September 23, 2025
Updated: August 17, 2026
Independent ranking of the best Dutch pentesting firms for enterprises and SMBs in 2026.
Mohammed Khalil

Independent ranking of the best Dutch penetration-testing providers for enterprises and SMBs in 2026.
Updated: August 2026. Company profiles, NIS2 status, Netherlands relevance, and the shortlist were rechecked against current public information. DeepStrike publishes this guide and remains #1 in this editorial ranking. Buyers should independently verify legal entity, assigned testers, onsite capability, accreditation, retesting, evidence handling, and commercial terms before procurement.
Choosing the right penetration-testing provider is more critical than ever. In 2026, Dutch organizations face mature cyber threats, identity abuse, AI-assisted attacks, supply-chain exposure, cloud complexity, and tighter regulatory obligations.
The legal position has also changed since the previous version of this article. The Dutch Cyberbeveiligingswet (Cybersecurity Act) entered into force on 15 August 2026, implementing NIS2 in the Netherlands and replacing the Wbni for covered organizations. The new law introduces registration, duty-of-care, incident-reporting, governance, and supervisory obligations for more than 8,000 organizations across 18 sectors.
This ranking is methodology-driven and does not accept paid inclusion. DeepStrike publishes this guide and reserves the first position for DeepStrike; competitor profiles are based on publicly verifiable information.
| Rank | Company | Best For | Netherlands Fit | Testing Model / Differentiator |
|---|---|---|---|---|
| 1 | DeepStrike | PTaaS, cloud/API, SaaS, developer remediation | Cross-border remote; no Dutch office evidenced | Manual-first exploit validation + continuous testing |
| 2 | Fox-IT / NCC Group | Critical infrastructure, government, enterprise red team | Delft / strong Dutch roots | Advanced offensive security + threat intelligence |
| 3 | Bureau Veritas Cybersecurity (formerly Secura) | Regulated sectors, OT/IoT, CCV-grade assurance | Amsterdam / Eindhoven | CCV-certified pentesting + 50+ specialist team |
| 4 | Northwave Cyber Security | Pentest + red team + SOC/IR + TIBER/ART | Utrecht HQ | 20+ hacker red team + integrated intelligence |
| 5 | Securify | Independent manual pentesting and code review | Netherlands-based | Human-led testing + code review + detection advice |
| 6 | Computest Security | Web/app/infrastructure testing and developer workflows | Zoetermeer | Practical manual testing + Marvin_ continuous security |
| 7 | WebSec B.V. | Advanced web/API/cloud/IoT offensive testing | Amsterdam | Boutique manual testing + R&D |
| 8 | KPN REDteam | Nationwide enterprise infrastructure and code testing | Strong Dutch enterprise footprint | Pentest + code review + social engineering |
| 9 | Orange Cyberdefense Netherlands | Threat-led pentesting, cloud/identity, red team | Utrecht office + local ethical hackers | Manual-first ethical hacking + global offensive scale |
| 10 | EY Netherlands | TIBER-EU, regulated enterprise, cloud/API and continuous pentest | Amsterdam / local cyber team | Pentest + red team + TIBER + continuous testing |
| 11 | PwC Netherlands | Audit-linked pentest, red team, critical infrastructure | Netherlands practice | Tailored pentesting + threat-informed red/purple team |
| 12 | The S-Unit | Focused Dutch offensive-security boutique | Netherlands-based | ~25 security professionals; 200+ pentests/year |
| 13 | Tesorion | Mid-market managed security + manual pentesting | Netherlands-based | Manual pentest + SOC + continuous-security ecosystem |
| 14 | Hadrian | Agentic pentesting and external attack-surface validation | Amsterdam HQ | AI hacker agents + continuous exploit validation |
Selecting a penetration-testing partner requires care. Common pitfalls include mistaking automated scans for true pentesting and underestimating the importance of experienced testers.
What really matters is technical rigor and transparency. Strong vendors blend manual techniques, creative attack chaining, realistic threat scenarios, and thorough reporting rather than relying on scanners alone.
We ranked each provider using procurement-relevant criteria. The evaluation considered tester capability, provider assurance, service scope, Netherlands presence, reporting quality, remediation support, retesting, and modern attack-surface coverage.
| Evaluation Criterion | Weight |
|---|---|
| Manual penetration-testing depth and exploit validation | 25% |
| Verified provider assurance and tester credentials | 20% |
| Netherlands presence, local relevance, or practical EU delivery | 15% |
| Web, API, cloud, identity, infrastructure, mobile, OT/IoT and red-team breadth | 15% |
| Reporting, remediation support, and retesting | 10% |
| Delivery model and buyer collaboration | 10% |
| Public evidence, case studies, and transparency | 5% |
Provider-level assurance and individual credentials are treated separately. CCV pentest certification, ISO certification, CREST company accreditation, NCSC CHECK, and other organizational schemes are not the same as individual credentials such as OSCP, OSWE, CISSP, CREST practitioner certifications, GIAC, or similar qualifications.
Capabilities that could not be directly evidenced were treated cautiously. Brand size alone did not increase rank.

