Skip to content
continuouspentest

A vendor-neutral reference on continuous penetration testing and what a subscription has to deliver before it counts.

Scope a program→
DefinitionWhy cadenceBoundariesObligationsCadence designerGuides
Home

About continuouspentest.org

Updated 13 September 2026

continuouspentest.org covers one narrow subject: penetration testing delivered on a repeating rhythm rather than as a single dated engagement, and the question of whether that is worth buying. The topic is dominated by vendor material, so the provenance of anything written about it is worth stating plainly.

Publisher

The site is published by SEQ SIA (reg. No. 40203410806), Lastādijas iela 12 k-3, Riga, LV-1050, Latvia, trading as OffSeq, a provider of penetration testing and security assessment services. Contact: support@offseq.com.

The site is not affiliated with NIST, CREST, OWASP, the PCI Security Standards Council, ISO, IEC, the UK National Cyber Security Centre, CISA, ENISA or any EU institution. Nothing here is an official interpretation of any standard, directive or regulation.

Authorship

SEQ SIA (OffSeq) is responsible for publishing, maintaining and updating this site. Articles carry team attribution rather than a personal byline. Every guide lists its sources so a reader can check the basis for each statement.

How the guidance is sourced

  • Regulatory statements cite the instrument itself: Directive (EU) 2022/2555, Commission Implementing Regulation (EU) 2024/2690 and Regulation (EU) 2022/2554, read on EUR-Lex.
  • PCI DSS requirement text is quoted from PCI Security Standards Council documents that reproduce it verbatim and are published without a license gate, because the standard itself is licensed.
  • ISO/IEC 27001 controls are referenced by number and title only. The control text is copyrighted and is not reproduced here.
  • Where a claim could not be verified against a primary source, it is left out. In particular, this site makes no claim that any analyst firm recognizes “PTaaS” as a defined market, because that could not be checked.
  • Engagement descriptions are generalized from real work and never identify a client, an environment or an unremediated finding.
  • The “Updated” date only moves when the text changes. An automated content-hash ledger reverts unearned date bumps.

Commercial interest

We sell the kind of testing this site describes. That is a direct interest in you concluding that you need it, and it should color how you read every recommendation here.

  • Links to OffSeq are our own service links, not a market comparison. We do not rank or score competing providers.
  • No vendor, platform or testing tool pays for a mention. There is no advertising and no affiliate revenue.
  • The cadence designer on the home page is built to return “you do not need this” for profiles that do not warrant a subscription, and the guides say the same in prose. If that reads as against our interest, it is.

Not advice

This site is not legal, audit or supervisory advice on what your organization must do. Testing obligations depend on your sector, your assessed scope and your own risk assessment. Confirm your position with your auditor, your QSA or your competent authority.

Corrections

If something here is wrong, send it to support@offseq.com with the source. Substantive changes are made and re-dated in the open.

continuouspentest

continuouspentest.org explains continuous penetration testing in plain terms: what the label does and does not guarantee, which obligations require retesting after significant change, and how to tell a real program from a scanner subscription.

Guides

  • What continuous testing is
  • Testing vs scanning vs bounty
  • Testing after change
  • Evidence for auditors

Professional help

  • Attack surface management
  • Security testing in DevSecOps
  • Scope a program
  • Talk to OffSeq

Information

  • About
  • Privacy policy
  • Cookies

continuouspentest.org is a free educational resource maintained by the OffSeq security team.

© 2026 · Operated by SEQ SIA · Riga, Latvia