Judge a penetration testing provider on six dimensions: who actually does the testing (individual tester credentials — OSCP, CREST, GIAC — not just company logos); a named methodology (PTES, OWASP, NIST); clear scoping and rules of engagement; a readable sample report with validated findings; an included remediation retest; and transparent commercials and liability cover. The single most revealing question is "who will test, and what are their qualifications?" — and the best defence against overpaying for a scan is to ask for a sample report and how much of the work is manual. See also boutique vs Big 4.
// 01 Who will actually do the testing? (Q1–4)
A penetration test is only as good as the person running it, so start here — and insist on answers about the individuals, not the brand.
- Q1. Who specifically will be assigned, and what are their certifications (OSCP, OSWE, OSEP, CREST, GIAC)?
- Q2. Is the testing done in-house, or subcontracted to a third party?
- Q3. What is the testers' experience in our sector and technology stack?
- Q4. What company-level accreditations do you hold (CREST, ISO 27001), and how do they translate to my engagement?
// 02 What methodology do you follow? (Q5–8)
A named, repeatable process is the difference between an auditable engagement and one tester's improvisation.
- Q5. Which standards do you follow (PTES, OWASP WSTG/MASVS, NIST SP 800-115)?
- Q6. What proportion of the engagement is manual versus automated?
- Q7. How do you test business logic that scanners cannot understand?
- Q8. Do you map findings to MITRE ATT&CK and to my compliance framework?
// 03 How is scope and safety handled? (Q9–12)
Good scoping protects both the quality of the test and the stability of your systems.
- Q9. How do you scope, and how do you handle scope changes mid-engagement?
- Q10. What are the rules of engagement, and how do you avoid business disruption?
- Q11. How and how often do you communicate during testing, especially on critical findings?
- Q12. What is your process if you find an active compromise during the test?
// 04 What does the deliverable look like? (Q13–16)
Ask for a sample report before you sign — it is the clearest evidence of what you are buying.
- Q13. Can I see a sample report? (A thin, scanner-style report is a red flag.)
- Q14. Do findings include evidence, reproduction steps and contextual risk ranking?
- Q15. Is there both an executive summary and technical detail?
- Q16. Do you provide an attestation letter for customers and auditors?
// 05 Remediation, commercials and trust (Q17–20)
The engagement does not end at the report — and the contract should reflect that.
- Q17. Is a remediation retest included, and for how long after the test?
- Q18. Will you support us in triaging and fixing findings?
- Q19. What does the price include, and what is out of scope? (See pricing drivers.)
- Q20. What professional liability insurance and data-handling controls do you carry?
// 06 Reading the answers
Strong providers answer all twenty comfortably and volunteer detail; weak ones deflect to brand, dodge the manual-versus-automated question, or cannot produce a sample report. If you take only three questions into a call, take these: who tests and what are their credentials, can I see a sample report, and how much of the work is manual. Those three separate genuine human-led testing from a scan in a nicer PDF. For the boutique-versus-large-firm trade-off specifically, see boutique vs Big 4; for regional options, our own approach is built for regulated GCC buyers.
// 07 Frequently asked questions
How do you choose a penetration testing company?
Evaluate six things: the testers' credentials and experience (not just the company), a named methodology, clear scoping and rules of engagement, a readable sample report, an included remediation retest, and transparent commercials and liability cover. The key question is who will test and what their qualifications are.
What certifications should a tester have?
Hands-on offensive certs like OSCP, OSWE, OSEP, CRTO, or GIAC (GPEN, GWAPT, GXPN), and CREST-registered/certified status. Company accreditations (CREST, ISO 27001) add assurance but don't replace the individual tester's practical credentials.
Should you ask for a sample report?
Always. It shows what you're buying: manual findings with evidence and reproduction steps, contextual risk ranking, clear remediation, and readability for engineers and executives. A thin, scanner-style report is a warning sign.
How do you avoid buying a scan disguised as a pentest?
Ask how much of the work is manual, request a sample report, and confirm the testers exploit and validate findings rather than listing scanner output. If a provider can't explain their manual methodology or show validated findings, you're likely overpaying for a scan.
// 08 Related reading
- Boutique vs Big 4 penetration testing — which fits a regulated buyer.
- How much does penetration testing cost? — pricing drivers and worked examples.
- How to read a penetration test report — judge a sample report.