A penetration testing RFP (request for proposal) makes providers answer the same questions in the same structure, so you compare on substance and get accurate quotes. Include nine sections: organisation overview, scope, test type & depth, required methodology, tester credentials, deliverables (report + retest + attestation letter), timeline, commercials, and legal/insurance/data-handling. Bake in the questions that separate real testing from a scan — percentage manual, named testers' certifications, sample report. Precise scope produces precise, comparable proposals; vague scope produces guesswork. The template below is ready to adapt.
// 01 Why bother with an RFP
You can email three firms "how much for a pentest?" and get three numbers you can't compare, because each scoped something different. An RFP fixes that. It does three things: it forces you to define scope up front (which sharpens the quotes and prevents nasty scope surprises later), it forces providers to answer identical questions in a comparable format, and — for regulated or larger buys — it creates an auditable selection trail. Even a one-page RFP lifts the quality of the responses and your decision. It doesn't need to be bureaucratic; it needs to be consistent.
// 02 The template, section by section
Organisation & objective
Who you are, your sector, and why you're testing — compliance driver, customer requirement, pre-launch, or risk reduction. Context shapes the right approach.
Scope
Systems, applications, IP ranges, user roles, API count, environment (production/staging). Enough for accurate scoping; sensitive detail follows an NDA.
Test type & depth
Target (web, API, network, cloud, mobile), perspective (external/internal), and knowledge level (black/grey/white box).
Methodology
Require a named standard — PTES, OWASP WSTG/MASVS, NIST — and MITRE ATT&CK mapping. Ask what's manual vs automated.
Team & credentials
Who will test, their certifications (OSCP, OSWE, CREST, GIAC), sector experience, and company accreditations. In-house or subcontracted?
Deliverables
Report format and sample, contextual risk ranking, remediation guidance, a retest, and a shareable attestation letter.
Timeline
Your required dates and any compliance deadline, plus their lead time, testing duration and reporting turnaround.
Commercials
Pricing structure, what's included and excluded, retest cost, and day-rate for scope changes. Ask for a fixed price against the defined scope.
Legal & assurance
Professional indemnity insurance, data-handling and confidentiality, authorisation process, and how they handle a critical or active-compromise finding.
// 03 The questions that expose a scan-in-disguise
Embed these directly in the RFP — the answers separate genuine human-led testing from an automated scan sold at pentest prices:
- What proportion of the engagement is manual versus automated scanning?
- Who specifically will perform our test, and what are their certifications?
- Can we see a redacted sample report?
- How do you test business logic that scanners can't understand?
- Is a remediation retest and attestation letter included?
- What's your process if you find a critical vulnerability or an active compromise mid-test?
Vague answers, no sample report, or heavy reliance on scanning are the red flags. Our 20 questions to ask a penetration testing company expands this into a full scorecard you can attach.
// 04 Common RFP mistakes to avoid
| Mistake | Fix |
|---|---|
| Vague scope ("test our website") | Specify apps, roles, size, environment, perspective |
| Price-only comparison | Weight methodology, credentials and deliverables too |
| No sample report requested | Always ask — it's the clearest quality signal |
| Ignoring the retest | Require it — "fixed" should mean verified |
| Leaving out the deadline | State the compliance date so timelines are realistic |
| Over-disclosing in the RFP | Keep sensitive detail for post-selection, under NDA |
// 05 Getting the scope right
Scope is where an RFP succeeds or fails, because it drives both the price and the value. Give providers enough to quote accurately — number and type of applications, approximate size (endpoints, IPs, user roles, API count), environment, and perspective — without over-disclosing architecture or credentials, which belong in the post-selection phase under an NDA. If you're unsure what your framework requires you to test, our requirements finder maps it, and the cost guide explains what drives the price. Precise scope in, precise and comparable proposals out.
// 06 Frequently asked questions
What should a penetration testing RFP include?
Organisation overview and reason for testing; scope (systems, apps, IPs, roles, environment); test type and depth; required methodology and standards; tester credentials and accreditations; deliverables (report, retest, attestation); timeline and any compliance deadline; commercials; and legal, insurance and data-handling terms. Clear scope and consistent questions make proposals comparable.
Why use an RFP?
It forces providers to answer the same questions in the same structure so you compare fairly, makes you define scope up front (improving quote accuracy and preventing scope surprises), and creates an auditable selection trail for regulated buys. Even a lightweight RFP raises the quality of proposals and decisions.
What questions expose a scan reseller?
Percentage manual vs automated; who specifically tests and their certifications; whether you can see a sample report; how they test business logic; whether a retest and attestation are included; and how they handle a critical or active-compromise finding. Vague answers, no sample report, or heavy scanning reliance are the red flags.
How much scope detail should the RFP have?
Enough for accurate scoping without unnecessary exposure: number and type of apps/systems, approximate size, environment, test perspective, and compliance drivers. Keep credentials and architecture for post-selection under NDA. Precise scope produces precise, comparable quotes.
// 07 Related reading
- How to choose a penetration testing company: 20 questions — attach it to your RFP.
- How much does penetration testing cost? — what drives the price.
- Requirements finder — scope to your framework.