A penetration test is a time-boxed, commissioned security assessment in which testers manually identify, chain and exploit vulnerabilities in a controlled manner to demonstrate their real-world risk. A vulnerability scan must be clearly distinguished from this: it checks automatically and at scale against known vulnerability patterns, but does not verify findings and regularly produces false positives – it is part of ongoing vulnerability management, not a substitute for a pentest. Red teaming, in turn, pursues a different goal: it covertly simulates a realistic attack on defined crown jewels and also tests the defenders' detection and response capabilities, whereas a penetration test examines a defined scope as completely as possible for vulnerabilities.
Understanding and commissioning penetration tests the right way
How a penetration test works, how it differs from vulnerability scans and red teaming – and which methodologies, processes and regulatory requirements matter when commissioning one.
A penetration test is an authorised, controlled attack on your own systems: security experts use the methods of real attackers to find vulnerabilities and demonstrate whether they can actually be exploited. It thereby answers a question that automated scans leave open – which weaknesses, in combination, can genuinely lead to a security incident. With NIS2, DORA and TISAX, demonstrating effective technical security measures is increasingly becoming a regulatory expectation. This article puts terminology, test types, methodologies, process and testing frequency into context.
The Essentials at a Glance
Six topic blocks — tap to expand.
Black, grey and white box compared
How much prior knowledge the testers receive – and what that means for testing depth and coverage. Perspective (external/internal) and prior announcement are defined during scoping.
- Testers start without any internal information – realistic from an attacker's perspective.
- Time-consuming and with lower coverage, because testing time is spent on reconnaissance.
- Lies between black and white box, typically with test accounts and documentation.
- In practice it has established itself as the efficient standard for most test objectives.
- Architecture documentation, configurations or source code are available.
- This enables the greatest testing depth per unit of time.
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
OWASP Web Security Testing Guide v4.2
Reference test catalogue for web applications and APIs; version 4.2 since December 2020, version 5.0 under development.
Ein Praxis-Leitfaden für IS-Penetrationstests
German-language guidance on the execution and commissioning of IS penetration tests (as of 08.11.2016).
Richtlinie (EU) 2022/2555 (NIS2)
Art. 21(2)(f) requires policies and procedures to assess the effectiveness of cybersecurity risk-management measures.
Verordnung (EU) 2022/2554 (DORA)
Art. 25 names penetration tests as part of the testing programme, Art. 26 requires TLPT at least every three years; applicable since 17 January 2025.
VDA Information Security Assessment (ISA) Version 6
Assessment basis for TISAX assessments; version 6.0 has been mandatory for newly commissioned assessments since 1 April 2024 (current release 6.0.3); the successor catalogue ISA 2027 applies to orders placed from 1 January 2027.
Related Services
Planning a penetration test?
In a no-obligation initial consultation, we work with you to define scope, testing depth and the right testing frequency for your systems.