The Pentest Process, Pricing, and When My Company Needs One

TL;DR: A pentest is an ethical hacker's work of looking at a company's systems through an attacker's eyes and finding vulnerabilities. There are web application, network infrastructure, mobile app, cloud environment and wireless network types. The OWASP Testing Guide and NIST SP 800-115 methodology are standard. Depending on scope it takes 5 to 25 business days, and the price range is wide. It is effectively mandatory for ISO 27001, PCI-DSS and KVKK compliance, and on the request of large customers.

This article is the pentest-focused support section of the Turkey Cyber Threat Landscape 2026 pillar article. We explain in everyday language which company needs a pentest and why, how the process proceeds, and the factors that determine the price.

What a Pentest Is, and What It Is Not

A pentest consists of the trio finding vulnerabilities + verifying exploitation + reporting. Its difference from a vulnerability scan is very clear: a scan only scans, saying "there is this opening on this port." A pentest proves that the opening is genuinely exploitable; it runs remote commands, escalates privileges, moves laterally across the network, and reaches sensitive data. Proof of exploitation increases the legal and technical weight of the report.

Selling the output of an automated scanner as a "pentest report" is a common bad practice. A real pentest is the human interpretation of the findings of automation. PTES (Penetration Testing Execution Standard) and NIST SP 800-115 tie this human intervention to standard steps.

Pentest Types

Web Application Pentest

Vulnerabilities in a web application are listed in the OWASP Top 10: SQL injection, XSS, broken authentication, IDOR (Insecure Direct Object Reference), CSRF, server-side request forgery, RCE (Remote Code Execution), insecure deserialization. During testing, every endpoint, every form, every API call is examined manually.

Network / Infrastructure Pentest

Carried out in two directions: internal (from within the network, from an employee's perspective) or external (from the internet, from an attacker's perspective). The steps followed are port scanning, OS fingerprinting, service-version detection, known-CVE matching, exploit verification and post-exploitation (privilege escalation, lateral movement, persistence).

Mobile App Pentest (iOS, Android)

Static analysis (code review), dynamic analysis (runtime), certificate-pinning bypass, root/jailbreak detection bypass, IPC (Inter-Process Communication) review, file-system traces. On iOS the main tools are Frida, Objection and Cycript; on Android, adb, Frida and Drozer.

Cloud Pentest (AWS, GCP, Azure)

IAM (Identity and Access Management) misconfiguration, S3 bucket exposure, lambda permission abuse, EKS RBAC, Azure Storage SAS leak, GCS service-account key. Within the framework of the cloud providers' shared responsibility model, the configuration for which the customer side is responsible is checked.

Wireless Pentest

Protocol-level testing of WPA/WPA2/WPA3, rogue AP (fake access point), evil twin, captive-portal bypass, KRACK attack, deauthentication. On a corporate wireless network, 802.1X/EAP verification is also within scope.

Social Engineering / Red Team

Phishing campaigns, vishing (voice social engineering), physical intrusion (badge clone, tailgating), USB drop tests. For detailed phishing indicators, see our phishing indicators article.

Pentest Classes

Black Box

No information is given to the hacker. Only the company name or the target IP/domain is known. The attacker's perspective is the most realistic, but the timeline lengthens and significant scope can be missed.

Gray Box

Limited information is shared: a user account, an IP list, an architecture diagram. The most common choice. Both fast and realistic.

White Box

Full access is given: source code, architecture diagram, admin account, documentation. The most comprehensive findings emerge. The most suitable choice ahead of an ISO 27001 audit.

