How to choose a penetration testing company
Penetration testing companies tend to describe themselves in the same words, so the differences have to be found by asking. This guide is meant to be useful whoever you hire: what actually varies between firms, the questions that expose it, the red flags, and how to compare quotes so that you are choosing between equivalent tests.
Key takeaways
- Most of what separates one penetration testing company from another is who does the testing and what they hand back. Ask who will lead your test, and ask to see a report.
- Individual certifications describe a person, company accreditations such as CREST and CHECK describe a firm, and Cyber Essentials and ISO 27001 certification describe how a supplier protects itself. The company-level ones can all be checked independently.
- A ranked list of the best penetration testing companies cannot see your scope. The right firm for a multi-tenant SaaS API can be the wrong one for an internal Active Directory network.
- A price offered before anybody asks what you built is a price for a scan, whatever the proposal calls it.
- Send every supplier the same written scope, then compare scope statements, testing days and retest terms before you compare totals.
- A good engagement does not end with the report. It ends with a dated retest verdict on every finding you fixed.
What actually differs between penetration testing companies
The words penetration test cover both an automated scan with a report template around it and a fortnight of manual work by a senior tester, and both are sold in the same vocabulary: manual testing, certified testers, actionable reports. So the differences between penetration testing firms are rarely in what they say about themselves. They sit in five places.
- The people. Who is actually assigned to your engagement, their experience with systems like yours, and whether the firm employs them or passes the work on.
- How much of the work a person does. Every competent tester uses tooling for coverage. What varies is whether a person then works through the authorisation model with several accounts and confirms each finding by hand, which is where access control and business logic flaws are found and where tools are weakest.
- What you receive. Findings with evidence, reproduction steps and remediation written for your stack, or a list that reads like a scanner export.
- What happens after the report. Whether verifying your fixes is included, and whether it means a person repeating the original steps or a rescan.
- How the work is delivered and priced. A document at the end or findings as they are confirmed, and a day rate or a fixed price.
Size is not on the list, on purpose. A large firm has more specialists, a small one is more likely to put the person who scoped the work on it, and either can give you the wrong tester.
Why a ranked list cannot choose for you
Search for the best penetration testing companies and most of what comes back is ranked lists. They are a reasonable way to find names and a poor way to choose, for three reasons.
- A list cannot see your scope. A multi-tenant SaaS API, an internal Active Directory network and a mobile banking app call for different skills, and a firm that is excellent at one can be ordinary at another.
- A list ranks firms, and you are buying people. The same firm can send its most experienced tester or its newest, and no ranking tells you which.
- You usually cannot see how the list was made. If the method is not published, or the publisher appears on the list, it tells you more about the publisher than about the firms.
Use lists to find names if they help. Then shortlist on the questions below, which no list can answer and a good supplier can answer in one call.
The questions to ask, and what a good answer sounds like
Ask every supplier the same questions, ideally in writing, so the answers can be laid side by side. A good answer is specific and checkable. A weak one is a reassurance.
| Question | A good answer sounds like | Be wary of |
|---|---|---|
| Who will do the testing? | The lead tester by name, their experience with systems like yours, and whether the team are employees or subcontractors. | A team of experts, never named. Work passed to another firm unannounced. |
| What certifications and accreditations do you hold? | Certifications held by the people on your engagement, the firm's accreditations listed separately, all checkable. | Credentials nobody on your engagement holds. Audit or management certificates offered as testing ones. |
| Which methodology do you follow? | Named standards, ideally with versions, such as the OWASP Web Security Testing Guide, applied to your system. | A proprietary methodology that cannot be described. |
| How is a finding confirmed before it is reported? | A person reproduces or exploits it, and the report carries the request and response or screenshots that prove it. | Unverified tool output included for completeness. |
| Can we see a sample report? | A redacted real report, or one written against a test environment, with the findings complete. | A brochure, or a summary with the findings taken out. |
| Is a retest included, and what is it? | Included, done by hand on each finding you fixed, with a dated verdict on each and clear terms for requesting it. | Billed as new work, or a rescan presented as a retest. |
| How is the price set, and what is excluded? | Priced on scope after questions about your system, exclusions in writing, and a clear answer on what happens if more attack surface turns up. | A figure before any questions. Extra days billed with no ceiling. |
| How will you protect our data, and what insurance do you carry? | Where evidence is stored and who sees it, how credentials are exchanged, when data is destroyed, nothing published without consent, and professional indemnity (errors and omissions) cover with a certificate. | Credentials sent by email. No answer on insurance. |
| What happens if you find something critical, or something breaks? | Written rules of engagement, named contacts on both sides, an out-of-hours escalation route, and a way to stop the test at once. | It will be in the report. |
Who will do the testing
Choosing a penetration testing vendor is mostly choosing people, and the UK National Cyber Security Centre's guidance on commissioning a test says as much: third-party testing should be done by qualified and experienced staff only. Some firms employ all their testers, some subcontract to freelancers or other firms, and some platforms route work to independent researchers. Any of these can produce good work, provided you know which you are buying, the lead tester is named before testing starts, and the same confidentiality terms bind everyone who touches your systems.
