October 27, 2025
Updated: August 10, 2026
Evidence-first comparison of penetration testing providers serving Latvia, with scope, local-presence, reporting, retest, and procurement checks.
Mohammed Khalil

Last Updated: August 2026
Organizations comparing penetration testing companies in Latvia should look beyond a company name or localized landing page. A defensible shortlist should confirm what the provider actually tests, whether it has a Latvia-based operation or delivers remotely, who the assigned testers are, how data is handled, what the report contains, and whether remediation and retesting are included. This 2026 list covers both Latvia-based and international providers serving Latvian buyers, using public evidence reviewed on August 10, 2026 and clear limitations rather than invented scores or national price benchmarks.
DeepStrike publishes this article and includes itself in the list. DeepStrike is placed first as an approved editorial placement, not because of an independent award, market-wide vote, or claim that it is the right provider for every buyer. The remaining providers are ordered by the strength and relevance of the public evidence available for this procurement task.
TL;DR: Verify the provider's actual Latvia relationship, active testing scopes, assigned tester qualifications, written authorization process, data-handling terms, reporting quality, remediation support, and retest deliverable. For regulated or critical environments, also verify whether Latvian or EU rules impose specific tester, independence, or testing requirements for your entity and system.
A company qualified for consideration when current public evidence showed an active penetration-testing or closely related offensive-security service, a credible operating business, a relevant relationship to Latvia, and enough scope detail to support a fair buyer-oriented profile. Directory listings alone were not enough.
We used three relationship categories:
A Latvia URL, a Riga mention in a directory, or the ability to accept an inquiry does not by itself establish a local office, local-language delivery, staffed presence, or Latvian contracting entity. Buyers should confirm the contracting party, assigned team, delivery language, on-site availability, time zone, insurance, and data-handling terms in the statement of work.
DeepStrike's first position is disclosed editorial placement. The same evidence categories and buyer-verification standard still apply to DeepStrike, including its main limitation for this market: no Latvian office or Latvian legal entity was verified in the August 10, 2026 research record.
| Provider | Latvia relationship | Verified testing scopes | Delivery evidence | Reporting/retest evidence | Buyer fit | What to verify |
|---|---|---|---|---|---|---|
| DeepStrike | International provider; no Latvian office/entity verified | Web, mobile, cloud, general penetration testing, continuous testing, red team | Remote/global delivery model | Reporting, remediation support, dashboard workflow, retest terms described on first-party pages | Teams wanting manual-first testing plus an ongoing workflow | Latvia contracting terms, assigned testers, language/on-site needs |
| OffSeq / SEQ SIA | Riga-registered provider | Application, API, mobile, cloud, red team, DORA/TLPT-related services | Latvia-based company evidence | Public service detail supports structured offensive-security delivery | Buyers wanting a Latvia-based specialist with broad application/cloud coverage | Assigned tester credentials, final report format, retest terms |
| Possible Security / I SIA | Riga-based company | Web/mobile, server/cloud, internal/external network testing | Local company evidence | Penetration-testing service is described directly | Buyers prioritizing locally based technical delivery | Languages, report sample, retest window, tester credentials |
| Cyber Circle | Public Latvia-headquarters claim | Penetration testing, red team, proactive/threat services | Latvia-headquarters evidence | Offensive-security and response capabilities are publicly described | Organizations valuing offensive testing alongside incident-response capability | Contracting entity, assigned team, retest terms, exact accreditation scope |
| Squalio | Riga address | Web, infrastructure, OT/ICS, cloud, API, mobile | Riga presence | First-party page describes manual review of automated results | Buyers with mixed IT/OT or multi-asset testing needs | Legal entity, tester qualifications, report/retest terms, on-site availability |
| OptiCom | Riga presence | Penetration testing | Local IT/security delivery context | Active penetration-test page | Buyers already sourcing broader infrastructure/security services | Exact team, methodology, reporting, retest, certification holder |
| IT Centrs | Latvia company presence | Information security and intrusion testing | SIA IT Centrs / Latvia evidence | Active service material | Buyers wanting a Latvia-based security/IT provider | Current testing depth, assigned testers, sample report, retest terms |
| CITM | Riga presence | Web, mobile, API, desktop intrusion testing | Local presence | First-party service descriptions | Buyers seeking application-focused local testing coverage | Contracting entity, methodologies, tester credentials, reporting and retest |

