You need a pentest company. Maybe your SOC 2 auditor asked for penetration testing evidence. Maybe your enterprise customer won't sign without a recent pentest report. Maybe your CISO wants to validate whether the security investments are actually working. Whatever the trigger, you're now evaluating pentest companies and every provider's website says the same thing.
The problem isn't finding options. It's choosing between them. Hundreds of pentest companies operate in the market, ranging from elite security firms with decades of experience to solo operators running automated scanners. Their websites look similar. Their proposals reference the same frameworks. Their pricing varies by an order of magnitude without obvious explanation.
This guide provides a structured, repeatable process for selecting a pentest company that delivers genuine security value rather than a branded scanner report. It walks through each selection step: defining your requirements, building a shortlist, evaluating proposals, scoring vendors, and making the final decision. For the detailed evaluation criteria, see our penetration testing company evaluation guide.
Step 1: Define What You Actually Need
Before contacting any pentest company, clarify what you need tested, why you need it tested, and what outcome you expect.
What Are You Testing?
Different testing types require different expertise.
Why Are You Testing?
Your motivation shapes provider requirements.
Compliance. You need testing evidence for SOC 2, ISO 27001, PCI DSS, HIPAA, or DORA. Choose a provider with compliance report mapping and CREST certification (accepted by regulators). See our compliance guide.
Security validation. You want to know if your application is actually secure. Choose a provider with deep manual testing capability and business logic testing expertise.
Customer requirement. An enterprise customer demands a pentest report before signing. Choose a provider that delivers reports your customer will accept (CREST-certified, zero false positives, compliance-mapped).
Pre-launch validation. You're launching a new product and need security confidence. Choose a provider offering fast turnaround without sacrificing depth.
M&A preparation. You're preparing for acquisition, fundraising, or IPO. See our M&A pentesting guide and IPO readiness guide.
What Outcome Do You Expect?
Define success before you start. Do you want a report that satisfies an auditor? A technical debrief that helps your engineers fix root causes? A comprehensive vulnerability inventory? A realistic assessment of what an attacker could achieve? Your expected outcome determines which provider delivers the best match.
Step 2: Set Your Budget and Timeline
Budget Reality
Penetration testing costs vary based on scope, depth, and provider quality.
If your budget is significantly below these ranges, understand what you're trading off: fewer manual testing hours, junior testers, limited remediation support, or no retesting. The cheapest engagement often delivers the least value. See our cost guide for detailed pricing factors.
Timeline Reality
Total from starting vendor selection to retesting completion: 10 to 22 weeks. If your auditor needs evidence in 4 weeks, start yesterday. Don't compress testing timeline; compress vendor selection instead.
Step 3: Build Your Shortlist
Where to Find Pentest Companies
CREST member directory. The CREST member directory lists certified companies. Starting here pre-filters for quality.
Industry referrals. Ask peers at other companies in your industry who they use. Security leaders in your network are the best source of honest provider feedback.
Existing compliance relationships. Your SOC 2 auditor or ISO 27001 certification body may recommend pentest providers they've seen produce quality work.
Review existing content. See our penetration testing companies guide, how to choose a provider guide, and evaluating testing quality guide.
Initial Filtering
Start with 5 to 8 candidates. Filter to 3 to 4 for detailed evaluation.
Immediate disqualifiers:
No certifications (CREST or equivalent). Cannot demonstrate relevant testing type expertise (e.g., you need cloud testing and they only list web application testing). No sample report available. Website focuses on tools rather than methodology. No evidence of manual testing capability.
Step 4: Request and Evaluate Proposals
What Your RFP Should Include
Your context. Industry, company size, technology stack, data sensitivity.
Scope. Specific systems, URLs, IP ranges, API endpoints, cloud accounts, mobile platforms.
Testing approach. Preference for black box, white box, or grey box.
Compliance requirements. Which frameworks the report must map to.
Timeline. When testing must complete and when the report is needed.
Deliverable requirements. Executive summary, compliance mapping, retesting, remediation support.
Evaluating Proposals
Read proposals critically. Look for evidence that the provider understands your specific situation rather than pasting a generic proposal template.