Why They Stand Out: DeepStrike leads this publisher ranking for its emphasis on manual, high-skill testing, cloud/API attack paths, PTaaS workflows, and remediation collaboration. Its model is especially relevant to cloud-native and software-driven organizations that want testing to fit development cycles instead of ending with a static report.
Testing Depth Model: Manual-first / PTaaS.
Key Strengths:
Potential Limitations:
Best For: Cloud-native enterprises, SaaS, fintech, API-heavy systems, and teams needing frequent remediation feedback loops.

Why They Stand Out: Fox-IT remains one of the best-known Dutch cybersecurity names and operates within NCC Group. Its strongest fit is high-assurance work where offensive testing needs to sit alongside threat intelligence, incident response, and experience in sensitive environments.
Testing Depth Model: Advanced enterprise / red-team model.
Key Strengths:
Potential Limitations:
Best For: Large enterprises, government, defense, finance, and critical infrastructure.

The earlier version listed Secura / Bureau Veritas Cybersecurity. That needs a 2026 naming update: Secura announced that it is becoming Bureau Veritas Cybersecurity, while retaining the same team and expanding global support.
Why They Stand Out: Secura was the first company in the Netherlands certified under the CCV pentesting scheme in 2021. Its public material states that the pentest team consists of more than 50 specialists, with practitioner certifications spanning eWPT, OSCP, OSCE, eCPPT, GPEN and others.
Testing Depth Model: High-assurance manual/hybrid model.
Key Strengths:
Potential Limitations:
Best For: Finance, healthcare, industrial/OT, government, product manufacturers, and audit-heavy environments.

Why They Stand Out: Northwave remains stronger than the earlier description suggested. Its current red-team material describes a 20+ hacker team performing challenging pentests and realistic red-team operations across Europe, with TIBER and ART capability.
Its pentest service clearly distinguishes vulnerability assessment from active exploitation and focuses on the impact and business risk of weaknesses.
Testing Depth Model: Threat-informed red-team / integrated-defense model.
Key Strengths:
Potential Limitations:
Best For: Mid-to-large enterprises seeking pentest, red team, threat intelligence, and incident-response capability from one Dutch provider.

Why They Stand Out: Securify remains one of the clearest specialist pentest options in the Netherlands. Its current pentest page emphasizes testing by seasoned security professionals, code review, business-context impact determination, and implementation-ready findings.
Securify’s 2026 content also demonstrates active involvement in the Dutch pentesting market, including MIAUW procurement methodology and DORA/TLPT guidance.
Testing Depth Model: Manual specialist.
Key Strengths:
Potential Limitations:
Best For: Organizations that prioritize manual pentest depth, application security, and direct access to specialists.

Why They Stand Out: Computest remains a strong Dutch developer-friendly testing company. Its current pentest page describes black-, gray-, and white-box work, real-life attack simulation, and practical remediation guidance.
Computest also maintains Marvin_, a hybrid continuous-security platform combining automated monitoring with daily review by security specialists.
Testing Depth Model: Manual specialist + hybrid continuous security.
Key Strengths:
Potential Limitations:
Best For: Software companies, fintech, SaaS, and organizations wanting practical testing plus continuous-security follow-up.

