How to Choose a Penetration Testing Company
Choose a penetration testing company on four evidence points, in this order: the credentials of the named testers, the stated balance of manual testing to automated scanning in the methodology, a sanitized sample report you can read before signing, and whether the statement of work names the individuals who will do the testing. Price is the fifth criterion, not the first, and it is a sanity check rather than a selection criterion: our penetration testing cost breakdown works through the published market ranges and the arithmetic that converts any quote into implied hours. A quote far below the range for the work described is not a bargain, it is usually a scanner with a cover page.
The reason for that order is that all four of the first criteria are checkable before you sign, and price is the only one that is legible without expertise. Buyers who lead with price are optimizing the one variable they can read.
Key takeaways
- Evaluate on four evidence points, in order: the credentials of the named testers, the stated manual-to-automated balance, a sanitized sample report, and whether the statement of work names individuals.
- All four are checkable before you sign. Price is the fifth criterion, and buyers who lead with it are optimizing the one variable they can read without expertise.
- The manual-to-automated question is the single most useful one in the evaluation, and a serious answer names a methodology someone else wrote down.
- A weak sample report is more informative than a strong reference call. Templates are visible on the page.
- Send every firm the identical package: asset list with exclusions, user roles and test accounts, environment, constraints and windows, and the reason you are testing. Only then do the differences in what comes back mean anything.
1. The named testers, and what their credentials actually tell you
Ask who will test, and ask for their certifications and their background.
The hands-on offensive certifications are the ones that carry information, because they require exploitation under time pressure rather than a multiple-choice exam: OSCP and the more advanced OSWE and OSEP from Offensive Security, GPEN and GXPN from GIAC, and CREST registration in markets where it is common. A tester with a decade of application security work and no certificate can be excellent. A firm that will name neither credentials nor experience is telling you something.
What credentials do not tell you is fit. A network-focused tester on a complex multi-tenant SaaS application with a rich authorization model is a mismatch regardless of the letters. Ask what they have tested that resembles your system, and listen for whether the answer is specific.
2. The manual-to-automated balance, stated in writing
This is the single most useful question in the whole evaluation, and it should have a written answer in the statement of work.
Every real engagement uses automation. Scanners are good at coverage and at the classes of defect that are mechanically detectable. What they cannot do is reason about your authorization model, chain two low findings into one serious one, or understand that a particular endpoint should never be reachable by a customer in a different tenant. That reasoning is the product you are buying, and it is delivered in hours of skilled human attention.
So ask: what proportion of this engagement is manual, and which methodology does it follow? A serious answer names something written down, typically the OWASP Web Security Testing Guide for web applications, the Penetration Testing Execution Standard for engagement structure, or NIST SP 800-115 for technical assessment planning. A vague answer about a proprietary approach usually resolves to a scan.
Our piece on penetration test versus vulnerability scan sets out how to tell them apart from the artifacts, which matters because your auditor and your enterprise customers increasingly can.
3. A sanitized sample report
Ask every shortlisted firm for a redacted example of the report you would receive. This is a routine request.
What to look for when you read it. Do findings carry severity, affected asset, reproduction steps, and a specific remediation, or do they carry a CVSS score and a paragraph of generic advice? Is there evidence of chaining, meaning findings that combine into a higher-impact scenario? Does the report distinguish what was tested from what was not? Is there an executive section that a non-technical reader could actually use, separate from the technical detail your engineers need?
A weak sample is more informative than a strong reference call. Templates are visible on the page.
While you are asking, request the attestation letter format too, if you need one for customers or an auditor. It is a different artifact from the technical report and it is worth seeing before you need it.
4. Named individuals in the statement of work
Testing quality is a property of the tester. A statement of work that commits to a qualified team lets the firm assign whoever is free, which in a capacity crunch is the newest person.
Ask for names in the document, a named alternate, and notice if the assignment changes. The other SOW elements worth pinning down for a test specifically are the targets and exclusions, whether testing is authenticated and against production or staging, the testing window, and the retest terms. What a security consulting SOW should include covers the full structure.
5. Price, as a sanity check
Now look at the number, and use it to check the story rather than to pick the winner.
The useful move is to convert the quote into implied hours at a plausible rate and ask whether the work described could be done in that time. A scoped web application test with several user roles and an API is not a two-day exercise, and a quote priced as though it were is describing something other than what you asked for. Our cost breakdown publishes the market ranges by test type with their sources, including the figure below which manual testing cannot plausibly exist, and is a cheap pentest worth it covers what actually gets delivered at the bottom of the market.
