Buyer’s Guide · Last updated: August 31, 2026

What to actually look for when choosing a physical penetration testing provider

Physical penetration testing is even less standardized than cyber pentesting. This guide shows how to spot a credible provider – from the multi-vector requirement to German law (§ 123 StGB) to price orientation.

11 selection criteria Legal framework (Germany) Fully sourced
TL;DR

A credible physical pentest tests multiple entry points and techniques over a period of time – not a single attempt. Before requesting a quote, you need to settle two decisions: pentest (covert) or audit (overt), and which objective is being tested – data access or goods protection. No test should happen without a written authorization document with a 24/7 emergency contact.

Before the first quote

Two decisions only you can make

These two decisions determine scope, price, and provider fit – and should be settled before you even request a quote.

Format
Pentest (covert)

Covert, realistic attacker simulation. Goal: get in undetected. More expensive, but more indicative of real day-to-day security.

Audit (overt)

Overt, complete vulnerability documentation without concealment. Cheaper, lower risk, but less realistic.

Objective
Data / IP

Server room, executive office, a conference room to bug, an unlocked, logged-in workstation.

Goods / merchandise

Jewelry store, freight carrier, warehouse, retail floor.

Process

How a credible physical pentest actually runs

Six phases, where reconnaissance regularly takes more time than the actual test attempt.

01

Scoping & pre-engagement

Objectives, no-go zones, permitted techniques, testing windows, destructive vs. non-destructive, authorization, emergency contacts.

02

Reconnaissance

OSINT plus multi-day onsite surveillance: floor plans, shift schedules, access systems, camera positions, traffic patterns.

03

Pretext development & preparation

Equipment, badges, and scenarios are prepared for the planned test attempts.

04

Multiple attempts across multiple vectors

Different entry points, different techniques, a spectrum from covert to overt – not a single attempt.

05

Objective achievement

Access to the defined objective, foothold on the internal network, optionally covert device placement.

06

Debrief & report

Every attempt is documented – including failed ones – with photos, videos, and timestamps.

The Criteria

11 things that actually matter

Compiled from OSSTMM, PTES, ISACA, and the practice of physical red-team providers.

Multi-vector testing, not a single attempt

Non-negotiable

Red teaming by definition means using multiple attack vectors simultaneously. How to check: ask how many distinct entry points and techniques are tested, and whether failed attempts are documented too. A provider describing only one attempt is selling break-in theater, not a credible assessment.

Scope and quality of the recon phase

Non-negotiable

PTES calls for multi-day onsite reconnaissance to establish reliable patterns. How to check: ask how many days of onsite recon are planned and what recon deliverable is provided – photos, shift schedules, access patterns.

Legally sound authorization

Non-negotiable

A written authorization document, signed by someone with legal authority, with a 24/7 emergency contact and escalation process, is mandatory – not optional. How to check: request the document before testing starts and confirm a 24/7 contact chain exists.

Clear separation: pentest (covert) vs. audit (overt)

The provider must know both formats and justify in the proposal which one fits your need. How to check: ask explicitly whether testing is covert or overt, and why.

Objective defined before testing starts

Without a defined goal, success can’t be evaluated. How to check: clarify upfront what the objective is – server room, executive office, conference room, warehouse.

Insurance for property damage

For destructive testing (e.g. forcing locks), standard cyber liability insurance isn’t enough. How to check: ask for separate property damage insurance if destructive techniques are in scope.

Fair debrief culture

Tested employees should learn something, not be humiliated. How to check: ask how the debrief with affected staff works, and whether individuals are named in the report.

GDPR approach for photo and video material

Recordings of employees are personal data. How to check: ask about data minimization, secure storage, and deletion after the report is delivered.

Works-council co-determination clarified

Targeted testing of employee behavior can trigger co-determination rights under German law. How to check: clarify with your works council upfront whether a confidentiality arrangement is needed for the test period.

Demonstrable physical track record

Cyber pentest experience says little about physical capability. How to check: request references specifically for physical assessments, not just network or web pentests.

Reporting quality

Every attempt belongs in the report, not just the successful one. How to check: request photos, videos, and timestamps for every attempt, plus prioritized remediation guidance.

Certification Landscape

Who actually matters in this community

This field is far less standardized than cyber pentesting certification. Practical track record with these four training and community providers counts for more than a formal management credential.

Practitioner Community

A selection, not an exhaustive list – other providers with comparable programs exist. These four are the most established in the community.

