Skip to content
← Field Notes

How to Choose a Penetration Testing Company

How to Choose a Penetration Testing Company

Choosing a penetration testing company comes down to four checks: ask for a sample report and see whether you can read it, confirm that people do the testing rather than a scanner alone, get scope and price in writing before anything starts, and make sure the retest is included instead of sold back to you later. Everything else on a vendor’s website is decoration. This guide walks through each check, the questions worth asking on the first call, and the red flags that should end a conversation early. It’s written for the business owner or manager buying a test, often for the first time, usually because an insurer, a client, or a contract asked for one.

The sample report tells you almost everything

The report is the product. When the engagement ends, the report is what you hold, what your insurer or client sees proof of, and what your IT team works from. So before you compare prices or credentials, ask every company on your list for a redacted sample report and read it the way you’d read anything else: can you follow it?

A good report has a summary you can understand without a translator, findings ranked by what an attacker could really do with them, evidence for each one, and a clear fix list your IT person can act on. A bad report is a few hundred pages of scanner output with a cover page. We wrote a full guide to what a penetration test report should look like, and it doubles as a checklist for judging samples.

If a company won’t share a sample report, that’s an answer too.

How penetration testing companies actually differ

From the outside, most penetration testing companies look the same: dark website, shield logo, a list of the same six services. The real differences sit underneath, and they’re the ones worth shopping on.

Manual testing or a scan with a better name. Some firms sell automated vulnerability scanning under the label of penetration testing. A scan has its place, but it’s a different product at a different depth, and it’s the difference between a checklist and a burglar actually trying your doors. If you’re not sure where the line sits, our comparison of a penetration test vs a vulnerability scan draws it plainly. A real test is people: someone finding the chain of small things, a reused password here, an overshared folder there, that a scanner would report as three unrelated low-severity items.

Price you can see or price behind a sales call. Many firms won’t name a number until you’ve sat through a discovery meeting. There are legitimate reasons scope affects price, but the starting point shouldn’t be a secret. We publish ours on the pricing page, and we think anyone in this business should be able to do the same.

Retest included or retest as an upsell. A test that ends at the report leaves the job half done. You fix the findings, and then someone should verify the fixes hold. Some companies bill that verification as a second engagement. Ours is included in every tier, because the point of the exercise is fixed problems, not documented ones.

Five questions to ask on the first call

You don’t need to be technical to run a good first call. These five questions, asked plainly, will sort most vendors quickly:

  1. Can I see a redacted sample report? The answer you want is yes, sent the same day.
  2. Who actually does the testing, and how much of it is manual? Listen for specifics about people and process, not tool names.
  3. Is the retest included in the price? If it costs extra, ask why.
  4. What will this cost, and what would change that number? A good answer names the drivers: external only or internal too, web applications, phishing. A vague answer means the number is coming later, and it will be bigger.
  5. What do you need from us, and what’s put in writing before you start? The answer should include a scope document and written authorization. Testing without that in place isn’t a service, it’s a liability. Our guide on how to prepare for a penetration test shows what the paperwork should cover.

Red flags that should end the conversation

Some signals are worth walking away from, whatever the price:

  • Fear as a sales tactic. If the pitch leans on breach horror stories and “it’s only a matter of time,” you’re being sold anxiety, not clarity. A test should leave you calmer and better informed, and a company that sells fear tends to write reports that do the same.
  • A report that’s mostly scanner output. Length is not quality. Two hundred pages of unprioritized findings is a way of looking thorough while helping nobody.
  • Alarm about things that are supposed to exist. Your VPN, your email server, and your remote-access portal are on the internet by design. A vendor that flags their existence as a finding, rather than asking whether they’re patched, configured correctly, and behind multi-factor authentication, is padding the count.
  • No talk of scope or authorization. Professional testing follows a defined methodology with rules of engagement agreed up front. NIST publishes one in SP 800-115, and any serious firm works to something like it.
  • Trash talk about your current IT. A tester’s job is an independent read on where you stand, not a wedge to replace your MSP. Vendors who arrive criticizing usually leave selling.

Do certifications matter?

Some. Credentials like OSCP involve hands-on exams and are a reasonable sign a tester can do more than run tools, so it’s fair to ask what the team holds. But treat certifications as a floor, not a deciding factor. They can’t tell you whether the report will be readable, whether the findings will be prioritized honestly, or whether anyone will pick up the phone after delivery. The sample report and the first call tell you those things. A wall of acronyms with a scanner-dump sample report is still a scanner dump.

Does local matter?

For some of the work, yes, in practical ways. A wireless assessment needs someone physically near your building. An internal test is simpler when shipping a device or scheduling a visit doesn’t involve three time zones. And if you’re in Phoenix, Scottsdale, Chandler, or anywhere else in Arizona, working with an Arizona penetration testing company means the people testing your network are accountable in a way a national firm’s rotating bench isn’t.

That said, plenty of national penetration testing companies do good work, and external testing in particular can be done well from anywhere. Local is an advantage, not a disqualifier for everyone else. Weigh it alongside the report, the process, and the price rather than instead of them.

Frequently asked questions

How much should a penetration test cost?

For a small or mid-sized business, a real manual test usually runs $4,000 to $10,000 depending on scope. Many national firms charge more than that for what turns out to be an automated scan. Any company should be able to tell you what moves the price before you commit, and ideally publishes its starting prices.

Should my IT provider do my penetration test?

It’s usually better to have someone independent test the environment your IT provider built. That’s not a knock on them. It’s the same reason financial audits aren’t done by the person who keeps the books. A good MSP welcomes the second opinion, and the report gives them a clear, prioritized list to work from.

What certifications should a penetration testing company have?

Certifications like OSCP are a reasonable signal that testers have hands-on skill, and it’s fair to ask about them. But a certification can’t tell you whether the report will be readable or the findings prioritized. A sample report and a plain-English conversation about scope tell you more than any acronym.

How do I know the testing is actually manual?

Ask who does the testing and what they do that a scanner doesn’t. A real answer describes people chaining small findings together and verifying what’s exploitable. Then check the sample report: manual testing produces a short list of proven findings with evidence, not hundreds of auto-generated entries.

Choosing a penetration testing company, in short

When you’re comparing penetration testing companies, read the sample reports first and let them do the sorting. Then confirm the testing is manual, the scope and authorization go in writing, the price is transparent, and the retest is included. A company that clears all five bars will probably serve you well. Most won’t clear three.

Not sure where to start? Tell us a little about your business and what’s prompting the test, and we’ll come back with a fair, fixed quote and a sample of what you’d receive. Request a quote.

Want to know where you stand?

Tell us a little about your business and what is prompting the test. We will come back with a fair, fixed quote.

Request a quote