ICS penetration testing: which test to buy, and how to keep the plant running

By The PenTest Index · Offers and rule text checked October 10, 2026

ICS penetration testing is a planned, authorized attack on an industrial control system, and the safe way to buy it is to choose the least intrusive test that answers your question. That usually means starting with a design review, a passive assessment or an IT-to-OT boundary test. Anything active on live controllers needs written sign-off from whoever runs the process.

Below are the five kinds of test, eight offers compared on what they publish and what they leave out, a scope brief you can copy, and what NERC CIP, TSA and NIST actually say.

Which ICS test do you need?

Pick the test from the question you need answered. "Pen test the plant" can mean five different jobs, and they carry very different risk to the process.

An industrial control system (ICS) is the set of computers that runs a physical process: a production line, a water plant, a substation. You will also see OT (operational technology), the wider family that includes ICS, and SCADA, the kind of ICS that supervises equipment spread over a distance. A PLC is the small rugged computer that runs a machine. An HMI is the operator's screen.

Table columns: Test type; What happens, in plain words; The question it answers; Touches live controllers?.
Test typeWhat happens, in plain wordsThe question it answersTouches live controllers?
1. Design reviewSpecialists read your network drawings, firewall rules and remote-access setup, and interview your engineers. Nothing is attacked."Is the plant network built so one hacked office laptop can't reach the line?"No
2. Passive assessmentA listening device copies network traffic. Specialists review device settings with your staff. Weaknesses are listed, not exploited."What is actually on our control network, and what is weak?"Listens only
3. IT-to-OT boundary testTesters start from the office network or the internet and try to reach the control network. They stop at a line you agree, often the buffer network (called a DMZ) between office and plant."Can an attacker who gets into the office reach the plant?"No. It touches the servers and jump hosts at the edge.
4. Controller and device testTesters attack PLCs, HMIs, engineering workstations or firmware directly."If someone reaches this controller, what can they make it do?"Only if live controllers are in scope, so where it happens matters most. See the next table.
5. Detection exerciseA tester runs agreed attack steps while your team tries to spot each one. Often called a purple team."Would we notice an attack in progress?"Only as far as you agree

This table is our own sorting of the work, not a standard. Providers bundle these differently, and one engagement can combine several.

Our recommendation: if this is your first OT security work, or nobody can hand you a current network drawing, start with type 1 or 2. If you need proof for a customer, insurer or board that the office can't reach the plant, buy type 3. Buy type 4 only when you have a specific question about a specific device and a safe place to test it.

Types 1 and 2 are not penetration tests in the strict sense, because nothing is exploited. They are often the right purchase anyway. If your requester insists on the words "penetration test," type 3 is usually the one that earns them. We explain the wider difference in penetration testing vs vulnerability scanning.

Where can the testing happen?

What you test and where you test it are two separate choices. Keep both in the proposal.

Table columns: Environment; Good for; What to write down.
EnvironmentGood forWhat to write down
The live processDesign reviews, passive listening, boundary tests that stop short of controllersExactly which systems may be touched, and which may not
A planned outageActive testing of the real equipment while it controls nothingThe window, who restores the system, and how you prove it is back to normal
A spare or bench unitController and firmware testingModel, firmware version and configuration, and how they differ from what is installed
A replica or simulationTrying attack paths with no risk to the plantWhat was simulated and what was left out, so nobody reads the result as proof about the real system

Testing a controller on a bench is like crash-testing the same model of car. It tells you a lot about that model. It does not tell you whether your own car's brakes were fitted correctly. A good report says which one it tested.

Three questions that pick your route

  1. Who asked, and what exactly did they ask for? A regulator, insurer or customer may accept an assessment where you assumed they wanted exploitation. Ask before you buy. The exact question to send them is in the rules section.
  2. Do you have a current network drawing and asset list? If not, or if you don't know, start with type 1 or 2. Testers can't safely attack what nobody has mapped.
  3. Do you have a spare controller or an outage window? If not, type 4 on live equipment is the riskiest thing on this page. Leave it out of the first engagement.

If you think an attack is happening right now, this is the wrong purchase. Call an incident response team first.

Already know which test you need? Jump to the eight offers.

Here to learn how to do this work rather than buy it? NIST's OT security guide lists SANS ICS courses and CISA's ICS training among its resources, and our step-by-step guide to how a penetration test is done covers the general process.

