Skip to product information
AWS Cloud Pentest - Baseline
€6.095,00
Fixed price. Fixed scope. No sales call. A manual security review and penetration test of one AWS account: the right fit for SaaS companies that run on AWS and need evidence for SOC 2, ISO 27001 or a customer security review.
Scope included
- 1 AWS account, 1 region
- Read-only access via an audit role you create with our CloudFormation template (no write permissions needed)
- Estimated effort: 5 tester-days
What we test
- Configuration review against the CIS AWS Foundations Benchmark
- IAM: overly permissive policies, unused or exposed access keys, missing MFA, risky trust relationships
- Publicly exposed resources: S3 buckets, snapshots, security groups, load balancers, API Gateway
- Logging and encryption: CloudTrail, S3 and EBS encryption, key management
- Manual validation of every finding, so you get real risks rather than a raw tool export
Deliverables
- PDF report with executive summary and technical findings (CVSS-scored, with remediation advice)
- Letter of attestation you can share with auditors and customers
- Critical findings reported to you immediately, not at the end of the test
Not included
- Retest of findings: add a Separate Retest ($1,499), or choose Extended where a free retest is included
- Privilege-escalation testing from a low-privileged role (see Extended)
- Azure and Google Cloud; application-level testing of workloads running on AWS (see Web Application Pentest)
- Social engineering / phishing, denial-of-service
Testing follows the AWS penetration testing policy: no prior approval from AWS is required for the permitted services.
If we discover during kick-off that your environment is larger than this tier, you can upgrade for the price difference or get a full refund, your choice.