Buyer's guide
How to compare penetration testing companies before you sign
Penetration testing companies often send quotes that look identical but buy very different work. This guide shows the five questions that separate them, including the ones most firms prefer you did not ask.
- Named tester before day one
- One retest within 30 days
- OWASP WSTG and NIST SP 800-115
Why quotes from penetration testing companies differ so much
Two quotes can name the same target and still differ several times over. Usually the gap comes from one of four things: manual hours, tester seniority, whether a retest is included, and how tightly the scope is written. So compare those, not the headline price.
Five questions to ask penetration testing companies
Send the same questions to every firm. Their answers make the comparison fair.
- How many hours of manual testing are included?
- Who will test, and what credentials do they hold?
- Is a retest included, and within what window?
- Which published method do you follow?
- Can we see a redacted sample report?
If a firm cannot say how many manual hours you are buying, that is the answer.
Score the penetration testing companies on your shortlist
Tick each item a firm answered clearly. Use it once per proposal.
Your result appears here as you tick, so you can see what is still open.
Warning signs in a proposal
Some signs are easy to spot once you know them. For example, a price far below the market for the scope, a report delivered in a day, or a findings list that reads like a tool export.
| Sign | What it usually means |
|---|---|
| Price under $4,000 for a real app | An automated scan sold as a test. |
| No named tester | Work assigned to whoever is free. |
| Retest charged separately | A second invoice after the first report. |
| Promise to find everything | Nobody can; it is a sales line. |
How we answer the same questions
We are one of many penetration testing companies, so here are our own answers. Testing is performed by vetted independent practitioners under contract, and we name yours before day one. The method follows OWASP WSTG and NIST SP 800-115. One retest inside 30 days is included. We are not a CREST-accredited company, and we never describe a test as certified.
Choosing between penetration testing companies
Pick the firm whose scope matches the requirement you were given, whose testers you can name, and whose report your auditor will accept. Price matters, but it comes after those three. Otherwise, a low-priced test that fails an audit costs twice.
Questions about choosing penetration testing companies
Are big penetration testing companies always better?
Not necessarily. Large firms often charge two to three times more for similar testers. What matters is the named person and the hours.
Should the auditor also do our test?
No. Independence rules stop the firm auditing you from also testing you, so a separate firm is normal.
What credentials should testers hold?
Common ones are OSCP, CREST CRT or CCT, and GXPN. They belong to people, not to firms or tests.
How many penetration testing companies should we ask?
Three is usually enough, provided each answers the same five questions.
Related guides
Send us the same five questions
Ask us exactly what you ask other penetration testing companies. We answer in writing with a scope and a fixed fee.
Get my estimate