Skip to main content
    PENETRATION TESTING/SOUTH CAROLINA
    ·By Budget Security

    Penetration Testing for South Carolina Companies

    Penetration testing in South Carolina is an authorized attack on your applications, cloud and networks, performed by OSCP-certified testers to show which weaknesses an attacker can exploit. Budget Security delivers it remotely to companies in Charleston, Greenville, Columbia and across the state, scoped online in tester-days, started within 7 days of booking, and reported through a dashboard built for audits.

    The rate is public: $985 per tester-day for US clients (€849 per day for EU clients). Price your scope in the calculator, book online, and pay after the report is delivered.

    Sign up · Try the calculator

    What we test for South Carolina companies

    Scope is set online, in tester-days. You register the asset, choose the goal (a full pentest, a single login flow, SOC 2 readiness, an insurance-regulator file, CMMC evidence) and the number of days. The platform proposes the plan and tells you what a shorter scope would leave out, so the trade-off is visible before you commit.

    Coverage:

    Every engagement is manual and led by OSCP-certified testers. Most South Carolina engagements run 3 to 5 tester-days.

    The SC Insurance Data Security Act: "regularly test and monitor" and the 15 February certification

    South Carolina was the first state to adopt the NAIC Insurance Data Security Model Law, as S.C. Code 38-99-10 to 38-99-100, in 2018. It applies to licensees: anyone licensed or required to be licensed under South Carolina insurance law, which takes in carriers, agencies, brokers and third-party administrators. Licensees with fewer than ten employees are exempt, as are HIPAA-compliant insurers that document it.

    Does it require a penetration test? Not by name. The words "penetration testing" do not appear in section 38-99-20. What it does require is a risk assessment that will "identify reasonably foreseeable internal or external threats", security measures that include "regularly testing and monitoring systems and procedures to detect actual and attempted attacks on, or intrusions into, information systems" (subsection D(2)(h)), and a duty to "at least annually assess the effectiveness of the safeguards' key controls, systems, and procedures" (subsection C(5)). There is no fixed annual-pentest clause like the one in New York's DFS rules.

    Three deadlines make it concrete:

    • Every year: executive management reports to the board in writing on the information security program.
    • 15 February: domestic insurers submit a written statement certifying compliance for the prior year.
    • 72 hours: the window to notify the Director of Insurance after determining that a cybersecurity event has occurred.

    A scoped annual pentest is the simplest way to satisfy the testing clause, document the annual assessment of your key controls, and have dated evidence in the file before 15 February. For agencies that also face SOC 2 requests from carriers, one test covers both: SOC 2 penetration testing.

    CMMC for Charleston and the Upstate

    The Lowcountry is a defense economy. NIWC Atlantic in North Charleston employs almost 8,000 people and carries a $2.1 billion economic impact, with Joint Base Charleston and the Charleston Defense Contractors Association around it. Boeing builds the 787 in North Charleston and announced a $1 billion site expansion in 2025. In the Upstate, BMW's Greer plant has 11,000 employees and is the state's largest industrial employer. Its supplier base increasingly overlaps with aerospace and defense work, from Eaton's $46 million aerospace expansion to ATI's titanium operation in Chesterfield County.

    If you hold Controlled Unclassified Information on any of those programs, CMMC applies to you. 32 CFR Part 170 took effect on 16 December 2024 and the DFARS rule began Phase 1 on 10 November 2025, so the requirement now appears in contract clauses, not just guidance.

    Level 2 follows NIST SP 800-171 and does not mandate a penetration test by name. It does require vulnerability scanning every 90 days and evidence that controls are effective. Level 3 requires an annual penetration test. Suppliers at either level use a pentest to prove the 800-171 controls hold under a real attack, which is what the assessor wants to see. Framework detail: CMMC penetration testing and NIST penetration testing.

    Healthcare after the 2025 South Carolina breach wave

    The South Carolina Department of Consumer Affairs logged 99 reported breaches in 2025, affecting 2,985,506 residents. Healthcare carried much of the list. Sandhills Medical's ransomware incident reached more than 78,000 residents. HCIactive's mid-2025 breach exposed 103,000 residents, medical records included. School District Five of Lexington and Richland Counties lost data on 31,475 people to Interlock ransomware in June 2025. The largest single report of the year, 700Credit, affected 108,829 South Carolinians.

    For clinics, health-tech vendors and benefit administrators, the federal rule is HIPAA 45 CFR 164.308(a)(8), which requires "a periodic technical and nontechnical evaluation". The clause does not say "penetration test", yet a pentest is the evidence HHS and your business-associate partners expect for it. The state overlay is 39-1-90, below. Together they mean a South Carolina healthcare organization that cannot show recent testing is exposed twice: to the breach itself, and to the question of what it did to prevent one. See HIPAA penetration testing.

