24/7 SOC monitoring & incident responsesales@bugfoe.com
BestPentestingby BugFoe
Buyer's guide

How to Choose a Penetration Testing Company: The 2026 Buyer's Checklist

Use this checklist to separate genuine manual testing from rebadged scanner output — and to pick a partner your auditors and engineers will both trust.

Updated October 20263 min readBy the BestPentesting Security Research Team

Choosing a penetration testing company is a trust decision. You're giving outsiders permission to attack your systems, and you'll rely on their report in front of auditors, customers and your board. This guide distils what experienced security leaders check before they sign.

Step 1: Define what you actually need

Before talking to vendors, write down three things:

  • Driver: Is this for compliance (SOC 2, ISO 27001, PCI DSS), a customer security questionnaire, a product launch, or genuine risk reduction? The answer shapes the report format and depth.
  • Assets: Which web apps, APIs, mobile apps, cloud accounts, networks or offices are in scope — and which are explicitly out?
  • Constraints: Deadlines, testing windows, production vs. staging, budget range.

Step 2: Evaluate the people, not the brand

The single biggest predictor of pentest quality is the skill of the individual tester assigned to you. Ask for anonymised CVs of the actual team and look for:

CertificationWhat it provesRelevant for
OSCP / OSEP (OffSec)Hands-on exploitation and evasion in a timed practical examNetwork, AD, general
OSWE (OffSec)White-box web exploitation from source codeWeb & API
CRTOPractical red team operations with C2 frameworksRed team
CREST CRT / CCTIndustry-recognised practical exams; CREST also accredits companiesRegulated / UK, APAC
GIAC GPEN / GWAPT / GCPNStrong knowledge-based exams in pentest, web and cloudGeneral, web, cloud
CEHFoundational knowledge; less hands-on on its ownEntry-level baseline

Step 3: Read a sample report

Ask every shortlisted vendor for a redacted sample report. A strong report has:

  • An executive summary a non-technical leader can act on
  • Clear risk ratings (CVSS or a documented risk model) with business context
  • Reproducible, step-by-step proof of concept for every finding
  • Specific, developer-ready remediation guidance
  • A methodology section and a precise statement of what was and wasn't tested
  • Attack narratives showing how findings chain together

If the sample looks like a scanner export — plugin IDs, generic descriptions, dozens of "informational" findings — walk away.

Step 4: Ask these 25 questions

People & process

  1. Who exactly will test our systems, and can we see their CVs?
  2. Are testers full-time employees or subcontractors / crowd?
  3. Are testers background-checked and bound by NDA?
  4. What share of the engagement is manual testing versus automated scanning?
  5. Which methodology do you follow (OWASP WSTG, PTES, NIST SP 800-115, OSSTMM)?
  6. How do you handle critical findings discovered mid-test?
  7. Will we have a direct line to the tester during the engagement?

Scope & logistics

  1. How did you estimate the number of tester-days?
  2. What is explicitly out of scope?
  3. Do you test from fixed IPs we can allow-list and monitor?
  4. How do you avoid disrupting production systems?
  5. What are your testing windows and time zones?
  6. How soon can you start, and how long until the final report?

Reporting & follow-up

  1. Can we see a redacted sample report?
  2. Is a retest included? Within how many days?
  3. Do you provide an attestation letter for customers or auditors?
  4. Will the report map to our framework (SOC 2, ISO 27001, PCI DSS, RBI)?
  5. Do you hold a debrief call with engineering?
  6. In what format are findings delivered (PDF, CSV, Jira, platform)?

Security & commercial

  1. How is our data stored, encrypted and deleted after the engagement?
  2. Do you hold ISO 27001 certification or equivalent controls?
  3. What professional indemnity / cyber insurance do you carry?
  4. Is the price fixed? What would trigger a change?
  5. Can you provide references from companies like ours?
  6. What happens if testers find evidence of an active breach?

Step 5: Watch for red flags

  • "Fully automated penetration test" — that's a scan.
  • No scoping call before a quote.
  • Guaranteed "zero findings" or "certification" after a test.
  • Refusal to name testers or share a sample report.
  • Unrealistically fast turnaround for the scope.
  • Pressure to sign an annual contract before a first test.

Step 6: Compare proposals fairly

Normalise proposals by tester-days, seniority, manual share, retest terms and report format. The lowest price per engagement is rarely the lowest price per meaningful finding. Our pricing guide lists typical ranges so you can spot outliers.

Free RFP template

Copy-paste RFP outline 1) Company background and testing driver · 2) Assets in scope with sizes (pages, roles, endpoints, IPs, cloud accounts) · 3) Out-of-scope items · 4) Environment (staging/production) and test windows · 5) Required methodology and compliance mapping · 6) Required deliverables (report, attestation, retest, debrief) · 7) Tester qualifications required · 8) Data handling and NDA terms · 9) Timeline · 10) Pricing format (fixed price, tester-days, rates).

Want us to scope it for you? Request a free scoping call or explore our penetration testing services.

BestPentesting Security Research Team
Written and technically reviewed by practising penetration testers and SOC analysts. Last reviewed October 2026. See our methodology.

Ready to find your risks before attackers do?

Tell us what you need tested or monitored. A senior consultant replies within one business day with a scoped, fixed-price proposal.

  • Fixed-price proposal
  • Reply within 1 business day
  • NDA on request