Is ICS penetration testing safe on a live plant?

It can be, but only with limits written down before anyone connects a laptop. Industrial controllers can fail under network traffic an office server would shrug off, and the consequence is a stopped process, not a slow website.

NIST, the U.S. standards agency, records an example in its OT security guide. In its words: "A natural gas utility hired an IT security consulting organization to conduct penetration testing on its corporate IT network. The consulting organization carelessly ventured into a part of the network that was directly connected to the SCADA system." The guide says the test "locked up the SCADA system." An earlier edition of the same guide says the utility could not send gas through its pipelines for four hours. (NIST SP 800-82 Rev. 3, Appendix C)

Notice what went wrong. Nobody was testing the control system. An ordinary office test wandered into it. That is why the same guide says penetration testing is "used with care on OT networks," and adds: "If penetration testing is performed on non-OT networks, extra care is taken to ensure that tests do not propagate into the OT network."

So the first safety step may have nothing to do with buying an ICS test. Tell your existing IT pen test firm, in writing, where the office network ends and which addresses are off limits.

Providers answer the safety question in very different ways. One requires explicit approval and controls for techniques that could affect production. Another publishes its limits: "No PLC writes without sign-off." We would rather see the second kind of answer, and we would want either one in the contract. A promise on a web page is not a term you can enforce.

ICS penetration testing offers compared

Eight providers publish an ICS or OT testing service we could read in full. Three publish clear limits for live equipment, one publishes a price, and none publishes a total cost or a deadline for checking your fixes. Use the table to decide who to call first, then make each of them answer the same brief.

Everything below is what each provider says on its own pages, read on October 10, 2026. We have not bought these services or judged anyone's testing quality. "Not stated" means we did not find it on the pages we read. It does not mean the answer is no. Providers are listed A to Z. How we compare offers is on our methodology page.

Table columns: Provider and service; What it says it tests; What it says about live production; Price published; Fix check (retest); Ask this before you book.
Provider and serviceWhat it says it testsWhat it says about live productionPrice publishedFix check (retest)Ask this before you book
Canary Trap (OT Penetration Testing)Workstations, PLCs, communication paths, policies and proceduresUses passive and controlled techniques where appropriate. Techniques that could affect production require explicit approval and controls; direct PLC testing must be scoped, approved and safe.Not statedRetesting remediated findings is included after report delivery, within the defined engagement window. Count and numeric deadline not stated."Put your production-impact limits in the contract. What happens, and who pays, if a device faults?"
CGI (ICS/OT Penetration Testing, UK G-Cloud 14)A range of ICS components. Lists "Ensure no bypass is present on safety systems.""Designed to be non-disruptive." Tests that may cause instability are discussed first.£980 to £1,600 a day (2024 G-Cloud 14 listing, "a unit a day"), excluding VAT. UK public-sector framework rate card, time and materials. Rates valid for 18 months from the framework's Effective Date; confirm current terms. No number of days given.Not stated"How many days for our scope, and what is the total?"
CyberLab (OT Penetration Testing, UK)PLCs, HMIs, SCADA, DCS, ICS networks, segmentation, industrial protocols"Passive-first reconnaissance." "Testing on non-production systems wherever possible." "Active testing in agreed maintenance windows only."Not statedNot stated"Which of our live systems would you touch, and which move to a bench or an outage?"
Dragos (Network Penetration Test; separate Network Vulnerability Assessment and Purple Team Exercise)Attack paths "such as pivoting from the enterprise network to the OT DMZ and into the process control network." The separate assessment finds weaknesses "without active exploitation."Not stated in the brief we readNot statedNot stated"Where does testing stop? Do we need any Dragos Platform equipment, and what does it cost?"
Mandiant (Google Cloud; ICS penetration testing)How far an attacker can "access, exploit, or otherwise manipulate critical ICS/SCADA systems"Not statedNot statedNot stated"Who does the ICS work, and how do your methods change for a running process?"
Pentest Limited (ICS / SCADA Penetration Testing, UK)Hardware, RTU/PLC/IED firmware, node services, application security, encryption, system testsWorks on site. Says it has tested "live production systems, as well as test environments."Not stated"Fix checks" can be provided. Count, deadline and cost not stated."Are fix checks in the price? How many, and until when?"
Red Trident (ICS & OT Penetration Testing, Houston, Texas)Critical systems, networks and applications across IT and OT, tailored per customerSays it finds weaknesses "without disrupting your operations." Agrees rules of engagement that can exclude time windows and heavy-traffic tools.Not statedDuring remediation, you can send fixes back for retesting and get a revised report. Count, deadline and cost not stated."It recommends remote testing. How would you reach our control network remotely, and who approves that access?"
SecureLayer7 (OT security testing)PLCs, HMIs, SCADA, engineering workstations and the IT-to-OT boundary, down to the industrial protocols"Read-only baseline first. Write-tests behind your change control. No PLC writes without sign-off."Not stated"Re-test included," by the same researcher. Count and deadline not stated."How many re-tests, and by what date must we ask?"

