For MSPs, MSSPs and IT service providers reselling cybersecurity

Launch a white-label pentesting service without hiring a pentester.

PentX runs real, exploit-proven pentests in hours. You deliver the report under your brand, keep the client relationship, and resell each engagement at up to 90% gross margin. Add a named CREST-certified human co-sign when your client, auditor, or insurer requires it.

No credit card required. Tell us about your business and we’ll set up your account within 24–48 hours.
PentX tests:Web AppsExternalInternalCloud
Trained on 10,000 real pentest projects CREST engineer co-sign ISO 27001

Already used by 70+ IT companies to deliver external, web, internal, and cloud pentests under their own brand.

70+
MSPs and IT companies delivering with PentX
Hours
to a finished engagement, not weeks
90%
gross margin you keep per pentest
Why MSPs sell it

Your clients already need pentesting. The only question is whether they buy it from you or someone else.

Every year, your clients face more cyber insurance questionnaires, compliance requests, vendor security reviews, and board-level security questions. When they ask for a pentest, most MSPs either say "we don't do that," subcontract the work, or send the client to a specialist provider. That means lost margin, lost control, and sometimes a weakened client relationship.

PentX lets you keep the opportunity inside your business. You scope the engagement, PentX runs the pentest, and your client receives a professional report under your brand.

💰

New revenue line

Sell annual pentests, retests, remediation support, vCISO packages, and compliance evidence without building an offensive-security team.

🤝

Higher client retention

Pentesting gives you a strategic security conversation with the client before a competitor, auditor, insurer, or boutique pentest firm gets there first.

Low delivery burden

No senior pentester hire. No report-writing bottleneck. No subcontractor margin split.

Your delivery engine

PentX is the pentesting delivery engine behind your MSP's cybersecurity offer.

PentX gives your MSP the ability to sell and deliver professional pentests without hiring offensive-security talent. Your team defines the scope, PentX performs reconnaissance, exploitation, validation, and reporting, and the final deliverable is exported under your brand.

Every finding is backed by proof: exploit chain, payload, request and response captures, screenshots, affected asset, business impact, and remediation guidance. When required, a CREST-certified senior engineer can review and co-sign the report before it reaches your client.

Use PentX to sell
The MSP pentesting problem

Demand is rising, but delivery is hard to own.

Pentesting should be one of the highest-margin services in your cybersecurity portfolio. In practice, most MSPs lose the opportunity before they can productize it.

💰

The subcontractor margin trap

You sell the project, but a boutique provider does the work, keeps most of the margin, and becomes visible to your client. You carry the relationship risk while someone else owns the specialist credibility.

The senior-pentester bottleneck

Hiring a real senior pentester is expensive, slow, and risky. Even when you find one, they become the bottleneck for scoping, testing, validation, reporting, client calls, and retests.

🔍

The scanner credibility gap

Vulnerability scanners create tickets. MSP clients need a defensible pentest report with proof, impact, remediation guidance, and, when necessary, a named human sign-off.

📉

The lost-account risk

When a client asks for a pentest and you cannot deliver it, they go to a security provider. That provider now has a strategic security conversation with your client.

Good fit / not a fit

Built for MSPs that want to sell cybersecurity, not just run tools.

Good fit PentX is a strong fit if you

  • Serve SMB or mid-market clients
  • Already sell managed IT, security, compliance, vCISO, Microsoft 365, cloud, or infrastructure services
  • Want to add annual pentesting without hiring a red team
  • Need white-label reports your clients can trust
  • Want predictable margins and repeatable delivery
  • Prefer to own the client relationship instead of introducing a subcontractor

Not ideal PentX is not the right fit if you

  • Only want a vulnerability scanner
  • Need manual red-team campaigns with social engineering and physical intrusion
  • Do not want to resell cybersecurity services
  • Cannot define or authorize client scope
  • Need unlimited custom consulting included in a fixed-price pentest credit
How delivery works

From client scope to white-label report in hours.

Your MSP controls the client relationship. PentX handles the pentest execution and reporting engine behind the scenes.

~2 min

Scope the client engagement

Add the approved assets: domains, web applications, IP ranges, internal network targets, or cloud environments. Scope is enforced at the network layer so the test cannot exceed what you authorize.

hours

PentX runs the pentest

PentX performs reconnaissance, exploitation, validation, and evidence collection across the approved attack surface. Your team does not need to manually drive the test.

auto

Findings are proven

Every confirmed vulnerability includes reproducible proof: exploit chain, payload, request and response captures, screenshots, affected assets, severity, business impact, and remediation steps.

your brand

You review and export

Export the final report with your logo, your colors, and your client-facing language. On the Partner tier, the client experience can be fully white-labeled.

optional

Add human co-sign when needed

For cyber insurance, regulated clients, enterprise sign-off, or auditor evidence, request a CREST-certified senior engineer review and co-sign before delivery.

included

Retest after remediation

After your MSP fixes or coordinates remediation, run the included retest and send the client proof that the issues were resolved.

