How to choose a pentest vendor: 9 questions that filter out scanner shops

2026-09-04

The pentest market is opaque: everyone has "certified experts" and "international methodologies", while prices for the same task differ severalfold. Everything is sold under the word "pentest": from an automated scan to deep manual work. Here are the questions that reveal who you are dealing with in 15 minutes.

Nine questions for the vendor

  • Who exactly will do the work? Ask for the names and certifications of the actual testers, not "we employ 50 experts". Practical certifications (OSCP, BSCP, CBBH) prove hacking skill; paper ones prove test-taking skill.
  • In-house or subcontracted? A significant share of the market resells other people's hands at a markup. Subcontracting is not a crime per se, but you must know who actually gets access to your systems and under what NDA.
  • What share of the work is manual? An honest answer describes the split: scanners for coverage and routine, hands for logic, access control and attack chains. If the methodology boils down to "we use modern tools" — it is a scan.
  • Can you show an anonymized sample report? The main test. In a real report every finding has a reproducible PoC, a business-terms risk assessment and concrete remediation steps. A scanner export with CVSS scores is not a report.
  • Any business logic findings in recent projects? IDOR, payment bypass, workflow abuse — things no scanner finds. No examples means no manual work happened.
  • Is a retest included in the price? A pentest without re-verifying fixes is half the job. Clarify upfront: is the retest included, within what period, how many iterations.
  • How is the price calculated? A transparent answer uses scope units: applications, roles, hosts, endpoints. "We'll work something out" with no calculation method means the price is arbitrary — in both directions.
  • What about the security of the engagement itself? NDA before any inputs, agreed testing windows, prohibited actions, data destruction after the project — for a mature vendor this is standard, not a concession.
  • What if you find nothing? The right answer: "we will say so, describing what we tested and how". A vendor who guarantees findings will pad the report with scanner noise.

Red flags

  • A price severalfold below market for the same declared scope — it is a scan inside; the economics of manual work do not close otherwise.
  • A guarantee of "critical findings" before even seeing the scope.
  • Refusal to show a sample report or methodology even under NDA.
  • A report promised 2–3 days after the "pentest" starts — only a scanner finishes that fast.
  • Selling a "pentest" without a single clarifying question about your infrastructure and goals.

On price: why a cheap pentest is false economy

A pentest is bought to answer "how will we be breached". A scan at a quarter of the price answers a different question — "which known vulnerabilities exist in our software versions" — and you can answer it for free by running a scanner yourself. Paying pentest money for it buys a false sense of security: the paper exists, while the real attack paths — logic, access, chains — remain untested.

Fair-price anchors for manual work: external perimeter — from $3,300, web application (grey box) — $2,800–6,900, infrastructure up to 50 hosts — $4,200–9,700. Significantly lower is a reason to ask what the price consists of.

How we answer these ourselves

In-house work, no subcontracting; testers hold BSCP and CBBH; every report contains a PoC and reproduction steps per finding, plus an executive summary; a retest after fixes is included in every package; the price is calculated per scope unit and fixed in the quote before the start; the NDA is signed before we receive any inputs. An anonymized sample report is available on request.

FAQ

Do we have to pick a large vendor?
No. In pentesting, quality is determined by the specific testers, not the size of the legal entity. A boutique team with strong specialists often delivers deeper results than a large integrator's assembly line — without the brand markup. Judge reports and people, not the logo.
Can we combine a cheap scan and an expensive pentest?
Yes, that is mature practice: a scanner continuously, for hygiene and known CVEs; a manual pentest 1–2 times a year and after major releases, for logic and chains. The only problem is substituting one for the other.
How fast do you quote?
Within 24 hours after a short brief: fixed scope, timeline and price. The quote does not change mid-project.
Test us with these same questions

Send your details — we return a quote in 24 hours and an anonymized sample report. In-house work, retest included, price fixed before the start.

Get a quote in 24 hours