Sources: Canary Trap, CGI listing, CyberLab, Dragos services brief, Mandiant, Pentest Limited, Red Trident, SecureLayer7.

Which offer deserves your first call?

Start from the test type you picked.

  • You want a findings list with nothing exploited (type 2). Dragos is the only one of the eight that publishes this as its own named service, separate from its penetration test. Its assessment uses active and passive information gathering without exploitation.
  • You want proof about the office-to-plant boundary (type 3). Dragos describes exactly that path. Mandiant fits when the same engagement also covers your wider company network.
  • You want live-plant limits stated before you even call. SecureLayer7 and CyberLab publish the clearest ones. Ask for the same words in the contract.
  • You need device and firmware work (type 4). Pentest Limited lists hardware and firmware by name, on site in the UK.
  • You want to test whether your team would notice (type 5). Dragos publishes a Purple Team Exercise of "roughly 30-35 adversary techniques."
  • You are a UK public-sector buyer who needs a rate up front. CGI is the only one with a published number. Confirm that its 2024 rate card still applies.
  • You are in North America and want an OT-focused firm. Red Trident is based in Houston. Ask about its remote-first approach before you agree to it.

Who should rule an offer out: if your operations team will not allow anything active on running equipment, any provider that won't write that limit into the contract is out, whatever its website says. If your requester needs testers with a particular qualification, check it with the body that issues it. CGI and CyberLab say they hold CREST and CHECK status, and Pentest Limited and SecureLayer7 show CREST badges. We have not checked those claims against the CREST or CHECK lists.

View Canary Trap's OT testing service View CGI's listing and rate card View CyberLab's OT testing service View Dragos's assessment and testing services View Mandiant's penetration testing services View Pentest Limited's ICS testing service View Red Trident's ICS testing service View SecureLayer7's OT testing service

Provider links go straight to each provider's own page. See how we make money.

Can your usual pen test firm do this?

Sometimes. For a boundary test (type 3), a good general firm can do the work if it accepts your plant rules and stops at the agreed line. For controller testing (type 4), ask who will be assigned, which equipment like yours they have tested, and for a sample ICS report with the client's details removed. If your current firm passes that check, you may not need a new one.

What goes in an ICS scope brief?

A usable brief names the process, the targets, the environment, what testers may and may not do, and who can stop the work. Send the same brief to every provider. A scope brief asks each supplier the same question, so their answers and prices line up.

This brief is a buying aid. It is not permission to test. Written authorization from the system owner must name the actual systems and actions, and equipment owned by a vendor or another company needs that owner's permission too.

Copy the ICS scope brief

Do not put passwords, keys, network diagrams or IP address lists in this brief. Agree how to share those with the provider you hire.

