Blog · H.20 · Commercial

Penetration testing procurement: a guide for procurement teams

Procurement is built to drive value - and for most purchases, comparing like-for-like on price works. Penetration testing is the category where that instinct backfires: two identical-looking quotes can be a real engagement and a scanner with a cover page, and the cheapest bid is usually the scan. Buy it like a commodity and you'll pay for a report that fails your auditor. Here's how procurement should actually buy testing - the quality criteria, fair comparison, red flags, and how to write requirements that get real work.

ProcurementVendor ManagementRFPQuality FirstScorecard
Procurement: Not a Commodity · Cheapest = Usually a Scan · Quality Criteria First · Sample Report & Manual % · Like-for-like Scope · Weighted Scorecard · Price Among Qualified Only Procurement: Not a Commodity · Cheapest = Usually a Scan · Quality Criteria First · Sample Report & Manual % · Like-for-like Scope · Weighted Scorecard · Price Among Qualified Only
// TL;DR

Penetration testing is not a commodity - quality varies enormously and price doesn't indicate it. The cheapest bid is usually a scan-in-disguise that fails your auditor or customers. Evaluate on quality first: methodology & manual-vs-automated split, tester qualifications (and whether subcontracted), a redacted sample report, retesting included, data-handling/residency, compliance-mapping, references, clear scoping. Compare like-for-like by specifying scope up front so vendors bid on the same work, using a weighted scorecard where price is one factor among qualified providers - not the selector. Red flags: dramatically cheap/fast, won't share a sample report, vague methodology, retest as an add-on. Write requirements that demand these. Detail below; pair with the RFP template and vendor questions.

// 01 Why testing isn't a commodity

Procurement's core competency - drive competition, compare like-for-like, secure the best price - works beautifully for commodities. Penetration testing is not a commodity, and treating it as one is where value-driven procurement destroys value. The problem: quality varies enormously, and price doesn't reliably signal it. Two quotes for “a web application penetration test” can mean completely different things - one a genuine human-led engagement, the other an automated scan with a report cover. The cheapest bid is frequently the scan, and it produces a document that looks like value but fails to find the flaws that cause breaches and may be rejected by your auditor or a demanding customer - see the signs of a bad pentest. So buying on lowest price often means paying for something that doesn't do the job, turning the apparent saving into a false economy that surfaces at the worst moment - during an audit or a stalled enterprise deal.

// 02 The quality criteria that matter

01

Methodology & manual %

A named standard (OWASP, PTES, NIST) and the manual-vs-automated split - the biggest quality signal.

02

Testers & sample report

Certifications, in-house vs subcontracted, and a redacted sample report proving finding quality.

03

Retest & reporting

Retesting included, and the ability to map the report to your framework.

04

Data & references

Data-handling and residency terms, references, and clear scoping/communication.

These reveal whether you're buying genuine testing. The rule that protects procurement: compare price only among providers that clear these quality bars - never use price to select before quality is assessed. The 15 questions to ask a vendor map directly onto these criteria.

// 03 Comparing proposals fairly

The single most effective procurement move is to specify the scope and requirements clearly up front, so vendors bid on the same work rather than each defining their own - the root cause of misleading price gaps (a cheaper bid is often cheaper because it's doing less). Then use a structured, weighted scorecard that leans toward quality - methodology, manual testing, tester qualifications, sample report, retesting, reporting - with price as one weighted factor, not the dominant one. Two requirements sharpen it instantly: insist every bidder provides a redacted sample report, and state their manual-versus-automated approach. Those two alone separate genuine testers from scan resellers faster than anything else. A scorecard that rewards demonstrable quality prevents the lowest bid winning by default when it's actually the least capable - the failure mode that pure-price procurement produces. Structure the RFP with the pentest RFP template, and involve whoever owns security in the evaluation.

// 04 Red flags in a bid

Train the evaluation to weight these heavily. Dramatically cheaper and faster than others - the clearest sign of a scan rather than a test (real testing takes tester-days). Refusal or reluctance to share a redacted sample report - a proud provider offers one; hesitation is the answer. Vague methodology or an inability to name a recognised standard. No named testers or verifiable certifications, or silent subcontracting offshore. Retesting treated as a separate paid engagement. Unclear data-handling terms - critical when the deliverable is a map of how to breach you. And the tell that captures them all: a provider who competes purely on being cheapest and fastest and promises to “test everything comprehensively for very little” is signalling that depth isn't what you'll get. Procurement's discipline here is to treat these as disqualifiers or heavy score penalties, not minor notes - because they predict a report that fails when it matters.

// 05 Writing requirements that get real testing

Prevention beats correction: write the RFP so a scan can't win. Explicitly require: a named methodology and a stated manual-testing proportion; tester certifications and disclosure of any subcontracting; a redacted sample report as a mandatory submission; retesting included within the engagement; report mapping to your compliance framework (PCI, SOC 2, ISO 27001, or your GCC regulator); data-handling and residency terms; and a defined critical-finding escalation. Score against these, weight quality above price, and shortlist only compliant bids. Done this way, procurement gets what the organisation actually needs - a test that satisfies the auditor, survives a customer's scrutiny, and finds the flaws that matter - at a fair price among qualified providers. That's the version of “value” that holds up. For the buyer-side view, see how to choose a provider and how to scope.

// 06 Frequently asked questions

Why can't you buy pentesting on price alone?

Because quality varies enormously and price doesn't indicate it. Two quotes for the same test can mean a genuine engagement or a scan with a cover page - and the cheapest is frequently the scan, producing a report that fails to find breach-causing flaws and may be rejected by your auditor or a customer. Lowest price often means paying for something that doesn't do the job. Evaluate on quality first, with price a factor among qualified providers only.

What quality criteria should procurement use?

Methodology and manual-vs-automated split; tester qualifications and whether testing is subcontracted; a redacted sample report; whether retesting is included; data-handling and residency; ability to map the report to your framework; references; and clear scoping and communication. These reveal genuine testing. Compare price only among providers that clear these bars.

How do you compare proposals fairly?

Specify scope and requirements up front so vendors bid on the same work. Weight the evaluation toward quality (methodology, manual testing, qualifications, sample report, retesting, reporting) with price as one weighted factor. Insist every bidder provides a redacted sample report and states their manual-versus-automated approach - which separates genuine testers from scan resellers. A structured scorecard prevents the lowest bid winning by default.

What are the red flags in a bid?

Dramatically lower price and shorter timeline (usually a scan); refusal to provide a sample report; vague methodology or no named standard; no named testers or certifications; retesting as a separate paid engagement; unclear data-handling; and promising comprehensive testing for very little. A provider competing purely on cheapest and fastest is signalling shallow depth - weight these heavily rather than defaulting to the lowest number.

// 07 Related reading

UG

Usama Gul

Founder & Penetration Testing Lead, CyberFortify

Helps GCC procurement teams buy testing on quality, not just price — writing requirements a scan can't win, and welcoming the sample-report and manual-testing scrutiny that separates real providers from scan resellers.

Running a pentest RFP?

We welcome quality-first procurement — sample report, manual-testing detail, named testers, retesting and data terms in writing. Score us against the criteria that actually predict a good test.

Invite us to bid → The RFP template →