Why They Stand Out: WebSec remains a strong independent offensive-security boutique in the original list. Its value is the combination of broad technical scope, research-oriented security work, and creative manual testing.
Testing Depth Model: Manual offensive specialist.
Key Strengths:
Potential Limitations:
Best For: Technology companies, fintech, SaaS, cloud environments, and buyers prioritizing technical offensive depth.

KPN is a major omission from the earlier list. Its current business-security pages explicitly describe penetration testing by experienced ethical hackers in KPN’s REDteam.
Services
Why They Stand Out: KPN combines a highly local Dutch enterprise footprint with a dedicated REDteam. The current security-testing portfolio separates Penetration Testing, Social Engineering, and Code Review, giving buyers multiple ways to validate technical and human controls.
Testing Depth Model: Enterprise manual/hybrid model.
Key Strengths:
Potential Limitations:
Best For: Dutch enterprises, infrastructure-heavy organizations, and buyers wanting a nationally established provider.

Why They Stand Out: Orange Cyberdefense’s Netherlands practice explicitly states that it has a local Dutch group of ethical hackers and security consultants. Its pentesting methodology emphasizes high-value manual testing and treats automated discovery as a starting point rather than the end of the assessment.
Orange also offers Threat-Led Penetration Testing, combining threat intelligence with targeted offensive assessment.
Testing Depth Model: Manual-first / threat-led model.
Key Strengths:
Potential Limitations:
Best For: Dutch enterprise, critical infrastructure, regulated organizations, and buyers wanting threat-led testing plus international offensive-security depth.

EY Netherlands has a far stronger current penetration-testing offering than the old shortlist reflected.
Its cybersecurity-services page explicitly lists:
Why They Stand Out: EY’s Netherlands cyber practice combines broad technical testing with TIBER-EU experience and continuous pentesting. Public profiles also show local Red Team management with OSCP/OSCE/CRTP expertise.
Testing Depth Model: Enterprise manual/hybrid + TIBER model.
Key Strengths:
Potential Limitations:
Best For: Banks, insurers, utilities, critical infrastructure, and large enterprises requiring technical testing tied to regulatory assurance.

PwC Netherlands has a direct offensive-security practice covering penetration testing, red teaming, purple teaming, and threat-informed security validation.
Its current offensive-security page lists tailored penetration testing for:
PwC also publishes a dedicated ethical-hacking practice for critical infrastructure such as rail, water-control, and power environments.
Testing Depth Model: Enterprise manual / threat-informed assurance model.
Key Strengths:
Potential Limitations:
Best For: Regulated enterprise, critical infrastructure, finance, and organizations wanting technical testing tied closely to board and audit assurance.

The S-Unit is a strong Netherlands-based offensive-security specialist that was missing from the original list.
Its current site states:
The company also publishes customer references across Dutch sectors and positions itself around penetration testing and red-team work.
Testing Depth Model: Specialist offensive-security boutique.
Key Strengths:
Potential Limitations:
Best For: Dutch organizations that want a dedicated offensive-security specialist rather than a broad consultancy.

Why They Stand Out: Tesorion remains relevant for Dutch mid-market organizations looking to connect manual pentesting with managed-security operations. Its current pentest page explicitly states that ethical hackers manually enter the environment and attempt to exploit vulnerabilities as cybercriminals would.
Testing Depth Model: Manual pentest + managed-security model.
Key Strengths:
Potential Limitations:
Best For: Mid-market organizations wanting pentest plus ongoing monitoring and security support.

