A pentest without a clear outside-in picture often tests the wrong surface or inflates scope. A scan report without analyst prioritisation creates alert fatigue. Both feel like security — neither delivers a defensible decision on what to fix first.
CASP vs penetration test — outside-in before active testing.
CASP and penetration testing are often mixed — that wastes budget. We separate them: CASP is passive outside-in profiling with authorisation; a pentest is active, approved scope with RoE and PoCs. So you know what is worth doing first.
- Two contracts
- Order with rationale
- DNS-TXT before CASP
Example decision (anonymised)
A mid-market firm plans “a pentest” but has 12 domains and unclear shadow IT. We recommend CASP Full first on prioritised domains (outside-in, DNS-TXT), a report with top risks, and a later narrower pentest on 2 critical apps. Result: pentest budget drops, findings map to goals — without selling CASP as a pentest substitute. Figures and names are anonymised; the flow matches typical engagements.
Method separation protects budget and signal quality. We document limits in writing — freelance, with public CASP price orientation, without critical guarantees. That is intentional and part of the positioning.
This page’s job: Owns the CASP vs pentest method and budget cut only. Not scan comparison, not pure authorisation how-to.
Decision matrix: CASP or pentest?
Quick orientation — final in the scope meeting:
- 01
Unclear outside-in exposure
→ CASP first.
- 02
Specific app/API to test with approval
→ Authorised pentest with RoE.
- 03
Both needed
→ Staged: outside-in, then active test.
- 04
No domain authorisation possible
→ No CASP; no serious start.
- 05
Only tool scan wanted
→ Not our CASP product; decline or separate honestly.
- 06
“Hack everything including partner domains”
→ Decline.
What the mix-up really costs
IT and business leaders in DACH SMEs and B2B who steer security budget and refuse to buy “just scan something”. Ideal before the first expensive active test or after unclear scanner reports.
Not for you if…
- You want unauthorised scans or a quick unapproved domain check
- You expect a fully automatic SaaS scanner app
- You only need a certificate without technical exposure clarity
Buying CASP vs pentest: how we differ — and what to watch.
Many vendors mix outside-in and active testing in one pitch. That creates false expectations and unclear reports. We separate methods and say when each makes sense — and when it does not.
How we differ on the method comparison
Two deliverables, two contracts
CASP reports and pentest findings are not sold as one “everything tested” sentence.
Sequence with rationale
Often outside-in first, active test after — not both by default, only when it serves the goal.
Authorisation is mandatory
DNS-TXT for CASP, written approval and RoE for pentest — no “quick test”.
No critical guarantees
We maximise clarity, not the sales story “we always find X”.
What to watch when CASP and pentest are compared or bundled
- One lump “scan + hack” offer without method separation or approvals
- Pentest price that is only automated tool output
- CASP/outside-in without domain authorisation
- Promises that CASP always replaces a pentest (or the reverse)
- No RoE, windows, or stop criteria for active testing
- Guarantees on finding counts or “hack-free afterwards”
Included vs. deliberately not (CASP vs pentest)
Typical boundaries in this decision space:
- We do / include
Honest recommendation: CASP only, pentest only, or staged
- We do / include
CASP passive with DNS-TXT; pentest active only with RoE
- We do / include
Separate deliverables and acceptance
- We do not / exclude
Active exploits inside CASP scope
- We do not / exclude
Unauthorised tests “because the client is in a hurry”
- We do not / exclude
Finding-count or ranking guarantees
If you want methods cut honestly: scope meeting. If you want a mixed all-inclusive security package without limits, we are not the fit.
What you decide, what is authorised, what is out of scope.
Method boundaries first — no mixed CASP/pentest theatre.
What you can decide
Decision confidence: outside-in picture and/or active proof in approved scope — not mixed methods.
What is authorised
DNS-TXT authorisation, clear CASP vs pentest limits, signed report or RoE and PoCs.
How fast you get clarity
CASP often orients in 10–21 days; pentest follows once the test space is sharp.
What comes from you
Domain approval and contacts — no months of tool onboarding for CASP.
Practical outcomes for you.
Budget where it works
Visibility and priority first — then targeted active tests, not blind flight.
No mixed deliverables
CASP report and pentest findings stay methodically and contractually separate.
Honest sales language
No fear marketing, no “we are everything” fluff.
Core offer and clear options.
CASP Lite or Full
Passive outside-in profiling, signed report, prioritisation.
Authorised penetration test
Active testing only after approval, RoE, and defined scope.
Clear decision help
Which offer first — in advisory and content.
Public price orientation
CASP Lite € 7,500 · Full € 19,900 — scope stays transparent.
What you can compare
- CASP: outside-in visibility, prioritisation, next steps
- Pentest: active validation in approved scope with PoCs
- Separate offers and acceptance
- Recommendation which path comes first
Typical sequence
- 01
Clarify goal
Decision, compliance evidence, or pre-pentest?
- 02
CASP (if outside-in is missing)
Authorisation, passive profiling, report.
- 03
Prioritise
What is urgent, what can wait, what belongs in active testing?
- 04
Pentest optional
Only with RoE and approved targets — separate scope.
Objections, answered honestly.
Is CASP a penetration test?
No. CASP is passive outside-in. A pentest validates actively in approved scope.
Do I always need both?
No. Many start with CASP. Pentest follows when goals and value are clear.
What does CASP cost?
Public: Lite from € 7,500, Full € 19,900. Details and scope in a conversation.
How do I start?
Contact with goal and domain. DNS-TXT before CASP start; pentest with written approval.
Can a pentest without CASP still make sense?
Yes, when scope and goals are already sharp. CASP helps when outside-in is unclear — not dogma.
How long does each typically take?
CASP Lite/Full in defined day windows (see pricing/business plan); pentest depends on scope and RoE.
Cut scope honestly
Tell us whether you need outside-in clarity, an active test, or both — we separate scopes.