Two pricing structures worth understanding before you compare quotes. Some firms include a retest round in the base price and others bill it separately, which can change the effective total materially. And testing delivered as a subscription rather than a project has a different shape again, which what is PTaaS explains.
Prepare five inputs before you ask for quotes
Quotes are only comparable when every firm was asked to price the same thing, and most buyers send three firms three subtly different briefs without noticing. Assemble these first.
An asset list. The applications, hostnames or URLs, IP ranges, and APIs in scope, with anything explicitly excluded named as excluded. Third-party services you do not control usually belong in the exclusions, and testing them may require the provider's permission.
User roles and test accounts. How many distinct privilege levels exist, and whether you can provide working credentials for each. Authorization testing is where the serious findings live in most modern applications, and it cannot happen without accounts. This single input moves a quote more than almost anything else.
Environment. Production or staging, how faithful staging is to production, and whether rate limiting, a web application firewall, or monitoring will be left in place or relaxed.
Constraints and windows. Blackout periods, change freezes, on-call arrangements, and the date you need the report by. If a customer or auditor deadline is driving the engagement, say so, because it affects sequencing and retest planning.
The reason you are testing. A test scoped to an audit boundary and a test scoped to real attacker interest are not always the same engagement. Saying which one you want, or that you want both, prevents the most common form of scope disappointment.
Send the identical package to every firm. The differences in what comes back then mean something.
When a penetration test is not what you need
Here is the part that costs us work.
If you have never run a vulnerability scan, do not have an asset inventory, and know you have unpatched internet-facing systems, a penetration test will produce a long report confirming things you could have found for a fraction of the cost. Fix the known problems first. A test is most valuable against an environment someone has already tried to secure.
If your driver is purely a customer questionnaire and the customer will accept a scan, and you are honest with them about which one it is, buy the scan. What you must not do is present scanner output as a penetration test, because the reviewers who matter can tell.
And if you are considering a red team engagement without having had a standard penetration test, you are buying the wrong thing. A red team tests detection and response against a mature program. The prerequisite is a program.
How often to repeat the exercise is a separate question, covered in how often should you run a penetration test.
Where Top Floor fits
Our penetration testing engagements are scoped the way this article describes: a real scoping conversation before a price, named senior testers in the statement of work, OWASP and PTES methodology stated in writing, a retest round, and an attestation letter for compliance use. The reasoning behind treating testing as more than an audit checkbox is in penetration testing beyond compliance.
We will also tell you when a scan is genuinely sufficient for what you are trying to prove, which happens more often than the market's marketing implies.
How to decide this week
Ask all three shortlisted firms for the same two artifacts: a sanitized sample report, and the names and credentials of the testers who would be assigned.
Ask each one to state the manual-to-automated balance in writing, and to name the methodology they follow.
Then convert every quote into implied hours and check whether the scope you described fits. If one quote fits and two do not, you have your answer, and it will not be the cheapest one.
Frequently asked questions
What certifications should a penetration tester have?
The hands-on offensive certifications carry the most information because they require demonstrated exploitation rather than a written exam: OSCP and the more advanced OSWE and OSEP, GIAC's GPEN and GXPN, and CREST registration in markets where it is common. Treat them as a floor rather than a ranking. Relevant experience against systems like yours matters at least as much, so ask what the assigned tester has tested that resembles your environment and listen for whether the answer is specific.
How can I tell if a penetration test is really just a vulnerability scan?
Ask for the manual-to-automated balance in writing and for a sanitized sample report. Scanner output shows up as findings that carry a tool identifier and generic remediation advice, with no chaining of issues, no business-logic or authorization findings, and no evidence of manual reproduction. A real report distinguishes what was tested from what was not, and shows at least some findings that no scanner could have produced.
Should I choose a penetration testing company based on price?
Price belongs late in the evaluation, as a check on whether the proposal is coherent. Convert the quote into implied hours at a plausible rate and ask whether the scope you described could be delivered in that time. A quote well below the published market range for the work described usually means automated scanning is being sold under a different name, and buying it twice, once cheaply and once properly after it is rejected, is the most expensive route available.
What should I ask a penetration testing firm before signing?
Five things, in writing: who will test and what are their credentials, what proportion of the work is manual and which methodology it follows, whether you can read a sanitized sample report, whether a retest round is included and for how long a window, and whether the named testers appear in the statement of work. Each is trivial for a serious firm to answer and awkward for the others, which is what makes the set useful.
Related Services
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.