    S.C. Code 39-1-90: the $1,000-per-resident fine

    S.C. Code 39-1-90 applies to "a person conducting business in this State, and owning or licensing computerized data or other data that includes personal identifying information". After a breach that exposes unencrypted data of residents, disclosure "must be made in the most expedient time possible and without unreasonable delay". Notify more than 1,000 people at once and you also notify the Consumer Protection Division of the Department of Consumer Affairs and the nationwide consumer reporting agencies.

    The penalty clause is what sets South Carolina apart. A person who "knowingly and wilfully" violates the section is subject to "an administrative fine in the amount of one thousand dollars for each resident whose information was accessible by reason of the breach". The fine scales with the number of residents affected, not with the size of your company.

    The statute does not order a penetration test. It makes the cost of not knowing your weaknesses very specific.

    This page is not legal advice. Verify the statute text at scstatehouse.gov or ask counsel before relying on it.

    Remote delivery from The Hague, on Eastern time

    Budget Security has no office in South Carolina. Testing is done remotely by our team in The Hague, Netherlands, during hours that overlap US Eastern time. Kick-off, daily check-ins and the debrief happen inside your business day.

    That is how most penetration testing is delivered, by local firms as well. Applications, APIs, cloud accounts and internet-facing networks are tested over the internet, from the same position an attacker holds. Internal network segments are tested through a VPN or a virtual machine you place inside the network. A tester in Charleston or Greenville sees exactly what a tester in The Hague sees.

    What replaces the site visit is the platform:

    • Online scoping with live trade-offs. Add a day and see what gets deeper coverage. Remove one and see what drops out, and whether the scope still meets your compliance goal.
    • A dashboard instead of a PDF over email. Findings, evidence, status, retests and your history across engagements, in one place your security lead or compliance officer can open any time.
    • Self-serve changes. Extend scope, add an asset or request a retest without a new sales conversation.
    • OSCP-certified testers. Senior people, manual work, the same caliber as a premium consultancy with the overhead removed.

    Timeline, report and payment

    Start: up to 7 days from booking. A faster start depends on tester availability and is not guaranteed. An urgency fee can apply. - Rescheduling: not free once a date is confirmed. The tester-days are held for you. - Report: in your dashboard within 48 hours after the test ends, with severity, reproduction steps and fix guidance per finding. Retests of fixed findings run from the dashboard. - Payment: after the report is delivered. Nothing is charged at booking. - Rate: $985 per tester-day for US clients (€849 per day for EU clients). The calculator shows your total before you sign up.

    Questions we get

    What does a penetration test cost in South Carolina?
    $985 per tester-day for US clients (€849 per day for EU clients). Most South Carolina engagements run 3 to 5 tester-days, which covers a customer-facing application and its API, or an external perimeter plus one internal segment. Use the [pentest calculator](/pentest-pricing/) to price your exact scope.
    Does the South Carolina Insurance Data Security Act require a penetration test?
    Not by name. Section 38-99-20 requires licensees to regularly test and monitor systems and procedures to detect actual and attempted attacks, and to assess the effectiveness of their key security controls at least annually. An annual scoped pentest satisfies both and gives you dated evidence before the 15 February certification.
    Do you have an office in Charleston, Greenville or Columbia?
    No. We test remotely from The Hague, Netherlands, with hours that overlap US Eastern time. Web, API, cloud and external targets are tested over the internet, as an attacker would. Internal networks are tested through a VPN or a virtual machine inside your environment.
    How quickly can the test start?
    Up to 7 days from booking. A start within 24 hours is not guaranteed; it depends on availability and an urgency fee can apply. Rescheduling a confirmed date is not free.
    I am a CMMC Level 2 supplier. Do I need a penetration test?
    Level 2 does not mandate one by name. It requires vulnerability scanning every 90 days and evidence that your NIST SP 800-171 controls are effective. A pentest is the evidence most suppliers bring to the assessor. Level 3 requires a penetration test every year.
    Can the report go into my regulator or auditor file?
    Yes. It documents scope, methodology, findings with severity and evidence, and the retest status of each fix. That is what an insurance department examiner, a SOC 2 auditor, a HIPAA compliance officer or a CMMC assessor needs to see.
    When do I pay?
    After the report is delivered, not at booking. You scope and book online, the test runs, the report arrives within 48 hours after the test ends, and then you pay.
    Which parts of South Carolina do you cover?
    The whole state. Charleston and North Charleston, Greenville and the Upstate, Columbia, Myrtle Beach, Rock Hill, Spartanburg and everywhere else, because delivery is remote and the location of your office does not change the test.
    NEXT STEP

    Scope your South Carolina pentest in minutes.

    Register your assets, pick the goal, set the days. Published rate: $985 per tester-day for US clients (€849 per day for EU clients). Start within 7 days of booking, report within 48 hours after the test ends, pay after delivery.