Observed arrival · 2026-09-14
Continuous penetration testing, without the marketing
A vendor-neutral reference that explains what PTaaS should include, how it differs from scanners and bug bounties, and how to choose a defensible testing cadence.
Field notes
The reference treats continuous testing as a sequence of scoped assessments rather than uninterrupted observation. Its cadence example contrasts one month of dated evidence with eleven months without it, while the guidance calls for retesting repaired findings and retaining each test’s scope, timing, results, severity, and remediation record. The page also separates contracted penetration tests from scanners, bug bounties, and automation, using citations to NIST, CREST, OWASP, DORA, PCI DSS, and NCSC.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue