Penetration Testing for South Carolina Companies
Penetration testing in South Carolina is an authorized attack on your applications, cloud and networks, performed by OSCP-certified testers to show which weaknesses an attacker can exploit. Budget Security delivers it remotely to companies in Charleston, Greenville, Columbia and across the state, scoped online in tester-days, started within 7 days of booking, and reported through a dashboard built for audits.
The rate is public: $985 per tester-day for US clients (€849 per day for EU clients). Price your scope in the calculator, book online, and pay after the report is delivered.
What we test for South Carolina companies
Scope is set online, in tester-days. You register the asset, choose the goal (a full pentest, a single login flow, SOC 2 readiness, an insurance-regulator file, CMMC evidence) and the number of days. The platform proposes the plan and tells you what a shorter scope would leave out, so the trade-off is visible before you commit.
Coverage:
- Web application penetration testing: customer portals, claims systems, admin consoles.
- API penetration testing: the integrations between your product, your partners and your carriers.
- Cloud penetration testing: identity, permissions and exposed services in your cloud accounts.
- External and internal network penetration testing: the perimeter, then what an attacker can reach once inside.
- Mobile penetration testing: iOS and Android apps and their back ends.
- Penetration testing as a service: recurring testing for teams that ship continuously.
Every engagement is manual and led by OSCP-certified testers. Most South Carolina engagements run 3 to 5 tester-days.
The SC Insurance Data Security Act: "regularly test and monitor" and the 15 February certification
South Carolina was the first state to adopt the NAIC Insurance Data Security Model Law, as S.C. Code 38-99-10 to 38-99-100, in 2018. It applies to licensees: anyone licensed or required to be licensed under South Carolina insurance law, which takes in carriers, agencies, brokers and third-party administrators. Licensees with fewer than ten employees are exempt, as are HIPAA-compliant insurers that document it.
Does it require a penetration test? Not by name. The words "penetration testing" do not appear in section 38-99-20. What it does require is a risk assessment that will "identify reasonably foreseeable internal or external threats", security measures that include "regularly testing and monitoring systems and procedures to detect actual and attempted attacks on, or intrusions into, information systems" (subsection D(2)(h)), and a duty to "at least annually assess the effectiveness of the safeguards' key controls, systems, and procedures" (subsection C(5)). There is no fixed annual-pentest clause like the one in New York's DFS rules.
Three deadlines make it concrete:
- Every year: executive management reports to the board in writing on the information security program.
- 15 February: domestic insurers submit a written statement certifying compliance for the prior year.
- 72 hours: the window to notify the Director of Insurance after determining that a cybersecurity event has occurred.
A scoped annual pentest is the simplest way to satisfy the testing clause, document the annual assessment of your key controls, and have dated evidence in the file before 15 February. For agencies that also face SOC 2 requests from carriers, one test covers both: SOC 2 penetration testing.
CMMC for Charleston and the Upstate
The Lowcountry is a defense economy. NIWC Atlantic in North Charleston employs almost 8,000 people and carries a $2.1 billion economic impact, with Joint Base Charleston and the Charleston Defense Contractors Association around it. Boeing builds the 787 in North Charleston and announced a $1 billion site expansion in 2025. In the Upstate, BMW's Greer plant has 11,000 employees and is the state's largest industrial employer. Its supplier base increasingly overlaps with aerospace and defense work, from Eaton's $46 million aerospace expansion to ATI's titanium operation in Chesterfield County.
If you hold Controlled Unclassified Information on any of those programs, CMMC applies to you. 32 CFR Part 170 took effect on 16 December 2024 and the DFARS rule began Phase 1 on 10 November 2025, so the requirement now appears in contract clauses, not just guidance.
Level 2 follows NIST SP 800-171 and does not mandate a penetration test by name. It does require vulnerability scanning every 90 days and evidence that controls are effective. Level 3 requires an annual penetration test. Suppliers at either level use a pentest to prove the 800-171 controls hold under a real attack, which is what the assessor wants to see. Framework detail: CMMC penetration testing and NIST penetration testing.
