Searching for a penetration testing company returns hundreds of options. Every provider claims "expert testers," "comprehensive methodology," and "actionable results." The marketing language is identical. The deliverables look similar. The proposals all reference OWASP and NIST. How do you tell the difference between a provider that will find the vulnerabilities attackers would exploit and one that will run a scanner and reformat the output?
The difference matters enormously. A quality penetration testing company discovers business logic flaws, access control failures, and vulnerability chains that prevent real breaches. A low-quality provider generates a report full of informational findings and false positives that wastes your remediation team's time and creates a false sense of security.
This guide provides the evaluation framework for choosing a penetration testing company: the 12 criteria that separate quality from noise, the questions to ask during evaluation, the red flags that disqualify a provider, and what to expect from a quality engagement. For a list of top providers, see our penetration testing companies guide. For detailed selection methodology, see our how to choose a penetration testing company guide.
Why Provider Selection Matters
The Quality Gap Is Enormous
The penetration testing industry has no barrier to entry. Anyone can claim to be a penetration testing company. The result is a market ranging from elite security firms with decade-long track records to solo consultants running automated scanners and reformatting the output as a "pentest report."
A quality provider finds critical vulnerabilities your automated tools miss: authentication bypass, privilege escalation chains, transaction logic abuse, and multi-step attack paths through your infrastructure. A poor provider finds the same things your vulnerability scanner already reports.
The Cost of Getting It Wrong
False assurance. A poor-quality pentest that finds nothing critical doesn't mean you're secure. It means the testers weren't skilled enough to find what's there. You make decisions based on a false picture.
Wasted budget. Paying for a scanner report dressed as a penetration test. Paying for remediation of false positives. Paying for a second pentest when the first doesn't satisfy your auditor.
Compliance failure. Auditors reviewing pentest evidence can tell the difference between manual expert testing and automated scanning. Insufficient testing creates audit findings. See our compliance guide.
The 12 Evaluation Criteria
Criterion 1: CREST Certification
CREST certification is the most widely recognized quality standard for penetration testing companies. CREST-certified companies undergo independent assessment of their testing methodology, tester qualifications, data handling, and operational security.
Why it matters: CREST certification is accepted by regulators (PCI SSC, MAS, HKMA, Bank of England) as evidence of qualified testing. Individual testers hold CREST certifications (CRT, CCT) demonstrating proven technical capability.
What to verify: Is the company CREST certified (not just the individual testers)? Is the certification current? Does the certification cover the testing type you need (infrastructure, application, or both)?
Criterion 2: Manual Testing Depth
The defining difference between a quality penetration test and an expensive vulnerability scan is manual expert testing. Automated tools find known vulnerability patterns. Manual testers find what tools can't: business logic flaws, access control failures, multi-step attack paths, and application-specific vulnerabilities.
Questions to ask: What percentage of the engagement is manual testing vs automated scanning? How do your testers evaluate business logic? Describe how you test for IDOR/BOLA. How do you discover vulnerabilities that automated tools miss?
Red flag: If the provider can't articulate their manual testing approach, or if the proposal focuses on scanner tool names, the engagement will be predominantly automated.
Criterion 3: Zero False Positive Commitment
Every finding in the report should be validated through exploitation. The tester proved the vulnerability exists, demonstrated its impact, and provided evidence (screenshots, request/response pairs, proof-of-concept).
Why it matters: False positives waste your team's remediation time, erode trust in the testing programme, and create noise that obscures real findings. See our evaluating testing quality guide.
Questions to ask: Do you commit to zero false positives? How do you validate findings before including them in the report? Can you show a sample report demonstrating exploitation evidence for each finding?
Red flag: Hundreds of findings with no exploitation evidence. Severity ratings based on CVSS alone without business context. Findings that read like scanner output.
Criterion 4: Relevant Industry Experience
A penetration testing company that has tested applications in your industry understands your specific risks, regulatory requirements, and common vulnerability patterns.
Why it matters: Banking applications have transaction logic vulnerabilities. Healthcare applications have ePHI exposure risks. SaaS applications have multi-tenant isolation requirements. Fintech applications have payment fraud vectors. Industry experience means testers know where to look. See our financial services testing criteria.
Questions to ask: Have you tested applications in our industry? Can you provide references from similar organisations? What industry-specific vulnerabilities do you typically find?
Criterion 5: Comprehensive Testing Capability
Your security needs will evolve. Choose a provider that covers the full testing spectrum rather than one that only offers a single testing type.
Testing types to evaluate:
Web application penetration testing. API penetration testing. Cloud penetration testing (AWS, Azure, GCP). Network penetration testing (external and internal). Mobile application testing. IoT testing. Red teaming. AI penetration testing.