01

Social-Engineer, LLC

Chris Hadnagy PASE – Practical Application of Social Engineering (incl. CESE certification)

The field’s original hands-on social-engineering framework. PASE is a multi-day practical course with exercises and homework, including free access to the CESE exam (Certified Ethical Social Engineer) – not a multiple-choice test.

02

Red Team Alliance

Training & certification for red teamers and physical pentesters

Widely regarded in the community as the platinum standard for hands-on red-team and physical-security training – broader than pure lockpicking courses.

03

Covert Access Team

CAT (Covert Access Training) · PACT (Physical Audit Certification Training)

Five-day in-person training covering alarm bypass, badge cloning, access control systems, lockpicking, and key impressioning – led by active practitioners.

04

Red Teamers Academy

Covert Entry & Physical Red Team Courses

Hands-on courses from European red-team operators covering lock/door/window bypass, PACS/badge systems, and OSINT-driven pretexting.

Formal, but supplementary
ASIS CPP · ASIS PSP · ASIS PCI

Recognized management- and assessment-oriented credentials requiring several years of experience – they demonstrate security-management competence more than current field skills.

TSCM

Relevant if bugging or sweeping conference rooms is part of the engagement. No unified certification – mostly private training providers.

Note: cyber certifications like OSCP say little about physical core competency – only relevant when physical access is meant to lead into a network foothold.

Warning Signs

9 red flags when choosing a provider

None of these signals is disqualifying on its own – but in combination, they’re worth asking about directly.

A single-attempt engagement with no additional vectors – “we got in once, done” is the most common sign of a low-quality provider.

A missing or superficial recon phase – no onsite surveillance, no recon deliverable.

No separation between pentest and audit in the proposal – the provider can’t explain whether testing is covert or overt.

No written authorization document and no 24/7 emergency contact chain – legally and operationally unacceptable.

No clear agreement on destructive vs. non-destructive testing.

No objective defined before testing starts.

Unprofessional, humiliating treatment of tested staff – no structured debrief.

Selling pure “break-in theater” instead of a credible, repeatable assessment.

A price that’s unusually low – often just one testing day, one attempt, no substantial report.

Price Ranges

What a physical pentest realistically costs (DACH, 2025/2026)

Orientation values compiled from general pentest and social-engineering cost overviews – no DACH provider publishes separate fixed prices for physical pentests alone.

Certified pentester day rateapprox. €1,000 – €2,000
Full project (SME, Germany)approx. €3,000 – €12,000
Social engineering pentest (incl. physical)approx. €2,000 – €18,000
Complex red-team engagementfrom approx. €30,000
Covert entry assessment (international, US reference)from approx. $32,000

International figures are US market prices (Schellman) and should be read as rough orientation only. Some DACH sources are provider self-publications – treat as orientation, not a binding quote.

Legal Framework

What must be settled under German law

Physical pentests touch criminal law, data protection, and works-council co-determination – these five points aren’t optional.

FAQ

Frequently asked questions about physical pentests

The recon phase regularly takes up the larger share of effort. PTES recommends at least 2–3 days of onsite observation to establish reliable patterns – access times, shift changes, camera positions.

Most credible providers work non-destructively: no locks are damaged, no doors forced – everything stays reversible. Destructive testing must be separately scoped and backed by property damage insurance.

That’s exactly what the written authorization document with a 24/7 emergency contact is for. A well-known case (Coalfire, Iowa 2019) shows that even with such a document, arrests can still happen – clear escalation chains and a reachable contact are critical.

Physical security is far less standardized than cyber pentesting certification. ASIS CPP/PSP are the strongest signals for physical security competence, but say little about social-engineering skill. Rely more on demonstrated track record and references than on any single credential.

For pure social-engineering tests, co-determination is a debated grey area but tends not to apply. As soon as technical means could evaluate employee behavior (e.g. whether someone plugs in a USB stick), German co-determination law can be triggered. Early alignment is advisable either way.

For pure ISO 27001 Annex A.7 evidence, an overt audit is usually enough – cheaper, with more complete documentation. If realistic attacker resilience is the goal, a covert multi-vector engagement is more appropriate.

Planning a physical pentest?

Whether you already have a rough objective and format in mind, or still have questions about the selection process – reach out, no pressure.

Book a free consultation
Sources

What this guide is based on

Compiled from publicly available industry sources and frameworks. Where possible, we link to primary sources rather than competitor blogs.

Buyer’s Guide · Last updated: August 31, 2026