Blog · H.09 · Buyer's Guide

How to choose a penetration testing company: 20 questions to ask

The market runs from world-class boutiques to scanner-resellers charging premium prices for automated output. These twenty questions cut through it — grouped so you can evaluate any provider on the six things that actually determine whether you get real, human-led testing.

Vendor SelectionCredentialsMethodologyReportingProcurement
Evaluate On: Who Tests (Credentials) · Methodology · Scope & RoE · The Report · Remediation & Retest · Commercials & Liability Evaluate On: Who Tests (Credentials) · Methodology · Scope & RoE · The Report · Remediation & Retest · Commercials & Liability
// TL;DR

Judge a penetration testing provider on six dimensions: who actually does the testing (individual tester credentials — OSCP, CREST, GIAC — not just company logos); a named methodology (PTES, OWASP, NIST); clear scoping and rules of engagement; a readable sample report with validated findings; an included remediation retest; and transparent commercials and liability cover. The single most revealing question is "who will test, and what are their qualifications?" — and the best defence against overpaying for a scan is to ask for a sample report and how much of the work is manual. See also boutique vs Big 4.

// 01 Who will actually do the testing? (Q1–4)

A penetration test is only as good as the person running it, so start here — and insist on answers about the individuals, not the brand.

// 02 What methodology do you follow? (Q5–8)

A named, repeatable process is the difference between an auditable engagement and one tester's improvisation.

// 03 How is scope and safety handled? (Q9–12)

Good scoping protects both the quality of the test and the stability of your systems.

// 04 What does the deliverable look like? (Q13–16)

Ask for a sample report before you sign — it is the clearest evidence of what you are buying.

// 05 Remediation, commercials and trust (Q17–20)

The engagement does not end at the report — and the contract should reflect that.

// 06 Reading the answers

Strong providers answer all twenty comfortably and volunteer detail; weak ones deflect to brand, dodge the manual-versus-automated question, or cannot produce a sample report. If you take only three questions into a call, take these: who tests and what are their credentials, can I see a sample report, and how much of the work is manual. Those three separate genuine human-led testing from a scan in a nicer PDF. For the boutique-versus-large-firm trade-off specifically, see boutique vs Big 4; for regional options, our own approach is built for regulated GCC buyers.

// 07 Frequently asked questions

How do you choose a penetration testing company?

Evaluate six things: the testers' credentials and experience (not just the company), a named methodology, clear scoping and rules of engagement, a readable sample report, an included remediation retest, and transparent commercials and liability cover. The key question is who will test and what their qualifications are.

What certifications should a tester have?

Hands-on offensive certs like OSCP, OSWE, OSEP, CRTO, or GIAC (GPEN, GWAPT, GXPN), and CREST-registered/certified status. Company accreditations (CREST, ISO 27001) add assurance but don't replace the individual tester's practical credentials.

Should you ask for a sample report?

Always. It shows what you're buying: manual findings with evidence and reproduction steps, contextual risk ranking, clear remediation, and readability for engineers and executives. A thin, scanner-style report is a warning sign.

How do you avoid buying a scan disguised as a pentest?

Ask how much of the work is manual, request a sample report, and confirm the testers exploit and validate findings rather than listing scanner output. If a provider can't explain their manual methodology or show validated findings, you're likely overpaying for a scan.

// 08 Related reading

UG

Usama Gul

Founder & Penetration Testing Lead, CyberFortify

Has sat on both sides of the procurement table and helps GCC buyers separate genuine human-led testing from automated scans dressed up as penetration tests.

Ask us all twenty

We'll answer every one on a scoping call — named testers and their certifications, our methodology, a sample report, and exactly what's included — so you can compare us honestly against anyone.

Book a scoping call → See our methodology →