Signs of a quality proposal:
Scope is tailored to your environment (references your technology stack, not generic descriptions). Testing approach addresses your specific risk profile. Timeline includes specific phases with durations. Deliverables are clearly defined. Pricing is itemised (you can see what you're paying for). The provider asks clarifying questions (demonstrating they're thinking about your engagement, not just sending a template).
Signs of a generic proposal:
Identical scope description regardless of what you described. Vague methodology ("we use industry best practices"). No clarifying questions asked. Pricing is a single number with no breakdown. Timeline is "2 weeks" regardless of scope complexity. Deliverables section is boilerplate.
Step 5: Score Vendors Using the Comparison Scorecard
The Vendor Scorecard
Rate each shortlisted provider on a 1 to 5 scale across weighted criteria.
Scoring Guidance
5 (Excellent). Best-in-class. Exceeds expectations. Clear differentiator.
4 (Good). Meets expectations fully. No concerns.
3 (Adequate). Meets minimum requirements. Some areas could be stronger.
2 (Below expectations). Significant gaps or concerns. Requires compensating factors.
1 (Inadequate). Does not meet requirements. Disqualifying unless all other criteria are exceptional.
How to Evaluate the Sample Report
The sample report is the single most revealing evaluation artifact. Request it from every shortlisted vendor.
What to look for:
Does every finding include exploitation evidence (screenshots, request/response pairs, proof-of-concept)? Is the executive summary understandable by non-technical leadership? Are severity ratings contextualised with business impact (not just CVSS)? Is remediation guidance specific and actionable (not "apply vendor patch")? Does the methodology section reference recognised standards? Is the report well-written and professionally formatted?
What it reveals: The sample report shows you exactly what your report will look like. If the sample is scanner output with a branded cover page, that's what you'll receive.
For detailed report evaluation, see our penetration testing reports guide.
Step 6: Conduct a Vendor Call
What to Cover
After scoring proposals and reviewing sample reports, schedule 30-minute calls with your top 2 to 3 vendors.
Questions about their approach:
Walk me through how you'd approach testing our specific application. How do you test for business logic vulnerabilities? How do you test access control and IDOR? What percentage of the engagement is manual testing vs automated scanning? Describe a complex vulnerability you discovered through manual testing that a scanner would miss.
Questions about logistics:
Who specifically will test our systems? What are their certifications? What's your critical finding escalation process? How do you handle scope questions during testing? What does your remediation support include? Is retesting included?
Questions about fit:
Have you tested applications similar to ours? Can you provide a reference from a similar organisation? How do you handle compliance mapping for [our specific framework]?
What to Listen For
Good signs: The vendor asks you questions back. They reference specific techniques for your technology stack. They can describe their approach without jargon. They name the actual testers and their qualifications. They're honest about limitations.
Bad signs: Vague answers to methodology questions. Unable to describe how they test business logic. Focus on tools rather than techniques. Can't name testers. Overselling with promises of "finding everything."
Step 7: Make the Decision
Decision Framework
The vendor with the highest scorecard total is your starting point, not your automatic selection. Consider these additional factors:
Chemistry. Will your team work well with this provider? Communication quality during evaluation predicts engagement quality. A technically strong provider that's difficult to communicate with delivers less value than a strong communicator with solid technical skills.
Growth fit. Choose a provider you can grow with. If your needs will expand from annual web app testing to continuous multi-scope testing, choose a provider with PTaaS and continuous testing capability. See our continuous vs annual comparison.
Reference check. Contact the references. Ask: "What did they find that surprised you?" "How was the remediation support?" "Would you use them again?" "What would you change?"
Common Decision Mistakes
Choosing on price alone. The cheapest pentest company delivers the least value. A $5,000 pentest of a complex application is automated scanning with a report cover. The vulnerabilities that lead to breaches (business logic, IDOR, auth bypass) require human expertise that costs more per hour than scanner licensing.
Choosing on brand alone. A large cybersecurity company is not necessarily the best pentest company. Pentesting quality depends on the individual testers assigned to your engagement, not the company's brand recognition or total revenue.
Choosing on speed alone. "We can start Monday" from an unfamiliar provider should trigger scrutiny, not relief. Quality providers are typically booked 2 to 4 weeks out. Immediate availability may indicate low demand for a reason.
