Kentico Penetration Testing
A Kentico page is readable once a user clears just one of three merged permission levels. We test roles, page-type rules and individual page ACLs against what each account can actually reach. CREST-certified testers, fixed price from £3,380 for a 3-day single-instance scope, quoted within 24 hours.
- Unlimited retesting
- Unlimited pre-retesting
- No hidden fees
“I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.”
“There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.”
Kentico checks page access across three separate permission levels, roles applied to all content, roles applied to one page type, and ACLs applied to an individual page, and merges the results rather than requiring every level to agree. We test which level is actually granting the access a user has.
Why a Kentico page can be reachable through any one of three permission levels
Kentico’s own page permissions documentation sets out three levels: permissions for all content, permissions for a specific page type, and page-level ACLs granted to roles or individual users. A user only has to clear one of the three to read a page, so a broad grant at one level can quietly override a narrower restriction set at another. We test which level is actually deciding access on the pages your team believes are restricted.
Roles control what a signed-in user can reach inside the Xperience administration interface, and custom modules or .NET code a development team has added run inside that same application, with the same access to its database and configuration. We test what an editor, marketer or administrator account can actually do once signed in, and what a custom module does with the access it inherits.
Xperience by Kentico’s headless channels are read through a content delivery API, and a request has to authenticate with an API key sent as an HTTP header, where the key’s access type is fixed once the key is created and the key itself is never shown again after that. We test how those keys are distributed and scoped, and whether the authorisation they imply is enforced consistently across every headless endpoint in scope.
SCOPE
What we pen test on a Kentico instance
Three-Level Page Permission Merge
Xperience checks page access across three separate permission levels, roles applied to all content, roles applied to one page type, and ACLs applied to an individual page or section, and merges the results rather than requiring every level to agree. We test which level is actually granting access on a page your team believes is restricted.
Administration Interface Access
The Xperience administration interface sits behind a sign-in page reached from the site’s own domain, and its applications are grouped by function once a user is authenticated. We test what an authenticated editor account can reach across those applications against what your business intends that role to see.
Editor and Role Assignment
Roles determine which applications and content a signed-in user can reach inside the administration interface, and a role granted more broadly than intended gives that access to everyone assigned to it. We test whether editor, marketer and administrator roles map to the access your business actually wants each one to have.
Custom Modules and .NET Code
Custom modules and .NET code a development team has added to Kentico run inside the same application as the CMS itself, with the same access to its database and configuration. We test what a custom module actually does with that access, not only the pages and forms Kentico ships by default.
Form Submission Data Access
Submitted form data can be exported with every field the form collects, filtered by the current search term, and the export includes every matching submission rather than only the ones currently displayed. We test who can reach that export and whether a form collecting sensitive data restricts it to the role that needs it.
Headless Channel API Keys
A headless channel’s API key is generated with a fixed access type that cannot be changed after creation, and the key itself is never stored or shown again once the creation dialog is closed. We test how those keys are distributed, stored and scoped once issued, and what a leaked key would actually expose.
Content Delivery API Authorisation
Every request that retrieves headless content has to authenticate with an API key sent as an HTTP header, so the header’s presence and the key’s access type are what decide what content a request can reach. We test whether that authorisation is enforced consistently across every headless endpoint in scope.
Xperience 13 vs Xperience by Kentico
Kentico Xperience 13 is the established self-hosted product, and Kentico’s own documentation confirms it stops receiving hotfixes and Refreshes after 31 December 2026, in favour of Xperience by Kentico, the newer SaaS platform. We confirm during scoping which product and version you run, since the admin, permission and API detail differs between them.
SaaS vs Self-Hosted Deployment
Xperience by Kentico is delivered as a SaaS platform built on Azure components, with Kentico operating the hosting and infrastructure, while Kentico Xperience 13 is a .NET application your own team installs and hosts. We test the application layer either way; infrastructure-level configuration on a self-hosted Xperience 13 instance is scoped separately.
