Payment and Payout Platform Penetration Testing
CREST-accredited penetration testing for the platforms that move money: payment service providers, payment institutions, e-money firms, payment orchestration and payout or disbursement platforms, wallets and subscription billing engines. We test your ledger, your payout and disbursement path, the webhooks you send and receive, and the merchant or client dashboards built on top of it, not your merchant customers’ own checkout pages. Fixed quote in 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
roles at minimum make a genuine maker/checker control on a payout or payee change: one to propose it, a different one to approve it. We test whether that separation is enforced server-side, not just in the interface.
The Platform That Moves the Money Is In Scope, Not Just the Checkout That Calls It
What we test. Your ledger and internal balance logic, your payout and disbursement engine, the webhooks you send and receive, and the merchant or client dashboards, wallets and billing logic built on top of them. If you are a merchant testing your own cart, checkout page or hosted checkout integration into a provider, see our checkout and payment flow page instead. This page is for the platform underneath: payment service providers, payment institutions, e-money firms, and payment orchestration or payout and disbursement platforms.
Maker/checker and payout integrity. Whether a payee, bank account or disbursement schedule can change without your maker/checker or dual-authorisation control catching it, whether a payout can be redirected to an account nobody approved, and whether refund amount, recipient or approval state can be tampered with once money has left the ledger.
PCI DSS and operational resilience. Where you store, process or transmit cardholder data as a service provider, PCI DSS Requirement 11.4.6 requires segmentation testing at least every 6 months where segmentation isolates the cardholder data environment, alongside the wider Requirement 11.4 testing schedule; see our PCI DSS penetration testing page. The FCA does not prescribe penetration testing, but operational resilience rules call for in-scope firms to identify important business services, set impact tolerances and test severe but plausible disruption scenarios; penetration testing can identify exploitable weaknesses in the systems supporting those services and inform that scenario testing. Where DORA applies, Article 26 requires threat-led penetration testing at least every 3 years for financial entities identified by their competent authority, not annually and not for every firm.
Who we test for. Payment service providers, payment institutions and e-money firms, payment orchestration and payout or disbursement platforms, wallet and stored-value providers, subscription billing engines and loyalty or rewards platforms. See our fintech and financial services pages for the wider regulatory picture.
SCOPE
What We Test on a Payment or Payout Platform
Ledger Integrity & Balance Consistency
Double-entry ledger integrity across deposits, disbursements and internal transfers, balance consistency and race conditions under concurrent requests, and reconciliation between your ledger and the bank, card network or rail you settle through.
Payment Orchestration, Payouts & Payee Changes
Merchant acquiring, payment orchestration and disbursement runs. Whether a payee, bank account or payout schedule can change without your maker/checker or dual-authorisation control catching it, and whether a payout can be redirected once it leaves the approval workflow.
Webhook Authenticity & Replay
Signature verification, origin validation, replay protection and event ordering for the webhooks your platform sends and receives, so a forged or replayed event cannot move money or change state twice.
Wallet & Stored-Value Balances
E-money accounts, gaming wallets and credit balances. Top-up, transfer and cash-out flows, and whether cash-out authority can be exercised by a role that should only be able to view a balance.
Subscription Billing & Entitlements
Plan changes, proration, renewal and cancellation logic, trial-to-paid conversion, credit and refund balances, and whether an entitlement survives a downgrade or a cancellation it should not.
Loyalty, Gift Cards & Points
Points wallets, gift cards and vouchers. Balance manipulation, double redemption of the same code, and transfer or referral mechanics that mint value nobody actually earned.
Merchant Dashboard & Segregation
Multi-merchant consoles and dashboards. Merchant-to-merchant segregation, chargeback and dispute workflows, refund authorisation, and changes to a merchant’s own payout bank account. See our online marketplace page for the seller-payout angle.
Consent, Tokens & Sandbox Boundaries
Consent scope and expiry for open banking connections and third-party tokens, isolation between the merchants or clients sharing your platform, and whether sandbox credentials, test rails or staging data can reach production.
OUR PROCESS
From Scope to Attestation in 4-6 Weeks
Scoping Call
30-minute call to map your payment flows, ledger and payout paths, plus which providers, rails or processors sit in scope. Fixed-price quote within 24 hours.
Test Environment
You provide a staging or sandbox environment with test rails, sandbox credentials and representative merchant or tenant accounts for each integration in scope.
Active Testing
3-15 days of hands-on testing by CREST-certified pen testers, covering the ledger, the payout path, webhooks and the dashboards built on top of them. Live findings in your client portal.