Not reviewing the sample report. This is the single most important evaluation step and the one most often skipped. If you skip everything else in this guide, review the sample report.
Ignoring communication quality. A provider that's slow, vague, or difficult to reach during the sales process will be the same during your engagement. Communication quality during evaluation is the best predictor of engagement experience.
What Happens After You Choose
Onboarding and Scoping
The selected provider works with you to finalise scope, create test accounts, provision access, sign rules of engagement, and schedule testing. See our guide on what to expect during a pentest engagement for the complete engagement walkthrough.
Building the Ongoing Relationship
The best pentest company relationships extend beyond a single engagement.
Year 1: Baseline engagement establishes your vulnerability landscape. Remediate findings. Retest.
Year 2: Second engagement measures improvement. Fewer critical findings demonstrate maturing security. Provider's familiarity with your architecture deepens.
Year 3: Consider adding scope (new applications, cloud, mobile). Consider advancing to red teaming for mature programmes. Consider rotating providers or adding a second provider for fresh perspective.
Ongoing: Move toward continuous testing or PTaaS as your deployment velocity increases. See our how often to test guide and PTaaS guide.
Choosing a Pentest Company by Organisation Type
SaaS Companies
Prioritise multi-tenant isolation testing, API security depth, SOC 2 mapping, and continuous testing for frequent releases. See our SaaS penetration testing guide.
Financial Services
Prioritise financial transaction logic testing, multi-framework compliance mapping, and red teaming capability. See our financial services testing criteria. Banking security and fintech security require specialised expertise.
Healthcare
Prioritise HIPAA-aware testing, ePHI exposure assessment, and BAA availability. See our healthcare testing guide. Healthcare security requires testers who understand health data sensitivity.
Startups
Prioritise right-sized engagements, SOC 2 readiness support, and affordable ongoing testing. See our startup penetration testing services and continuous security for startups guide.
Enterprises
Prioritise comprehensive testing capability, red teaming, multi-framework compliance, and PTaaS. Application security assessment and offensive security testing provide end-to-end coverage.
Pentest Company Selection Checklist
Requirements Definition
- Testing types needed identified (web, API, cloud, network, mobile, etc.)
- Testing motivation clarified (compliance, security validation, customer requirement)
- Expected outcome defined
- Budget range established
- Timeline requirements documented
- Compliance framework requirements listed
Shortlisting
- 5 to 8 initial candidates identified
- Filtered to 3 to 4 based on certifications, capability, and initial fit
- CREST certification verified for shortlisted vendors
- Relevant testing type capability confirmed
Proposal Evaluation
- RFP issued with specific scope and requirements
- Proposals received and reviewed for tailoring vs generic content
- Pricing compared with understanding of scope coverage
- Timeline and deliverables clearly defined in each proposal
Deep Evaluation
- Sample report requested and reviewed from each shortlisted vendor
- Vendor scorecard completed for each shortlisted vendor
- Vendor calls conducted with top 2 to 3 candidates
- Manual testing approach evaluated
- Business logic testing methodology confirmed
- Compliance mapping capability verified
Final Decision
- Scorecard results reviewed
- References contacted and feedback collected
- Communication quality factored into decision
- Growth fit considered (can this provider scale with our needs?)
- Decision documented with rationale
- Contract and SOW reviewed before signing
How AppSecure Stands Out
AppSecure is a CREST-certified pentest company delivering expert-led manual testing that finds what automated tools miss.
Why Organisations Choose AppSecure:
Expert Manual Testing. Every engagement led by certified testers evaluating business logic, access control, vulnerability chains, and application-specific attack paths.
Zero False Positives. Every finding validated through exploitation with evidence. Your team fixes confirmed vulnerabilities, not scanner noise.
Comprehensive Coverage. Web, API, cloud, network, mobile, IoT, AI, and red teaming. One provider for every testing need.
Multi-Framework Reports. Findings mapped to PCI DSS, SOC 2, ISO 27001, HIPAA, GDPR, and DORA.
3-Week Delivery. 90-day remediation support. Complimentary retesting. Continuous testing and PTaaS for ongoing security validation.
