
How to Actually Compare Penetration Testing Companies
The short answer: compare penetration testing companies on verifiable certifications, documented methodology, retest policy, reporting platform, and communication standards — not on price or marketing claims alone. Use the 12-point scoring matrix below to turn a subjective sales process into an objective vendor evaluation.
Why Most Vendor Comparisons Fail
Most security buyers compare pentest vendors the wrong way. They collect three quotes, pick the cheapest option that sounds credible, and discover the gaps only after the engagement ends — when the report is a 40-page PDF with no remediation support, the findings can't be verified, and the testers are nowhere to be found.
Penetration testing is not a commodity. The difference between a rigorous manual engagement and an automated scan dressed up as a pentest is the difference between knowing your attack surface and having a false sense of security. The stakes are high enough that the procurement process deserves a structured framework.
This guide gives you one.
The 12-Point Evaluation Framework
Each criterion below maps to a weight in the scoring matrix. Apply the matrix to every vendor you evaluate, then compare totals.
1. Verifiable Certifications
Anyone can claim "certified ethical hacker" on a sales deck. What matters is certifications that require demonstrated hands-on skill and can be independently verified. The guide on how to verify pentester certifications walks through exactly how to check OSCP, GPEN, CREST, and other credentials before signing:
- OSCP (Offensive Security Certified Professional) — requires passing a 24-hour live exam on a real network
- GPEN / GWAPT (GIAC) — written exams backed by practical labs
- CREST (Council of Registered Ethical Security Testers) — UK-origin accreditation body with public registries
Ask the vendor for tester names and certificate IDs, then verify them directly on the issuing body's website. If they hesitate, that's a red flag.
2. Documented Methodology
A credible vendor follows a recognized, auditable framework — not a proprietary "secret sauce" process:
- PTES (Penetration Testing Execution Standard) — covers reconnaissance, exploitation, and post-exploitation phases
- OWASP Testing Guide — the reference standard for web application security testing
- NIST SP 800-115 — the US federal technical guide to information security testing
Ask for a methodology document before signing. It should map each phase to specific techniques, tools, and objectives. Generic descriptions ("we test your systems for vulnerabilities") are not methodology.
3. Manual vs. Automated Testing Ratio
Automated scanners (Nessus, Burp Suite, OpenVAS) find known CVEs and low-hanging fruit. Manual testing finds logic flaws, business-layer vulnerabilities, and chained attack paths that no scanner will catch. A serious engagement is predominantly manual, with automated tools used to accelerate enumeration — not to replace analysis.
Ask for a percentage breakdown. If a vendor can't answer, assume it's mostly automated.
4. Retest Policy
Finding vulnerabilities is half the job. The other half is confirming they've been fixed. Some vendors charge a separate fee for each retest cycle; others include unlimited retests within the engagement period.
Unlimited retests are the correct model. A vendor that charges for retests has a financial incentive not to help you remediate quickly.
5. Reporting Platform (Real-Time vs. PDF)
A static PDF delivered at engagement end is the 2005 model. Modern vendors offer:
- A live dashboard with findings updated as the engagement progresses
- Severity classifications with CVSS scores and business-context descriptions
- Evidence artifacts (screenshots, request/response pairs, PoC code) attached to each finding
- Remediation guidance written for developers, not just auditors
Real-time visibility lets your team start fixing critical findings before the engagement closes — compressing the window of exposure.
6. Time-to-Delivery
How long from signed statement of work to final report? Industry norm for a standard web application pentest is 2–4 weeks. Faster is not necessarily better — rushed engagements cut manual testing hours. But vendors with 8–12 week queues create real business risk if you're trying to meet a compliance deadline or close a deal.
Get a committed delivery date in the contract, not a verbal estimate.
7. References and Case Studies
Ask for two or three client references in your industry vertical. Then call them. Ask specifically: Did the report contain actionable findings? Were there surprises (things your internal team missed)? How was communication during the engagement? Would you hire them again?
Published case studies are useful context, but direct reference calls are the signal.
8. Communication During Engagement
What happens when the tester finds a critical vulnerability on day three of a ten-day engagement? You need a defined escalation path: direct Slack/Teams channel, named point of contact, SLA for critical-finding notifications.
Ask for the communication protocol in writing before you sign.
9. NDA and Rules of Engagement Quality
The rules of engagement (RoE) document defines scope, permitted techniques, out-of-scope systems, emergency stop procedures, and liability. A thin or template RoE is a sign the vendor has not done enough of these to have refined the document.
Your legal team should review the RoE. Pay attention to how liability is allocated if collateral damage occurs — it happens, and well-run vendors account for it contractually.
