Physical penetration testing is even less standardized than cyber pentesting. This guide shows how to spot a credible provider – from the multi-vector requirement to German law (§ 123 StGB) to price orientation.
Looking for a buyer’s guide for classic cyber pentesting? Go to the general pentest provider guide →
A credible physical pentest tests multiple entry points and techniques over a period of time – not a single attempt. Before requesting a quote, you need to settle two decisions: pentest (covert) or audit (overt), and which objective is being tested – data access or goods protection. No test should happen without a written authorization document with a 24/7 emergency contact.
These two decisions determine scope, price, and provider fit – and should be settled before you even request a quote.
Covert, realistic attacker simulation. Goal: get in undetected. More expensive, but more indicative of real day-to-day security.
Overt, complete vulnerability documentation without concealment. Cheaper, lower risk, but less realistic.
Server room, executive office, a conference room to bug, an unlocked, logged-in workstation.
Jewelry store, freight carrier, warehouse, retail floor.
Six phases, where reconnaissance regularly takes more time than the actual test attempt.
Objectives, no-go zones, permitted techniques, testing windows, destructive vs. non-destructive, authorization, emergency contacts.
OSINT plus multi-day onsite surveillance: floor plans, shift schedules, access systems, camera positions, traffic patterns.
Equipment, badges, and scenarios are prepared for the planned test attempts.
Different entry points, different techniques, a spectrum from covert to overt – not a single attempt.
Access to the defined objective, foothold on the internal network, optionally covert device placement.
Every attempt is documented – including failed ones – with photos, videos, and timestamps.
Compiled from OSSTMM, PTES, ISACA, and the practice of physical red-team providers.
Red teaming by definition means using multiple attack vectors simultaneously. How to check: ask how many distinct entry points and techniques are tested, and whether failed attempts are documented too. A provider describing only one attempt is selling break-in theater, not a credible assessment.
PTES calls for multi-day onsite reconnaissance to establish reliable patterns. How to check: ask how many days of onsite recon are planned and what recon deliverable is provided – photos, shift schedules, access patterns.
A written authorization document, signed by someone with legal authority, with a 24/7 emergency contact and escalation process, is mandatory – not optional. How to check: request the document before testing starts and confirm a 24/7 contact chain exists.
The provider must know both formats and justify in the proposal which one fits your need. How to check: ask explicitly whether testing is covert or overt, and why.
Without a defined goal, success can’t be evaluated. How to check: clarify upfront what the objective is – server room, executive office, conference room, warehouse.
For destructive testing (e.g. forcing locks), standard cyber liability insurance isn’t enough. How to check: ask for separate property damage insurance if destructive techniques are in scope.
Tested employees should learn something, not be humiliated. How to check: ask how the debrief with affected staff works, and whether individuals are named in the report.
Recordings of employees are personal data. How to check: ask about data minimization, secure storage, and deletion after the report is delivered.
Targeted testing of employee behavior can trigger co-determination rights under German law. How to check: clarify with your works council upfront whether a confidentiality arrangement is needed for the test period.
Cyber pentest experience says little about physical capability. How to check: request references specifically for physical assessments, not just network or web pentests.
Every attempt belongs in the report, not just the successful one. How to check: request photos, videos, and timestamps for every attempt, plus prioritized remediation guidance.
This field is far less standardized than cyber pentesting certification. Practical track record with these four training and community providers counts for more than a formal management credential.
Practitioner Community
A selection, not an exhaustive list – other providers with comparable programs exist. These four are the most established in the community.
The field’s original hands-on social-engineering framework. PASE is a multi-day practical course with exercises and homework, including free access to the CESE exam (Certified Ethical Social Engineer) – not a multiple-choice test.
Widely regarded in the community as the platinum standard for hands-on red-team and physical-security training – broader than pure lockpicking courses.
Five-day in-person training covering alarm bypass, badge cloning, access control systems, lockpicking, and key impressioning – led by active practitioners.
