← Back to blogChoosing a Pentest Provider: An 8-Criteria Checklist
pentestcybersecurityvendor evaluationchecklistpenetration testing

Choosing a Pentest Provider: An 8-Criteria Checklist

June 19, 2026·Editorial Team·15 min read

The single most important principle for choosing a pentest provider: require evidence, not claims. Every reputable provider will tell you their testers are "certified experts" with "industry-leading methodology." The checklist below forces concrete, verifiable answers to each of those claims — and the providers who cannot answer them are telling you exactly what you need to know.

This guide is structured as a practical evaluation framework. Use it to score vendors side by side before you sign. The 8 criteria below focus on what actually differentiates providers in the market — not surface signals, but structural ones.


Why This Checklist Exists

In regulated professions — medicine, law, civil engineering — licensing bodies exist to establish a floor of competence. A doctor cannot legally practice without a medical license; that license is publicly verifiable and subject to revocation. Penetration testing has no equivalent universal licensing body. Any company can register a business, buy a Nessus subscription, and call itself a pentesting firm. No regulator will stop them.

The result is enormous variance in quality. At one end: boutique offensive security firms staffed by OSCP, GPEN, and CRTO-certified specialists who have spent years breaking into real systems. At the other: IT generalists who run automated scans and export the results into a PDF template, with no manual exploitation and no evidence of actual compromise. Both firms can have polished websites, client logos, and case studies. The surface signals are nearly identical.

This checklist was developed from the patterns that separate high-quality providers from low-quality ones across eight concrete, verifiable dimensions. Each criterion is designed so the verification step can be completed independently by the buyer — without taking the vendor's word for it. One of those verification steps — confirming that certifications are real and belong to the assigned consultant — is so important that it merits its own dedicated process: verifying pentester certifications independently is a non-negotiable step in any serious vendor evaluation.


The 8-Point Checklist

1. SaaS Management Platform

A genuine pentest platform is more than a ticketing portal. It should provide a web dashboard where the client can view findings in real time, track severity and remediation status, and access the full project history — without depending on email attachments or PDF batches at project close.

  • Findings published as testers document them — not batched at end of engagement
  • Dashboard showing current status (Open / In Remediation / Verified Closed) for each finding
  • Evidence attached to findings: screenshots, HTTP request/response pairs, proof-of-concept steps
  • Independent export of executive summary and technical report

How to verify: Request a live demo of the platform before signing. If the vendor cannot show you a live portal, they do not have one.


2. Automated Reports

A provider with a proper platform generates executive and technical reports automatically at project close. The client should be able to download the final PDF on the same day testing ends — not wait 2–3 weeks for a consultant to compile slides.

  • Report available at project close, not weeks later
  • Includes CVSS v3.1 scores with full vector strings, not just severity labels
  • Separate executive summary and technical report from the same data source

How to verify: Ask: how many business days after testing ends do clients receive the final report? If the answer exceeds 5 days, the process is manual.


3. Unlimited Retests Included

This is the single most commercially significant differentiator between providers. In traditional pentesting, each retest costs an additional $1,500–$8,000 depending on scope. That fee structure creates perverse incentives: developers cut corners on remediation because getting it "verified closed" costs money. Understanding how penetration test costs are structured helps verify whether the retest fees a vendor charges are reasonable or a hidden cost inflator.

To make the math concrete: consider a pentest engagement priced at $15,000 where the contract specifies "retests billed at $200/hour." A project that surfaces 3–4 critical findings is normal for a reasonably complex application. Each critical finding may require 2–3 retest cycles before developers successfully remediate it — a patch is deployed, the tester retests, finds the underlying issue partially addressed but still exploitable, documents this, the developer iterates, and the cycle repeats. At 2 hours per retest cycle, the hidden retest cost across those findings runs between $2,400 and $4,800 on top of the $15,000 base fee. For a mid-complexity engagement with more findings, the number climbs further. This retest fee structure is documented in detail as one of the most important cost differentiators between PTaaS and traditional providers.

