Learning Management System (LMS) Penetration Testing
CREST-accredited penetration testing for learning management systems, online course platforms and training portals. We test the boundaries between learner, instructor and admin accounts, assessment and grading integrity, and who can reach course content and coursework submissions. Fixed quote in 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
test accounts is the minimum we ask for: one learner, one instructor and one admin. Without all three, role boundaries and assessment integrity cannot be tested.
Role Boundaries and Assessment Integrity Are What LMS Testing Is For
What role boundaries mean. An LMS separates learners, instructors and administrators, and often separates instructors from each other by course or cohort. We test whether a learner account can reach another learner’s submissions or grades, whether an instructor can see or edit a course they do not own, and whether an admin function can be reached from a lower-privileged account through the interface or the API.
Assessment integrity. We test quiz timers and attempt limits, question bank exposure before a test opens, autograding logic, grade change trails, and whether a submission or exam session can be tampered with once it has started.
Content access and children’s data. Enrolment keys, guest access, unpublished courses and cross-cohort content leakage are common gaps. Where the LMS sits in a school or college, some records belong to under-18 learners and to parent or guardian logins where they exist, and that data needs extra care in how we scope and handle it during testing.
Who we test for. Schools and multi-academy trusts, colleges, universities, and corporate training providers and edtech vendors building their own LMS or course platform. See our education penetration testing page for the wider sector picture, and our Moodle, Canvas and Blackboard pages if you already know which platform you run.
SCOPE
What We Test in a Learning Management System
Every path a learner, instructor or admin can reach, across the browser, the API and any integrated tools.
Learner, Instructor & Admin Boundaries
Crossing every role: can a learner reach another learner’s work, can an instructor act outside their own course, can an admin function be reached from a lower-privileged account or the API.
Assessment & Grade Integrity
Quiz timers and attempt limits, question bank exposure, autograding logic, and whether grades or grade-change trails can be altered outside the intended workflow.
Exam & Remote Assessment Sessions
Session controls for timed or remote exams, including whether a submission or exam window can be extended, restarted or tampered with once it has started.
Enrolment, Courses & Content Access
Enrolment keys, guest and self-enrol paths, unpublished courses, and cross-cohort or cross-school content leakage in multi-school and multi-academy trust deployments.
SSO & School or Trust Identity
Login through a school or trust identity provider, SAML and OIDC flows, provisioning from the MIS, and account linking across multiple schools sharing one LMS instance.
LTI & Third-Party Tool Integrations
Learning Tools Interoperability launches and other embedded tools, including whether a launch can be replayed, forged, or used to reach a course or role the tool was not scoped for.
OUR PROCESS
From Scope to Attestation in 4-6 Weeks
Scoping Call
30-minute call to map learner, instructor and admin roles and which courses or cohorts are in scope. Fixed-price quote within 24 hours.
Test Accounts
You provide at least one learner, one instructor and one admin account in a staging environment, plus any LTI or SSO integrations in scope.
Active Testing
3-10 days of hands-on testing by CREST-certified pen testers, crossing role, course and assessment boundaries. Live findings in your client portal.
Report & Retest
CVSS-scored report with reproduction steps, a walkthrough call, free retest and a letter of attestation for your trust, auditor or procurement team.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST LMS penetration test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Aligned to Every Framework
Findings map to specific control references in each framework, so your DPO, trust or auditor can use the report directly without translation work.
DfE Digital and Technology Standards
Evidence for the annual cyber risk assessment under the cyber security core standard, which schools and colleges should be working towards by 2030. A test is evidence for the assessment, not a substitute for it.
UK GDPR Article 32(1)(d)
Evidence that you regularly test the effectiveness of technical security measures protecting learner, parent/guardian and staff data.
Cyber Essentials
A funding-agreement requirement for colleges; some schools choose to complete it too as part of their wider cyber security activity. A separate self-assessment from a penetration test.
ISO 27001 Annex A 8.8
Technical vulnerability management evidence for edtech vendors and course platform providers, once you declare the control applicable.
SOC 2
Evidence for the evaluations your auditor reviews under CC4.1, for LMS and course platform vendors selling into education and enterprise procurement.
MAT and Trust Procurement
An independent report to attach to multi-academy trust, college and university procurement and supplier assurance questionnaires.
PRICING
Transparent LMS Penetration Testing Pricing
Pricing depends on the number of roles, courses, integrations such as SSO or LTI, and whether coursework or exam data is in scope. The day count flexes; the included deliverables stay the same across all engagements.
Depends on app complexity
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quoteDepends on app complexity
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quoteDepends on app complexity
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteWHY EJN LABS
What You Get From LMS Penetration Testing
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What is LMS penetration testing?
Testing whether a learner, instructor or admin account can do more than its role allows: reading another learner’s grades or submissions, editing a course it does not own, or reaching admin functions through the interface or the API.
Do you test Moodle, Canvas or Blackboard?
Yes. See our dedicated Moodle, Canvas and Blackboard pages for platform-specific scope, or use this page if you run a custom or different LMS.
Can you test assessment and grading integrity?
Yes. Quiz timers, attempt limits, question bank exposure, autograding logic and grade change trails are part of the standard test, alongside the role boundaries around them.
We run one LMS across several schools in our trust, can you test that?
Yes. Multi-school and multi-academy trust deployments are one of the boundaries we test: whether staff or learners from one school can reach another school’s courses, cohorts or records through the shared instance.
Do you test single sign-on from our school or trust identity provider?
Yes. SAML and OIDC logins from a school MIS or trust identity provider, provisioning and account linking are covered. See our SSO and identity testing page.
What do you need from us to scope an LMS test?
Staging access with at least one learner, one instructor and one admin account, details of any LTI or third-party tool integrations, and a note of which courses or cohorts hold live coursework or exam data.
Can a penetration test satisfy our DfE cyber security standard evidence?
A test is evidence for your annual cyber risk assessment under the DfE core standard, not a replacement for it. It cannot substitute for Cyber Essentials either, which is a separate self-assessment and a funding-agreement requirement for colleges. See our cyber security audit for schools page if you need the wider school estate assessed alongside the LMS.
What’s in the report?
Executive summary (board-ready), technical report with CVSS 3.1 scores, reproduction steps, screenshots, specific remediation guidance, and a 60-minute walkthrough call. Letter of attestation issued after free retest.
Do you sign NDAs?
Yes. We sign client-supplied NDAs as standard. Engagement data is protected under our ISO 27001 (BSI-audited) information security management system.
How quickly can you start?
From signed scope to active testing in 24 hours where required. Standard pipeline is 3-5 business days from initial scoping call to test start.
Are your testers UK-based and what certifications do they hold?
Every engagement is performed by vetted UK-based CREST-certified testers matched to your engagement based on security clearance, compliance scope, and sector specialism. Testers hold CREST certifications relevant to their discipline (CRT, CCT APP, CCT INF, CCSAM).
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get my LMS pen test scope
Tell us which LMS you run, how many roles and courses are in scope, and any SSO or LTI integrations. A CREST-certified pen tester will contact you within one business day with a fixed price.



