- Job title
- Administrative manager
- Sector
- Chemistry
- Organization type
- regional distributor
- Joined
- Dec 2022
- Message
- 239
We are a team of 7 based in Barcelona developing appointment scheduling and document tracking software for local governments and public agencies. Last week, we started preparing our bid for a municipal digital infrastructure tender in Catalonia with a 55,000 EUR budget. However, the technical specifications require an up-to-date "pentest report" certified by an independent cybersecurity firm.
We've never gone through this type of audit before. We handle conventional software testing internally and assumed our system was secure. The first two quotes we received from outside firms range between 4,500 EUR and 7,000 EUR, which is a substantial cash outlay for a boutique software shop like ours.
What does a penetration test actually cover and what purpose does it serve? Is it just an automated vulnerability scan or does it involve manual testing? Does it really make sense to spend this money when winning the contract isn't guaranteed, or is this just standard protocol for public tenders?