Blog · L.07 · Buying Asset

Penetration testing RFP template: what to ask and include

A vague request gets vague, incomparable quotes — and often a scan dressed up as a pentest. A well-built RFP forces every provider to answer the same questions the same way, so you compare them on substance, not gloss. Here's the template, section by section.

RFPProcurementScopingVendor SelectionTemplate
RFP Sections: Overview · Scope · Test Type & Depth · Methodology · Credentials · Deliverables (report + retest + attestation) · Timeline · Commercials · Legal RFP Sections: Overview · Scope · Test Type & Depth · Methodology · Credentials · Deliverables (report + retest + attestation) · Timeline · Commercials · Legal
// TL;DR

A penetration testing RFP (request for proposal) makes providers answer the same questions in the same structure, so you compare on substance and get accurate quotes. Include nine sections: organisation overview, scope, test type & depth, required methodology, tester credentials, deliverables (report + retest + attestation letter), timeline, commercials, and legal/insurance/data-handling. Bake in the questions that separate real testing from a scan — percentage manual, named testers' certifications, sample report. Precise scope produces precise, comparable proposals; vague scope produces guesswork. The template below is ready to adapt.

// 01 Why bother with an RFP

You can email three firms "how much for a pentest?" and get three numbers you can't compare, because each scoped something different. An RFP fixes that. It does three things: it forces you to define scope up front (which sharpens the quotes and prevents nasty scope surprises later), it forces providers to answer identical questions in a comparable format, and — for regulated or larger buys — it creates an auditable selection trail. Even a one-page RFP lifts the quality of the responses and your decision. It doesn't need to be bureaucratic; it needs to be consistent.

// 02 The template, section by section

01

Organisation & objective

Who you are, your sector, and why you're testing — compliance driver, customer requirement, pre-launch, or risk reduction. Context shapes the right approach.

02

Scope

Systems, applications, IP ranges, user roles, API count, environment (production/staging). Enough for accurate scoping; sensitive detail follows an NDA.

03

Test type & depth

Target (web, API, network, cloud, mobile), perspective (external/internal), and knowledge level (black/grey/white box).

04

Methodology

Require a named standard — PTES, OWASP WSTG/MASVS, NIST — and MITRE ATT&CK mapping. Ask what's manual vs automated.

05

Team & credentials

Who will test, their certifications (OSCP, OSWE, CREST, GIAC), sector experience, and company accreditations. In-house or subcontracted?

06

Deliverables

Report format and sample, contextual risk ranking, remediation guidance, a retest, and a shareable attestation letter.

07

Timeline

Your required dates and any compliance deadline, plus their lead time, testing duration and reporting turnaround.

08

Commercials

Pricing structure, what's included and excluded, retest cost, and day-rate for scope changes. Ask for a fixed price against the defined scope.

09

Legal & assurance

Professional indemnity insurance, data-handling and confidentiality, authorisation process, and how they handle a critical or active-compromise finding.

// 03 The questions that expose a scan-in-disguise

Embed these directly in the RFP — the answers separate genuine human-led testing from an automated scan sold at pentest prices:

Vague answers, no sample report, or heavy reliance on scanning are the red flags. Our 20 questions to ask a penetration testing company expands this into a full scorecard you can attach.

// 04 Common RFP mistakes to avoid

MistakeFix
Vague scope ("test our website")Specify apps, roles, size, environment, perspective
Price-only comparisonWeight methodology, credentials and deliverables too
No sample report requestedAlways ask — it's the clearest quality signal
Ignoring the retestRequire it — "fixed" should mean verified
Leaving out the deadlineState the compliance date so timelines are realistic
Over-disclosing in the RFPKeep sensitive detail for post-selection, under NDA

// 05 Getting the scope right

Scope is where an RFP succeeds or fails, because it drives both the price and the value. Give providers enough to quote accurately — number and type of applications, approximate size (endpoints, IPs, user roles, API count), environment, and perspective — without over-disclosing architecture or credentials, which belong in the post-selection phase under an NDA. If you're unsure what your framework requires you to test, our requirements finder maps it, and the cost guide explains what drives the price. Precise scope in, precise and comparable proposals out.

// 06 Frequently asked questions

What should a penetration testing RFP include?

Organisation overview and reason for testing; scope (systems, apps, IPs, roles, environment); test type and depth; required methodology and standards; tester credentials and accreditations; deliverables (report, retest, attestation); timeline and any compliance deadline; commercials; and legal, insurance and data-handling terms. Clear scope and consistent questions make proposals comparable.

Why use an RFP?

It forces providers to answer the same questions in the same structure so you compare fairly, makes you define scope up front (improving quote accuracy and preventing scope surprises), and creates an auditable selection trail for regulated buys. Even a lightweight RFP raises the quality of proposals and decisions.

What questions expose a scan reseller?

Percentage manual vs automated; who specifically tests and their certifications; whether you can see a sample report; how they test business logic; whether a retest and attestation are included; and how they handle a critical or active-compromise finding. Vague answers, no sample report, or heavy scanning reliance are the red flags.

How much scope detail should the RFP have?

Enough for accurate scoping without unnecessary exposure: number and type of apps/systems, approximate size, environment, test perspective, and compliance drivers. Keep credentials and architecture for post-selection under NDA. Precise scope produces precise, comparable quotes.

// 07 Related reading

UG

Usama Gul

Founder & Penetration Testing Lead, CyberFortify

Responds to penetration testing RFPs across the GCC and helps buyers write ones that produce comparable proposals and surface genuine, human-led testing.

Have an RFP to send?

Send it our way. We'll respond with named testers and their certifications, our methodology, a sample report, and a fixed price against your scope — everything your RFP should ask for.

Submit your RFP → The 20 questions →