Comparison

Audit, pentest, penetration test, red team:
what does each one actually mean?

These terms get used interchangeably, but they describe different approaches with different scopes, costs, and regulatory weight. Here is how to tell them apart and pick the right one for your situation.

The 4 approaches compared

CriterionExternal reviewPenetration test (pentest)
MethodObservation and analysis from the outside, no access neededSimulated attack with formal authorization
Common synonymsSecurity audit, application audit, security reviewPentest, penetration testing, intrusion testing
Authorization requiredNone (read-only, public surface)Required (contract, scope, rules of engagement)
Typical duration1 to 5 days2 to 6 weeks
SMB costEUR 1,900 to 4,200EUR 5,000 to 25,000
What is testedExposure surface, APIs, auth, accessible data, configurationResistance to active attacks, exploitation, escalation
Production impactZeroRisk of controlled disruption
ReportReproducible evidence, GDPR context, remediationAttack paths, documented exploitation
Regulatory valueGDPR due-diligence evidence (Art. 32)Required by DORA, PCI-DSS (advanced levels), some insurers
Red team (advanced variant)Not applicableExtended version: multi-vector attack (phishing + technical + physical), targets the whole organization

Start with an external review if...

  • Your application has never been audited
  • You do not have a dedicated security team
  • You need fast, actionable results
  • You need to demonstrate a security process (GDPR, client, investor)
  • Your budget does not stretch to a formal pentest
  • You want to know what is exposed before testing resistance

Move to a pentest if...

  • Exposure flaws are fixed and you want to test depth
  • Your industry requires a formal penetration test (DORA, PCI-DSS, cyber insurance)
  • You are preparing for ISO 27001 or SOC 2 certification
  • You have a technical team that can support active testing
  • You want to simulate a realistic end-to-end attack scenario

FAQ

Need an external review of your HR SaaS?

Share your product, stack, and client context. We will come back with the right review scope.

Discuss your audit