How to Choose a Penetration Testing Company: A Buyer's Checklist

Choosing a penetration testing company is a trust decision. You are handing someone direct access to the systems your business runs on and relying on them to tell you the truth about what they find. Yet most buyers compare providers on price alone, because the real differences are hard to see from a website. This checklist makes them visible.
1. Certifications: what they actually mean
Certifications are a floor, not a ceiling, but they tell you a tester has proven hands-on skill rather than just read about it.
- OSCP (Offensive Security Certified Professional): a demanding practical exam. A good baseline that a tester can actually exploit, not just scan.
- CREST (CRT, CCT): a respected industry standard in the UK and Europe, often expected by regulated buyers.
- OSWE, OSEP, GXPN: deeper specializations in web exploitation, evasion, and advanced techniques.
Ask who will actually perform your test and what they hold, not what the company holds collectively. The person on the keyboard is what matters.
2. Manual testing versus a rebranded scan
Automated scanners are useful, but they cannot understand your business logic, chain vulnerabilities, or tell a real risk from a theoretical one. If a provider cannot clearly explain what they do manually beyond the scanner, you are buying a scan with a nicer cover page. Ask directly: what percentage of this engagement is manual testing?
Senior versus junior matters. Ask whether juniors will be learning on your environment and whether work is outsourced. The tester who tests your systems should be senior enough to defend every finding and experienced enough to find the ones a scanner misses.
3. Methodology and scope
A credible provider aligns to a recognized methodology, OWASP for web and APIs, OWASP MASVS for mobile, PTES or NIST for infrastructure, and can explain how they scope. Watch how they handle scoping: a good firm asks sharp questions about your architecture and what you are actually worried about, rather than sending a one-size-fits-all intake form.
4. The report is the product
You are not paying for the testing; you are paying for what you can do afterward. Ask for a sample report and check that it includes:
- An executive summary a non-technical leader can act on.
- Technical findings with clear reproduction steps and proof of concept.
- Risk ratings (CVSS) that reflect real business impact, not just raw severity.
- Prioritized, specific remediation guidance, not generic advice to patch.
A report your engineers can hand to auditors and act on without a translation layer is worth far more than a longer list of low-severity noise.
5. Retesting and aftercare
Finding issues is half the job; confirming they are fixed is the other half. Does the provider retest your remediations, and is that included or billed again? Free retesting with written confirmation that an issue is closed should be standard, not an upsell.
6. Transparent pricing
Opaque, contact-us-only pricing is a warning sign. Providers who publish tiers or clear day rates tend to be more confident and easier to budget around. Understand what drives the number so you can compare fairly, our guide to penetration testing cost breaks it down.
The questions to ask every provider
your shortlist questionnaire
# Ask each provider these before you sign
1. Who will run our test, and what certifications do they hold?
2. What share of the engagement is manual vs automated?
3. Which methodology do you follow for our asset type?
4. Can we see a sample report (redacted)?
5. Is retesting of our fixes included?
6. Is any work outsourced or run by juniors?
7. How many tester-days does this quote assume?
8. How do you handle findings you discover are out of scope?
How we would answer
Every tester on our team is senior, with years of hands-on experience and active offensive certifications, no juniors on your environment and no outsourcing. We follow OWASP, NIST, and ISO-aligned methodologies, publish transparent pricing from 2,500 EUR, include free retesting on every engagement, and deliver reports built to hand straight to your board or auditor. See our full range of services or start a conversation and judge us against your own checklist.

