What's the difference between Silver, Gold, and Diamond?+
The three EHT tiers differ in methodology depth, retest coverage, and engagement duration. Silver delivers OWASP Top 10 testing with automated and manual techniques, one retest within 30 days, and 2–3 week delivery — ideal for startups and basic compliance needs. Gold adds OWASP ASVS Level 2 coverage, STRIDE threat modeling, and business logic analysis, with two retests across 90 days over a 3–4 week engagement. Diamond is the most comprehensive tier, with full OWASP ASVS Level 3, deep fraud detection, unlimited retests for six months, source-assisted review, and compliance mapping for PCI-DSS and ISO 27001.
Which tier should I choose?+
The right tier depends on your security maturity, compliance requirements, and the criticality of the system being tested. Startups and early-stage products with basic compliance obligations are usually served well by Silver. Mid-size companies with production systems handling customer data and moderate regulatory exposure typically choose Gold, which is our most popular tier. Financial institutions, enterprises, and organizations subject to strict regimes like PCI-DSS or ISO 27001 should choose Diamond for its depth and compliance mapping. If you are unsure, our consultants will assess your environment and recommend the right tier at no cost.
Do you offer retests?+
Yes. Retesting is included in every EHT tier so you can verify that remediation actually closed the findings. Silver includes one retest within 30 days of the initial report. Gold includes two retests within 90 days, giving teams more time to fix and validate. Diamond offers unlimited retests for six months, recognizing that enterprise and financial environments often require iterative fixes across multiple teams and change windows. Retests are conducted using the same methodology as the initial engagement, and we update the final report to reflect the current state of each finding.
How long does a pentest engagement take?+
Engagement length varies by tier and scope. A Silver test typically runs for 2–3 weeks from kickoff to final report, including reconnaissance, testing, reporting, and debrief. Gold takes 3–4 weeks due to deeper methodology and threat modeling. Diamond runs for 4–6 weeks, covering full OWASP ASVS Level 3 coverage, business logic and fraud testing, and source-assisted review. We also factor in a kickoff meeting to align on scope and rules of engagement, and a closing session to walk stakeholders through findings. Rush timelines can be accommodated when necessary and commercially reasonable.
Do you test mobile apps?+
Yes. Berghem tests mobile applications across Android and iOS as part of our EHT engagements, including native apps, hybrid apps, and mobile SDKs. We follow the OWASP MASVS and MASTG methodology, covering insecure data storage, insecure communication, authentication and session management, cryptography, code tampering, reverse engineering resistance, and runtime protections like SSL pinning and root or jailbreak detection. Mobile testing can be scoped standalone or as part of a broader engagement that also includes backend APIs and web admin panels, giving you coverage across the full mobile application stack.