Healthcare after the 2025 South Carolina breach wave
The South Carolina Department of Consumer Affairs logged 99 reported breaches in 2025, affecting 2,985,506 residents. Healthcare carried much of the list. Sandhills Medical's ransomware incident reached more than 78,000 residents. HCIactive's mid-2025 breach exposed 103,000 residents, medical records included. School District Five of Lexington and Richland Counties lost data on 31,475 people to Interlock ransomware in June 2025. The largest single report of the year, 700Credit, affected 108,829 South Carolinians.
For clinics, health-tech vendors and benefit administrators, the federal rule is HIPAA 45 CFR 164.308(a)(8), which requires "a periodic technical and nontechnical evaluation". The clause does not say "penetration test", yet a pentest is the evidence HHS and your business-associate partners expect for it. The state overlay is 39-1-90, below. Together they mean a South Carolina healthcare organization that cannot show recent testing is exposed twice: to the breach itself, and to the question of what it did to prevent one. See HIPAA penetration testing.
S.C. Code 39-1-90: the $1,000-per-resident fine
S.C. Code 39-1-90 applies to "a person conducting business in this State, and owning or licensing computerized data or other data that includes personal identifying information". After a breach that exposes unencrypted data of residents, disclosure "must be made in the most expedient time possible and without unreasonable delay". Notify more than 1,000 people at once and you also notify the Consumer Protection Division of the Department of Consumer Affairs and the nationwide consumer reporting agencies.
The penalty clause is what sets South Carolina apart. A person who "knowingly and wilfully" violates the section is subject to "an administrative fine in the amount of one thousand dollars for each resident whose information was accessible by reason of the breach". The fine scales with the number of residents affected, not with the size of your company.
The statute does not order a penetration test. It makes the cost of not knowing your weaknesses very specific.
This page is not legal advice. Verify the statute text at scstatehouse.gov or ask counsel before relying on it.
Remote delivery from The Hague, on Eastern time
Budget Security has no office in South Carolina. Testing is done remotely by our team in The Hague, Netherlands, during hours that overlap US Eastern time. Kick-off, daily check-ins and the debrief happen inside your business day.
That is how most penetration testing is delivered, by local firms as well. Applications, APIs, cloud accounts and internet-facing networks are tested over the internet, from the same position an attacker holds. Internal network segments are tested through a VPN or a virtual machine you place inside the network. A tester in Charleston or Greenville sees exactly what a tester in The Hague sees.
What replaces the site visit is the platform:
- Online scoping with live trade-offs. Add a day and see what gets deeper coverage. Remove one and see what drops out, and whether the scope still meets your compliance goal.
- A dashboard instead of a PDF over email. Findings, evidence, status, retests and your history across engagements, in one place your security lead or compliance officer can open any time.
- Self-serve changes. Extend scope, add an asset or request a retest without a new sales conversation.
- OSCP-certified testers. Senior people, manual work, the same caliber as a premium consultancy with the overhead removed.
Timeline, report and payment
Start: up to 7 days from booking. A faster start depends on tester availability and is not guaranteed. An urgency fee can apply. - Rescheduling: not free once a date is confirmed. The tester-days are held for you. - Report: in your dashboard within 48 hours after the test ends, with severity, reproduction steps and fix guidance per finding. Retests of fixed findings run from the dashboard. - Payment: after the report is delivered. Nothing is charged at booking. - Rate: $985 per tester-day for US clients (€849 per day for EU clients). The calculator shows your total before you sign up.
FAQ
Questions we get
What does a penetration test cost in South Carolina?
Does the South Carolina Insurance Data Security Act require a penetration test?
Do you have an office in Charleston, Greenville or Columbia?
How quickly can the test start?
I am a CMMC Level 2 supplier. Do I need a penetration test?
Can the report go into my regulator or auditor file?
When do I pay?
Which parts of South Carolina do you cover?
Scope your South Carolina pentest in minutes.
Register your assets, pick the goal, set the days. Published rate: $985 per tester-day for US clients (€849 per day for EU clients). Start within 7 days of booking, report within 48 hours after the test ends, pay after delivery.