  1. Why and for whom. The question the test must answer. Who receives the report. The exact wording of any rule, contract or insurer request. Your deadline.
  2. The process. What the system controls, and what a stoppage or wrong action would mean for safety, the environment, product quality and uptime.
  3. Targets. Named sites, systems and network segments in scope. Who owns each. What is out of scope, including vendor-owned equipment.
  4. Equipment. Controller and device families, with firmware and software versions where you know them. Say plainly where your inventory has gaps.
  5. Environment. Live process, planned outage, spare or bench unit, or replica. If not live, how it differs from what is installed.
  6. Starting point. Where testers begin (internet, office network, a named account, inside the control network) and what you will give them.
  7. Allowed and forbidden actions. List each separately: listening, reading settings, active scanning, exploiting weaknesses, writing to controllers. Name a no-touch list, and put safety systems on it unless operations decides otherwise.
  8. Plant rules. No writes to controllers (setpoints, logic, firmware, mode changes) without written sign-off for each action. Active scanning only on named devices, at an agreed rate. Agreed time windows with an operator present. Controller programs backed up and a restore tried before work starts.
  9. Stop and restart. One named person at the plant who can stop testing at any moment. Who is called, in what order, if something behaves oddly. Who decides when work resumes.
  10. The people. Who will be assigned, what comparable equipment and sectors they have tested, and a sample ICS report with client details removed.
  11. The report. What it must show (see the report section below), who walks your engineers through it, and how findings and collected data are stored, sent and destroyed.
  12. Price, dates and fix checks. Currency and price basis. Travel, lab setup and any required equipment or software. Start date, testing window and report date as three separate dates. How many fix checks are included, when the clock starts, and the last day you can ask for one.

A worked example

Say you run a 200-person packaging plant that never shuts down. Your insurer's renewal form asks about "OT penetration testing." You have no spare controllers. What you really want to know is whether a stolen office password could reach the plant's remote-access gateway. This buyer is made up. The offers we check it against are real.

Table columns: What this buyer needs; What the published pages support; Finding; Next question.
What this buyer needsWhat the published pages supportFindingNext question
A test of the office-to-plant boundary (must have)Dragos describes a test that moves from "the enterprise network to the OT DMZ and into the process control network."Supported as the right kind of service. Whether it covers your named gateway is not settled by a web page."Will the scope cover our starting point and stop at our gateway?"
No active work on running controllers (must have)SecureLayer7: "No PLC writes without sign-off." CyberLab: "Active testing in agreed maintenance windows only." The Dragos and Mandiant pages we read say nothing either way.Unresolved for all four: the published precautions do not establish this buyer's controller exclusion."Put the controller exclusion and the stop authority in the proposal."
A complete price (must have)Seven of eight publish no price. CGI publishes a UK public-sector day rate with no number of days.Unresolved for all eight. An unknown cost is not zero."Send an itemized total for this brief, including travel and any required equipment."
A check of our fixes about three months later (must have)Red Trident, SecureLayer7, Pentest Limited and Canary Trap mention retesting or fix checks. None gives a count or a deadline.Unresolved for all eight."How many fix checks, and what is the last day we can ask?"
Controller or firmware testingThe brief leaves it out.Not applicable. Don't let it be added to the quote.None, unless your question changes.

A finding of Supported covers that one condition, on that date, from the provider's own words. It is not a verdict on the provider.

Now picture two proposals coming back. Both are invented. Proposal A is the cheapest, but it covers only internet-facing office systems and never reaches the remote-access gateway. That fails the first must-have, so it is out at any price. Proposal B covers the gateway but leaves the controller exclusion unwritten. It stays on hold until that sentence is in the document. A revised B with the limits, the named team, the report format and the full cost is the one your operations manager can sign.

And before any of that, this buyer should send the insurer one question, because the insurer may accept a design review. That question is in the next section.

If you would like a general checklist for the parts of a pen test purchase that are not ICS-specific, such as report requirements and offer comparison questions, our free tool has one you can copy or print. It does not list ICS providers, and it asks for no email or sign-up. Keep the plant rules from the brief above.

Find My PenTest Match

Does NERC CIP, TSA or NIST require it?

The rule text we read asks for vulnerability assessments and design reviews on set schedules. It does not, in the passages below, order a penetration test of live controllers. Your regulator, auditor, insurer or customer decides what they accept, so ask them before you buy.