10. Pricing Transparency
Can the vendor explain exactly what drives the price — number of testers, days of engagement, scope size? Or is it a black-box quote with no line items?
Transparent pricing lets you make real trade-offs. It also signals that the vendor understands their own cost structure, which correlates with operational maturity.
11. Industry and Vertical Expertise
A tester who has run ten engagements in fintech understands regulatory expectations, common business logic flaws in payment flows, and how to frame findings for a CISO presenting to a board. General security knowledge matters, but vertical expertise accelerates both the engagement and the remediation conversation.
Ask what percentage of their clients are in your industry.
12. SLA for Remediation Support
After the report is delivered, your engineering team will have questions: "What does this finding actually mean in our stack?" "Is this a true positive?" "Is this remediation approach sufficient?"
A serious vendor includes post-delivery support — typically 30 to 90 days of access to the tester who ran the engagement. If support ends at report delivery, the engagement value drops significantly.
Scoring Matrix
Apply this matrix to each vendor. Score each criterion from 1 (poor) to 5 (excellent), multiply by the weight, and sum the weighted scores. The maximum possible score is 100.
| # | Criterion | Weight | Score (1–5) | Weighted Score | Notes |
|---|---|---|---|---|---|
| 1 | Verifiable certifications (OSCP, GPEN, CREST) | 12 | Can you verify cert IDs independently? | ||
| 2 | Documented methodology (PTES, OWASP, NIST) | 10 | Did they share a methodology doc? | ||
| 3 | Manual vs. automated testing ratio | 10 | What % is manual? | ||
| 4 | Retest policy (unlimited vs. charged) | 10 | Included or billed separately? | ||
| 5 | Reporting platform (real-time vs. PDF) | 8 | Live dashboard or end-of-engagement PDF? | ||
| 6 | Time-to-delivery | 7 | Committed date in contract? | ||
| 7 | References and case studies | 8 | Did you call the references? | ||
| 8 | Communication during engagement | 8 | Named PoC, SLA for critical findings? | ||
| 9 | NDA and rules of engagement quality | 7 | Reviewed by your legal team? | ||
| 10 | Pricing transparency | 7 | Line-item quote or black box? | ||
| 11 | Industry / vertical expertise | 8 | % clients in your vertical? | ||
| 12 | SLA for remediation support | 5 | Days of post-delivery access? | ||
| Total | 100 |
Scoring guide: 80–100 = strong vendor; 60–79 = acceptable with caveats; below 60 = significant risk, proceed only with contractual protections in place.
8 Questions to Ask During the Sales Call
Before you issue a purchase order, run these questions through the sales process. The quality of the answers — not just the content — tells you a lot about the vendor's operational maturity.
-
"Can you give me the names and certificate IDs of the testers who will work my engagement, so I can verify their credentials?" A confident vendor answers immediately. A hesitant one is a warning sign.
-
"Walk me through your methodology. Which framework do you follow — PTES, OWASP, NIST SP 800-115 — and how does your process map to its phases?" You want specifics, not a sales deck summary.
-
"What percentage of your testing is manual versus automated?" Push for a number. "Mostly manual" is not an answer.
-
"Is retesting included in the price, or is it billed separately? How many retest cycles are covered?" Get this in writing before you sign.
-
"Do you have a real-time reporting platform, or do we receive a PDF at the end?" Ask for a demo of the platform if they claim one exists.
-
"What is your escalation procedure if we find a critical vulnerability mid-engagement?" There should be a named contact, a channel, and an SLA.
-
"Can you provide two references from clients in our industry vertical? We will call them." Any legitimate vendor expects this request.
-
"What post-delivery support is included — and for how long can we contact the tester who ran our engagement?" The answer reveals how they think about remediation, not just discovery.
Common Traps in Vendor Comparisons
Even buyers who use a structured framework can fall into evaluation traps that distort the final decision. These are the most common ones.
Comparing sticker prices without scope equivalence. A $6,000 quote and a $15,000 quote may be for completely different scopes. One vendor may be pricing a two-day automated scan; another may be pricing a ten-day manual engagement with unlimited retests. The only way to make prices comparable is to send an identical, standardized scope document to all vendors simultaneously and request itemized responses. Without a shared scope baseline, price comparison is meaningless.
Treating certifications as interchangeable. CISSP is a management and architecture certification — no offensive skills are tested. CEH is largely a multiple-choice exam that tests recall of concepts. OSCP requires 24 hours of live exploitation on a real isolated network with no internet access to solutions. These are not equivalent credentials. When evaluating offensive testing vendors, weight practical, hands-on certifications (OSCP, OSEP, CRTO, GPEN, GXPN) substantially higher than management-track or theory-only credentials.
