm if a customer contract, a tender, or a scheme such as CHECK, CBEST, GBEST or ASSURE names one.
  • Buy from an accredited 3PAO if you are in a FedRAMP process.
  • Ask your QSA before relying on an AI-only test for PCI DSS 11.4. PCI names no certification, but your QSA decides what qualified means.
  • Hire a human team for OT and SCADA estates, mainframes, and anything that needs a person on site.

Start with a free scan, then decide who you need

Run a free scan to see your exposed surface and the report format. A full report costs €149. Continuous testing costs €299 a month. If it turns out you need a CREST-signed or 3PAO-signed report, we will tell you to hire an accredited firm.

Run free scan