Table columns: Who is asking; What the text says; What that means for you.
Who is askingWhat the text saysWhat that means for you
NERC CIP-010-4, Requirement R3 (applicable Bulk Electric System entities)For high and medium impact BES Cyber Systems and their associated assets covered by R3: "At least once every 15 calendar months, conduct a paper or active vulnerability assessment." For high impact BES Cyber Systems, "where technically feasible, at least once every 36 calendar months," an "active vulnerability assessment in a test environment," or in production "in a manner that minimizes adverse effects." The 36-month assessment must model the BES Cyber System's production baseline configuration. Results and an action plan must be documented.R3's wording is "vulnerability assessment." If you already run this cycle, check with your compliance team whether a separate pen test adds anything they need.
TSA Security Directive Pipeline-2021-02F, section III.G (TSA-designated U.S. hazardous-liquid and natural-gas pipelines and LNG facilities; this version states an expiration date of May 2, 2026)The cited 02F required operators to have a Cybersecurity Assessment Plan to "ascertain the effectiveness of cybersecurity measures and to identify and resolve device, network, and/or system vulnerabilities." The plan had to "include a cybersecurity architecture design review at least once every two years," and results had to be reported to TSA each year.The design review has a fixed schedule in the text we read. TSA reissues this directive, so read the version that applies to you for what it says about other testing.
NIST SP 800-82 Rev. 3 (guidance; voluntary outside U.S. federal systems)Penetration testing is "used with care on OT networks." In its set of suggested controls for OT, the penetration testing control is selected only for high-impact systems.It is guidance, not a rule that every plant must be pen tested. Your own policy or a contract may still adopt it.
IEC 62443 (international industrial security standards)We have not read the clauses. These are paid documents.Several providers say their reports are "mapped to IEC 62443." Ask your customer or certifier which part and clause they need evidence for.
Insurer, customer or parent companyWhatever their form or contract says.Send them the question below.

Sources: NERC CIP-010-4, Table R3; TSA SD Pipeline-2021-02F; NIST SP 800-82 Rev. 3, Appendix F. All read October 10, 2026. Confirm which version of each applies to you. On that date NIST SP 800-82 Rev. 3 was the final guide. A draft Rev. 4 was published on September 21, 2026, with comments open until November 30, 2026. A draft is not the current guide.

The question to send whoever asked for the test:

Which systems must be covered? Do you require active exploitation, or will a vulnerability assessment or design review meet the requirement? Must the tester be independent or hold a particular qualification? What do you need to receive, and by when?

Outside North America, your own regulator's rules apply. One UK provider in our table says it maps its testing to the NIS Regulations 2018 and the NCSC's assessment framework. That is the provider's statement, so ask your regulator what it expects.

How much does it cost?

We found one published price. CGI's 2024 G-Cloud 14 listing gives £980 to £1,600 a day on a UK government purchasing framework, excluding VAT, charged as time and materials from its staff rate card (listing, read October 10, 2026; its pricing document is dated May 7, 2024). The document limits those rates to 18 months from the framework's Effective Date; confirm current terms. The other seven providers ask you to request a quote.

A day rate is not a total. The listing gives no number of days. If a scope took 10 consultant-days, which is our illustration and not CGI's estimate, the rate card alone would come to £9,800 to £16,000 before VAT and any additional expenses. That framework is also for UK public-sector buyers, so treat it as a reference point, not a quote for a private plant.

We won't give a "typical range." Nobody publishes enough real ICS prices to support one. Ask every provider to fill in the same lines so a cheaper quote can't hide a smaller job:

Table columns: Quote line; What must be spelled out.
Quote lineWhat must be spelled out
ScopeNamed sites and targets, starting point, allowed actions, exclusions
People and effortWho is assigned, and days of work as distinct from the calendar window
EnvironmentOn-site days, lab or bench setup, any equipment you must ship
Required extrasTravel, hardware, software or platform charges, each marked included or extra
TotalCurrency, fixed or estimated, payment schedule, change and rescheduling fees
DatesStart, testing window and report date, each on its own line
Fix checksHow many, when the clock starts, the last day to ask, and the cost of more

If budget is the blocker and you are in the United States, CISA, the federal cybersecurity agency, has published a no-cost Risk and Vulnerability Assessment that includes penetration testing. Its fact sheet is dated February 2022, says availability is limited, and does not mention OT or ICS. CISA also ended six other free assessments, according to a September 2026 report by Cybersecurity Dive. Ask CISA whether the service is open to you and whether it would go near your control network at all.

For general budgeting, see published penetration test prices. To compare quotes you already hold, use our quote check.

What should the report prove?

It should say what was actually tested, where, and with what limits, so you can tell a proven finding from an educated guess. On an ICS job that distinction matters more than usual, because much of the plant was deliberately left untouched.

