CASP vs penetration test — outside-in before active testing.

CASP and penetration testing are often mixed — that wastes budget. We separate them: CASP is passive outside-in profiling with authorisation; a pentest is active, approved scope with RoE and PoCs. So you know what is worth doing first.

  • Two contracts
  • Order with rationale
  • DNS-TXT before CASP
Concrete example

Example decision (anonymised)

A mid-market firm plans “a pentest” but has 12 domains and unclear shadow IT. We recommend CASP Full first on prioritised domains (outside-in, DNS-TXT), a report with top risks, and a later narrower pentest on 2 critical apps. Result: pentest budget drops, findings map to goals — without selling CASP as a pentest substitute. Figures and names are anonymised; the flow matches typical engagements.

Method separation protects budget and signal quality. We document limits in writing — freelance, with public CASP price orientation, without critical guarantees. That is intentional and part of the positioning.

This page’s job: Owns the CASP vs pentest method and budget cut only. Not scan comparison, not pure authorisation how-to.

Checklist

Decision matrix: CASP or pentest?

Quick orientation — final in the scope meeting:

  1. 01

    Unclear outside-in exposure

    → CASP first.

  2. 02

    Specific app/API to test with approval

    → Authorised pentest with RoE.

  3. 03

    Both needed

    → Staged: outside-in, then active test.

  4. 04

    No domain authorisation possible

    → No CASP; no serious start.

  5. 05

    Only tool scan wanted

    → Not our CASP product; decline or separate honestly.

  6. 06

    “Hack everything including partner domains”

    → Decline.

Problem & fit

What the mix-up really costs

Cost of the status quo

A pentest without a clear outside-in picture often tests the wrong surface or inflates scope. A scan report without analyst prioritisation creates alert fatigue. Both feel like security — neither delivers a defensible decision on what to fix first.

What “done” looks likeYou know when outside-in clarity is enough and when an authorised pentest is worth the next euro — with separate scopes and deliverables.
Who this comparison is for

IT and business leaders in DACH SMEs and B2B who steer security budget and refuse to buy “just scan something”. Ideal before the first expensive active test or after unclear scanner reports.

Not for you if…

  • You want unauthorised scans or a quick unapproved domain check
  • You expect a fully automatic SaaS scanner app
  • You only need a certificate without technical exposure clarity
Differentiation & buying guide

Buying CASP vs pentest: how we differ — and what to watch.

Many vendors mix outside-in and active testing in one pitch. That creates false expectations and unclear reports. We separate methods and say when each makes sense — and when it does not.

How we differ on the method comparison

Two deliverables, two contracts

CASP reports and pentest findings are not sold as one “everything tested” sentence.

Sequence with rationale

Often outside-in first, active test after — not both by default, only when it serves the goal.

Authorisation is mandatory

DNS-TXT for CASP, written approval and RoE for pentest — no “quick test”.

No critical guarantees

We maximise clarity, not the sales story “we always find X”.

What to watch when CASP and pentest are compared or bundled

  • One lump “scan + hack” offer without method separation or approvals
  • Pentest price that is only automated tool output
  • CASP/outside-in without domain authorisation
  • Promises that CASP always replaces a pentest (or the reverse)
  • No RoE, windows, or stop criteria for active testing
  • Guarantees on finding counts or “hack-free afterwards”

Included vs. deliberately not (CASP vs pentest)

Typical boundaries in this decision space:

  • We do / include

    Honest recommendation: CASP only, pentest only, or staged

  • We do / include

    CASP passive with DNS-TXT; pentest active only with RoE

  • We do / include

    Separate deliverables and acceptance

  • We do not / exclude

    Active exploits inside CASP scope

  • We do not / exclude

    Unauthorised tests “because the client is in a hurry”

  • We do not / exclude

    Finding-count or ranking guarantees

If you want methods cut honestly: scope meeting. If you want a mixed all-inclusive security package without limits, we are not the fit.

How delivery works

What you decide, what is authorised, what is out of scope.

Method boundaries first — no mixed CASP/pentest theatre.

/ 01

What you can decide

Decision confidence: outside-in picture and/or active proof in approved scope — not mixed methods.

/ 02

What is authorised

DNS-TXT authorisation, clear CASP vs pentest limits, signed report or RoE and PoCs.

/ 03

How fast you get clarity

CASP often orients in 10–21 days; pentest follows once the test space is sharp.

/ 04

What comes from you

Domain approval and contacts — no months of tool onboarding for CASP.

What changes

Practical outcomes for you.

01

Budget where it works

Visibility and priority first — then targeted active tests, not blind flight.

02

No mixed deliverables

CASP report and pentest findings stay methodically and contractually separate.

03

Honest sales language

No fear marketing, no “we are everything” fluff.

In the package

Core offer and clear options.

01
Core

CASP Lite or Full

Passive outside-in profiling, signed report, prioritisation.

02
Optional

Authorised penetration test

Active testing only after approval, RoE, and defined scope.

03
Bonus

Clear decision help

Which offer first — in advisory and content.

04
Bonus

Public price orientation

CASP Lite € 7,500 · Full € 19,900 — scope stays transparent.

What you can compare

  • CASP: outside-in visibility, prioritisation, next steps
  • Pentest: active validation in approved scope with PoCs
  • Separate offers and acceptance
  • Recommendation which path comes first
Steps

Typical sequence

  1. 01

    Clarify goal

    Decision, compliance evidence, or pre-pentest?

  2. 02

    CASP (if outside-in is missing)

    Authorisation, passive profiling, report.

  3. 03

    Prioritise

    What is urgent, what can wait, what belongs in active testing?

  4. 04

    Pentest optional

    Only with RoE and approved targets — separate scope.

FAQ

Objections, answered honestly.

Is CASP a penetration test?

No. CASP is passive outside-in. A pentest validates actively in approved scope.

Do I always need both?

No. Many start with CASP. Pentest follows when goals and value are clear.

What does CASP cost?

Public: Lite from € 7,500, Full € 19,900. Details and scope in a conversation.

How do I start?

Contact with goal and domain. DNS-TXT before CASP start; pentest with written approval.

Can a pentest without CASP still make sense?

Yes, when scope and goals are already sharp. CASP helps when outside-in is unclear — not dogma.

How long does each typically take?

CASP Lite/Full in defined day windows (see pricing/business plan); pentest depends on scope and RoE.

Next step

Cut scope honestly

Tell us whether you need outside-in clarity, an active test, or both — we separate scopes.

Scope before active workNext step
Request a scope meeting