We are a 14-person company based in Moscow developing logistics and cargo tracking software. Last month, we rewrote our enterprise web portal, where our clients track freight movements and customs documentation. Under a master framework agreement we signed with a major enterprise client, we are required to submit an independent penetration testing report prior to going live.
The contractor firm handling our software development argues that a pentest will run around 450,000 rubles and is an unnecessary expense. Instead, they suggested running static code analysis, where they scan the source code using automated tools. They want 120,000 rubles for this analysis and claim all vulnerabilities in the codebase will be thoroughly caught this way regardless.
Since the budget difference is nearly fourfold, I'm stuck. Can static code analysis actually replace a penetration test, or are we going to face a nasty surprise during an audit or the first serious cyberattack? Where exactly does the technical dividing line between the two lie?