A provider covering all types ensures consistent methodology, consolidated reporting, and a single relationship that grows with your needs.
Criterion 6: Methodology Documentation
Quality providers follow documented, industry-recognized methodology.
Acceptable methodology references: PTES (Penetration Testing Execution Standard). OWASP Testing Guide (for web and API). NIST SP 800-115. CREST methodology. See our penetration testing methodology guide.
Questions to ask: What methodology do you follow? How is methodology adapted for different engagement types? Can you provide methodology documentation?
Red flag: No methodology documentation. Vague references to "proprietary methodology" without substance. Methodology that's just a list of tools.
Criterion 7: Report Quality
The report is your primary deliverable. It must serve both technical teams (for remediation) and leadership (for risk understanding).
What quality reports include: Executive summary written for non-technical leadership. Each finding with severity, exploitation evidence, business impact, and specific remediation guidance. Compliance mapping to applicable frameworks. Methodology documentation. Tester qualifications. See our penetration testing reports guide.
Questions to ask: Can you provide a sample report (redacted)? How do you determine severity ratings? Do reports include compliance mapping?
Red flag: Reports that are just scanner output. No executive summary. Remediation guidance limited to "apply vendor patch." No exploitation evidence. Hundreds of findings without prioritisation.
Criterion 8: Remediation Support
Finding vulnerabilities is half the value. Helping your team fix them is the other half.
What to expect: Post-report debrief walking through findings with your technical team. Availability for questions during remediation (30 to 90 days). Guidance on implementation approach when fixes are complex. See our security remediation maturity guide.
Questions to ask: What remediation support is included? How long is the support period? Can our developers contact your testers directly with implementation questions?
Red flag: "Report delivery is the end of the engagement." No debrief offered. No post-report support.
Criterion 9: Retesting Included
After your team remediates findings, retesting verifies the fixes work. Retesting should be included in the engagement, not charged as a separate engagement.
Why it matters: Fixes sometimes don't work. A developer may implement an input filter that's bypassable. An IAM change may not propagate completely. Without retesting, you have no confirmation. Compliance auditors want to see retesting evidence.
Questions to ask: Is retesting included? What's the retesting scope (all findings or just critical/high)? What's the timeline for retesting?
Red flag: Retesting charged as a separate engagement at the same rate. No retesting offered.
Criterion 10: Communication and Professionalism
You're granting this company access to your most sensitive systems. Communication quality during the engagement directly affects the value you receive.
What to evaluate: Responsiveness during pre-sales (indicates engagement-phase responsiveness). Critical finding escalation process (immediate notification, not end-of-engagement surprise). Regular status updates during testing. Clear, professional written communication.
Questions to ask: How do you handle critical finding discovery during testing? Will we receive status updates? Who is our primary point of contact?
Red flag: Slow pre-sales responsiveness. No critical finding escalation process. No status updates planned.
Criterion 11: Compliance Mapping Capability
If you're testing for compliance (PCI DSS, SOC 2, ISO 27001, HIPAA, GDPR, DORA), the report must map findings to your compliance framework requirements. One engagement should satisfy multiple frameworks. See our penetration testing compliance guide.
Questions to ask: Can your reports map findings to SOC 2, ISO 27001, PCI DSS, and other frameworks? Have your reports satisfied auditor requirements for these frameworks?
Criterion 12: Continuous Testing Options
Annual testing is the compliance minimum. Your application changes faster than once a year. Evaluate whether the provider offers continuous penetration testing or PTaaS models for ongoing validation. See our continuous vs annual pentest comparison and PTaaS guide.
Questions to ask: Do you offer continuous testing models? How does PTaaS differ from annual engagements? Can testing be triggered by our deployment pipeline?
Red Flags That Disqualify a Provider
Questions to Ask During Evaluation
About the Testing
How many hours of manual testing does this engagement include? What tools do your testers use alongside manual testing? How do you test for business logic vulnerabilities specific to our application type? How do you approach multi-tenant isolation testing (for SaaS)? What do you test that automated tools cannot find?
About the Team
Who specifically will test our systems? What certifications do they hold (OSCP, CREST CRT/CCT, OSWE)? How many years of experience do they have? Will the same testers be available for questions during remediation?
About the Deliverables
What does your executive summary typically look like? How do you determine severity ratings (CVSS alone or with business context)? Do you include exploitation evidence for every finding? How quickly after testing ends is the report delivered? Can the report be customised for our compliance frameworks?
About the Relationship
What happens if you discover a critical vulnerability on day one? How do you handle scope questions during testing (e.g., you discover an adjacent system; is it in scope)? What's included after the report (support, retesting, follow-up)? Can we engage you for ad-hoc testing between annual engagements?
