forumNew topic

Asked for a pentest for a public tender: what is it exactly and when is it worth it?

İİbrahim Y***Member
Job title
Administrative manager
Sector
Chemistry
Organization type
regional distributor
Joined
Dec 2022
Message
239
#1

We are a team of 7 based in Barcelona developing appointment scheduling and document tracking software for local governments and public agencies. Last week, we started preparing our bid for a municipal digital infrastructure tender in Catalonia with a 55,000 EUR budget. However, the technical specifications require an up-to-date "pentest report" certified by an independent cybersecurity firm.

We've never gone through this type of audit before. We handle conventional software testing internally and assumed our system was secure. The first two quotes we received from outside firms range between 4,500 EUR and 7,000 EUR, which is a substantial cash outlay for a boutique software shop like ours.

What does a penetration test actually cover and what purpose does it serve? Is it just an automated vulnerability scan or does it involve manual testing? Does it really make sense to spend this money when winning the contract isn't guaranteed, or is this just standard protocol for public tenders?

OOkan I***Member
Job title
Front office accounting
Sector
Cosmetics
Organization type
sole proprietorship
Joined
Nov 2023
Message
260
Most Helpful#2

Short answer: A pentest is a controlled simulation where ethical security specialists approach your system like an actual attacker to identify vulnerabilities, exploit them, and show how deep an intrusion could go. It uses manual testing to uncover business logic flaws, privilege escalation gaps, and complex database exploits that automated scanners completely miss.

People often confuse automated vulnerability scanning with a pentest. An automated scan is just software listing known CVEs, taking a few hours. A genuine penetration test involves specialists digging through your application source code, API endpoints, session handling, and server configurations for days. If the tender specifies an 'independent pentest report', the municipality expects an established methodology with risk-scored findings and a re-test, not just an automated green-checkmark PDF.

Looking at the tender itself: public entities in Spain are legally required to mandate this test for third-party software under public sector data security standards. This cost isn't just an expense for this single bid; it's a badge of enterprise maturity for your product. Check the scope of that 4,500 EUR quote carefully; ensure it includes a free validation re-test once you patch the reported flaws. Once you hold this report, you can confidently reuse it across other public tenders for an entire year.

HHilal B***Veteran
Job title
Graphic Designer
Sector
Electrical-electronics
Organization type
regional distributor
Joined
Dec 2023
Message
17
#3

Check the test methodology specified in the RFP. Black-box testing is done with zero prior knowledge of the system, while grey-box provides user credentials to audit interface and authorization vulnerabilities. Municipalities almost always ask for grey-box.

OOrhan D***Expert
Job title
Store associate
Sector
IT services
Organization type
early-stage startup
Joined
Nov 2024
Message
228
#4

We paid 5,200 EUR for an audit on a similar project in Madrid last year. They uncovered two critical privilege escalation bugs in our own code; an outside user could access documents belonging to everyone else. We won the contract, but more importantly, we dodged a massive data leak scandal.

YYasemin K***MemberCommunity member
Joined
Jan 2024
Message
82
#5

There are shops out there charging 1,500 EUR just to run an open-source automated vulnerability scanner and dress up the report with AI. Public agencies immediately discard superficial reports during technical review, so you'd just be throwing money away.

SSinemExpert
Job title
Project manager
Joined
Oct 2023
Message
176
#6

Define your scope carefully when requesting quotes. Ask for pricing strictly covering the specific module and host server required by the tender. If you throw your entire corporate infrastructure into the mix, costs will balloon and burn through your budget needlessly.

DDoruk Y***Member
Job title
Accounting Manager
Sector
Seafood
Organization type
two-branch business
Joined
Oct 2025
Message
86
#7

The engagement usually follows three phases: 1) Scoping and contracting. 2) Attack simulation and vulnerability reporting. 3) A re-test after you remediate the issues. Agencies will want to see that vulnerabilities were actually resolved in the final sign-off report.

JJale D***Member
Job title
Front office accounting
Sector
Logistics
Organization type
boutique agency
Joined
Aug 2025
Message
8
#8

unfortunately, this has become standard procedure if you're gonna do business with the public sector. i'd say don't look at it as a one-time expense but rather as part of the product's quality control costs.

UUğur K***ExpertCommunity member
Joined
Mar 2023
Message
44
#9

When they run this test do they work in a staging environment or attack the live server? Is there any risk of the system crashing or customer data getting corrupted during testing?

ÖÖzge C***Expert
Job title
Purchasing manager
Sector
Cosmetics
Organization type
300-person organization
Joined
Mar 2023
Message
141
#10

I totally understand that the budget seems high at first. But when selling software to the public sector neutral security certifications like this give you immense leverage at the table, just as much as customer references do—dont hesitate.

AAhmet B***MemberCommunity member
Joined
Jan 2023
Message
280
#11

I think it's hard to be that definitive about what is a pentest. Most time waste accumulates in tasks waiting for approval.

If permission and scope aren't in writing, don't start that test.

GGizem Y***Member
Job title
Board member
Sector
Livestock
Organization type
a company within a holding
Joined
Jan 2024
Message
209

Doki · Server maintenance contract · 2025

#12

This thread is archived.

RRamazan Y***New member
Job title
Content Editor
Sector
Jewelry
Organization type
workshop
Joined
Sep 2026
Message
8
#13

How did you solve this? Forgotten test environments are more often the entry point than live systems.

The biggest time-waster for us was not knowing who had the final say.

GGürkan B***MemberCommunity member
Joined
Oct 2024
Message
407
#14

Great work. Most time waste accumulates in tasks waiting for approval.

The harder it is to reverse a decision, the slower you should make it. Just leaving this note, it might be useful.

MMustafa P***Expert
Job title
Content Editor
Sector
E-commerce
Organization type
300-person organization
Joined
Aug 2023
Message
140
#15

My perspective changed after experiencing that. Most time waste accumulates in tasks waiting for approval.

Good luck with that.

MMerve Ö***MemberCommunity member
Joined
Feb 2026
Message
1
#16

Correct.

NNagihanMember
Job title
Recruitment Specialist
Organization type
workshop
Joined
May 2024
Message
98
#17

I'm in the same situation, that's why I'm asking. If it's your first time, start small; scaling comes later.

If you post the result here, it will help others too.

HHasan E***Expert
Job title
Content Editor
Sector
Construction
Organization type
family business
Joined
Dec 2023
Message
88
#18

i feel the same way... like any unwritten clause becomes a point of disagreement later as both sides remember it differently.

if permission and scope arent in wriiting dont start that test. just leaving this note, it might be useful.

OOkanMember
Job title
Bookseller
Joined
Jan 2024
Message
71

Doki · Server maintenance contract · 2026

#19

The opposite happened to me, that's why I'm writing. If you get three different answers on a topic the question was asked wrong.

The harder it is to reverse a decision the slower you should make it. like proven by experience.

BBeren Ç***MemberCommunity member
Joined
Jul 2024
Message
398
#20

Timely topic.

Reply