Contact AppSecure:
Frequently Asked Questions
1. How do I choose the right pentest company?
Follow a structured process: define your requirements (testing type, compliance needs, expected outcome), set budget and timeline, build a shortlist from CREST-certified providers and industry referrals, evaluate proposals for tailoring vs generic content, review sample reports (the most revealing evaluation artifact), score vendors using a weighted comparison scorecard, conduct vendor calls to evaluate approach and communication, check references, and make a decision that balances technical quality with communication and growth fit.
2. What is the most important factor when choosing a pentest company?
Manual testing depth. The defining difference between a quality pentest and an expensive vulnerability scan is expert human testing that discovers business logic flaws, access control failures, and vulnerability chains that automated tools miss. During evaluation, ask the provider to describe their manual testing approach. If they can't articulate how they test business logic or find vulnerabilities beyond what scanners report, the engagement will be predominantly automated.
3. How much should a pentest cost?
Single web application: $15,000 to $30,000. Complex web application: $25,000 to $45,000. API testing: $15,000 to $35,000. Network testing: $10,000 to $35,000. Cloud infrastructure: $15,000 to $40,000. Comprehensive multi-scope: $50,000 to $100,000+. Pricing significantly below these ranges indicates automated scanning with minimal manual testing. The cheapest engagement typically delivers the least value because business logic and access control testing require human expertise.
4. Should I choose a CREST-certified pentest company?
Yes. CREST certification independently verifies that the company follows documented methodology, employs qualified testers, handles data securely, and maintains operational standards. CREST is accepted by financial regulators globally as evidence of qualified testing. Individual CREST certifications (CRT, CCT) demonstrate proven tester capability through practical exams, not just theoretical knowledge.
5. How do I evaluate a pentest company's sample report?
Look for exploitation evidence with every finding (screenshots, request/response pairs proving the vulnerability). Check whether severity ratings include business impact context beyond CVSS scores. Verify remediation guidance is specific and actionable. Assess the executive summary for non-technical readability. Note the finding-to-informational ratio (a quality report has fewer, higher-value findings, not hundreds of scanner results). If the sample report is scanner output with a branded cover, that's what your report will be.
6. How many pentest companies should I evaluate?
Start with 5 to 8 candidates based on certifications and capability. Filter to 3 to 4 for proposal requests. Deep-evaluate (sample report review, scorecard, vendor calls) on 2 to 3. This gives you enough comparison points without creating decision paralysis. If your requirements are specialised (financial transaction testing, IoT, AI), the shortlist may be shorter because fewer providers have the required expertise.
7. Should I use the same pentest company every year?
Using the same provider for 2 to 3 years builds valuable institutional knowledge: they understand your architecture, track improvement, and need less ramp-up time. After 2 to 3 years, consider adding a second provider for fresh perspective or rotating entirely. Some organisations alternate providers: Provider A in odd years, Provider B in even years. The balance between familiarity and fresh perspective is the key consideration.
8. What is the difference between a pentest company and a vulnerability scanner?
A pentest company employs human security experts who think creatively, test business logic, validate access controls, chain vulnerabilities into attack paths, and produce verified findings with exploitation evidence. A vulnerability scanner is a software tool that checks for known patterns. Many low-quality pentest companies primarily run scanners and reformat the output. Quality pentest companies use scanners as one input alongside extensive manual testing that discovers what scanners cannot.
9. How do I know if a pentest company is actually doing manual testing?
Ask during evaluation: "What percentage of hours is manual testing vs scanning?" "Describe how you test business logic for our application type." "Walk me through finding a vulnerability a scanner would miss." In the report: look for findings that couldn't come from a scanner (business logic flaws, IDOR with business context, multi-step attack paths, application-specific abuse). If every finding could be a scanner result, it probably is.
10. When should I start looking for a pentest company?
Start 8 to 12 weeks before you need the report. Allow 2 to 4 weeks for vendor selection, 1 to 2 weeks for scoping, 1 to 3 weeks for testing, and 1 week for reporting. If you need the report for a specific date (audit, customer deadline, board meeting), count backward and add buffer. Quality providers are typically booked 2 to 4 weeks out. Last-minute searches limit your options and may force you to compromise on quality.
SecureLayer