10 Questions to Ask Before Hiring a Pentest Company
Most penetration testing quotes look identical on paper: a scope, a timeline, a price. The difference between a vendor who finds the vulnerability a real attacker would use and one who hands you a scanner printout with a logo on it only shows up in how they answer questions before you sign anything.
Three questions expose weak vendors fastest: whether they can describe a real attack scenario specific to your industry, not a generic checklist, whether they will show you a sanitised sample report before you commit, and whether retesting after you fix issues is included or billed separately. If a vendor hesitates on any of those three, that is worth noticing before you go further.
Below are all 10 questions worth asking before choosing penetration testing services, what a strong answer sounds like, and what a red flag sounds like.
- The 10 Questions to Ask a Penetration Testing Vendor
- 1. What's a real attack scenario you'd specifically test for a business like ours?
- 2. Which testing methodology do you follow?
- 3. Can you share a sanitised sample report?
- 4. What certifications do your individual testers hold, not just the company?
- 5. Is the testing manual, automated, or both?
- 6. Is retesting included after we fix the issues you find?
- 7. What is your pricing model, and what's excluded?
- 8. How do you avoid conflicts of interest if you also sell security tools or managed services?
- 9. How do you handle scope changes and safety during testing?
- 10. What happens if you find a critical vulnerability mid-test?
- Pricing Transparency: What Should Be Itemised in a Quote
- Ask for a Sample Report Before You Sign Anything
- Vendor Scorecard: A Quick-Reference Summary
- FAQs
- Ask us these 10 questions
The 10 Questions to Ask a Penetration Testing Vendor
Each question below includes what a strong answer sounds like and what a red flag sounds like, so you can score vendors on the spot rather than guessing after the call.
1. What’s a real attack scenario you’d specifically test for a business like ours?
Why it matters: this separates vendors who understand your industry from vendors running the same generic checklist on every client.
Good answer: they describe a specific business-logic scenario tied to your sector, such as a discount-code abuse path for e-commerce, a patient-record access flaw for health-tech, or a payment-flow manipulation for fintech.
Red flag: they immediately list generic vulnerability categories without connecting them to how your business actually operates.
2. Which testing methodology do you follow?
Why it matters: methodology determines depth and repeatability, not just a marketing checkbox.
Good answer: a named standard such as the OWASP Testing Guide or PTES, with a brief explanation of how it shapes their actual day-to-day process.
Red flag: a vague reference to industry best practices with no named framework behind it.
3. Can you share a sanitised sample report?
Why it matters: a sample report tells you more about a vendor’s actual output quality than any sales conversation will.
Good answer: they can send one within a day, and the methodology section actually describes what was tested rather than what could, in theory, be tested.
Red flag: reluctance, delay, or a report that is mostly marketing pages with a short findings list at the back.
4. What certifications do your individual testers hold, not just the company?
Why it matters: company-level accreditation does not guarantee the person testing your systems is individually qualified.
Good answer: named, verifiable individual certifications tied to the specific tester assigned to your engagement, not just a general company credential list.
Red flag: only company-level marketing claims, with no individual credentials offered.
5. Is the testing manual, automated, or both?
Why it matters: automated scanning alone misses business-logic flaws and chained vulnerabilities that only a human tester finds.
Good answer: automated tools are used for coverage, but manual testing is the core of the engagement, with a clear explanation of where a human takes over.
Red flag: heavy emphasis on tooling and dashboards, with little description of actual manual testing effort.
6. Is retesting included after we fix the issues you find?
Why it matters: a report full of unverified fixes is not proof that anything was actually resolved.
Good answer: retesting is built into the standard engagement rather than sold as a separate add-on. CyberSapiens, for example, includes a free remediation retest as part of every VAPT engagement.
Red flag: retesting is offered only as a new, separately priced engagement.
7. What is your pricing model, and what’s excluded?
Why it matters: the cheapest quote is often cheapest because it excludes manual testing depth, retesting, or a proper report.
Good answer: a clear breakdown of what is included, such as scoping, testing, reporting and retest, and what would trigger additional cost, such as scope changes or extra environments.
Red flag: a single flat number with no explanation of what is actually covered.
8. How do you avoid conflicts of interest if you also sell security tools or managed services?
Why it matters: a vendor selling you a firewall should not also be the one grading how well that firewall performs.
Good answer: a clear statement of independence, or a disclosure of any overlap and how it is managed.
Red flag: the question is brushed off as irrelevant.
