[{"data":1,"prerenderedAt":153},["ShallowReactive",2],{"wissen-en-penetration-testing-as-a-service":3,"wissen-related-en-penetration-testing-as-a-service":146},{"id":4,"title":5,"body":6,"description":126,"extension":127,"lang":128,"meta":129,"navigation":130,"path":131,"related":132,"seo":136,"short":137,"sitemap":138,"stem":139,"synonyms":140,"updated":144,"__hash__":145},"wissenEn\u002Fen\u002Fwissen\u002Fpenetration-testing-as-a-service.md","Penetration Testing as a Service (PTaaS)",{"type":7,"value":8,"toc":114},"minimark",[9,13,18,21,25,60,64,67,71,74,78,81,85,88,92],[10,11,12],"p",{},"Penetration testing as a service (PTaaS) is a delivery model for manual penetration tests in which results are provided continuously through a platform rather than as a one-off PDF report. Human testers examine systems, document findings with evidence directly in the tool that also runs automated vulnerability management, and repeat the tests on a regular schedule. Retests of fixed findings are part of the service.",[14,15,17],"h2",{"id":16},"why-ptaas-matters","Why PTaaS matters",[10,19,20],{},"The classic pentest has a timing problem: it describes the state of one week, the report arrives two weeks later, and a year passes until the next test. Findings end up in a PDF that someone has to transfer manually into tickets; nobody checks whether they were fixed. PTaaS solves this by putting findings where the team already works, letting retests be requested with a click and matching test frequency to the rate of change of the systems. For NIS2, ISO 27001, DORA and cyber insurers, evidence that vulnerabilities from pentests were demonstrably closed is important as well.",[14,22,24],{"id":23},"how-ptaas-works","How PTaaS works",[26,27,28,36,42,48,54],"ol",{},[29,30,31,35],"li",{},[32,33,34],"strong",{},"Scope and interval",": which systems are tested (web applications, APIs, external infrastructure, internal networks) and how often (for example monthly, quarterly, semi-annually, annually).",[29,37,38,41],{},[32,39,40],{},"Manual test",": certified pentesters examine the systems for logic flaws, privilege escalation, authentication weaknesses and chains that automated scanners do not detect.",[29,43,44,47],{},[32,45,46],{},"Findings in the platform",": every finding appears with severity, description, reproduction steps and evidence images; the team assigns and fixes it.",[29,49,50,53],{},[32,51,52],{},"Retest",": after remediation the tester checks again and closes the finding. The status is visible at any time.",[29,55,56,59],{},[32,57,58],{},"Report",": a pentest report for auditors and management is generated from the platform data, at any time and up to date.",[14,61,63],{"id":62},"how-blacklensio-implements-ptaas","How blacklens.io implements PTaaS",[10,65,66],{},"With the pentest licence, human testers work in the same platform as automated vulnerability management. Manually confirmed findings carry the \"Verified\" label and include evidence images; retests are requested directly on the finding. A dedicated pentester role governs what testers can see and change. The test cadence is set per target, from weekly to yearly, and the Penetration Test Report is generated from the platform as one of six PDF report types. Automated scans (external, Sentry, cloud) and manual tests share status, workflow and integrations such as Jira or ServiceNow.",[14,68,70],{"id":69},"does-ptaas-replace-automated-vulnerability-scans","Does PTaaS replace automated vulnerability scans?",[10,72,73],{},"No, it complements them. Scanners find known vulnerabilities broadly and continuously; pentesters find logic flaws, privilege escalations and chains. PTaaS joins both in one workflow so that two separate lists do not exist side by side.",[14,75,77],{"id":76},"what-is-the-difference-between-ptaas-and-bug-bounty","What is the difference between PTaaS and bug bounty?",[10,79,80],{},"In bug bounty, unknown external researchers test without a fixed scope and without any guarantee of coverage; payment is per valid finding. PTaaS works with known, contractually bound testers, a defined scope, a planned test cadence and complete documentation. For regulated companies the traceability of PTaaS is usually decisive.",[14,82,84],{"id":83},"how-often-should-a-penetration-test-take-place","How often should a penetration test take place?",[10,86,87],{},"At least annually and after significant changes to exposed systems. For web applications with frequent releases, quarterly or monthly intervals make sense. Between tests, continuous scanning takes over monitoring.",[14,89,91],{"id":90},"related-terms","Related terms",[93,94,95,102,108],"ul",{},[29,96,97],{},[98,99,101],"a",{"href":100},"\u002Fen\u002Fwissen\u002Fvulnerability-management","Vulnerability Management",[29,103,104],{},[98,105,107],{"href":106},"\u002Fen\u002Fwissen\u002Fcontinuous-threat-exposure-management","Continuous Threat Exposure Management (CTEM)",[29,109,110],{},[98,111,113],{"href":112},"\u002Fen\u002Fwissen\u002Fexternal-attack-surface-management","External Attack Surface Management (EASM)",{"title":115,"searchDepth":116,"depth":116,"links":117},"",3,[118,120,121,122,123,124,125],{"id":16,"depth":119,"text":17},2,{"id":23,"depth":119,"text":24},{"id":62,"depth":119,"text":63},{"id":69,"depth":119,"text":70},{"id":76,"depth":119,"text":77},{"id":83,"depth":119,"text":84},{"id":90,"depth":119,"text":91},"PTaaS explained: how penetration tests run through a platform, how it differs from classic pentests and bug bounty, and how blacklens.io implements PTaaS.","md","en",{},true,"\u002Fen\u002Fwissen\u002Fpenetration-testing-as-a-service",[133,134,135],"vulnerability-management","continuous-threat-exposure-management","external-attack-surface-management",{"title":5,"description":126},"PTaaS delivers manual penetration tests through a platform instead of a PDF: findings appear continuously, retests are built in, and tests repeat on a regular schedule.",{"loc":131},"en\u002Fwissen\u002Fpenetration-testing-as-a-service",[141,142,143],"PTaaS","Pentest as a service","Continuous penetration testing","2026-09-15","4jUml4sY5kRms3iIkH_mRXCCf1tdiqmz2X5e6maioMs",[147,149,151],{"path":106,"title":107,"short":148},"CTEM is a programme described by Gartner with five phases (scoping, discovery, prioritisation, validation, mobilisation) that reduces the attack surface continuously instead of at points in time.",{"path":112,"title":113,"short":150},"External attack surface management inventories and monitors from the outside every internet-facing asset of a company, exactly as an attacker sees it.",{"path":100,"title":101,"short":152},"Vulnerability management is the ongoing process of detecting vulnerabilities in systems, prioritising them by risk, fixing them and evidencing the fix.",1789638256022]