How to Pick a Good Pen Test Vendor

Every penetration test ends with a report. That is often the only thing two penetration tests have in common.

Two firms can quote the same engagement, deliver documents of similar length, and produce completely different value. One report is a repackaged vulnerability scan with the scanner's logo removed. The other reflects a skilled tester who chained three low-severity findings into full domain compromise and then showed your team exactly how to close the gap.

From the outside (especially before you have signed anything), those two vendors can look nearly identical. Here is how to tell them apart.

Start with who is actually doing the work

The single biggest driver of quality is the person doing the testing. Tools are largely the same across the industry. Talent is not.

Ask directly:

  • Who specifically will be testing my environment, and what is their experience?

  • Will the testing be performed in-house, or subcontracted?

  • Can I speak with the tester during the engagement, or only through a project manager?

A good vendor will answer plainly. If you cannot find out who is touching your network until the kickoff call, that tells you something.

Ask how much of the test is manual

Automated tools have a legitimate place. They are excellent at coverage and terrible at judgment. Business logic flaws, chained attack paths, authentication and authorization weaknesses, and privilege escalation almost always require a human.

Ask what percentage of the engagement is manual testing, and ask them to describe an attack chain they discovered that a scanner would have missed. The answer separates testers from tool operators very quickly.

Ask about methodology

A credible vendor should be able to describe the methodology they follow and explain it in plain language. What matters is not the acronyms, but whether they can describe a repeatable process rather than improvising.

Ask to see a sample report

This is the most revealing question you can ask, and it costs you nothing. Request a redacted sample and read it critically:

  • Is there an executive summary a non-technical leader could actually use?

  • Are findings prioritized by real business risk, or just sorted by CVSS score?

  • Does each finding include clear reproduction steps and specific remediation guidance?

  • Does it read like it was written for your environment, or like it was auto-generated?

If a vendor will not share a sample, ask yourself why.

Ask what happens after the report is delivered

Finding vulnerabilities is the easy part. Fixing them is the point.

Ask whether remediation guidance is specific or generic, whether your team can ask follow-up questions without a new statement of work, and—critically—whether retesting is included to verify the fixes actually worked. If retesting is a separate line item, understand what it costs before you sign, not after.

Ask how they scope

Good scoping is a conversation, not a form. A vendor should want to understand your environment, your threat model, what matters most to your business, and what you are trying to accomplish. Scoping shapes everything: effort, depth, and whether the test answers the question you actually have.

Red flags

Some warning signs are worth walking away from:

  • An instant quote with no scoping conversation. Nobody can price a meaningful test without understanding what they are testing.

  • A "penetration test" that is really a vulnerability scan. If the deliverable is scanner output with a cover page, you paid for the wrong thing.

  • No named testers. Accountability matters. So does knowing whether a senior tester or a first-week analyst is on your network.

  • Refusal to share a sample report. Reputable firms are proud of their reports.

  • Retesting that is unavailable or quietly expensive. Without verification, you have documentation, not improvement.

  • Guarantees. Nobody can guarantee compliance, or guarantee they will find every issue. Confidence is good; certainty is a sales tactic.

  • Heavy emphasis on AI or automation as the differentiator. Ask what the humans do. The answer should be substantial.

  • No secure file-sharing infrastructure, engagement planning process, or proof of insurance. These are basic professional hygiene.

  • A price far below everyone else. Penetration testing is skilled labor. Deep discounts usually mean fewer hours or less experienced people—one of the two.

Comparing quotes fairly

Vendors rarely quote the same thing, which makes side-by-side comparison misleading. Normalize the proposals before you compare:

  • How many days of actual testing effort are included?

  • What is the seniority of the people performing those days?

  • Is reporting time included in the quoted effort, or additional?

  • Is retesting included?

  • Is the scope truly identical across bids?

Once you normalize, the cheapest quote is often not the cheapest test—it is simply the smallest one.

The bottom line

You are not buying a document. You are buying expert attention on your environment and a clear path to reducing risk. The vendors worth hiring will welcome hard questions, because good answers are their advantage.

Ask the questions. The right partner will be glad you did.

Terry Bradley, CISSP, is the President and Founder of Mile High Cyber, with over 30 years of experience in cybersecurity. A CISSP since 2008, he specializes in penetration testing, vulnerability management, and virtual CISO services, helping small and mid-sized organizations identify, remediate, and verify their most critical security risks.

Next
Next

AI Wrote Your Code. Who’s Testing Its Security?