Secure development lifecycle (SSDLC): what it is and how to put it in place
What the secure development lifecycle is, what happens in each phase, what SAST, DAST and SCA add, and where to start if you have nothing in place today.
A pentest, or penetration test, is an authorised and bounded attack against your own systems to find how somebody without permission would get in. This page explains the whole project, not the definition: what is decided before it starts, what happens each day, what you get at the end, how it differs from a vulnerability scan and what makes it cost what it costs. If you only want the short definition, it is on the penetration test glossary entry.
A pentest is an engagement defined by three things: written permission, a closed scope and an objective. Without all three, it is not a pentest.
The work consists of doing what an attacker would do: finding what you have exposed, finding flaws, chaining them and proving how far that gets. The important word is proving. A pentest does not say "this might be exploitable": it exploits it, in a controlled way, and shows you the evidence.
What it is not:
It is the question every first-time buyer asks, and the reason people pay for a pentest and receive something else.
A vulnerability scan is automated, broad and recurring. A tool is run across many assets, compares versions and configurations against a database of known flaws, and returns a list. It is cheap, it can be run every month and it is good for what it is good for: knowing what you have left unpatched.
A pentest is manual, narrow and one-off. A person tries to get in. It costs more, it covers less surface and it finds what no tool sees: business logic flaws, permissions that do not separate one customer from another, chains of three harmless things that together grant access.
They do not compete, they are sequenced. The recurring scan is hygiene and goes first, because using a pentest to find something a scanner would have shouted about for free is throwing money away. The pentest comes afterwards and answers a different question.
How to tell what you are being sold, with a single question: ask for the sample report. If it has hundreds of findings, all in the same format and none with a reproducible request, it is a scanner export with a cover page.
This phase is not billed and it decides the whole result. All of it is closed in writing and taken together it is called the rules of engagement.
The detail of how we do it is in our methodology, and there are two full worked examples written phase by phase: a web application pentest and an internal network one.
They are named after what is tested, and it is normal to need two or three, not all nine. Start where your business is and with whatever faces the internet.
If what you want to measure is not the vulnerabilities but the ability to detect and respond, the format is a red team, or an assumed breach exercise that starts from the assumption that the attacker is already inside. And if you do not know which to start with, the usual way in is ethical hacking.
When the project ends, what you are left with is a document. What it has to carry:
A PDF is a document; findings inside your team’s workflow are work already started. In our case they live on the platform from the moment they are found, with their status, instead of all appearing together at the end.
A pentest without a retest is a photograph: somebody says what is wrong, your team fixes it and nobody checks that it is fixed. It happens a lot that the fix closes the path that was tested and leaves the one next to it open.
What has to be closed off in the contract, beforehand and not afterwards: whether the retest is included or billed separately, how long you have to request it, whether it covers only what was fixed or also whatever changed around it, and what document it produces. The usual output is a version of the report with each finding marked as fixed, mitigated or open, which is what you later show a customer or an auditor.
And something that costs nothing and avoids almost every deadlock: agreeing beforehand who fixes, within what deadline by severity, and who can decide that a risk is accepted instead of corrected.
You will not find a price here, and that is on purpose: a number without your scope in front of it is not information, it is bait. What can be explained is what moves it, which is what you need in order to ask for a quote without being handed a template figure.
A pentest is priced in days of work, and the days come from:
On duration, what can be said without inventing anything: the testing part is usually a good deal shorter than the whole project, because the scope, coordinating access, the report and the retest also take up calendar. If somebody offers you "the whole infrastructure" in two days, what fits into two days is one pass of a tool.
And the compliance side, which is the real reason behind many projects. ENS is Spain’s national security framework for public sector information systems: it requires periodic audit and it reaches whoever sells to Spanish public administration through their contracts. ISO 27001 is not certified with a pentest, but the pentest is the evidence that several of its controls rest on. NIS2, the European directive, reaches the supply chain, so it can arrive as a clause from your customer. And DORA, the European regulation for the financial sector, requires certain entities to run threat-intelligence-led testing, TLPT, which is not a normal pentest. For personal data protection the framework is the GDPR, the European regulation Spanish texts call the RGPD.
The full catalogue is at services, how to choose a provider is in this guide, and for a specific scope, contact.
If any of this looks like a problem you are carrying, half an hour on a call scoping it with a senior pentester is worth more than reading another article.
Hablar con un pentester seniorPick a time that suits you. You tell us what you need and where you are, and we explain how we work and how we can help.