GDPR Article 32. Testing evidence, started today

Article 32 asks for regular testing. Here's the regular testing.

GDPR Article 32 requires a process for regularly testing, assessing, and evaluating the effectiveness of your technical security measures. A penetration test is the clearest way to demonstrate that. We test your internet-facing systems and infrastructure with manual exploitation, report the findings, and give you evidence you can point to. Start online, no sales call.

Article 32 evidence Manual testing Published pricing Attestation letter included
Why GDPR teams end up here

EU data protection authorities want to see you tested your controls, not just documented them.

GDPR doesn't name "penetration test" as a required control, but Article 32 requires a process for regularly testing the effectiveness of technical security measures — and a documented pentest report is the most direct evidence most data controllers and processors can produce. This page is for the privacy or security lead who needs that evidence on file, on a reasonable timeline, without three weeks of vendor calls first.

What audit-grade means

Four commitments that separate a real pentest from a quick-find scan.

"Audit-grade" is a category, not a slogan — it's what we commit to on every engagement, not just a claim.

Manual validation

Findings are manually confirmed, not scanner output. What's in your report actually happened.

Full in-scope coverage

Every system you list gets tested. No sampling, no shortcuts.

Published pricing

Fixed rates by asset count, listed on this page. No quote call required to start.

Free 14-day retest

Remediate and we retest everything from scratch at no charge within 14 days.

Honest pricing

Published rates. No quotes. No sales calls.

Data controllers and processors vary widely in infrastructure size. Pricing scales with the number of hosts, IPs, or cloud endpoints you want tested.

How pricing works: The first asset covers the essential work every engagement requires — scoping, setup, validation, and reporting. Pricing scales with your environment from there. Count each public-facing host, IP, or cloud endpoint you want tested — they don't have to be contiguous or in the same network. If you have more than 256 assets, contact us.
Hosts, IPs, or cloud endpoints to test Price Price per asset
1$4,995$4,995
2–4$7,995$1,999 – $3,997
5–8$10,995$1,374 – $2,199
9–16$15,995$1,000 – $1,777
17–32$25,995$812 – $1,529
33–64$36,995$578 – $1,121
65–128$52,995$414 – $815
129–256$72,995$285 – $566

Manual validation included on every engagement. No false-positive reports. Fixed pricing designed for fast procurement.

GDPR FAQ

What data protection teams ask before they buy.

Does GDPR require a penetration test?
Not by name. Article 32 requires a process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational security measures. A penetration test is widely used to satisfy that requirement, but GDPR doesn't mandate this specific test — we won't tell you otherwise.
What's tested?
Your internet-facing systems and infrastructure: web applications, APIs, VPNs, mail, DNS, and any public endpoint processing personal data. List what's in scope and we test all of it.
How fast is the report?
There's no sales queue to wait on — scoping starts as soon as you check out. Report delivery timing scales with the number of assets tested; we'll confirm your specific timeline before testing begins.
Is there a sales call?
No. Choose your scope from the pricing table and checkout online. Email hello@pentestexpress.com if you have scoping questions first.
Get started

Ready to get your Article 32 testing evidence?

Self-serve checkout, published pricing. No call, no quote, no waiting.