Hadrian is headquartered in Amsterdam and represents the fast-growing agentic penetration-testing / adversarial-exposure-validation segment.
Its platform continuously discovers internet-facing assets, validates exploitable exposures, and uses AI hacker agents trained by offensive-security professionals to test attack paths.
Testing Depth Model: Agentic / autonomous penetration-testing platform.
Key Strengths:
Potential Limitations:
Best For: Large external attack surfaces, cloud-first enterprises, and teams that want continuous adversarial exposure validation between deeper manual tests.
| Company | Specialization | Testing Depth Model | Best For | Netherlands Fit | Assurance / Compliance Positioning | Ideal Organization Size |
|---|---|---|---|---|---|---|
| DeepStrike | Cloud/API, PTaaS, app/mobile/red team | Manual-first | Cloud-native and SaaS | Cross-border | Compliance-ready reporting | SMB–Enterprise |
| Fox-IT / NCC Group | Advanced offensive security + threat intel | Red-team/enterprise | Critical infrastructure/government | Delft / Netherlands | High-assurance enterprise | Enterprise |
| Bureau Veritas Cybersecurity | Pentest, OT/IoT, regulated assurance | High-assurance manual/hybrid | Finance, healthcare, industry | Amsterdam/Eindhoven | CCV + ISO | Mid–Enterprise |
| Northwave | Pentest + red team + SOC/IR | Threat-informed | Integrated enterprise security | Utrecht | TIBER/ART + ISO | Mid–Enterprise |
| Securify | Manual pentest, code review, TLPT | Manual specialist | Focused technical testing | Netherlands | Strong Dutch procurement/TLPT context | SMB–Enterprise |
| Computest | App/network pentest + continuous monitoring | Manual + hybrid | Software/fintech/SaaS | Zoetermeer | ISO 9001/27001 | SMB–Enterprise |
| WebSec | Web/API/cloud/mobile/IoT | Manual offensive | High-tech and fintech | Amsterdam | Dutch pentest/ISO positioning | SMB–Mid |
| KPN REDteam | Network, code review, social engineering | Enterprise manual/hybrid | Infrastructure-heavy enterprise | Strong Netherlands fit | Enterprise governance | Mid–Enterprise |
| Orange Cyberdefense NL | Ethical hacking, TLPT, cloud/identity, red team | Manual-first/threat-led | Regulated and critical enterprise | Utrecht/local team | NIS2/DORA/TIBER relevance | Mid–Enterprise |
| EY Netherlands | Pentest, TIBER, continuous pentest | Enterprise manual/hybrid | Finance/critical infrastructure | Amsterdam | TIBER-EU/NIS2/DORA | Enterprise |
| PwC Netherlands | Pentest, red/purple team, ethical hacking | Enterprise manual | Audit/critical infrastructure | Strong Netherlands practice | Board/audit assurance | Enterprise |
| The S-Unit | Pentest + red team | Specialist manual | Focused Dutch offensive work | Netherlands-based | Project-based specialist | SMB–Enterprise |
| Tesorion | Pentest + managed security | Manual + managed | Mid-market | Netherlands-based | Managed-security integration | SMB–Mid |
| Hadrian | Agentic pentesting / external attack surface | Autonomous/agentic | Large dynamic external surfaces | Amsterdam HQ | Exposure-validation platform | Mid–Enterprise |
Choosing between a large firm or a boutique depends on your needs.
Large enterprises often require global reach, formal certifications, large testing teams, TIBER/TLPT capability, OT support, public-sector governance, or 24/7 response integration. Fox-IT/NCC, Bureau Veritas Cybersecurity, Northwave, KPN, Orange Cyberdefense, EY, and PwC are strong fits where scale and governance matter.
SMBs and mid-market organizations may benefit from smaller or niche providers. Securify, Computest, WebSec, The S-Unit, and Tesorion can offer more direct access to specialists and tighter project coordination.
Tech-driven companies may also compare conventional manual engagements with PTaaS or agentic testing. DeepStrike fits the manual-first PTaaS model, while Hadrian represents continuous agentic external validation.
The trade-off is not simply large versus small. Match the provider to the attack surface, required evidence, and the people who will actually perform the test.
The earlier article quoted broad daily rates of €1,000–€1,500 and suggested common fixed-price thresholds. Those figures can be useful anecdotes, but they should not be presented as a statistically representative Netherlands-wide benchmark without a strong market dataset.
Cost depends on:
Buyers should compare matched statements of work instead of headline day rates alone.
The Cyberbeveiligingswet entered into force on 15 August 2026, implementing NIS2 in the Netherlands and replacing the Wbni. Covered organizations across 18 sectors face registration, duty-of-care, incident-reporting, governance, and supervisory obligations.
Penetration testing can support risk-management and control-validation programs, but the law should not be reduced to a universal annual pentest requirement for every covered organization.