Ask for each finding to carry one of these labels. The labels are our suggestion, not a standard:

Table columns: Label; What it means.
LabelWhat it means
TestedThe tester did this on a named target, in a named environment, and here is the evidence
ReviewedA document or configuration was read. Nothing was attacked.
Inferred"An attacker could probably do X," with the assumptions stated
Not testedLeft out, why, and what question remains open
RecheckedWhich fix was checked, when and how

Also ask for fixes your engineers can use. Many controllers can't be patched without a shutdown. A good ICS report puts changes you can make now, such as network separation, access changes and monitoring, beside the ones that must wait for an outage.

The providers describe their reports differently. Dragos lists an attack timeline and validated vulnerabilities. Red Trident lists an activity timeline and steps to reproduce each finding. CyberLab says findings include "operational and safety impact." SecureLayer7 offers a sample OT report with client details removed on request. Ask for a sample before you sign, and show it to whoever must accept the final report.

How long does it take, and how often should you repeat it?

Plan around your outage calendar. Access approvals, safety inductions and waiting for a maintenance window usually decide the schedule more than the testing itself does. That is our judgment, not a measured figure.

Providers give only loose numbers. Canary Trap says most engagements run "two to four weeks." CyberLab says "smaller, well-scoped engagements can be delivered in a few days." Neither is a booking date. Get the start date, testing window and report date in writing as three separate dates.

On frequency, the guidance we read sets no single schedule for ICS penetration tests. Canary Trap says most organizations test annually or after significant changes. Red Trident recommends once a year as a minimum. Those are sellers' recommendations. NERC's 15-month cycle covers paper or active vulnerability assessments for applicable high and medium impact BES Cyber Systems and their associated assets; its 36-month active-assessment cycle is for high impact BES Cyber Systems where technically feasible. A sensible trigger for any plant is a change in how the office and the plant connect: new remote access, a new vendor link, a new line.

Four questions before you contact a provider

Is ICS penetration testing the same as OT or SCADA penetration testing?

Sellers use the three names almost interchangeably. ICS is one kind of OT, and SCADA is one kind of ICS. The label tells you little. Read the scope: which systems, which actions, which environment.

Does the provider have to be on site?

It depends on the test type. Pentest Limited says its ICS testing "takes place onsite." Red Trident says it typically recommends remote testing. A design review or boundary test can often be done remotely. Controller and firmware work usually needs hands on the equipment or a unit shipped to a lab. If you must ship equipment or restrict where data goes, put that in the brief.

Our control network is air gapped. Do we still need this?

First find out whether it really is. A network that was isolated when it was built often gains a vendor modem, a remote-support tool or a link to the business system later. A design review or passive assessment (types 1 and 2) can help answer that without exploiting devices; passive listening cannot reveal every silent or unmonitored connection.

Can we keep our current provider?

Yes, if the people they assign, the scope, the plant rules and the report meet the same brief. Send them the 12 fields and ask what is already included before you buy anything new.

Sources and how we checked

We read each provider's public service page and the rule documents below on October 10, 2026. We did not buy any service, speak to any provider, or test anything. The test-type table, the environment table, the scope brief, the report labels and the worked example are our own analysis. The buyer and the two proposals in the worked example are invented.

  • NIST SP 800-82 Rev. 3, Guide to Operational Technology (OT) Security, September 2023: Appendix C (incident example) and Appendix F, control CA-8. nvlpubs.nist.gov
  • NIST SP 800-82 Rev. 4 initial public draft, status page. csrc.nist.gov
  • NERC CIP-010-4, Table R3, Parts 3.1, 3.2 and 3.4. nerc.com
  • TSA Security Directive Pipeline-2021-02F, section III.G. tsa.gov
  • CISA Risk and Vulnerability Assessment fact sheet, February 2022. cisa.gov
  • Canary Trap, OT Penetration Testing page and service brief. canarytrap.com
  • CGI, ICS/OT Penetration Testing, UK Digital Marketplace G-Cloud 14 listing and pricing document. digitalmarketplace.service.gov.uk
  • CyberLab, OT Penetration Testing. cyberlab.co.uk
  • Dragos, OT Cyber Services brief (marked updated August 2026) and assessment and penetration testing datasheet. dragos.com
  • Mandiant (Google Cloud), penetration testing services. cloud.google.com
  • Pentest Limited, ICS / SCADA Penetration Testing. pentest.co.uk
  • Red Trident, ICS & OT Penetration Testing. redtrident.com
  • SecureLayer7, OT security testing. securelayer7.net

Spotted an error or a changed offer? Send us the source and we will recheck it.