9. How do you handle scope changes and safety during testing?
Why it matters: production environments need clear rules of engagement so testing does not cause an outage.
Good answer: a written rules-of-engagement document covering approved testing windows, environments, and an escalation process if something unexpected happens, in line with guidance such as NIST SP 800-115.
Red flag: no formal scoping document, with testing starting based on a verbal agreement only.
10. What happens if you find a critical vulnerability mid-test?
Why it matters: a critical finding sitting in a report you receive three weeks later is a critical finding an attacker had three weeks to find first.
Good answer: an immediate, real-time notification process for critical findings, kept separate from final report delivery.
Red flag: “you will see it in the final report,” with no mention of interim escalation.
Pricing Transparency: What Should Be Itemised in a Quote
The cheapest quote in a stack of proposals is rarely the cheapest option once you account for what it does not include. Ask every vendor to break their quote down before comparing prices side by side.
Four components should be itemised separately: scoping and planning, the testing itself, reporting, and retesting. A quote that bundles all four into one number without itemising them is harder to compare honestly against one that does.
Ask for a Sample Report Before You Sign Anything
Question 3 above is worth its own section because it is the fastest way to evaluate a vendor without waiting for the engagement to finish. A sample report shows you exactly how findings are explained, how severity is scored, and whether the recommendations are specific enough to actually act on.
CyberSapiens publishes real, sanitised sample reports rather than asking you to request one and wait. A free web application VAPT sample report and a free network VAPT sample report are both available to download now, with no engagement required.
If a vendor cannot produce something similar within a day of asking, that hesitation tells you more than their sales deck ever will.
Vendor Scorecard: A Quick-Reference Summary
Save or screenshot this table and use it while you are actually on a call comparing vendors.
| Question | Good sign | Red flag |
|---|---|---|
| Attack scenario | Industry-specific, business-logic example | Generic vulnerability list only |
| Methodology | Names a standard (OWASP, PTES, NIST 800-115) | Industry best practices, no specifics |
| Sample report | Available within a day, detailed | Delayed, mostly marketing content |
| Tester certifications | Named, individual, verifiable | Company-level claims only |
| Testing approach | Manual-led, automation for coverage | Mostly automated, minimal manual description |
| Retesting | Included in the engagement | Separately priced add-on |
| Pricing | Itemised by phase | One flat number, no breakdown |
| Independence | Clear statement or disclosure | Question brushed off |
| Scoping | Written rules of engagement | Verbal agreement only |
| Critical findings | Real-time escalation | Final report only |
FAQs
How much should a penetration test cost?
It depends heavily on scope, but the price alone tells you less than what’s included in it. Use the pricing breakdown above to compare quotes on an apples-to-apples basis rather than by the headline number.
Should I always choose the vendor with the most certifications?
Certifications are a useful filter, but they matter most when held by the specific tester assigned to your engagement, not just listed as company credentials. A vendor with fewer but verified individual certifications is often a safer choice than one with a long company list and no named tester credentials.
Is an automated vulnerability scan the same as a penetration test?
No. An automated scan finds known vulnerabilities using tooling, while a penetration test includes manual testing that can uncover business-logic flaws and chained vulnerabilities automated tools are not designed to detect. A real penetration test should include both, with manual testing as the core of the engagement.
How long does a typical penetration test take?
This varies by scope, but a vendor should be able to give you a realistic range once they understand your environment, rather than a fixed number before any scoping conversation has happened.
What should I do if a vendor can’t answer these questions clearly?
Treat hesitation or vague answers as useful information. A vendor confident in their process should be able to answer all 10 questions specifically, without needing to check with someone else or deflect to a sales deck.
Content Reviewed By
Abdul Rameez
Senior Security Analyst
VAPT | Web VAPT | Mobile VAPT | Ethical Hacker | Security Consultant
Abdul Rameez is a Senior Security Analyst at CyberSapiens with 4 years of experience specialising in web and mobile application penetration testing. He holds the Certified AppSec Practitioner (CAP) and Certified Mobile Application Penetration Tester credentials, and mentors other security researchers alongside his testing work.
Ask us these 10 questions
We will answer every one of them, plus send you a real sample report before you decide anything. Our penetration testing services are built to hold up to exactly this kind of scrutiny.
Get a Pentest QuoteCall Us
1300 507 668Email Us
[email protected]Our Office
Lvl 1, 206 Lorimer St, Port Melbourne, Australia