Financial entities subject to DORA must maintain digital operational resilience testing programs. Certain entities are subject to threat-led penetration testing requirements, and Dutch providers such as Northwave, EY, Securify, Orange Cyberdefense, Fox-IT/NCC, and others can be relevant where TIBER/TLPT capability is required.
GDPR Article 32 is risk-based and requires appropriate technical and organizational measures and processes for regularly testing and evaluating security effectiveness. It does not create a universal named annual penetration-test obligation.
The Dutch CCV pentest certification scheme provides provider-level assurance around management systems, administrative processes, testing procedures, tooling, reporting, and tester competence. It is particularly relevant to buyers that want a Dutch quality framework around penetration-testing delivery.
There is no single reliable Netherlands-wide average. Cost depends on scope, manual testing days, cloud/API or identity complexity, OT/physical requirements, reporting, TIBER/TLPT, and retesting.
Both matter, but neither replaces experience. Provider-level schemes such as CCV or ISO provide organizational assurance. Individual credentials such as OSCP, OSWE, CREST practitioner certifications, or GIAC qualifications can indicate practitioner capability. The more important question is whether the team can validate real exploit paths and communicate the findings clearly.
Focused tests can take several days to one or two weeks. Larger infrastructure, cloud, red-team, or TIBER/TLPT exercises can take multiple weeks. Reporting and retesting add time after the active-testing phase.
A strong engagement should produce a technical report and, where needed, an executive summary. Findings should include evidence, affected assets, attack context, severity or risk rationale, remediation guidance, and clear limitations. Critical issues should ideally be escalated during the engagement rather than waiting for final delivery.
There is no universal schedule. Test after major changes and according to system criticality, risk, customer commitments, and regulation. Stable systems may be tested periodically, while high-change SaaS, API, cloud, or exposure-heavy environments may benefit from more frequent or continuous validation.
No. A vulnerability assessment focuses on identifying weaknesses broadly. A penetration test goes further by actively validating exploitation and impact within an agreed scope. Some Dutch providers explicitly distinguish the two, so buyers should make sure the statement of work matches the outcome they expect.
Not for every use case. Automated and agentic testing can dramatically improve frequency and external attack-surface coverage. Bespoke application logic, internal identity attack paths, physical testing, social engineering, and advanced red-team objectives still benefit from human-led offensive expertise.
The Dutch penetration-testing market is substantially deeper than the original ten-company shortlist suggested.
The strongest established Dutch options include Fox-IT/NCC Group, Bureau Veritas Cybersecurity, Northwave, Securify, Computest, WebSec, KPN REDteam, Orange Cyberdefense Netherlands, EY Netherlands, PwC Netherlands, The S-Unit, and Tesorion.
The update also adds Hadrian because Amsterdam is now home to a significant agentic-pentesting company, but the article keeps that model clearly separate from consultant-led manual testing.
DeepStrike remains #1 in this publisher ranking for organizations prioritizing manual-first PTaaS, cloud/API attack-path validation, developer collaboration, and remediation retesting. Dutch buyers with strict local delivery, CCV, TIBER/TLPT, government, critical-infrastructure, OT, or national-enterprise requirements may reasonably prefer one of the strong Netherlands-based providers above.
The best shortlist comes from comparing methodology, assigned testers, exploit-validation depth, report quality, retesting, cloud/API maturity, local procurement requirements, and actual fit — not simply the size of the brand.

Mohammed Khalil is a Cybersecurity Architect at DeepStrike, specializing in advanced penetration testing and offensive security operations. With certifications including CISSP, OSCP, and OSWE, he has led numerous red-team engagements for Fortune 500 companies, focusing on cloud security, application vulnerabilities, and adversary emulation. His work involves dissecting complex attack chains and developing resilient defense strategies for clients in finance, healthcare, technology, and other high-risk sectors.
Technical Review: DeepStrike Offensive Security Team
Last Reviewed: August 2026

Stay secure with DeepStrike penetration testing services. Reach out for a quote or customized technical proposal today
Contact Us