Predictable scope

What counts as one pentest credit?

MSPs need predictable scope so they can price confidently. Every engagement is confirmed before launch, so you know your delivery cost before you quote or deliver.

Engagement typeWhat one credit covers
External pentestOne approved external attack surface for one client, such as a defined set of public IPs, domains, and exposed services.
Web application pentestOne approved web application or client-facing portal, including the agreed URLs, authentication flow, and test accounts where applicable.
Internal pentestOne approved internal network scope, delivered through the agreed internal access method and limited to the assets authorized by the client.
Cloud pentestOne approved cloud environment or account scope, limited to the assets and permissions authorized before launch.
RetestOne retest of the same scope after remediation, included with each pentest credit.

Large, complex, multi-environment, or multi-application scopes may require more than one credit. You will always know this before the engagement starts. No surprise usage. No margin leakage.

Client deliverables

What your client receives.

A professional pentest deliverable under your brand, built for technical teams, executives, insurers, and auditors.

📊

Executive summary

Clear business-level explanation of risk, impact, and priority actions.

🧾

Technical findings

Confirmed vulnerabilities with severity, affected assets, exploit evidence, and reproduction details.

📷

Proof of exploitation

Screenshots, payloads, request and response captures, and exploit chain where applicable.

🛠

Remediation guidance

Practical steps your MSP can execute or coordinate with the client's internal team.

🔄

Retest report

Evidence that previously identified issues were fixed or remain unresolved.

Optional CREST-certified co-sign

A named senior engineer review and sign-off for clients that require additional assurance.

Downstream revenue

The report creates the next managed security conversation.

Pentesting should not end with a PDF. Each finding gives your MSP a reason to help the client reduce risk, improve controls, and buy ongoing security support.

🔧

Remediation projects

Fix exposed services, misconfigurations, vulnerable applications, weak authentication, cloud issues, and network segmentation gaps.

🛡

Managed security upgrades

Turn findings into firewall, EDR, identity, backup, logging, monitoring, and hardening projects.

📋

Compliance evidence

Use the report and retest as evidence for ISO 27001, SOC 2, PCI-DSS, cyber insurance, and vendor reviews.

🧮

vCISO roadmap

Convert findings into a quarterly security roadmap and board-ready risk register.

The economic opportunity

Turn pentesting into a high-margin MSP service line.

With 10-pack pricing, your delivery cost can drop to €250 per pentest. You choose your client price, bundle it into your security packages, and keep the margin.

Make cybersecurity your edge over every other MSP your clients could choose.
Start Free Trial
One pentest · 10-pack pricingEUR
Example client price€2,500
Your PentX delivery cost€250
Gross profit before your internal time€2,250
Gross margin90%
How MSPs can package PentX
🛡

Annual Security Validation

One external or web pentest per year, executive summary, remediation plan, and retest.

💳

Cyber Insurance Readiness

Pentest report, evidence of remediation, and optional CREST-certified co-sign for insurer review.

🧮

vCISO Evidence Pack

Pentest, risk register update, board-ready summary, remediation roadmap, and retest confirmation.

The pentest is not the only revenue. MSPs also monetize remediation, monthly security management, compliance advisory, policy work, vCISO reviews, and follow-up projects triggered by the findings.

How to sell it

A ready-made offer your sales team can explain in one call.

You do not need to educate the market from scratch. Your clients already understand the need: cyber insurance, compliance, vendor reviews, board pressure, and real attack exposure.

Use this with your clients
"We now offer annual penetration testing as part of our cybersecurity services. This gives you a professional, evidence-backed report showing how your external, web, internal, or cloud environment could be exploited, what needs to be fixed, and proof after remediation. We deliver the engagement under our security practice, and when required, we can include a named CREST-certified engineer sign-off for auditor, insurer, or enterprise review."
Best moments to sell
Cyber insurance renewal ISO 27001 or SOC 2 preparation PCI-DSS 4.0 evidence request New website, portal, VPN, firewall, or cloud deployment Quarterly business review After a vulnerability scan finds critical issues Before a board or investor security review After onboarding a new managed IT client
Objection handling
"We already have vulnerability scanning."
Scanning tells you what might be vulnerable. A pentest proves what can actually be exploited and gives you a client-ready report with evidence, impact, and remediation guidance.
"Is this just automated?"
The platform automates the testing and evidence collection, but the report is based on proven exploit chains, not theoretical scanner output. For regulated or insurer-facing work, we can add a named CREST-certified engineer review and co-sign.
"Why do we need this every year?"
Your environment changes constantly: new apps, new users, new cloud assets, new vulnerabilities, and new insurer requirements. Annual testing gives you defensible evidence that you are checking real exposure, not just assuming controls work.
Why MSPs choose PentX

Not a scanner. Not a subcontractor. Not another tool your team has to operate.

