Everything we know about proving what's exploitable.
Regulation guides written against the actual article text, honest comparisons against the alternatives, proof from real engagements, and free tools that tell you where you stand before you talk to anyone.
Compliance guides
Written against the article text, not the marketing summary. Each one states what the regulation actually requires, what auditors accept as evidence, and where a pentest fits.
Article 21 evidence requirements
What national CSIRTs actually accept as security-testing documentation, and how to assemble it without a six-week project.
Article 24 pentest requirements
Which financial entities owe threat-led testing, how often, and what BaFin and the BSI expect to see in the report.
Annex A controls and auditor expectations
The controls that put testing in scope, and the gap between "we tested" and evidence a certification auditor will sign off.
What Articles 15 and 55 actually require
Adversarial testing obligations for high-risk and general-purpose AI systems, and what counts as evidence of them.
How SQUR compares
Four honest head-to-heads. Each one names the cases where the other option is the better buy, because a comparison that never concedes anything is an advert.
Autonomous testing vs German expert-led pentest
Where a hand-run boutique engagement is worth the wait and the budget, and where 24 hours at a fifth of the price wins.
Autonomous EU pentest vs a traditional German firm
Scheduling, scope changes, retests and report format, compared on the terms a German buyer actually decides on.
EU SME on-demand vs enterprise network validation
Two different products that get put in the same bucket. Deployment model, licence shape and who each one is built for.
EU SME on-demand vs US enterprise NodeZero
Data residency, contract shape and entry price, plus where NodeZero's internal-network depth is the right call.
Proof from real engagements
SQUR's whole claim is that it proves exploitability instead of guessing at it. These are the cases where that difference showed up, including the ones where the honest answer was "not exploitable".
Catching a false positive: JPP bypass disproved
A flagged bypass that independent verification could not reproduce, and why reporting that is worth more than reporting the alert.
Mass assignment: self-verification bypass
A real exploit chain reproduced end to end, with the proof attached rather than a severity label.
DORA year one
What twelve months of TLPT enforcement revealed about how supervisors read a testing programme.
EU cybersecurity briefings
Periodic reads on what moved in EU regulation and enforcement, written for people who have to act on it.
Free tools
No signup wall on the first two. Answer the questions, get the answer, decide what to do with it.
NIS2 entity classifier
Essential, important or out of scope. The classification that decides which obligations land on you at all.
DORA readiness quiz
Where your Article 24 posture stands today, and which gaps a supervisor would ask about first.
Free Attack Surface
Shows what's exposed on your external footprint. It never tests anything, so it shows the doors that exist, not whether they open.
By industry
The same product, described in the regulation and the threat model your sector is actually judged against.
Glossary and product docs
Plain definitions for the terms that show up in an audit request, plus the documentation for the platform itself.
What is penetration testing?
Types, scope and why it is the only thing that establishes whether an exposure is actually exploitable.
What is DORA?
The Digital Operational Resilience Act in plain terms: who it binds, and what it obliges them to test.
What is a CVSS score?
How severity ratings are built, what they measure, and the question they deliberately do not answer.
SQUR documentation
How the platform works, what a report contains, and how to run your first engagement.
Read enough?
Start with the free Attack Surface to see what's exposed, or go straight to the pentest that proves what's exploitable.