Choosing a penetration testing company is a trust decision. You're giving outsiders permission to attack your systems, and you'll rely on their report in front of auditors, customers and your board. This guide distils what experienced security leaders check before they sign.
Step 1: Define what you actually need
Before talking to vendors, write down three things:
- Driver: Is this for compliance (SOC 2, ISO 27001, PCI DSS), a customer security questionnaire, a product launch, or genuine risk reduction? The answer shapes the report format and depth.
- Assets: Which web apps, APIs, mobile apps, cloud accounts, networks or offices are in scope — and which are explicitly out?
- Constraints: Deadlines, testing windows, production vs. staging, budget range.
Step 2: Evaluate the people, not the brand
The single biggest predictor of pentest quality is the skill of the individual tester assigned to you. Ask for anonymised CVs of the actual team and look for:
| Certification | What it proves | Relevant for |
|---|---|---|
| OSCP / OSEP (OffSec) | Hands-on exploitation and evasion in a timed practical exam | Network, AD, general |
| OSWE (OffSec) | White-box web exploitation from source code | Web & API |
| CRTO | Practical red team operations with C2 frameworks | Red team |
| CREST CRT / CCT | Industry-recognised practical exams; CREST also accredits companies | Regulated / UK, APAC |
| GIAC GPEN / GWAPT / GCPN | Strong knowledge-based exams in pentest, web and cloud | General, web, cloud |
| CEH | Foundational knowledge; less hands-on on its own | Entry-level baseline |
Step 3: Read a sample report
Ask every shortlisted vendor for a redacted sample report. A strong report has:
- An executive summary a non-technical leader can act on
- Clear risk ratings (CVSS or a documented risk model) with business context
- Reproducible, step-by-step proof of concept for every finding
- Specific, developer-ready remediation guidance
- A methodology section and a precise statement of what was and wasn't tested
- Attack narratives showing how findings chain together
If the sample looks like a scanner export — plugin IDs, generic descriptions, dozens of "informational" findings — walk away.
Step 4: Ask these 25 questions
People & process
- Who exactly will test our systems, and can we see their CVs?
- Are testers full-time employees or subcontractors / crowd?
- Are testers background-checked and bound by NDA?
- What share of the engagement is manual testing versus automated scanning?
- Which methodology do you follow (OWASP WSTG, PTES, NIST SP 800-115, OSSTMM)?
- How do you handle critical findings discovered mid-test?
- Will we have a direct line to the tester during the engagement?
Scope & logistics
- How did you estimate the number of tester-days?
- What is explicitly out of scope?
- Do you test from fixed IPs we can allow-list and monitor?
- How do you avoid disrupting production systems?
- What are your testing windows and time zones?
- How soon can you start, and how long until the final report?
Reporting & follow-up
- Can we see a redacted sample report?
- Is a retest included? Within how many days?
- Do you provide an attestation letter for customers or auditors?
- Will the report map to our framework (SOC 2, ISO 27001, PCI DSS, RBI)?
- Do you hold a debrief call with engineering?
- In what format are findings delivered (PDF, CSV, Jira, platform)?
Security & commercial
- How is our data stored, encrypted and deleted after the engagement?
- Do you hold ISO 27001 certification or equivalent controls?
- What professional indemnity / cyber insurance do you carry?
- Is the price fixed? What would trigger a change?
- Can you provide references from companies like ours?
- What happens if testers find evidence of an active breach?
Step 5: Watch for red flags
- "Fully automated penetration test" — that's a scan.
- No scoping call before a quote.
- Guaranteed "zero findings" or "certification" after a test.
- Refusal to name testers or share a sample report.
- Unrealistically fast turnaround for the scope.
- Pressure to sign an annual contract before a first test.
Step 6: Compare proposals fairly
Normalise proposals by tester-days, seniority, manual share, retest terms and report format. The lowest price per engagement is rarely the lowest price per meaningful finding. Our pricing guide lists typical ranges so you can spot outliers.
Free RFP template
Want us to scope it for you? Request a free scoping call or explore our penetration testing services.