PentX is built for MSPs that want to sell a finished cybersecurity deliverable under their own brand.

OptionWhat happensMSP problem
Hire a pentesterYou build internal capacityHigh fixed cost, hard hiring, report bottleneck, retention risk
Subcontract to a boutiqueSomeone else delivers the projectLower margin, slower delivery, client relationship exposure
Use a scannerYou get technical findingsYour team still has to validate, explain, prioritize, and write the report
Use traditional PTaaSA third party delivers the pentestLess control, slower delivery, thinner reseller economics
Use PentXYou deliver a white-label, exploit-proven pentest under your brandHigh margin, fast delivery, optional human co-sign, client relationship stays with you

PentX gives MSPs the economics of software, the credibility of exploit-proven testing, and the commercial control of a white-label service.

The trust question

Your reputation is on the report. That is why every finding must be defensible.

MSPs cannot risk sending clients hallucinated CVEs, generic scanner noise, or weak reports. PentX is built around evidence, scope control, and optional human review.

🧾

Exploit-proven, not guessed

A finding only reaches the report when it is backed by reproducible evidence: exploit path, request and response captures, payload, screenshots, affected asset, severity, and remediation guidance.

🔐

Controlled scope

The authorized scope is enforced at the network layer. PentX cannot test outside the assets approved for the engagement. Rate-limiting, kill switches, and audit logs are part of the delivery model.

Optional named human co-sign

When a client, insurer, auditor, or enterprise buyer requires human accountability, a CREST-certified senior engineer can review and co-sign the engagement before delivery.

🏷

White-label delivery

Your client sees your brand, your report, and your security practice. PentX stays behind the scenes unless you choose otherwise.

Already in production

MSPs and security providers are already using PentX to replace subcontracting, reduce delivery cost, and scale pentesting revenue.

125

From 8–12 outsourced pentests a year to 125 engagements in 5 months. A US Northeast IT company serving financial-sector clients replaced outsourced delivery with PentX, cut cost per engagement by 70%, and turned PCI-DSS 4.0 and SOC 2 evidence into an on-demand service. Result: payback inside month one.

US financial-sector IT company
95%

Faster report turnaround. CTDefense used PentX to reduce report turnaround from 25 hours of manual writing to 4 hours of senior review, freeing senior engineers for remediation and client-facing advisory. Result: more delivery capacity without reducing report defensibility.

CTDefense
100%

Auditor acceptance over 12 months. Forward Defense submitted PentX-powered reports to Big Four auditors over 12 months with 100% acceptance and zero revisions. Result: MSP-grade delivery with auditor-ready evidence.

Forward Defense
ISO 27001 ISO 9001 GDPR compliant CREST PCI-DSS 4.0
Pricing

Start with one pentest. Scale into a white-label MSP security practice.

Every paid pentest includes one retest. Use PentX as a one-off delivery engine, a 10-client annual pentest package, or a full white-label partner program.

Pilot
Test PentX on your own environment, or deliver your first client engagement.
€500 / pentest / year
1 pentest + 1 retest
  • 1 pentest
  • 1 retest of the same scope
  • External, web, internal, or cloud scope
  • Exploit-proven findings
  • Client-ready report
  • White-label report export
  • Optional CREST-certified co-sign available
Start Free Trial
Best if you want to validate report quality before committing to a partner package.
MSP 10-Pack
MSPs adding annual pentesting to 5–10 clients.
€2,500 / year
10 pentests + 10 retests · €250 per pentest
  • 10 pentest credits
  • 10 retests of the same scopes
  • External, web, internal, or cloud engagements
  • Exploit-proven findings
  • White-label report exports
  • Reusable client-facing report format
  • Optional CREST-certified co-sign available
  • Margin model built for resale
Start Free Trial
Best if you already have clients who need annual testing, cyber insurance evidence, or compliance support.
★ Recommended for MSPs
White-label Partner
Launch a branded pentesting service line.
€2,500 / year
10 pentests + 10 retests · + €2,500 one-time MSP Launch Kit
  • Everything in MSP 10-Pack
  • Fully white-label client experience
  • Your logo, colors, report branding, and client-facing positioning
  • MSP sales deck, proposal template, and email sequence
  • Quote calculator and objection-handling battlecard
  • Compliance use-case sheets and sample report
  • Partner onboarding session and first client quote review
  • Priority partner support
  • Optional pay-after-paid terms for qualified partners
Start Free Trial
Best if you want more than pentest credits: the sales assets, positioning, and partner support to start selling immediately.
Scale Partner
Larger MSPs, MSSPs, and security providers delivering 25+ pentests per year.
Custom
Volume pricing
  • 25, 50, 100+ pentest credit packages
  • Volume pricing
  • Multi-client delivery workflow
  • Partner success support
  • Custom white-label setup
  • Optional co-selling support
  • Optional CREST-certified review packages
  • Flexible commercial terms for qualified partners
Talk to the partner team
Best if pentesting is becoming a strategic service line, not an occasional project.
Every paid pentest includes one retest. PentX can run pentests across web applications, external networks, internal networks, and cloud environments.
White-label partner program