Ignoring platform maturity. A vendor who emails zipped PDFs as the primary finding delivery mechanism creates significant operational overhead for any security team managing active development cycles. Tracking remediation in a spreadsheet, manually creating tickets from PDF findings, and waiting for a follow-up engagement to retest — all of this overhead is invisible on a quote but very visible in execution.
Selecting the vendor who found the most findings in a sample report. Finding volume is not a proxy for engagement quality. A sample report with 80 scanner-generated informational findings and no exploited critical vulnerabilities is demonstrably weaker than a report with four manually-verified critical attack chains. Evaluate findings by business impact and exploitation evidence, not by count.
Frequently Asked Questions
How many vendors should I compare before selecting?
Three to five vendors is the practical range for a rigorous comparison. Fewer than three limits your ability to calibrate the scoring matrix — you need variation to distinguish strong from weak responses. More than five creates diminishing returns: the evaluation overhead grows and the incremental signal from a sixth vendor is usually minimal. For high-stakes engagements (compliance-driven, pre-IPO, or post-breach), five vendors with full scoring matrix evaluation is worth the effort.
Is it appropriate to ask vendors for a proof-of-concept before signing?
A full proof-of-concept engagement before signing is not standard practice and most reputable vendors will not agree to it — nor should they, since it represents significant unpaid work. What is appropriate: requesting a sanitized sample report from a real prior engagement (with client identifying information removed), a live demo of the reporting platform, and a technical scoping call where you can evaluate the methodology depth of the assigned tester. Some vendors also offer small-scope paid pilots as a way to evaluate quality before committing to a larger engagement.
How do I evaluate vendors if I have no prior security expertise?
Focus on verifiable proxies rather than technical judgment. Certifications can be independently verified through issuing body portals regardless of your own security knowledge. References can be called and direct questions asked about outcomes, communication, and value delivered. Sample reports can be reviewed for structural completeness — evidence per finding, CVSS scores with vector strings, specific remediation guidance — without needing to evaluate technical depth. If your organization has no internal security expertise, engaging a fractional CISO or security advisor to assist with vendor evaluation is a legitimate and cost-effective approach.
Should I consider vendor location and time zone?
Time zone alignment matters primarily for communication during the engagement — specifically for critical-finding escalations. If a tester operating from a UTC+9 time zone discovers a critical vulnerability at their local 2 p.m., that may be 2 a.m. your time. Define expected communication hours and escalation SLAs explicitly in the rules of engagement, regardless of vendor location. Beyond communication, local legal jurisdiction can matter for regulated industries: some compliance frameworks (particularly in financial services and healthcare) require that data and findings not cross certain jurisdictional boundaries. Verify this with your legal counsel before engaging a vendor in a different region.
What is the typical turnaround time for a vendor comparison process?
From issuing a scoping document to signing a contract, a thorough vendor comparison typically takes three to six weeks. The first week covers distributing the scope document and setting evaluation criteria. Weeks two and three are for receiving and reviewing proposals, verifying certifications, and reviewing sample reports. Week four involves reference calls and final scoring. Weeks five and six cover legal review of the rules of engagement and contract terms. Compressing this timeline is possible but tends to produce worse outcomes — the steps that get skipped under time pressure (reference calls, certification verification, legal review) are precisely the ones that catch problems before they become expensive.
Don't Buy on Price Alone
The cheapest pentest is often the most expensive decision you make. A missed critical vulnerability, a compliance failure, or a breach traced back to a finding the vendor didn't catch — these costs dwarf the delta between a serious vendor and a discount one.
Use the scoring matrix. Call the references. Verify the certifications. Ask the eight questions. The checklist for choosing a pentest provider complements this matrix with an 8-point framework focused on platform, independence, and specialization criteria.
Applying this matrix to vendors you evaluate will surface the same patterns — a provider that scores high across all dimensions is typically one that has invested in tooling, process, and certification long-term.
WhiteJaguars is one provider built around these criteria: verifiable certifications (OSCP, CISSP, CEH and CISM, among others) shared upfront, unlimited retests included in the engagement price, a live reporting platform, and post-delivery remediation support.
References: Penetration Testing Execution Standard (PTES), OWASP Web Security Testing Guide, NIST SP 800-115 Technical Guide to Information Security Testing and Assessment.
Looking for a reliable pentesting provider?
Check our comparison guide with the key criteria for evaluating providers: verifiable certifications, methodology, SLAs, reporting and support. Make an informed decision.
Independent analysis · No commercial sponsorship · Based on verifiable criteria