Back to Blog
Penetration TestingBuyer GuideCompliance

How to Choose a Penetration Testing Company: A Buyer's Checklist

June 9, 20269 min read
How to Choose a Penetration Testing Company: A Buyer's Checklist

Choosing a penetration testing company is a trust decision. You are handing someone direct access to the systems your business runs on and relying on them to tell you the truth about what they find. Yet most buyers compare providers on price alone, because the real differences are hard to see from a website. This checklist makes them visible.

1. Certifications: what they actually mean

Certifications are a floor, not a ceiling, but they tell you a tester has proven hands-on skill rather than just read about it.

  • OSCP (Offensive Security Certified Professional): a demanding practical exam. A good baseline that a tester can actually exploit, not just scan.
  • CREST (CRT, CCT): a respected industry standard in the UK and Europe, often expected by regulated buyers.
  • OSWE, OSEP, GXPN: deeper specializations in web exploitation, evasion, and advanced techniques.

Ask who will actually perform your test and what they hold, not what the company holds collectively. The person on the keyboard is what matters.

2. Manual testing versus a rebranded scan

Automated scanners are useful, but they cannot understand your business logic, chain vulnerabilities, or tell a real risk from a theoretical one. If a provider cannot clearly explain what they do manually beyond the scanner, you are buying a scan with a nicer cover page. Ask directly: what percentage of this engagement is manual testing?

Senior versus junior matters. Ask whether juniors will be learning on your environment and whether work is outsourced. The tester who tests your systems should be senior enough to defend every finding and experienced enough to find the ones a scanner misses.

3. Methodology and scope

A credible provider aligns to a recognized methodology, OWASP for web and APIs, OWASP MASVS for mobile, PTES or NIST for infrastructure, and can explain how they scope. Watch how they handle scoping: a good firm asks sharp questions about your architecture and what you are actually worried about, rather than sending a one-size-fits-all intake form.

4. The report is the product

You are not paying for the testing; you are paying for what you can do afterward. Ask for a sample report and check that it includes:

  • An executive summary a non-technical leader can act on.
  • Technical findings with clear reproduction steps and proof of concept.
  • Risk ratings (CVSS) that reflect real business impact, not just raw severity.
  • Prioritized, specific remediation guidance, not generic advice to patch.

A report your engineers can hand to auditors and act on without a translation layer is worth far more than a longer list of low-severity noise.

5. Retesting and aftercare

Finding issues is half the job; confirming they are fixed is the other half. Does the provider retest your remediations, and is that included or billed again? Free retesting with written confirmation that an issue is closed should be standard, not an upsell.

6. Transparent pricing

Opaque, contact-us-only pricing is a warning sign. Providers who publish tiers or clear day rates tend to be more confident and easier to budget around. Understand what drives the number so you can compare fairly, our guide to penetration testing cost breaks it down.

The questions to ask every provider

your shortlist questionnaire

# Ask each provider these before you sign
1. Who will run our test, and what certifications do they hold?
2. What share of the engagement is manual vs automated?
3. Which methodology do you follow for our asset type?
4. Can we see a sample report (redacted)?
5. Is retesting of our fixes included?
6. Is any work outsourced or run by juniors?
7. How many tester-days does this quote assume?
8. How do you handle findings you discover are out of scope?

How we would answer

Every tester on our team is senior, with years of hands-on experience and active offensive certifications, no juniors on your environment and no outsourcing. We follow OWASP, NIST, and ISO-aligned methodologies, publish transparent pricing from 2,500 EUR, include free retesting on every engagement, and deliver reports built to hand straight to your board or auditor. See our full range of services or start a conversation and judge us against your own checklist.

Share this article:

Need Help With Security Testing?

Our experts can help you identify and fix vulnerabilities before attackers find them.

Get a Free Consultation
Business security background

Ready to secure your business?

Get in touch today!

0+

Pentests performed every year

0+

Vulnerabilities found in the past year

0+

Industries served

0%

Client satisfaction

Let's connect

How can we help you?

Get in touch

Protect what mattersLet's talk security

Ready to take your business's security to the next level? Our team is here to help you identify and resolve vulnerabilities before they become threats. Get in touch today through our contact form, and let's discuss how we can secure your digital environment with expert precision.


FAQ

Got questions?We got the answers