The MSP Launch Kit gives your team the words, assets, and workflow to start selling.

Most MSPs do not fail at pentesting because they lack demand. They fail because they do not have the offer, sales story, pricing model, and client-facing materials. The MSP Launch Kit closes that gap.

📊

Sales deck

A client-facing presentation your team can use to explain annual pentesting, cyber insurance evidence, and compliance support.

📄

Proposal template

A ready-to-edit proposal for external, web, internal, and cloud pentest engagements.

🧮

Quote calculator

A simple pricing model so your team can protect margin and quote consistently.

Email sequence

Client emails for cyber insurance renewal, annual security review, QBR follow-up, and compliance-triggered outreach.

🛡

Objection-handling battlecard

Clear answers to "Is this automated?", "Is this just a scan?", "Why do we need it?", and "Will auditors accept it?"

📋

Sample report

A client-safe example report to use during sales conversations.

Compliance use-case sheets

Positioning for ISO 27001, SOC 2, PCI-DSS 4.0, cyber insurance, and vendor security reviews.

🎓

Partner onboarding session

A practical session to help your team package, price, and sell the first engagements.

💬

First client quote review

We help you review your first quote so you avoid underpricing, overscoping, or losing margin.

Your questions, answered

Everything an MSP asks before the first engagement.

Is PentX a vulnerability scanner?

No. Vulnerability scanners identify potential issues. PentX delivers a pentest-style engagement with validated, exploit-proven findings, evidence, business impact, remediation guidance, and a client-ready report. Your team does not need to manually turn scanner output into a professional pentest report.

Will my client know PentX is involved?

On the Partner tier, the client experience can be fully white-labeled with your logo, colors, report branding, and client-facing positioning. Your MSP owns the relationship and delivers the report.

Can we sell this as our own pentesting service?

Yes. PentX is designed for MSPs and IT service providers that want to resell pentesting under their own brand. You control the client relationship, the pricing, the packaging, and the follow-on remediation conversation.

What does one pentest credit include?

One pentest credit covers one approved engagement scope, such as an external, web, internal, or cloud pentest for one client. The exact assets are confirmed before launch. Large, complex, or multi-environment scopes may require more than one credit, but you will know that before the engagement starts. Each pentest includes one retest of the same scope.

Do we need an internal pentester to use PentX?

No. PentX was built so MSPs can deliver pentesting without hiring a dedicated offensive-security engineer. Your team defines the client scope and reviews the output; PentX handles reconnaissance, exploitation, validation, evidence collection, and reporting.

Is there human review?

PentX validates findings with reproducible exploit evidence. For clients that require named human accountability, a CREST-certified senior engineer can review and co-sign the report before delivery. This is useful for cyber insurance, regulated clients, auditors, and enterprise sign-off.

How do MSPs make money with PentX?

With 10-pack pricing, your delivery cost can be €250 per pentest. You resell the engagement at your own client price and keep the margin. Many MSPs also generate follow-on revenue from remediation, retesting, compliance support, managed security upgrades, and vCISO services.

Can we use PentX for cyber insurance and compliance evidence?

Yes. PentX reports can support cyber insurance reviews, vendor security reviews, and compliance-driven evidence requests. For higher-assurance situations, you can add a CREST-certified engineer co-sign.

How fast can we deliver the first engagement?

A typical external engagement can complete in hours once the scope is approved. New partners can usually move from signup to their first client-ready quote within days.

What happens after the client fixes the issues?

Each pentest includes one retest of the same scope. After remediation, you can rerun the test, verify what was fixed, and deliver retest evidence to the client.

Get started

Start with your own environment. Then sell it to your clients.

Tell us about your business and we’ll set up your account and follow up with next steps — white-label setup, 10-pack pricing, volume packages, and pay-after-paid terms for qualified MSPs.

No credit card required.  Most MSPs hear back within 24–48 hours with their account ready to go.
Start Free Trial