How to choose a pentest vendor: 9 questions that filter out scanner shops
The pentest market is opaque: everyone has "certified experts" and "international methodologies", while prices for the same task differ severalfold. Everything is sold under the word "pentest": from an automated scan to deep manual work. Here are the questions that reveal who you are dealing with in 15 minutes.
Nine questions for the vendor
- ◇Who exactly will do the work? Ask for the names and certifications of the actual testers, not "we employ 50 experts". Practical certifications (OSCP, BSCP, CBBH) prove hacking skill; paper ones prove test-taking skill.
- ◇In-house or subcontracted? A significant share of the market resells other people's hands at a markup. Subcontracting is not a crime per se, but you must know who actually gets access to your systems and under what NDA.
- ◇What share of the work is manual? An honest answer describes the split: scanners for coverage and routine, hands for logic, access control and attack chains. If the methodology boils down to "we use modern tools" — it is a scan.
- ◇Can you show an anonymized sample report? The main test. In a real report every finding has a reproducible PoC, a business-terms risk assessment and concrete remediation steps. A scanner export with CVSS scores is not a report.
- ◇Any business logic findings in recent projects? IDOR, payment bypass, workflow abuse — things no scanner finds. No examples means no manual work happened.
- ◇Is a retest included in the price? A pentest without re-verifying fixes is half the job. Clarify upfront: is the retest included, within what period, how many iterations.
- ◇How is the price calculated? A transparent answer uses scope units: applications, roles, hosts, endpoints. "We'll work something out" with no calculation method means the price is arbitrary — in both directions.
- ◇What about the security of the engagement itself? NDA before any inputs, agreed testing windows, prohibited actions, data destruction after the project — for a mature vendor this is standard, not a concession.
- ◇What if you find nothing? The right answer: "we will say so, describing what we tested and how". A vendor who guarantees findings will pad the report with scanner noise.
Red flags
- ◇A price severalfold below market for the same declared scope — it is a scan inside; the economics of manual work do not close otherwise.
- ◇A guarantee of "critical findings" before even seeing the scope.
- ◇Refusal to show a sample report or methodology even under NDA.
- ◇A report promised 2–3 days after the "pentest" starts — only a scanner finishes that fast.
- ◇Selling a "pentest" without a single clarifying question about your infrastructure and goals.
On price: why a cheap pentest is false economy
A pentest is bought to answer "how will we be breached". A scan at a quarter of the price answers a different question — "which known vulnerabilities exist in our software versions" — and you can answer it for free by running a scanner yourself. Paying pentest money for it buys a false sense of security: the paper exists, while the real attack paths — logic, access, chains — remain untested.
Fair-price anchors for manual work: external perimeter — from $3,300, web application (grey box) — $2,800–6,900, infrastructure up to 50 hosts — $4,200–9,700. Significantly lower is a reason to ask what the price consists of.
How we answer these ourselves
In-house work, no subcontracting; testers hold BSCP and CBBH; every report contains a PoC and reproduction steps per finding, plus an executive summary; a retest after fixes is included in every package; the price is calculated per scope unit and fixed in the quote before the start; the NDA is signed before we receive any inputs. An anonymized sample report is available on request.
FAQ
Send your details — we return a quote in 24 hours and an anonymized sample report. In-house work, retest included, price fixed before the start.
Get a quote in 24 hours