The Process Step by Step (PTES + NIST SP 800-115)

  1. Pre-engagement. Scope (what is in, what is out), Rules of Engagement (attack hours, "no-touch" rules for sensitive systems), NDA signature, payment terms, the delivery format of the report.
  2. Reconnaissance. Passive (OSINT, DNS, WHOIS, social media, leaked credentials) + active (port scan, service enumeration).
  3. Threat modeling. What is the most valuable asset, who is the most likely threat actor, which scenarios will be tested.
  4. Vulnerability analysis. Listing vulnerabilities with manual and automated tools.
  5. Exploitation. Proving that the vulnerability found is genuinely exploitable.
  6. Post-exploitation. Privilege escalation, lateral movement, persistence, data access.
  7. Reporting. Executive summary + technical details + remediation.
  8. Cleanup. The files, accounts and persistence mechanisms left during testing are cleaned up.
  9. Re-test. A check pentest after the fixes (usually within 30-60 days).

How Long Does It Take?

It varies by scope:

  • Web app (medium complexity): 5-10 business days.
  • Network external (50 IPs, many services): 7-15 business days.
  • Mobile app (iOS + Android): 8-15 business days.
  • Cloud (AWS multi-account, EKS, S3 fleet): 10-20 business days.
  • Red team campaign (multi-vector): 4-8 weeks.

The critical factors affecting the timeline: scope breadth, the liveness of the system (test bandwidth), the test class, reporting depth, and whether a re-test is included.

What Determines the Price?

A pentest price is not a single line item but a combination of five main factors:

  1. Scope: How many IPs, how many applications, how many endpoints, how many cloud accounts.
  2. Test class: Black/gray/white box (white box is more comprehensive but faster).
  3. Test type: Web + network + mobile + cloud + red team layers.
  4. Urgency: Express (within 1-2 weeks) vs standard (queued for 4-6 weeks).
  5. Certification requirement: If a CREST-approved or OSCP/OSWE-level pentester is required, the cost rises.

There is no fixed price list in the industry, because no two organizations ever have the same scope. The standard process: a scope discussion, an RFP/RFQ, a written quote. DSET provides a quote within 48 hours after a free scope discussion.

When Is It Needed?

  1. A company that will obtain/renew ISO 27001: Annex A 8.8 (technical vulnerability management) and A 8.29 (security testing in development).
  2. PCI-DSS compliance: an annual requirement for card-processing e-commerce.
  3. Proof of KVKK compliance: an indicator of technical safeguards in a Board review.
  4. A request from a large corporate customer: a pentest report is requested in an RFP/RFI.
  5. SaaS sales: within the framework of a SOC 2 audit.
  6. A new product launch: ahead of a critical release.
  7. Major release: ahead of a major update 1-4 times a year.
  8. Post-incident: to prove that the openings have been closed after a ransomware or breach.

As part of its ISO 27001 preparation package, DSET offers a pentest service. For detail, see our How to obtain ISO 27001 article.

Pentester Certifications

  • OSCP (Offensive Security Certified Professional): the industry standard, a practical 24-hour exam.
  • OSWE (Web Expert): deep dive into web applications.
  • OSEP (Evasion): EDR/AV bypass.
  • CRTO (Red Team Ops): adversary simulation.
  • GIAC GPEN: a SANS certification.
  • CREST: UK-origin, an independent competence assessment.
  • CEH (Certified Ethical Hacker): entry-level, insufficient in depth.

The choice is made according to need. The combination of OSCP and CREST is the gold standard for corporate buyers.

The Structure of a Pentest Report

A report that stands up in court or before a regulator contains these sections:

  • Executive Summary: 1-2 pages for management, the risk score, prioritization.
  • Technical Details: for each finding, the vulnerability name, the CVSS score, evidence (screenshot, log), an impact description, a remediation recommendation.
  • Methodology: PTES and NIST references, the tools used and their versions.
  • Appendices: tool outputs, screenshots, exploit code.
  • Re-test results: verification of the fixes.

CVSS Scoring

The Common Vulnerability Scoring System (CVSS 4.0 is new, 3.1 still widespread) is the standard metric for prioritizing vulnerabilities. The score ranges:

  • Critical (9.0-10.0): Patch urgently; production may even be stopped.
  • High (7.0-8.9): Patch within 7-30 days.
  • Medium (4.0-6.9): Patch within 30-90 days.
  • Low (0.1-3.9): Within the plan, a year-end sprint.