Understanding Pricing
What Influences Cost
Scope. More systems, more endpoints, more complexity equals higher cost. A single web application costs less than web + API + cloud + network + mobile. See our penetration testing cost guide.
Testing depth. Surface-level automated scanning is cheaper than deep manual testing. The cheap option misses the vulnerabilities that matter most.
Tester experience. Senior testers with CREST CCT or OSCP/OSWE certifications cost more than junior testers. They also find more and produce better reports.
Engagement model. One-time annual engagements have different pricing than continuous testing or PTaaS subscriptions.
The Cheapest Option Is Rarely the Best
A $5,000 pentest of a complex web application with 200 API endpoints is not going to include meaningful manual testing. At that price, you're buying a scanner run with a branded report cover. The vulnerabilities that actually lead to breaches (business logic, access control, chaining) require human expertise and time.
Reasonable engagement costs: Single web application: $15,000 to $40,000 depending on complexity. API (50+ endpoints): $15,000 to $35,000. External network: $10,000 to $25,000. Internal network: $15,000 to $35,000. Cloud infrastructure: $15,000 to $40,000. Comprehensive multi-scope: $40,000 to $100,000+.
These ranges reflect manual testing depth, not just tool scanning. For detailed pricing, see our penetration testing cost guide.
Provider Evaluation Checklist
Qualifications
- CREST certified (company-level certification, not just individual)
- Individual tester certifications verified (OSCP, CREST CRT/CCT, OSWE)
- Industry experience relevant to your sector
- References available from similar organisations
- Years of operation and company stability
Methodology and Approach
- Documented methodology referencing industry standards (PTES, OWASP, NIST)
- Manual testing approach clearly articulated
- Business logic testing methodology described
- Testing types cover your needs (web, API, cloud, network, mobile)
- Approach tailored to your specific scope (not one-size-fits-all)
Deliverables
- Sample report reviewed and meets quality expectations
- Executive summary included for leadership
- Each finding includes exploitation evidence
- Severity includes business context (not just CVSS)
- Remediation guidance is specific and actionable
- Compliance mapping included for applicable frameworks
Engagement Model
- Zero false positive commitment
- Remediation support included (30 to 90 days)
- Retesting included at no additional cost
- Critical finding escalation process defined
- Status updates during testing
- Debrief call included
- Continuous testing or PTaaS options available
Pricing and Terms
- Pricing reflects adequate manual testing hours
- Scope definition clear and detailed
- Out-of-scope items explicitly listed
- Timeline reasonable for scope (not compressed to cut costs)
- Data handling and NDA terms acceptable
Choosing a Provider by Organisation Type
SaaS Companies
Prioritise providers with multi-tenant isolation testing experience, API security depth, SOC 2 report mapping, and continuous testing capability. See our SaaS penetration testing guide.
Financial Services
Prioritise providers with financial transaction logic testing, regulatory report mapping (PCI DSS, NYDFS, DORA, MAS TRM), and red teaming capability. See our financial services testing criteria.
Healthcare
Prioritise providers with HIPAA-aware testing, ePHI exposure assessment, and healthcare security experience. See our healthcare testing guide.
Startups
Prioritise providers offering right-sized engagements (not enterprise-scale proposals for a single application), SOC 2 readiness support, and scalable pricing. See our startup penetration testing services.
Enterprises
Prioritise providers with comprehensive testing capability (all types), red teaming, multi-framework compliance mapping, and PTaaS models for ongoing testing. Application security assessment and offensive security testing provide end-to-end coverage.
What a Quality Engagement Looks Like
Before Testing
Detailed scoping discussion (not a generic questionnaire). Provider asks about your technology stack, data sensitivity, compliance requirements, and specific concerns. Scope document is specific and tailored.
During Testing
Status updates at agreed intervals. Immediate escalation of critical findings. Testers ask intelligent questions about your application's intended behaviour (indicating they understand your business logic).
The Report
Concise executive summary your CEO can read. Findings that make your senior developer say "I didn't know that was possible." Exploitation evidence that proves every finding is real. Remediation guidance specific enough to implement. Compliance mapping that satisfies your auditor.
After Testing
Debrief call where testers explain their approach and findings. Remediation support when your team has questions. Retesting that confirms fixes work. Annual relationship where improvement is tracked over time.
For a walkthrough of the complete engagement experience, see our guide on what to expect during a penetration testing engagement.
How AppSecure Meets Every Criterion
AppSecure is a CREST-certified penetration testing company delivering expert-led manual testing across every testing type.
CREST Certified. Company and individual tester certifications. Quality independently verified.