.NET Surface Beyond Kentico
Where a Kentico site’s authentication, custom module or integration code sits in a broader .NET application beyond Kentico’s own admin and content layer, our wider .NET penetration testing covers that layer alongside the Kentico-specific testing described here.
OUR PROCESS
Kentico Penetration Testing: From Scope to Attestation
Scope and Access
We agree the URLs, environments and role-based accounts we need, and confirm whether you run Xperience by Kentico or Kentico Xperience 13, self-hosted or SaaS.
Permission and Configuration Mapping
We map the three-level page permission merge or Xperience by Kentico’s role model, every custom module in scope, and how headless channel API keys are issued and scoped.
Manual Testing
A CREST-certified tester manually exploits permission-level gaps, custom module access, form data exposure and headless API authorisation, chaining findings where they compound.
Attestation and Retest
You get a technical report with CVSS scores and reproduction steps, a walkthrough call, a free retest once fixes are deployed, and an attestation letter for auditors.
CREDENTIALS
Verified Accreditations Auditors Accept
Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.
GET YOUR QUOTE
Get a CREST Kentico pen test quote in 24 hours
A fixed-price quote back in one business day, from a named CREST assessor. No sales pipeline, no chasing.
- CREST and IASME accredited. Testing your auditors and clients already recognise.
- Fast-track testing within 24 hours where required. Free retest of every fix included.
- Live findings via your client portal, not a four-week PDF.
- Fixed price from £3,500 for a single-role, single-app scope, agreed up front. Most engagements run £5,000 and up. No day-rate surprises.
Under NDA Further named references available on a scoping call.
- We reply within one business day with a fixed-price quote from a named CREST assessor.
- You approve the scope and we book a start date, usually within 24 hours.
- Live findings land in your client portal as we test, with a free retest of every fix.
Get your fixed pen test quote in 24 hours
Quote request received
We will reply within one business day with your fixed-price quote from a named CREST assessor.
Your data stays with us. No newsletter signup.
or book a 20-min scoping call first
We reply within one business day. Your data stays with us. No newsletter signup.
COMPLIANCE READY
Reports Mapped to Every Framework
Findings are written so your team can reference the report against each framework without translation work.
ISO 27001:2022
Annex A.8.8 management of technical vulnerabilities plus A.5.15-5.18 and A.8.2-8.5 access control validation.
SOC 2 Type I & II
CC6 logical access, CC7 system operations, CC8 change management evidence.
PCI DSS
Requirement 11.4 application penetration testing across cardholder data environments, including ecommerce penetration testing for online retail platforms.
FCA SYSC
SYSC 4.1.1R, 6.1.1R, 13 mapped to each finding for FCA-regulated firms.
UK GDPR
Article 32 effectiveness testing, customer-data security controls, ICO-acceptable evidence.
Cyber Essentials Plus
Direct certification through our IASME body status, single-vendor delivery.
PRICING
Transparent Kentico Penetration Testing Pricing
Pricing depends on the number of roles, integrations and environments in scope. See our pricing page for how we quote.
3 to 4 testing days
Single user role, basic CRUD application, marketing website with auth. Around 5 working days from kickoff to report.
Get a fixed quote4 to 6 testing days
Multi-role SaaS, business application with payment integration. Around 8 to 12 working days from kickoff to report.
Get a fixed quote6 to 8 testing days
Multi-tenant platform, complex authorisation matrix, integration-heavy applications. Around 15 to 20 working days from kickoff to report.
Get a fixed quoteSECTORS
Sectors We Test Kentico For
Sector-specific scoping for regulated UK organisations.
Fintech & FCA-Regulated
FCA SYSC, Open Banking FAPI 1.0, PSD2 SCA, payment-flow scrutiny, KYC/AML testing.
Fintech sector pageSaaS Companies
SOC 2 Type I & II evidence, multi-tenant boundaries, role escalation, customer-tenant isolation.