Hands-on courses from European red-team operators covering lock/door/window bypass, PACS/badge systems, and OSINT-driven pretexting.
Recognized management- and assessment-oriented credentials requiring several years of experience – they demonstrate security-management competence more than current field skills.
Relevant if bugging or sweeping conference rooms is part of the engagement. No unified certification – mostly private training providers.
Note: cyber certifications like OSCP say little about physical core competency – only relevant when physical access is meant to lead into a network foothold.
None of these signals is disqualifying on its own – but in combination, they’re worth asking about directly.
A single-attempt engagement with no additional vectors – “we got in once, done” is the most common sign of a low-quality provider.
A missing or superficial recon phase – no onsite surveillance, no recon deliverable.
No separation between pentest and audit in the proposal – the provider can’t explain whether testing is covert or overt.
No written authorization document and no 24/7 emergency contact chain – legally and operationally unacceptable.
No clear agreement on destructive vs. non-destructive testing.
No objective defined before testing starts.
Unprofessional, humiliating treatment of tested staff – no structured debrief.
Selling pure “break-in theater” instead of a credible, repeatable assessment.
A price that’s unusually low – often just one testing day, one attempt, no substantial report.
Orientation values compiled from general pentest and social-engineering cost overviews – no DACH provider publishes separate fixed prices for physical pentests alone.
International figures are US market prices (Schellman) and should be read as rough orientation only. Some DACH sources are provider self-publications – treat as orientation, not a binding quote.
Physical pentests touch criminal law, data protection, and works-council co-determination – these five points aren’t optional.
Unauthorized entry into business premises is a criminal offense in Germany. Prior consent from the person holding domiciliary rights already excludes the offense – legally a consent that precludes the offense itself, not a later justification.
Consent must come from someone with legal authority to give it (managing director, authorized signatory, empowered IT lead) and may only cover areas under the client’s own authority – critical in rented buildings or co-tenant situations.
The so-called “permission to attack” or “get out of jail free” document contains the scope, proof of authorization authority, and a 24/7 emergency contact chain to de-escalate with security staff or police.
Recordings of employees are personal data (typically Art. 6(1)(f) GDPR / § 26 BDSG) – requiring data minimization, secure storage, and deletion once the report is delivered.
For tests that specifically include technical monitoring of employee behavior, German co-determination law can apply. Pure social-engineering tests usually don’t trigger it – but an early alignment with the works council is advisable regardless.
This is general orientation, not legal advice. Have § 123 StGB, GDPR/§ 26 BDSG, and works-council questions reviewed by a lawyer for your specific case.
The recon phase regularly takes up the larger share of effort. PTES recommends at least 2–3 days of onsite observation to establish reliable patterns – access times, shift changes, camera positions.
Most credible providers work non-destructively: no locks are damaged, no doors forced – everything stays reversible. Destructive testing must be separately scoped and backed by property damage insurance.
That’s exactly what the written authorization document with a 24/7 emergency contact is for. A well-known case (Coalfire, Iowa 2019) shows that even with such a document, arrests can still happen – clear escalation chains and a reachable contact are critical.
Physical security is far less standardized than cyber pentesting certification. ASIS CPP/PSP are the strongest signals for physical security competence, but say little about social-engineering skill. Rely more on demonstrated track record and references than on any single credential.
For pure social-engineering tests, co-determination is a debated grey area but tends not to apply. As soon as technical means could evaluate employee behavior (e.g. whether someone plugs in a USB stick), German co-determination law can be triggered. Early alignment is advisable either way.
For pure ISO 27001 Annex A.7 evidence, an overt audit is usually enough – cheaper, with more complete documentation. If realistic attacker resilience is the goal, a covert multi-vector engagement is more appropriate.
Whether you already have a rough objective and format in mind, or still have questions about the selection process – reach out, no pressure.
Book a free consultationCompiled from publicly available industry sources and frameworks. Where possible, we link to primary sources rather than competitor blogs.