Manual Testing Depth. Every engagement led by expert testers evaluating business logic, access control, vulnerability chaining, and application-specific attack paths.
Zero False Positives. Every finding validated through exploitation with evidence.
Comprehensive Coverage. Web, API, cloud, network, mobile, IoT, AI, and red teaming.
Multi-Framework Reports. Findings mapped to PCI DSS, SOC 2, ISO 27001, HIPAA, GDPR, DORA, and other frameworks.
3-Week Delivery. 90-day remediation support. Complimentary retesting. Continuous testing and PTaaS for ongoing security.
Contact AppSecure:
Frequently Asked Questions
1. How do I choose a penetration testing company?
Evaluate against 12 criteria: CREST certification, manual testing depth, zero false positive commitment, relevant industry experience, comprehensive testing capability, documented methodology, report quality, remediation support, retesting inclusion, communication professionalism, compliance mapping capability, and continuous testing options. Request a sample report. Ask specifically about manual testing approach and business logic methodology. Check references from organisations similar to yours.
2. What certifications should a penetration testing company have?
CREST certification at the company level is the most widely recognized quality standard, accepted by financial regulators globally. Individual tester certifications to look for: OSCP (Offensive Security Certified Professional), CREST CRT (Certified Registered Tester), CREST CCT (Certified Competency Tester), and OSWE (Offensive Security Web Expert). Company-level certifications verify methodology and operations. Individual certifications verify tester skill.
3. What is the difference between a pentest and a vulnerability scan?
A vulnerability scan runs automated tools checking for known weaknesses (missing patches, common misconfigurations). A penetration test uses expert human testers who exploit vulnerabilities, test business logic, validate access controls, and chain findings into real attack paths. Scanners find known patterns. Testers find what scanners miss. The #1 OWASP vulnerability (broken access control) and business logic flaws are invisible to scanners. Compliance frameworks require penetration testing, not just scanning.
4. How much does penetration testing cost?
Costs range based on scope and depth. Single web application: $15,000 to $40,000. API testing: $15,000 to $35,000. External network: $10,000 to $25,000. Internal network: $15,000 to $35,000. Cloud infrastructure: $15,000 to $40,000. Comprehensive multi-scope: $40,000 to $100,000+. Dramatically lower pricing indicates automated scanning, not manual testing. The cheapest option typically delivers the least value.
5. What should a penetration testing report include?
An executive summary for leadership. Each finding with severity rating, exploitation evidence (screenshots, request/response pairs), business impact assessment, and specific remediation guidance. Compliance mapping to applicable frameworks. Methodology documentation. Tester qualifications. Quality reports include zero false positives (every finding validated) and remediation guidance specific to your technology stack.
6. Should retesting be included in the engagement?
Yes. Retesting verifies that remediated vulnerabilities are actually fixed. Fixes sometimes don't work (bypassable input filters, incomplete IAM changes). Compliance auditors want retesting evidence. Retesting should be included in the engagement fee, not charged as a separate engagement. Ask about retesting scope: all findings or just critical/high.
7. How do I evaluate a sample penetration testing report?
Look for exploitation evidence with every finding (not just tool output). Check whether severity ratings include business context (not just CVSS). Verify remediation guidance is specific and actionable (not generic "apply patch"). Assess the executive summary (is it understandable by non-technical leadership?). Count the findings and assess whether the ratio of critical/high to informational seems reasonable. If the report has hundreds of findings with no exploitation evidence, it's scanner output.
8. What is the difference between CREST certification and OSCP?
CREST certification is a company-level quality assurance standard verifying methodology, operations, and tester qualifications. OSCP is an individual-level technical certification demonstrating hands-on penetration testing skill through a practical exam. Both are valuable but serve different purposes. A CREST-certified company employs qualified testers and follows verified methodology. An OSCP-certified individual has proven technical capability. Look for both: company-level CREST plus individual certifications.
9. How often should I use the same penetration testing company?
Working with the same provider for 2 to 3 consecutive years builds institutional knowledge: they understand your architecture, track improvement, and spend less time on reconnaissance. After 2 to 3 years, consider rotating providers or adding a second provider to bring fresh perspective. Some organisations use one provider for annual testing and a different provider for periodic validation. The key is balancing institutional knowledge with fresh eyes.
10. What is the difference between penetration testing and red teaming?
Penetration testing identifies exploitable vulnerabilities in defined systems within a defined scope and timeframe. Red teaming simulates a realistic adversary campaign testing your entire security programme (people, process, technology) without informing the defensive team. Pentesting answers "what vulnerabilities exist?" Red teaming answers "can a motivated attacker achieve their objective?" Most organisations start with penetration testing and add red teaming as their security programme matures.
SecureLayer