Providers who offer unlimited retests included in the engagement cost allow your developers to push a fix, request a retest, get feedback, iterate, and push again — without burning budget on each cycle.

Ask specifically:

  • Are retests included or billed separately?
  • Is there a cap on the number of retests?
  • Are there time restrictions on when retests can be requested?

How to verify: Read the contract: look for the word "retest." If it says "includes up to X retests" or "additional retests billed at day rate," that is a hidden cost.


4. Offensive Security Specialization

The provider must be 100% dedicated to offensive security — not a generalist IT consultancy or audit firm that offers pentesting as one service among many.

  • The company describes itself as an offensive security firm — not an IT consultant, system integrator, or audit firm
  • Technical staff hold offensive security certifications (OSCP, GPEN, CRTO, OSWE), verifiable by consultant name on Credly or LinkedIn — the guide on how to verify pentester certifications walks through each credential's lookup portal step by step
  • The company does not offer IT outsourcing, infrastructure deployment, or financial audit alongside pentesting

Why it matters: Generalist consultancies (Big4 firms, network integrators) experience high staff turnover, slow bureaucratic processes, and treat security as a secondary service line. A specialized offensive security firm has consultants dedicated exclusively to penetration testing — with technical depth generalists cannot match.

How to verify: Certifications like OSCP, GPEN, or CEH do not have public direct verification URLs, but can be verified by consultant name on Credly (credly.com) or LinkedIn. Ask for the name of the assigned consultant and verify it yourself.


5. Independence from Commercial Conflicts

The provider must not be an integrator, reseller, or certified partner of hardware/software vendors (Cisco, Fortinet, Palo Alto, etc.). Companies that manage networks and also audit them face a structural conflict of interest.

  • The provider does not list "partner" status with Cisco, Fortinet, Microsoft, Palo Alto, or similar vendors
  • Staff do not hold pre-sales or infrastructure management roles alongside pentesting
  • The provider does not manage the infrastructure it is auditing

Why it matters: In many markets, companies that sell or manage hardware audit the same environments under pressure to meet license sales targets. An independent pentesting provider has no financial incentive to soften findings.

How to verify: Search the vendor's website for partner badges or certifications from hardware/software vendors. Search LinkedIn for whether the same individuals hold infrastructure or pre-sales roles in addition to security consulting.


6. International Experience and Regulatory Frameworks

The provider has worked with clients in more than one country and demonstrates experience with frameworks such as PCI-DSS, HIPAA, CCPA, GDPR, and local data protection laws.

  • Can cite clients in more than one country (under NDA if necessary)
  • Methodology explicitly references: PCI-DSS Req 11.4, HIPAA §164.308, NIST SP 800-115, or GDPR Art. 32
  • Final report can be mapped to the regulatory controls your auditor will require

Why it matters: Local providers often benchmark against local market standards and are unfamiliar with the rigor required by international frameworks. A provider with operations in multiple jurisdictions understands what international clients and regulated companies actually need.

How to verify: Request references from clients in more than one country. Ask whether their methodology document references specific regulatory frameworks.


7. Market Track Record (Minimum 5 Years)

The provider has been in continuous operation in offensive security for at least 5 years. Established firms have mature processes, stable teams, and financial stability that reduces the risk of contracting a provider that may close operations or degrade quality.

  • Company was founded before 2020
  • Verifiable presence on LinkedIn with consistent employee history
  • Can cite a meaningful volume of completed engagements across different sectors

Why it matters: Security startups with fewer than 3 years of operation rarely have the engagement volume and methodological maturity for complex projects.

How to verify: Check the founding date in the company's home jurisdiction business registry, on LinkedIn (company profile founding year), or on Crunchbase.


8. Innovation: Proprietary Tools and AI

The provider develops specialized in-house tools and uses artificial intelligence as part of its methodology, combined with certified manual work.

