OSSTMM Penetration Testing Providers

Open Source Security Testing Methodology Manual · Published by ISECOM

The Open Source Security Testing Methodology Manual (OSSTMM) is a peer-reviewed methodology for performing security tests and metrics, developed and maintained by the Institute for Security and Open Methodologies (ISECOM). Unlike other testing frameworks that focus primarily on finding vulnerabilities, OSSTMM takes a scientific approach to security testing by measuring the actual attack surface and quantifying security through its Risk Assessment Values (RAV) scoring system.

OSSTMM version 3 defines five channels of security testing: Human Security, Physical Security, Wireless Communications, Telecommunications, and Data Networks. Each channel is tested for operational security, controls, and limitations using a consistent set of testing modules. The methodology's emphasis on measurable security outcomes rather than subjective risk ratings makes it particularly valuable for organisations that need to demonstrate security improvements over time or compare security posture across different systems and environments.

OSSTMM's comprehensive scope, covering physical, human, and technical dimensions, makes it well-suited for organisations seeking a holistic security assessment rather than purely technical testing. The methodology is freely available under a Creative Commons licence, and its structured approach to quantifying security helps organisations move beyond checkbox compliance toward genuine security improvement.

Key Features

  • —Five-channel security testing model
  • —RAV quantitative scoring system
  • —Covers human and physical security
  • —Scientific measurement approach
  • —Peer-reviewed methodology

Best For

  • —Holistic security assessments
  • —Quantitative security measurement
  • —Physical security testing
  • —Telecommunications security
  • —Security posture benchmarking

Providers using OSSTMM (15)

15 providers
Paris, France · Checked Sept 2026

Cybersecurity division of the Thales Group, with ANSSI, CREST, FedRAMP 3PAO, and NATO-cleared personnel. Defence, government, and critical infrastructure penetration testing worldwide.

Accreditations: CREST, FedRAMP 3PAO, ISO 27001, ISO 9001
Services: Web Application, Network, Cloud, IoT +9
Reston, United States · Checked Sept 2026

US-headquartered cybersecurity consultancy with 800+ employees, serving ~40% of the Fortune 500. FedRAMP 3PAO, PCI QSA, and HITRUST accreditations.

Accreditations: FedRAMP 3PAO, PCI QSA, SOC 2, ISO 27001
Services: Web Application, Network, Mobile App, Cloud +11
Frankfurt, Germany · Checked Sept 2026

Frankfurt-based European payment security specialist holding the full set of PCI credentials (QSA, PFI, ASV, P2PE). Manual-first penetration testing for fintechs, acquirers, and regulated enterprises.

Accreditations: PCI QSA, PCI PFI, PCI ASV, ISO 27001
Services: Web Application, Network, Cloud, API +5
Denver, United States · Checked Sept 2026

Denver-based offensive security boutique with a community-first red team culture. Home of PTES co-authors and the Continuous Red Team retainer.

Accreditations: OSCP Employer, SOC 2
Services: Web Application, Network, Cloud, Wireless +6
Vienna, Austria · Checked Sept 2026

Vienna-headquartered Austrian cybersecurity consultancy with a prolific Vulnerability Lab research program and deep expertise in IoT and embedded systems security across the DACH region.

Accreditations: ISO 27001
Services: Web Application, Network, Mobile App, IoT +7
Seattle, Washington, United States · Checked Sept 2026

Boutique security consultancy specialising in IoT, SCADA/ICS, embedded systems, and hardware security research with world-renowned researchers.

Accreditations: OSCP Employer
Services: Web Application, Network, IoT, SCADA/ICS +7
Berlin, Germany · Checked Sept 2026

Berlin-headquartered German cybersecurity consultancy with 30+ years of BSI IT-Grundschutz experience. Trusted by federal agencies, DAX corporations, and critical infrastructure operators.

Accreditations: BSI Certified, ISO 27001, ISO 9001
Services: Web Application, Network, Cloud, API +7
Ely, United Kingdom · Checked Mar 2026

Established Ely-based compliance and cybersecurity consultancy offering CREST-approved penetration testing as part of a comprehensive governance, risk management, and compliance portfolio.

Accreditations: CREST, ISO 27001, PCI QSA, Cyber Essentials
Services: Web Application, Network, Vulnerability Assessment, Configuration Review
New York, New York, United States · Checked Sept 2026

Creators of OSCP, Kali Linux, and Exploit-DB, offering penetration testing services from the team that trains the world's ethical hackers.

Accreditations: OSCP Employer
Services: Web Application, Network, Red Teaming, Social Engineering +4
Zurich, Switzerland · Checked Sept 2026

Swiss cybersecurity firm with major Singapore operation. CREST accredited, CSA-licensed in Singapore. Manual exploitation focus with the proprietary MAD reporting platform.

Accreditations: CREST, ISO 27001
Services: Web Application, Network, Mobile App, Cloud +4
Paris, France · Checked May 2026

Airbus group cybersecurity consultancy with ANSSI PASSI qualification. Aerospace, defence, and critical infrastructure penetration testing across Europe.

Accreditations: ANSSI PASSI, ISO 27001, Cyber Essentials
Services: Web Application, Network, Cloud, IoT +8

OSSTMM FAQs

What makes OSSTMM different from other methodologies?+

OSSTMM uniquely focuses on measuring security quantitatively through its RAV scoring system, rather than simply finding vulnerabilities. It also covers physical and human security channels alongside technical testing.

Is OSSTMM free to use?+

Yes, OSSTMM is available under a Creative Commons licence from ISECOM. The full methodology manual can be downloaded freely from their website.

What is the RAV score?+

The Risk Assessment Value (RAV) is OSSTMM's quantitative scoring system that measures the relationship between operational controls and the attack surface to produce a numerical security score, enabling objective comparison over time.

Other Methodologies