DeepStrike's penetration testing services describe a manual-first approach supported by automation where useful, validated findings, reporting, and remediation guidance across multiple testing scopes. Separate first-party pages cover web application, mobile application, cloud, continuous penetration testing, and red-team services.
The delivery model is relevant to organizations that want testing integrated with a continuing remediation workflow rather than a one-off scanner report. DeepStrike's public material also describes a dashboard-led process and retesting terms. Those commercial details should be confirmed for the buyer's specific statement of work rather than treated as universal guarantees.
Latvia relationship: DeepStrike is an international provider. No Latvian office or Latvian legal entity was verified in the August 10, 2026 research record.
Best-fit buyer scenario: Teams that want manual validation across several application or infrastructure surfaces and prefer a collaborative testing/remediation workflow.
What is not publicly verified for this market: Latvian-language staffing, an on-site Latvian team, a Latvia contracting entity, and Latvia-specific data-residency commitments.
Confirm before signing: the exact contracting entity, assigned testers and qualifications, authorization process, in-scope assets, testing window, data location and deletion, reporting deliverables, critical-finding escalation, remediation support, and retest window.

OffSeq's first-party company and service material identifies SEQ SIA in Riga and describes offensive-security services spanning application, API, mobile, cloud, red-team, and DORA/TLPT-related work. That combination makes it one of the stronger locally evidenced candidates for buyers who need several technical scopes under one provider relationship.
The public evidence is useful for confirming local company identity and service breadth. It does not replace engagement-level due diligence.
Best-fit buyer scenario: Latvia-based buyers seeking a local specialist for application, API, mobile, cloud, or adversary-simulation work.
What is not publicly verified here: the exact assigned tester for a future engagement, final report format, retesting terms, data-retention terms, and whether every advertised scope is delivered by the same legal entity/team.
Confirm before signing: the contracting entity and registration details, named or assigned testers, relevant qualifications, rules of engagement, report sample, remediation workflow, retest scope, and DORA/TLPT eligibility where that specialist regime applies.

Possible Security's penetration-testing page describes testing for web and mobile applications, servers and cloud environments, and internal and external networks. The same-day research record identifies Riga-based I SIA as the operating company.
That scope can suit buyers who want local delivery across both application and infrastructure attack surfaces without assuming that one methodology fits all assets.
Best-fit buyer scenario: Latvian organizations looking for locally based testing across applications, cloud/server environments, and network infrastructure.
What is not publicly verified here: assigned-team credentials, delivery language for every engagement, the exact reporting structure, retesting terms, and data-location commitments.
Confirm before signing: which assets are manually tested, how automated findings are validated, tester qualifications, production-safety controls, report and evidence format, remediation support, retest window, and emergency escalation path.

Cyber Circle's proactive security services include penetration testing and red-team-style work, while its company material presents a Latvia headquarters relationship. Its broader security operations and incident-response context may be useful to buyers that want a provider capable of connecting offensive findings to response readiness.
Any CSIRT or Trusted Introducer status should be interpreted only in its exact issuing-directory scope; it should not be presented as certification of the penetration-testing service itself.
Best-fit buyer scenario: Organizations that value penetration testing alongside broader incident-response, threat, or readiness services.
What is not publicly verified here: the exact contracting entity for every engagement, the assigned offensive-security team, retest terms, report sample, and whether an external accreditation applies to the pentest service.
Confirm before signing: entity and team, tester credentials, precise offensive scope, report deliverables, retest process, escalation path, and the scope of any cited independent assurance.

Squalio's penetration-testing service describes testing across web applications, infrastructure, OT/ICS, cloud, APIs, and mobile environments. The public source record also showed a Riga address and a statement that automated results receive manual review.
That breadth is relevant to buyers with mixed estates, especially when applications, cloud services, infrastructure, and operational technology require different test boundaries and safety controls.
Best-fit buyer scenario: Organizations with multiple asset classes, including buyers that need to evaluate IT and OT/ICS scope in one procurement process.
What is not publicly verified here: the exact local legal entity used for contracting, assigned tester credentials, report format, retesting policy, and site-specific OT safety process.
Confirm before signing: the contracting entity, who performs each asset-specific test, OT/ICS safety controls, methodology, evidence and reporting format, data-handling requirements, remediation support, and retest terms.

OptiCom maintains an active penetration-tests service page and a Riga presence. For buyers already using an IT integrator, that can make security testing easier to procure alongside broader infrastructure work, but the testing team and independence requirements still need to be evaluated on their own merits.
References to standards or individual certifications should be checked carefully so that a personal qualification is not mistaken for company-level accreditation.
Best-fit buyer scenario: Established organizations that prefer a local IT provider and want penetration testing procured within a wider technology relationship.
What is not publicly verified here: the exact assigned testers, methodology depth, report template, retesting terms, and current holder/scope of any cited certification.
Confirm before signing: independence from the systems being tested where relevant, assigned tester credentials, testing methodology, evidence quality, report structure, remediation support, and retest deliverable.

