Externally reachable systems, e.g. web servers, VPN gateways, mail servers.
Regular, documented tests support your evidence of continuous effectiveness – for example in the context of NIS2 (Art. 21) or Section 30 BSIG. Does not replace individual legal advice.
New deployments, new access, new CVEs. Your attack surface today is not the one from three months ago.
Every remediated vulnerability is automatically re-verified in the next cycle. No extra quote.
Status, findings, history – always available on your existing platform, app.access-granted.de.
Most automated providers just hand you a findings list. With us, a real pentester puts the results into context with you every month – in a personal meeting.
A snapshot from your customer platform: every finding with criticality, status, and history. No waiting for next year's report.
Providers built purely on automated scanning or attack-simulation platforms hand you a list of findings and leave you to figure out the rest. With AccessGranted Continuous you also get a fixed point of contact: a pentester who discusses the results with you every month, ranks them by what actually matters for your business, and answers your questions.
"You're talking directly to the person who puts the results into context for your business, not a dashboard."
Two numbers, one price: enter your external and internal endpoints, see the result instantly.
Please select your endpoints and term first so we can put together a matching quote.
Externally reachable systems, e.g. web servers, VPN gateways, mail servers.
Internal endpoints incl. Active Directory environment. We align testing depth (e.g. AD exploit runs) with you during scoping, possibly at a reduced cadence depending on scope.
Due once when booking at least one internal endpoint – not part of the monthly rate.
All prices are net, plus statutory VAT. This offer is aimed exclusively at businesses within the meaning of Section 14 of the German Civil Code (BGB).
Test scope, systems, framework conditions – 30 minutes that make the rest plannable.
Access and approvals for the automated testing platform, set up.
Full baseline test, including report and initial discussion.
Automated tests, re-tests, review meeting.
…and repeats automatically, every month from here on.
A scanner reports signatures of known vulnerabilities, nothing more. Our automated testing platform goes further: real exploit attempts, targeted privilege escalation paths, for example within an Active Directory environment.
The difference to classic SaaS scanners: you don't get a list of open ports, you get evidence of whether and how a vulnerability is actually exploitable – automated, repeated every month.
External endpoints are tested automatically on a monthly rhythm. For internal testing depth, especially Active Directory exploit runs, we align the exact cadence with you during scoping – depending on scope and criticality, a slightly reduced rhythm can make sense here.
Regardless of cadence: findings already reported are automatically re-verified (re-tested) in the following cycle, without you having to commission that separately.
You talk to a real consultant, not a PDF. Together we go through the last cycle's results, rate new findings by criticality, and clarify what's changed since.
The meeting is also the place for your IT team's questions and to prioritize your team's next steps.
AccessGranted Continuous provides you with regular, documented test results and reports that can serve as a building block for evidencing the continuous effectiveness of your security measures, for example in the context of NIS2 (Art. 21) or Section 30 BSIG.
Whether and in what form this is sufficient for your specific compliance evidence depends on your individual situation. We recommend aligning this with us during the initial consultation and, if needed, with your legal advisor – we do not replace legal advice.
We proceed in a controlled manner. Before the first test cycle, we jointly define rules of engagement: critical systems, maintenance windows, and escalation paths. Our automated testing platform is designed for stability and uses safety checks before executing riskier actions such as privilege escalation attempts.
A residual risk can never be fully excluded with real exploit simulation. That's why we deliberately align testing depth and scope with your environment during scoping, rather than running everything unfiltered on every system.
You start on a 1-year term by default, with no discount. Book 3 years and your monthly rate drops by 5%; 5 years drops it by 10% – the discount applies only to the recurring monthly rate, not to the one-time setup fee for internal endpoints.
Which term makes sense depends on how confident you are about your needs over the next few years – growing companies with a changing endpoint count often prefer the flexibility of 1 year, while a stable footprint makes the discount add up significantly over the term. We're happy to advise you on this during the initial consultation.