SaaS sector pageLaw Firms
SRA Cyber Standard, privileged data, conveyancing fraud defence, partner-tier procurement.
Law firm sector pageHealthcare
NHS DTAC, DSP Toolkit v6, UK GDPR Article 32, EHR systems, telehealth platforms.
Healthcare sector pageInsurance
FCA / PRA Operational Resilience, cyber underwriting, claims data, broker portals.
Insurance sector pagePublic Sector
CCS / G-Cloud framework, NCSC-aligned, citizen-facing services, PSN-compliance scrutiny.
Public sector pageWHY EJN LABS
What You Get From Kentico Penetration Testing
Six concrete differentiators competitors don’t all match.
CREST-Certified Testers, Verifiable
Every test by a CREST-certified pen tester (CRT, CCT APP, CCT INF where applicable). Verify our company status at crest-approved.org.
24-Hour Startup, Where Required
From signed scope to active testing in a single business day for incident response, audit deadlines, or regulator-driven timelines.
Live Findings, Not 4-Week PDFs
Critical issues reported during testing through your client portal. Your team remediates while testing continues.
Audit-Ready Reports
Executive summary plus full technical report with CVSS scores and explicit framework mappings (ISO 27001, SOC 2, PCI DSS, FCA SYSC).
Free Retests, Standard
Verify remediation of every finding before close-out. Letter of attestation for audit submission included. Most competitors charge £1,500-£3,000 per retest.
UK-Based CREST Testers
Every engagement performed by vetted, UK-based CREST-certified testers, matched to your needs, security clearance, and compliance scope.
FAQ
Frequently Asked
What access do you need to test our Kentico instance?
We need an account for every distinct role your administration interface defines, such as editor, marketer and administrator, plus a headless channel API key if that content delivery API is in scope.
Will testing touch our live data?
We test whichever environment you give us access to. If that is production, we agree exclusions upfront, such as bulk deletes and any outbound emails your site would normally trigger, and we do not run destructive tests against real customer records without that agreement in writing.
How long does a Kentico penetration test take?
A single Kentico instance sits in our 3-day single-instance scope, with a report typically landing around 6 to 8 working days after kickoff. An instance with several custom modules, a large role matrix or a heavily used headless API moves into a wider scope with more testing days.
Do you test Xperience by Kentico and Kentico Xperience 13 the same way?
The core permission and role testing is the same, but where the risk sits differs: Xperience by Kentico’s headless API keys and SaaS administration are specific to that product, while Kentico Xperience 13’s three-level page permission merge is specific to the self-hosted product. We confirm which one you run during scoping.
What is out of scope for a single-instance Kentico test?
Kentico’s own SaaS hosting and infrastructure for Xperience by Kentico is out of scope, since Kentico operates it rather than you. Infrastructure-level configuration on a self-hosted Xperience 13 server, such as the underlying network or cloud account, is also out of scope and covered by our cloud penetration testing service instead.
Do you need our source code?
No. Testing is black-box against the running administration interface and content delivery API by default. A grey-box option, where we review the relevant custom modules, role configuration and API key scoping alongside testing, is available if you want faster or deeper coverage of specific findings.
Does Kentico have a customer penetration-testing policy we need to follow?
A self-hosted Kentico Xperience 13 instance is yours to test as you choose, since you install and control the server yourself. For Xperience by Kentico’s SaaS environment, Kentico operates the underlying hosting and infrastructure, so we confirm Kentico’s current testing terms with you during scoping before testing begins.
20+ CREST-accredited testing services in one place
Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.
Get a fixed price for your Kentico instance
A Kentico page is readable once a user clears just one of three merged permission levels. We test roles, page-type rules and individual page ACLs against what each account can actually reach. CREST-certified testers, fixed price from £3,380 for a 3-day single-instance scope, quoted within 24 hours.