Report & Retest
CVSS-scored report with reproduction steps for every finding, walkthrough call, free retest and a letter of attestation.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST payment and payout platform pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Aligned to Every Framework
Findings map to specific control references in each framework, so your audit team submits the report directly without translation work.
PCI DSS 11.4
Documented methodology, internal and external penetration testing at least annually, and, where segmentation isolates the cardholder data environment, segmentation testing every 6 months for service providers (11.4.6).
PCI DSS 11.6.1
Weekly detection of unauthorised changes to payment-page scripts and content, where in scope.
UK GDPR
Article 32(1)(d) evidence that you regularly test the effectiveness of your security measures.
ISO 27001
Annex A 8.8 technical vulnerability management, once you declare that control applicable.
Operational Resilience
Evidence for FCA and PRA work on important business services and severe-but-plausible scenario testing, where you are in scope.
DORA
Threat-led penetration testing (TLPT) at least every 3 years, for financial entities identified by their competent authority under Article 26.
PRICING
Transparent Payment and Payout Platform Pen Testing Pricing
Pricing depends on the number of rails, processors and payout paths in scope, plus ledger and wallet complexity. The day count flexes; the included deliverables stay the same across all engagements.
Depends on app complexity
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quoteDepends on app complexity
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quoteDepends on app complexity
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteWHY EJN LABS
What You Get From Payment and Payout Platform Penetration Testing
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What’s the difference between testing our platform and testing a merchant’s checkout?
We test the platform that moves the money: your ledger, payout and disbursement engine, webhooks, merchant or client dashboards, wallets and billing logic. Testing a single merchant’s cart, checkout page or hosted checkout integration into a provider is a different, narrower engagement. See our checkout and payment flow page for that scope.
What counts as a payment or payout platform for this test?
Any platform that moves money on behalf of others: a payment service provider, a payment institution or e-money firm, a payment orchestration layer that routes across acquirers, a payout or disbursement engine, a wallet or stored-value platform, or a subscription billing engine. If your platform holds a ledger and can move funds or credits between accounts, it is in scope.
Do you test our integrations with Stripe, Adyen or GoCardless?
Yes, from your side of the integration. We test how your platform authenticates to each processor, handles the webhooks and callbacks it receives, reconciles its own ledger against theirs, and fails over between rails. We do not test the processor’s own infrastructure, that sits inside its own security programme. See our Stripe, Adyen and GoCardless pages.
Can you test our open banking or third-party token integrations?
Yes. We test consent scope and expiry for open banking connections, how third-party tokens are issued, refreshed and revoked, and whether a token or consent from one customer can be used to reach another customer’s data or funds. See our open banking API page.
Can you test our wallet or points balance before a gaming or loyalty launch?
Yes. For a wallet, points or gift-card balance we test top-up, transfer, cash-out and redemption logic, including whether the same code or voucher can be redeemed twice and whether a balance can go negative or be created from nothing under concurrent requests.
How do you test maker/checker controls on payouts?
We attempt to change a payee, bank account or disbursement amount using an account that should only be able to propose the change, not approve it, and check whether the approval step is enforced server-side rather than only in the interface. We also test whether a payout can be redirected once it has left the approval workflow.
Does PCI DSS apply to our platform as a service provider?
If you store, process or transmit cardholder data on behalf of merchants, PCI DSS classes you as a service provider, which brings segmentation testing at least every 6 months where you use segmentation to isolate cardholder data (Requirement 11.4.6), alongside the standard annual penetration testing schedule. Your QSA or acquiring bank confirms your exact scope. See our PCI DSS penetration testing page.
What’s in the report?
Executive summary (board-ready), technical report with CVSS 3.1 scores, reproduction steps, screenshots, specific remediation guidance, and a 60-minute walkthrough call. Letter of attestation issued after free retest.
Do you sign NDAs?
Yes. We sign client-supplied NDAs as standard. Engagement data is protected under our ISO 27001 (BSI-audited) information security management system.
How quickly can you start?
From signed scope to active testing in 24 hours where required. Standard pipeline is 3-5 business days from initial scoping call to test start.
Are your testers UK-based and what certifications do they hold?
Every engagement is performed by vetted UK-based CREST-certified testers matched to your engagement based on security clearance, compliance scope, and sector specialism. Testers hold CREST certifications relevant to their discipline (CRT, CCT APP, CCT INF, CCSAM).
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get my payment and payout platform pen test scope
Tell us which providers, rails and payout paths you run, and how your ledger and dashboards are built. A CREST-certified pen tester will contact you within one business day with a fixed price.