Ask what the lead tester has worked on recently that resembles your system, and expect an answer that describes the work without naming the client. Public work such as credited vulnerability disclosures or published research is checkable in a way a claim is not, though its absence proves nothing, because much good testing is done under NDA.
Certifications, accreditations and what each one proves
Three kinds of credential appear on penetration testing firms' websites, often side by side, and each answers a different question.
Individual certifications describe a person
Certifications such as OSCP, or CREST's CRT and CCT, are earned by individuals through exams that test practical skill; OSCP, for example, gives the candidate a time-limited lab of machines to compromise and a report to write. A firm will often list what its team holds between them, which is fine as far as it goes, but what matters is what the people on your engagement hold.
Not every respected qualification is a testing one. CISSP and CISA are well-regarded certifications in security management and IT audit, but neither examines whether somebody can break into a system, and a firm presenting them as evidence of testing ability has either missed the difference or hopes you will.
Company accreditations describe the firm
CREST, a not-for-profit body operating internationally, accredits member companies for named services, penetration testing among them, after assessing how each company works, and separately certifies individuals. Its public Marketplace lists each member and the services it is accredited for, and the detail matters: accreditation for one service is not accreditation for another.
CHECK is narrower. It is the NCSC's scheme under which assured companies test central government, public sector and critical national infrastructure systems, using testers who hold UK Cyber Security Council security testing titles and security clearance. The NCSC lists every CHECK provider, and says organisations outside the public sector do not need one.
If you take card payments, PCI DSS does not require your tester to be a QSA (a firm qualified to assess compliance with the standard) or an ASV (a firm approved by the PCI Security Standards Council to run the external vulnerability scans under requirement 11.3.2). Neither is a penetration testing credential, and the PCI DSS guide explains the difference.
Organisational certifications describe how a supplier protects itself
Cyber Essentials is the minimum standard of security the UK government recommends for organisations of all sizes, covering five technical controls, and Cyber Essentials Plus adds independent technical testing of them. ISO/IEC 27001 certification means a certification body has audited the organisation's information security management system; ISO itself certifies nobody, and the certificates worth relying on come from an accredited certification body. Both bear on how a supplier will look after your data. Neither says whether it can test your systems.
Precision matters most with ISO 27001. A person can hold a Lead Auditor or Lead Implementer qualification while their company holds no certification at all, and a firm whose website blurs the two is making the larger claim on the strength of the smaller one.
Every company-level credential here can be checked: on the CREST Marketplace, the NCSC's list of CHECK providers, the Cyber Essentials certificate search that IASME runs for the NCSC, and for ISO in IAF CertSearch or with the issuing certification body, where the certificate's scope shows which parts of the business it covers. A firm that holds what it claims will expect you to look.
Red flags
Any one of these is a reason to ask a harder question. Two or three together are usually a reason to move on.
Scanner output sold as a penetration test
Automated scanning is useful. Selling it as a penetration test is not. The signs are a price offered before anybody asks about your user roles, a turnaround measured in hours, and a sample report made mostly of configuration findings such as missing headers and weak cipher suites. Be as wary of the opposite claim: every competent tester uses tooling, so a firm promising 100 per cent manual testing is misdescribing its own process.
