The pentest market is opaque. The same label is used by an enthusiast running an automated scanner and by a team of certified specialists — both call it a "penetration test". Here is how to tell them apart before you sign.
Why vendor selection is so hard
Penetration testing is a field where a layperson essentially cannot judge quality up front. The vendor presents certifications and a nice website, but you only see the real work in the output — and by then you've already paid. Worse, the barrier to entry is low: anyone can download an open-source scanner and forward its output. The gap between that and honest manual work is enormous.
The good news: a handful of signals reliably separate professionals from people just reselling tool output. Let's walk through them.
Signal 1: They ask more than they promise
The best filter shows up immediately. A good vendor asks questions: which systems, why you're testing, what's critical, what the environment is, what depth you expect. They want to refine the scope before quoting.
A bad vendor sends a flat "web pentest for $X" by return mail without a single question. That means they're selling a pre-packaged product, not a service tailored to your risk. In security, a generic package is a warning sign.
Signal 2: They can explain their methodology
Ask directly: "What methodology do you follow?" A professional will, without hesitation, point to established frameworks such as OWASP (for web and API), PTES, OSSTMM or MITRE ATT&CK, and explain what that means in practice.
If the vendor answers vaguely, only talks about "advanced tools", and cannot name a methodology, it's likely their process is to run a scanner and forward the output.
Signal 3: Ratio of manual to automated work
Ask how much of the test is manual. Automated scanners are useful for initial mapping, but real value comes from a tester who manually verifies, chains vulnerabilities and finds logic flaws no tool can catch.
If the answer is mostly automated scanning with minimal manual work, you're paying for something you could run yourself for a fraction of the price. A vendor who describes how they manually verify findings and eliminate false positives knows what they're doing.
Signal 4: Quality of the sample report
This is the single strongest test. Ask for an anonymised sample report. A good report has:
- an executive summary understandable to leadership and a detailed technical section for specialists,
- proof of exploitability for every finding — not just an assertion,
- findings prioritised by real risk in your context, not just sorted by raw scanner score,
- concrete, actionable remediation — not platitudes like "update your software".
If the vendor refuses to share a sample, or sends a few pages exported from a scanner, you have your answer.
Signal 5: Certifications and team qualification
Certifications aren't everything, but they're a useful indicator. For individuals, ask about recognised certs like OSCP, OSWE, CRTO, GPEN or CEH. For a firm, an accreditation like CREST may matter — especially if you need the test for a demanding regulation.
What matters is who actually performs the test. Ask specifically about the people assigned to your project, not just "the firm has certified specialists". The seniority and certifications of the tester who does your work are what count.
Signal 6: A clear contract, insurance and NDA
You're giving the vendor permission to attack your systems and access sensitive information. A professional takes that seriously and will have:
- a contract and explicit written authorisation to test (authorisation letter) protecting both sides,
- an NDA as a matter of course,
- liability insurance in case something is damaged during the test,
- a clearly agreed critical-finding escalation process — who notifies whom, how quickly, before the report is even written.
A vendor who waves away contractual handling is a risk in themselves.
Signal 7: What happens after the test
The test does not end when the report is delivered. Ask:
- Is a retest included to verify you've fixed the findings? (Often billed separately — ask up front.)
- Do they offer a consultation on the output, walking you through findings and helping prioritise fixes?
- Will they talk to your developers during remediation?
A vendor playing the long game offers these things. One who just wants to invoice and move on hands over a PDF and is done.
Red flags in one place
Be wary if the vendor:
- quotes a price without any scope questions,
- is significantly cheaper than the rest (almost certainly proposes a shallower scope),
- cannot name a methodology,
- refuses a sample report,
- guarantees they will "find everything" or that you'll be "100% secure" (no serious tester ever promises this),
- resists contracts, authorisation letters and NDAs,
- can't tell you who specifically will do the test.
The five questions that decide it
If you have time for nothing else, ask these five questions and listen to how the vendor answers:
- What methodology do you follow and how much is manual?
- Can I see an anonymised sample report?
- Who specifically will run our test and what's their qualification?
- What happens if you find a critical vulnerability during the test?
- Is retest and post-test consultation included in the price?
How confidently, concretely and clearly the vendor answers will tell you more than their entire website.
Comparing vendors is hard when each one sends a quote in a different format. TrustScope lets you reach out to vendors with one structured brief and get comparable proposals back — so you pick on substance, not packaging.