Blog · L.09 · Buying

15 questions to ask a penetration testing vendor

Every pentest quote looks similar on paper — and some of them hide a scanner with a cover page. The way to tell the real provider from the scan-and-invoice shop is to ask the right questions and listen for the right answers. Here are the 15 that matter, grouped by theme, each with the answer you want to hear and the red flag that should make you walk.

Vendor SelectionProcurementDue DiligenceRed FlagsBuying Guide
Ask about: Methodology · Testers & Certs · Manual vs Scan · Sample Report · Retesting · Data Handling · Regulatory Fit · Escalation · Insurance Ask about: Methodology · Testers & Certs · Manual vs Scan · Sample Report · Retesting · Data Handling · Regulatory Fit · Escalation · Insurance
// TL;DR

Ask a pentest vendor these, and listen for confident, specific answers: (1) methodology — which recognised standard; (2) manual vs automated split; (3–4) tester certifications & who actually tests; (5) a redacted sample report (the single most revealing ask); (6) how findings are graded; (7–8) retesting & remediation support; (9–10) data handling & residency; (11) critical-finding escalation; (12) regulatory fit to your framework; (13) references; (14) insurance & legal; (15) what's explicitly out of scope. The biggest red flags: won't share a sample report, can't name a methodology, unusually cheap/fast, and treats retesting as an add-on. Full list with ideal answers below; pair it with how to choose a provider.

// 01 Methodology & approach (Q1–2)

Q1 — “What methodology do you follow?” You want a named, recognised standard — OWASP (WSTG/MASVS), NIST SP 800-115, PTES — and a coherent explanation of their phases. Red flag: a vague “we use industry best practice” with nothing behind it. Q2 — “How much of the test is manual versus automated?” The answer should make clear that scanning is a starting point, and the value is human testing on top — chaining issues, probing business logic, bypassing controls. Red flag: a process that's essentially “run the scanner, format the output.” This one question exposes most scan-in-disguise providers.

// 02 The testers & the report (Q3–6)

Q3

Who tests?

Named, in-house testers — or silently subcontracted offshore? You want to know who touches your systems.

Q4

Certifications?

OSCP, CREST, GIAC and the like — evidence of real skill, not just a company logo.

Q5

Sample report?

The most revealing ask. A redacted sample shows the true quality of what you'll receive.

Q6

How graded?

Risk-based severity tied to real impact — not raw CVSS pasted from a scanner.

Q5 is the one to insist on. A provider proud of their work shares a redacted sample readily; the report reveals whether findings are genuine, whether remediation guidance is specific, and whether your auditor would accept it. Hesitation here is itself the answer — and you'll know a real report from a scanner dump at a glance.

// 03 Retesting & remediation (Q7–8)

Q7 — “Is retesting included?” This is where a report full of findings becomes proof you're now secure. You want retesting included, available for a reasonable window after the test, producing an updated report or attestation. Red flag: retesting billed as a whole second engagement. Q8 — “What remediation support do you offer?” A good provider will walk your team through findings on a readout call and answer questions as you fix — not disappear the moment the PDF lands. The difference between a vendor and a partner shows up entirely in what happens after the report.

// 04 Data handling, escalation & regulatory fit (Q9–12)

Q9–10 — data handling & residency: Where are your findings and the report stored, who can access them, how long are they retained, and does data stay in-region? A pentest report is a map of how to break into you, so this is not a formality — and for regulated GCC buyers, data residency can be decisive. Q11 — critical-finding escalation: if they find something actively exploitable mid-test, will they call you immediately, or bury it in the report weeks later? You want a defined escalation path. Q12 — regulatory fit: can they map the report to your framework — CBB, NCA, PCI DSS, ISO 27001? A generic report that ignores your regulator means rework at exactly the wrong time.

// 05 References, cover & scope (Q13–15)

Q13 — references: ask for clients in your sector or of your size; a confident provider offers them. Q14 — insurance & legal: confirm professional indemnity cover and a clear liability position — you're authorising someone to attack your systems, so the paperwork matters. Q15 — “What's explicitly out of scope?” A mature provider is clear about limits — what they won't test, what needs a separate engagement, where assumptions could leave gaps. Red flag: a vendor who claims to cover everything cheaply and quickly; that's not thoroughness, it's a scan. Taken together, these fifteen turn a lineup of look-alike quotes into a clear decision. For the wider selection framework, see how to choose a penetration testing company.

// 06 Frequently asked questions

What's the most important question to ask?

Ask to see a redacted sample report. It reveals whether they do genuine manual testing or re-badge a scan, how clearly they explain findings and impact, whether remediation guidance is actionable, and whether it would satisfy your auditor. A proud provider shares one readily; hesitation, or obvious scanner output with a cover page, tells you what you need to know.

How can I tell a real pentest from a scan?

Ask the manual-vs-automated split, ask for certifications and a sample report, and look for findings needing human insight — chained vulnerabilities, business-logic flaws, access-control bypasses no scanner reports. A real test proves impact by exploiting and chaining weaknesses. If the quote is unusually cheap and fast and the report is a list of CVEs with generic text, it's a scan in disguise.

Should I ask about retesting?

Always. Retesting verifies your fixes actually closed the findings — turning a list of vulnerabilities into evidence you're now secure, which auditors, insurers and customers want. Ask whether it's included, for how long after the test, and whether it produces an updated report or attestation. A provider who treats retesting as an expensive afterthought is a warning sign.

What data-handling questions should I ask?

Where findings, evidence and the report are stored and processed, who has access, retention period, and whether data stays in-region if your regulator requires it. A pentest report maps how to break into you, so provider data protection is critical. For regulated GCC organisations data residency can be decisive; a professional provider answers confidently and puts it in the contract.

// 07 Related reading

UG

Usama Gul

Founder & Penetration Testing Lead, CyberFortify

Answers these fifteen questions for GCC buyers every week — and encourages every prospect to ask them of us and our competitors, because the sample report and the retesting terms tell the real story.

Put these questions to us

Ask us all fifteen — and ask our competitors too. We'll share a redacted sample report, name our testers and certifications, and put retesting and data residency in writing.

Start the conversation → How to choose →