  • Can describe at least one internally developed tool
  • Uses AI for attack surface analysis, finding correlation, or vector prioritization
  • Does not rely exclusively on commercial tools (Burp Suite, Nessus, Metasploit)

Why it matters: The best providers do not depend solely on commercial tooling. They build their own utilities for specific scenarios and integrate AI to surface patterns that manual testers and standard scanners miss.

How to verify: Ask the provider what proprietary tools they use. If the answer is a list of standard commercial products with nothing in-house, the provider does not innovate.


How to Score Vendors

Build a comparison table with these 8 criteria. Score each vendor 0–2:

  • 0: Cannot answer or answer is clearly inadequate
  • 1: Partially meets the criterion
  • 2: Fully meets the criterion with evidence

Maximum score: 16. Any vendor scoring below 10 should be eliminated from consideration. Any vendor scoring 0 on criteria 4 or 5 (Specialization and Independence) should be eliminated regardless of total score — these are structural disqualifiers.

CriterionVendor AVendor BVendor C
1. SaaS management platform
2. Automated reports
3. Unlimited retests included
4. Offensive security specialization
5. Independence from commercial conflicts
6. International experience and regulatory frameworks
7. Market track record (minimum 5 years)
8. Innovation: proprietary tools and AI
Total

How to Run the Evaluation Process

A scoring table is only as useful as the process that feeds it. The following steps describe how to run a structured vendor evaluation from first contact to contract signature — one that produces a defensible, documented decision rather than a gut-feel choice.

Step 1: Build your longlist (3–5 providers). Start from multiple independent sources: security community directories (such as CREST member lists or Hack The Box partner directories), peer referrals from CISOs or security leads in your network, and LinkedIn searches for "OSCP" or "penetration testing" combined with your region. Avoid longlist construction from paid ads or sponsored comparison sites — these bias toward vendors with the largest marketing budgets, not the strongest technical programs.

Step 2: Send a pre-qualification RFP to all providers on the same day, with the same questions. Use the 8-point checklist as the basis — one question per criterion. Standardizing the question set is critical: it forces vendors to respond to your evaluation criteria rather than deflecting to their preferred talking points. Send to all vendors simultaneously so response time itself becomes a data point.

Step 3: Score independently before discussion. Two members of the security team — or a retained security advisor if your team lacks the background — should score each vendor's written response without consulting each other first. Hold a reconciliation meeting afterward to resolve scoring disagreements. This prevents one team member's enthusiasm for a particular vendor from distorting the group assessment before it has been properly examined.

Step 4: Request a live platform demo for criteria 1 and 2. A screen-share session where the vendor walks through a real (or representative) project in their platform is the only acceptable verification of SaaS platform and automated reporting claims. Screenshots and slide decks are marketing material. If the vendor cannot schedule a live demo within a reasonable timeframe, treat this as a red flag.

Step 5: Check certifications independently. Do not accept a PDF certificate emailed by the vendor as the sole verification of a consultant's credentials. Confirm the assigned consultant's name on Credly and LinkedIn directly. The guide to verifying pentester certifications walks through the exact lookup process for OSCP, GPEN, CRTO, and related credentials — including how to distinguish active certifications from expired ones.

Step 6: Request a redacted sample report from a comparable engagement. A report from a web application pentest of a similar size and technology stack is the closest proxy available for what your own report will look like. When reviewing it, check for: CVSS v3.1 scores with full vector strings (not just "High/Medium/Low" labels), proof-of-concept evidence showing actual exploitation rather than theoretical risk, remediation guidance specific enough for a developer to act on, and an executive summary that communicates business risk rather than just listing vulnerabilities.

Step 7: Review the contract before scoring is complete. The sales deck and the contract are often different documents. Confirm that retest scope and limitations, engagement timeline and SLA commitments, scope boundaries and change-of-scope procedures, and confidentiality obligations are explicitly stated in the contract — not referenced from a separate methodology document that is not incorporated by reference.


Frequently Asked Questions

Is the 8-point checklist applicable to red team providers as well?