IT Centrs' service material describes information-security and intrusion-testing services. The August 10 research record identified SIA IT Centrs, registration number 40003481064, as a Latvia-based company.
This makes it a reasonable local candidate when the buyer wants a Latvia-based provider and can validate the exact testing depth for the required asset.
Best-fit buyer scenario: Organizations prioritizing a local provider for security and intrusion-testing work.
What is not publicly verified here: current assigned-team credentials, detailed methodology, report sample, retest terms, and language/on-site commitments for a specific engagement.
Confirm before signing: current entity details, exact penetration-testing scope versus assessment/scanning, named team, rules of engagement, evidence format, report deliverables, remediation support, and retest conditions.

CITM's first-party site describes intrusion-testing work for web, mobile, API, and desktop contexts and shows a Riga presence. That application-oriented coverage is relevant to software teams comparing local providers for several client-facing or internal application types.
Best-fit buyer scenario: Teams that want a Riga-based option for web, mobile, API, or desktop application testing.
What is not publicly verified here: the exact contracting entity, current methodology references, assigned tester credentials, report structure, retest terms, and data-handling commitments.
Confirm before signing: entity and staffing, test methodology, authenticated-role coverage, business-logic testing depth, API/mobile test boundaries, report and evidence format, remediation support, and retest deliverable.
“Serving Latvia” can describe materially different buying relationships. A Latvia-registered provider may contract locally and staff work from Latvia. An international provider may have a verified Latvian legal entity or office. A remote provider may serve Latvian organizations without any local legal entity or staff.
Procurement should therefore ask for the legal company name on the contract, registered address, invoicing entity, assigned tester location, working language, availability for on-site testing, time-zone coverage, cyber/professional liability insurance where required, and an emergency contact path.
Data handling is equally important. Confirm what production data testers can access, whether credentials or evidence leave the EEA, where screenshots and logs are stored, who can access them, retention periods, deletion commitments, and whether subprocessors are involved. These terms should be explicit in the contract or data-processing documentation rather than inferred from marketing language.
Start with the asset and attack surface. A web application, mobile app, cloud tenant, external network, internal Active Directory environment, API, wireless environment, or OT system needs different authorization boundaries, safety controls, and skills. DeepStrike's web application testing guidance is one example of why application-specific scope matters.
Then ask how the provider combines automation with manual testing. Scanners are useful for coverage and repeatability, but buyers should understand what testers manually validate, how they test authentication and authorization logic, how chained issues are handled, and how false positives are removed.
Evaluate the assigned team, not only the brand. Request the names or qualification profile of the people who will actually test the environment, especially where a regulation, contract, or internal policy imposes experience, certification, or independence requirements.
Define written authorization and rules of engagement before testing begins. The agreement should identify targets, exclusions, source IPs where appropriate, test window, prohibited techniques, production-safety controls, social-engineering boundaries, data-access limits, stop conditions, and emergency contacts.
For cloud testing, confirm which cloud accounts, subscriptions, tenants, identities, and third-party services are in scope. A provider's cloud penetration-testing capability does not eliminate the need for customer- and cloud-provider-specific authorization.
Reporting should serve both remediation and governance. Ask for reproducible evidence, affected assets, attack preconditions, severity rationale, business impact, remediation guidance, and an executive summary that does not hide technical detail. Confirm how critical findings are escalated during the test rather than waiting for the final report.
Retesting should be defined in writing. Clarify which findings can be retested, the time window, whether new regressions are in scope, what evidence is required, how many cycles are included, and what the final retest deliverable says. Where continuous testing is useful, compare it with a continuous penetration-testing model rather than assuming a subscription is automatically better.
Finally, match the engagement to language, on-site, regulatory, and commercial constraints. Procurement should document assumptions, exclusions, change-control rules, travel/on-site costs, report language, data-transfer terms, and whether the provider can satisfy any sector-specific tester or independence requirement.
Latvia's National Cyber Security Law entered into force on September 1, 2024 and implements NIS2 within Latvia for defined categories rather than every business in the country. Buyers should use the current consolidated law and competent-authority guidance to determine whether their entity and systems are covered.
Latvia's Cabinet Regulation No. 397, Minimum Cyber Security Requirements, entered into force on July 2, 2025. In the consolidated text reviewed for this update, Clause 131 addresses penetration testing for Class A information systems, including testing before commissioning and at least once every three years during operation. That rule is system- and entity-specific; it is not a three-year pentest mandate for every Latvian company. Buyers should recheck the current Regulation No. 397 text before relying on clause numbers.