Certification claims that do not hold up
An accreditation missing from its register, certifications nobody on your engagement holds, audit qualifications sold as testing ones, one person's ISO 27001 qualification presented as the company's certification: each takes a minute to check, and each tells you how carefully the rest of the proposal was written.
A fixed price with no scoping conversation
A fixed price is a good thing when it is fixed after the supplier understands the work. Offered before any questions, it is either a price for a standard scan or a number that a change request will revisit once the real scope emerges. The cost guide explains why questions about your roles, your API and your environment are the ones that move the number.
No explanation of the deliverable
If a supplier cannot show you a sample report, redacted or written against a test environment, or explain what a finding will contain, you are being asked to buy the one thing you are certain to receive without seeing it. Judge any sample against what a good finding contains: could your engineer reproduce and fix it without a meeting?
Pressure to buy a bundle
Programmes combining testing with monitoring, or several tests a year, can be good value when you need what is in them. The red flag is pressure: a discount that expires this week, a retest included only with the annual plan, a scope that grows to fit the package. A good supplier quotes the test you asked for and explains anything else it recommends.
Promises about the outcome
Nobody can promise a number of findings before testing, or that a report will get you through an audit. A test is evidence that may support an assessment, not a certification, and your assessor decides what satisfies the standard. A supplier that guarantees an outcome either does not understand that or is counting on you not to.
How to compare quotes like for like
Comparing penetration testing providers on price only works when the quotes describe the same test, and by default they rarely do.
The most common mistake
Sending a one-line request to several suppliers and choosing the lowest number. Each supplier scopes a vague request differently, so the quotes describe different tests, and the cheapest is usually the one that scoped least. Fix the scope first, and the comparison becomes one between suppliers rather than between their guesses.
- Write the scope once and send the same brief to every supplier; the scoping guide ends with one you can send in a single message. Two or three suppliers quoting against it is usually enough.
- Ask each proposal to restate the scope in its own words: targets, roles, environment, approach and exclusions. Disagreement with your brief is far cheaper to find before signing.
- Lay the proposals out on the same rows: scope, testing days and who does them, methodology, deliverables, retest terms, exclusions, data handling, insurance and price. A blank is a question to send back, not a point in that supplier's favour.
- Read the scope statements before the totals. Where one quote is much lower, find the line that explains it. It is usually a missing retest, a narrower scope or fewer days.
- Compare one finding from each sample report side by side, and speak to the person who would lead the test, not only to sales. Between them, they are the closest you will get to seeing the work before you pay for it.
What a good engagement looks like, from scoping to retest
Whoever you hire, a good engagement has roughly this shape, and knowing it makes a skipped step easier to spot.
- A scoping conversation in which the supplier asks more than it tells: what the system does, which roles exist, what is out of scope, and who is asking for the test and by when.
- A proposal that states the scope as targets rather than descriptions, with the approach, testing days, lead tester, methodology, deliverables, retest terms and price.
- Paperwork before any testing: a contract, confidentiality terms, a data processing agreement where personal data is involved, and rules of engagement signed by somebody with the authority to approve the test.
- Access arranged before day one: a working test account for every role, and credentials exchanged through something better than email.
- Testing with a channel open: critical findings escalated when confirmed rather than held for the report, and a tester you can question while the work happens. The NCSC guidance accepts that no tester can guarantee a system will not react unexpectedly, which is why the way to stop the test has to work at two in the morning.
- A report in which every finding carries evidence, a severity with its reasoning, and remediation your engineers can act on.
- A retest: a person repeating the original steps against each finding you fixed, with a dated verdict recorded against each. That record is what an auditor or customer goes on to ask for, as the audit evidence checklist explains.
- A clear ending: what the supplier keeps after the engagement, for how long and why, and confirmation when the rest has been destroyed.
If you are weighing us against other penetration testing companies, hold us to the same questions. Our methodology, rules of engagement and the questions we ask before quoting are published on how we test.
Keep reading
- How to scope a penetration testThe written brief to send every supplier, and the scoping mistakes that make quotes impossible to compare.
- What a penetration test costsWhat moves the number, and what is usually missing from the cheaper quote.
- How to read a penetration test reportWhat a good finding contains, so you can judge a sample report before you buy.
- The audit evidence checklistWhat a report has to contain before an auditor will accept it, framework by framework.