Across the industry the SLA target for Critical + High vulnerabilities is under 30 days.

The Difference Between "Bug Bounty" and a Pentest

Bug bounty: continuously open, a large number of hackers, outcome-based payment (payment only for a finding). Pentest: a defined period, a contracted team, a fixed fee. They complement each other. Bug bounty has a broad "everyone looks at every angle" logic; a pentest is deep, focused work. A mature security program uses both.

DSET's Difference: The KAOS Local AI Engine

The differentiating side of DSET's pentest service is the KAOS local AI security engine. Turkish natural-language queries, MITRE ATT&CK technique matching, automated exploit verification (XBOW-style generate-and-verify). It saves the pentester hours from reconnaissance and initial enumeration, opening space to concentrate on manual exploitation. Data does not leave the country, and the process is KVKK-compliant.

What Is Done After a Pentest?

  1. Fix Critical/High first: patch within the SLA.
  2. Verify with a re-test: a check pentest within 30-60 days.
  3. Set up a vulnerability-management program: a continuous process, not a one-off.
  4. Integrate SAST/DAST into the CI/CD pipeline: catch it as the code is written.
  5. Regular pentests: annual or every 6 months (by regulation or good practice).

A Pentest Together With ISO 27001

For companies that will obtain and renew the ISO 27001 certificate, a pentest is effectively mandatory under Annex A 8.8 (Management of technical vulnerabilities) and A 8.29 (Security testing in development and acceptance). The detailed process is in our How to obtain ISO 27001 article.

KVKK and Confidentiality

During a pentest, everything the pentester sees may be a corporate secret and personal data under the KVKK. The NDA is signed mutually, the lab is air-gapped, the reports are encrypted, and temporary evidence files are deleted in line with NIST SP 800-88 Purge. Data does not leave the country.

Frequently Asked Questions

My company is small, is a pentest necessary?

If the regulation does not require it, it is not essential. But if there is a corporate-customer request, exporting, an ISO 27001 goal or SaaS sales, it is effectively necessary. Even a one-off initial pentest, not annual, closes major openings.

Does the output of an automated tool replace a pentest?

No. A vulnerability scan is a different service. A pentest includes exploit verification, a scan does not. The regulator notices this too.

Will my system crash during the pentest?

Rules of Engagement are clarified during the pre-engagement phase. High-risk actions are not taken on the production system; they are done in staging or in a controlled window. On production, only passive and low-impact tests.

How often should I have a pentest?

At least once a year (by regulation), every time before a major release, and definitely after a breach. Mature programs run at a 6-month frequency.

What should I look for when I say "certified pentester"?

A minimum of OSCP, ideally OSCP + OSWE + CREST. CEH alone is not enough.

Who is the pentest report shared with?

The content is sensitive. Only management, IT, the regulator (if needed), the audit body (for ISO 27001), and a redacted version if a customer requests it.

Is the re-test fee standard?

In most DSET contracts the re-test is included (1 re-test within 60 days of contract signature). An independent re-test is priced separately.

Working With DSET

The DSET pentest service runs with the support of the KAOS local AI engine. Our Ankara Hacettepe Teknokent center, an OSCP + CREST certified pentester team, the OWASP + NIST + PTES methodology, ISO 27037-compliant reporting, a KVKK-compliant process.

The Turkey Cyber Threat Landscape 2026 main content and our How to obtain ISO 27001 article are complementary resources.

Contact: Hacettepe Teknokent, Ankara. Phone: +90 536 662 38 09. Email: [email protected].

The scope discussion is free, and a written quote follows within 48 hours.


Sources: OWASP Top 10, OWASP Testing Guide, NIST SP 800-115, PTES, OSCP, CREST, MITRE ATT&CK