The reviewed text also contains tester qualification and independence conditions in Clause 132 for specified covered entities. Where those provisions apply, procurement should verify the assigned tester, not merely a company logo or generic certification page. Critical ICT infrastructure has additional conditions and competent-authority oversight, so ordinary external-testing requirements should not be generalized to that category.
NIS2 establishes cybersecurity risk-management and incident-reporting obligations for covered entities, but it does not create one universal named penetration-testing cadence for every organization. Use the NIS2 Directive together with Latvia's national implementation.
DORA applies to defined financial entities and their ICT risk framework. Threat-led penetration testing applies to selected entities under the DORA framework and delegated rules; an ordinary web or network pentest is not automatically equivalent to TLPT. Buyers in scope should review the DORA Regulation and the applicable TLPT rules with qualified counsel or the competent authority.
GDPR Article 32 is risk-based and refers to a process for regularly testing, assessing, and evaluating security measures where appropriate. It does not prescribe one universal penetration-test frequency. PCI DSS, ISO/IEC 27001, customer contracts, insurers, and sector rules may create additional assurance expectations, but each source should be applied according to its actual scope.
This article is procurement guidance, not legal advice. If applicability is uncertain, obtain qualified Latvian legal/compliance advice or confirmation from the competent authority before turning a regulatory summary into a testing requirement.
There is no defensible single national price band for penetration testing in Latvia. Cost depends on the work actually authorized and the evidence expected from the provider.
The largest drivers usually include:
Use a provider's current quote rather than a country-wide benchmark. DeepStrike's penetration-testing pricing page can be used to understand its own engagement terms, while a broader penetration-testing cost guide can help buyers identify common scoping variables. Neither should be treated as a Latvia market price index.
Before signing a statement of work, request and verify:
For additional procurement checks, use a dedicated provider-selection framework and document the decision criteria before comparing proposals.
Check the legal entity, registered address, contracting party, and staffed local presence from first-party or official records. A Latvia landing page or local keyword is not enough. Also confirm who will perform the work and whether delivery is local, on-site, or remote.
Not for every company. The reviewed Cabinet Regulation No. 397 text includes an at-least-once-every-three-years requirement for Class A information systems within its defined scope. Determine whether the rule applies to your entity and system before adopting that cadence.
The reviewed Regulation No. 397 text includes qualification and independence conditions for specified covered entities. The exact current clause, entity category, alternatives, and exceptions should be verified in the consolidated text. Procurement should validate the assigned tester's evidence, not assume the provider automatically qualifies.
Yes, remote delivery can be technically workable when authorization, access, time zone, data handling, contracting, language, and any sector-specific tester requirements are satisfied. Remote availability does not prove local presence or local data residency.
There is no reliable single Latvia-wide figure. Price depends on asset count, architecture, authenticated roles, test depth, cloud/mobile/network scope, production constraints, reporting, remediation, retesting, language/on-site needs, and urgency. Compare quotes using the same statement of work.
No. Scanning can identify potential weaknesses at scale, while a penetration test should involve human analysis and controlled validation within an authorized scope. Buyers should ask how automated findings are manually validated and how exploitability and business impact are demonstrated.
No universal rule says every organization must perform the same penetration test on the same schedule. NIS2 and GDPR are scope- and risk-dependent. National law, sector rules, PCI DSS, contracts, or internal risk treatment may create more specific obligations.
Choosing a penetration testing company in Latvia is primarily an evidence problem. Confirm what the provider can test, what its relationship to Latvia actually is, who will perform the work, what rules apply to your environment, how data and production safety are handled, and what reporting and retesting you will receive.
DeepStrike should be considered alongside other qualified providers using the same procurement standard. If its delivery model fits your scope, request a technical scoping discussion and a proposal that names the assets, assumptions, testing approach, reporting, and retest terms.
Mohammed Khalil is a Cybersecurity Architect at DeepStrike, specializing in advanced penetration testing and offensive security operations. With certifications including CISSP, OSCP, and OSWE, he has led numerous red team engagements for Fortune 500 companies, focusing on cloud security, application vulnerabilities, and adversary emulation. His work involves dissecting complex attack chains and developing resilient defense strategies for clients in the finance, healthcare, and technology sectors.

Stay secure with DeepStrike penetration testing services. Reach out for a quote or customized technical proposal today
Contact Us