Penetration testing and security assessments for applications and IT infrastructure

Dutch pentesting partner since 2012 OSCP-certified ethical hackers with CCV Keurmerk Pentesten certification and ISO 27001:2022. Trusted by 500+ organizations.

Manual testing by experts Our ethical hackers use the same methods as real attackers. Four-eyes principle with peer review on every finding.

For DigiD, NIS2, ISO 27001 and DORA Pentests for web apps, networks, cloud, OT, APIs and mobile apps. Compliant with OWASP, PCI DSS, NEN 7510, GDPR and NCSC guidelines.

Response within 1 business day Complimentary scoping conversation. Quotation within 3 business days. Data stays in Europe. Reporting directly usable for your auditor.

Why choose DongIT

Nine reasons why 500+ organizations trust us with their pentesting and security assessments.

 

Manual testing by experts

Predominantly manual assessment by OSCP, OSWE, OSEP and OSED-certified ethical hackers. We find business logic flaws and context-specific risks that scanners systematically miss.

 

Four-eyes principle

Every pentest is performed by a minimum of two ethical hackers, with peer review on every finding. More perspectives lead to higher-quality reports and more discovered vulnerabilities.

 

CCV Keurmerk Pentesten

Officially certified per the requirements of the Dutch Centre for Crime Prevention and Safety (CCV). Demonstrable proof of quality for your auditor, DPO and supervisory authority.

 

ISO 27001:2022 certified

We have been ISO 27001-certified since 2025. We know first-hand what external auditors expect and deliver reporting that aligns directly with their requirements.

 

Compliance mapping

Reporting directly usable for DigiD audits (Logius v4.0), NIS2, DORA, NEN 7510, GDPR and PCI DSS. Findings explicitly linked to the controls of your framework.

 

Security Reporter platform

Reporting via our self-developed platform. Direct contact with the pentester per finding, exports for your development team and compliance mapping in one environment.

 

Technology independent

Experience with virtually every framework and tech stack: web apps, mobile apps, APIs (REST, GraphQL), cloud (Azure, AWS, GCP), Kubernetes, OT systems and network infrastructure.

 

Flexible testing methods

Black-box, grey-box and white-box testing. Time-boxed or budget-boxed based on your preference. From one-off pentests to periodic assessments and retests.

 

Web Security Scan Trustmark

Display the Web Security Scan Trustmark logo on your website as proof of your commitment to security and customer trust. Available after a successfully completed pentest.

Strengthen the security of your applications and IT infrastructure

Detect and remediate vulnerabilities in your web applications, networks, cloud environments and APIs before attackers do. Every pentest is tailored to your technology, goals and compliance requirements, with concrete recommendations your development team can implement directly.

Response within 1 business day, quotation within 3 business days.

Schedule a complimentary scoping conversation

Why organizations choose to have a pentest performed

An upcoming audit, a client asking for demonstrable security, an incident at a competitor, or new legislation such as NIS2, DORA and the Cyber Resilience Act. Six concrete reasons why 500+ organizations ask us to test their applications and infrastructure:

  1. Find vulnerabilities before attackers do

    Ethical hackers approach your systems like real attackers, with the same techniques and creativity. That way you know where your weak spots are not after an incident, but before, when remediation can still be planned and affordable.

  2. Meet concrete deadlines

    The Dutch Cybersecurity Act (NIS2) has been in effect since 15 August 2026. The Cyber Resilience Act requires software vendors to report actively exploited vulnerabilities from 11 September 2026. DORA requires annual testing for financial entities and DigiD audits are mandatory every year. Our pentests deliver the reporting your supervisory authority expects.

  3. Prevent financial damage and fines

    The fines stack up: up to €10 million under NIS2, up to €15 million under the CRA and up to 4% of annual turnover under the GDPR. Add remediation costs that often run ten times higher than the investment in prevention. A pentest is the cheapest form of risk management.

  1. Give customers and partners confidence

    Clients and partners increasingly ask for demonstrable security: from SMB customers who expect a quality label to enterprise buyers running formal TPRM assessments. With a recent pentest report and the Web Security Scan Trustmark on your website, you have the answer to due diligence questions ready.

  2. Strengthen your commercial position

    Cybersecurity has become a selling point. Organizations that demonstrably test through a CCV-certified party score higher in tenders and with procurement departments, and stand stronger with cyber insurers, from premium negotiation to acceptance.

  3. Protect reputation and client trust

    A cyber incident is one of the most expensive events that can happen to your organization: client churn, media attention, contract losses and operational disruption. For SMBs an incident can threaten business continuity, for enterprises the damage extends to shareholders and supervisory authorities. Preventive pentesting demonstrably reduces impact and detection time.


 

Development and security expertise under one roof

DongIT combines deep pentesting expertise with a background in software development. Since 2012 we have worked with the tech stacks your teams use: from Node.js, .NET and Java to React, Kubernetes and cloud-native architectures (Azure, AWS, GCP). Our remediation guidance includes concrete code examples your development team can apply directly, instead of abstract lists of risks.

Manual and automated testing

 

Our pentests go beyond standard security scans. Where automated tools find known vulnerabilities, our OSCP-certified ethical hackers discover what scanners systematically miss: business logic flaws, IDOR patterns, race conditions and creative exploit chains. Four-eyes principle with peer review on every finding ensures the highest report quality.

Proven attack techniques from the field

 

As specialized ethical hackers we use the same techniques, tools and tactics that real attackers deploy daily. We actively track the threat landscape, MITRE ATT&CK frameworks and new attack vectors. This realistic approach shows not only where you are vulnerable, but also how your detection and response capabilities perform during an actual incident.