Book an Appointment

Understanding and commissioning penetration tests the right way

How a penetration test works, how it differs from vulnerability scans and red teaming – and which methodologies, processes and regulatory requirements matter when commissioning one.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

7phases in the PTES (version 1.0) – from pre-engagement interactions to reporting
4.2current stable version of the OWASP WSTG (Dec 2020), version 5.0 under development
per year at least for critical systems – established practice, no universal mandatory frequency
3years: TLPT at least this often (DORA Art. 26, financial entities designated by the authorities)

A penetration test is an authorised, controlled attack on your own systems: security experts use the methods of real attackers to find vulnerabilities and demonstrate whether they can actually be exploited. It thereby answers a question that automated scans leave open – which weaknesses, in combination, can genuinely lead to a security incident. With NIS2, DORA and TISAX, demonstrating effective technical security measures is increasingly becoming a regulatory expectation. This article puts terminology, test types, methodologies, process and testing frequency into context.

The Essentials at a Glance

Six topic blocks — tap to expand.

Black, grey and white box compared

How much prior knowledge the testers receive – and what that means for testing depth and coverage. Perspective (external/internal) and prior announcement are defined during scoping.

Attacker's perspective
  • Testers start without any internal information – realistic from an attacker's perspective.
  • Time-consuming and with lower coverage, because testing time is spent on reconnaissance.
attacker's perspectivereconnaissancelower coverage

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

OWASP Foundation · 2020

OWASP Web Security Testing Guide v4.2

Reference test catalogue for web applications and APIs; version 4.2 since December 2020, version 5.0 under development.

Bundesamt für Sicherheit in der Informationstechnik (BSI) · 2016

Ein Praxis-Leitfaden für IS-Penetrationstests

German-language guidance on the execution and commissioning of IS penetration tests (as of 08.11.2016).

Amtsblatt der EU / EUR-Lex · 2022

Richtlinie (EU) 2022/2555 (NIS2)

Art. 21(2)(f) requires policies and procedures to assess the effectiveness of cybersecurity risk-management measures.

Amtsblatt der EU / EUR-Lex · 2022

Verordnung (EU) 2022/2554 (DORA)

Art. 25 names penetration tests as part of the testing programme, Art. 26 requires TLPT at least every three years; applicable since 17 January 2025.

Verband der Automobilindustrie (VDA) / ENX Association · 2023

VDA Information Security Assessment (ISA) Version 6

Assessment basis for TISAX assessments; version 6.0 has been mandatory for newly commissioned assessments since 1 April 2024 (current release 6.0.3); the successor catalogue ISA 2027 applies to orders placed from 1 January 2027.

Planning a penetration test?

In a no-obligation initial consultation, we work with you to define scope, testing depth and the right testing frequency for your systems.