Guide

How to Choose a Penetration Testing Vendor.

The shortlist signals worth weighting, the proposal questions worth asking in writing, and the red flags worth walking away from.

File · Start with

Start with the checklist

The fastest way to surface a vendor's real position is to send the twelve-question checklist and require written answers. If they will not commit in writing, that is the answer.

File · The shortlist

The shortlist signals worth weighting

  • [01] Named operator on scoping calls. Not a sales engineer pretending to be one.
  • [02] Public, bylined positions. The people doing the work publish under their own names and take a stance you can disagree with. A vendor whose only public voice is a marketing team has nothing to defend.
  • [03] Written retest policy. Unlimited and untimed, or itemized and metered. There is no in-between.
  • [04] Written artifact destruction policy. 30 days or under. Written attestation provided.
  • [05] References on request. Not logo walls. Not sanitized case studies.

File · Red flags

Red flags worth walking away from

  • [01] A proposal that does not name the delivery operator.
  • [02] Per-finding retest charges.
  • [03] Logo walls instead of references.
  • [04] Unwillingness to commit retest policy or artifact destruction in writing.
  • [05] A 'platform' as the primary deliverable instead of a report.

File · FAQ

Frequently Asked Questions

Q1 How many vendors should I shortlist?

Three is the right number. Two does not give you signal; five wastes everyone's calendar.

Q2 Should I weight price equally with quality?

No. Operator quality compounds across an engagement. A cheaper proposal with worse operators returns less actionable findings, not the same findings at a discount.

Q3 Is a public-sector reference list a green flag?

It indicates the vendor has cleared procurement gates. It does not indicate the technical depth of the offensive work.

Talk to an Operator

Ready to See Your Environment the Way Attackers Do?

Real operators. Real attack paths. Real business impact. Talk to us about your security goals.