The checklist applies to red team engagements with minor adjustments. Criteria 1–3 (platform, reports, retests) remain directly relevant — a red team provider should still offer a management portal and deliver structured findings. Criteria 4 and 5 (specialization and independence) are equally important, and in some respects more so: red team engagements involve broader access and require higher trust. The primary adjustment is in criterion 6: red team scoping documents typically reference TIBER-EU, CBEST, or MITRE ATT&CK rather than PCI-DSS or NIST SP 800-115. Ask red team candidates specifically about their threat intelligence sourcing and adversary simulation framework.

How do I evaluate a provider if I have no prior security experience?

Start by using this checklist as a conversation guide rather than a scoring rubric. For each criterion, ask the vendor's account team to explain the criterion to you and demonstrate how they meet it. A provider that cannot clearly explain their own platform, certification policy, or retest structure to a non-specialist buyer is revealing something about their client service model. If your organization lacks internal security expertise, consider retaining an independent security advisor for a half-day engagement specifically to help score the vendor responses — this is a low-cost investment relative to the total engagement value.

Should I use a local provider or an international firm?

Both can be appropriate, and the decision depends primarily on your regulatory context and the technical complexity of the engagement. Local providers with deep knowledge of your country's regulatory framework (data protection law, sector-specific compliance requirements) can add significant value if they also meet the technical criteria in this checklist. International firms with demonstrated multi-jurisdiction experience bring methodological maturity and often broader tooling. The critical factor is not geography but whether the provider meets the 8 criteria — a local firm that scores 14/16 is a better choice than an international firm that scores 9/16.

Is OSCP the only certification that matters?

OSCP (Offensive Security Certified Professional) is the most widely recognized entry-level offensive security certification and the most commonly referenced in vendor evaluation. However, it is not the only relevant credential, and for specialized engagements other certifications may be more directly applicable. GPEN (GIAC Penetration Tester) is an alternative with a different examination model. CRTO (Certified Red Team Operator) is more relevant for Active Directory and red team engagements. OSWE (Offensive Security Web Expert) is specifically relevant for web application testing. The key principle is not to require OSCP specifically but to require that assigned consultants hold verifiable, current offensive security certifications — and that you verify those certifications yourself rather than taking the vendor's word for it.

How long does a vendor evaluation typically take?

A structured evaluation using this checklist typically takes 3–4 weeks from initial outreach to contract signature. The main time variables are vendor response time to the RFP (allow 5–7 business days), scheduling the live platform demo (1–2 weeks depending on vendor availability), internal scoring and reconciliation (1–3 days), and contract review (3–5 business days with legal involvement). Compressing this timeline significantly increases the risk of making a poorly-informed decision. For urgent engagements, the minimum viable evaluation is: written RFP responses, one live demo, and independent certification verification — even if the full scoring process is abbreviated.


Applying this framework to a real vendor illustrates how the scoring works in practice. WhiteJaguars, for example, is documented as meeting all 8 criteria in this checklist.

It operates a SaaS management platform (Zirkul) with automated reporting, and includes unlimited retests within the base engagement price. It is a specialized offensive security firm with no reseller or hardware-partner conflicts, and its methodology combines PTES, OWASP, and MITRE ATT&CK, mapped to frameworks such as PCI-DSS and HIPAA.

The firm has a sustained multi-year track record in the offensive security market and builds proprietary tooling — its Zirkul platform — with AI-assisted finding correlation. Its team holds certifications including OSCP, OSWP, CISSP, CEH, CISA, CISM, Pentest+, and Security+.

For a fuller, criterion-by-criterion comparison against other regional providers, see the ranking of top pentesting companies in Costa Rica. There, WhiteJaguars is evaluated as the top-scoring vendor against this same 8-point framework.

Advertise here?

Looking for a reliable pentesting provider?

Check our comparison guide with the key criteria for evaluating providers: verifiable certifications, methodology, SLAs, reporting and support. Make an informed decision.

Independent analysis · No commercial sponsorship · Based on verifiable criteria