5 October 2026 · 9 min read · By Michael van Mameren, Lead Penetration Tester (OSCP)
How to Choose a Penetration Testing Company: The 12 Questions That Separate Testers From Scanners
Every penetration testing company says it does manual testing with certified experts. Most buyers cannot tell which ones mean it until the report lands. These twelve questions, asked before you sign, make the difference visible up front.
Why the choice matters more than the price
A penetration test is only as good as the person running it. Two firms can quote the same number of days against the same scope and deliver completely different results: one finds the authorisation flaw that exposes every customer's data, the other delivers forty medium-severity scanner findings and misses it. The report from the first firm passes your audit, satisfies your enterprise customer and tells your engineers what to fix. The second one has to be repeated.
That is why procurement for penetration testing should look like hiring a specialist, not buying a commodity. The questions below are the ones we would ask if we were on the buying side.
The 12 questions to ask every penetration testing company
Ask them in writing. A firm that answers all twelve clearly is one you can trust with production access.
1. Who exactly will test, by name?
Not the sales engineer, not the team. The individuals who will hold your credentials. If a firm cannot name them before signing, it may be subcontracting or assigning whoever is free. Named testers are also what auditors and enterprise customers ask for.
2. What certifications do those testers hold?
OSCP is the baseline for hands-on network and infrastructure testing; OSWE or equivalent for web application depth; OSEP, CRTO or CREST CCT for red team work. Vendor badges and generic security certificates do not demonstrate offensive skill.
3. How much of the test is manual?
Ask for a percentage and for examples of findings that a scanner could not have produced: business-logic abuse, authorisation chains, privilege escalation paths. A firm that cannot give examples is selling scans.
4. Which methodology, and can we see a sample report?
OWASP Testing Guide, PTES and NIST SP 800-115 are the recognised references. A redacted sample report shows you the evidence quality, the severity model and whether your engineers could act on it.
5. How is scope defined and what happens when it changes?
Expect a written scope with applications, hosts, roles and test positions, and a clear rule for scope growth discovered during testing. Vague scope is the most common source of disputes and of untested systems.
6. How are critical findings handled during the test?
A remotely exploitable critical should reach you the day it is found, not in the report three weeks later. Ask for the escalation path and who answers the phone.
7. Is a retest included, and within what window?
Remediation verification closes the loop for ISO 27001, SOC 2, PCI DSS and DORA. Firms that omit it leave you with a report of open findings at audit time.
8. What does the report contain?
Executive summary for the board, scope statement for the auditor, findings with reproducible evidence and CVSS severity for engineers, compliance mapping where relevant, and a remediation plan with priorities. One document that serves all three audiences.
9. How is our data handled during and after the test?
Where findings and evidence are stored, who has access, encryption, retention and deletion. For EU organisations this is an Article 28 GDPR question and the answer should be in the contract.
10. Are you insured and will you sign our NDA and rules of engagement?
Professional indemnity and cyber liability insurance, plus a signed rules-of-engagement document before any testing starts. DORA Article 27 makes insurance an explicit requirement for TLPT testers.
11. Which frameworks can you report against?
If you need the test for ISO 27001, SOC 2, PCI DSS, DORA, NIS2 or HIPAA, the firm should know the clauses and map findings to them without being asked twice.
12. Can we speak to two reference clients in our sector?
References confirm the answers above. A firm that tests banks and SaaS platforms every month will have them; a reseller will stall.
Red flags versus green flags
Quick signals from the first conversation.
| Topic | Red flag | Green flag |
|---|---|---|
| Quote | A price without a scoping call | A written scope with day count and named lead tester |
| Testers | A team name, no individuals | Named testers with OSCP, OSWE or CREST credentials |
| Method | Our platform scans continuously | Manual testing described with examples of logic findings |
| Report | No sample available | Redacted sample with evidence, severity and remediation |
| Pricing claims | Lowest price in the market | Scope-based pricing explained line by line |
| Retest | Not mentioned | Included within a stated window |
| Compliance | We cover everything | Specific clause mapping for your framework |
The shortlist process that works
Three steps, two weeks, one decision you will not regret.
- Write a one-page scope: what to test, why, by when, and which framework the report must serve
- Send it to three firms and ask the twelve questions in writing alongside the quote
- Hold a 30-minute call with the named lead tester, not the account manager, and ask how they would approach your highest-risk system
- Compare day counts and deliverables, not totals
- Check two references, then sign rules of engagement before any testing starts
How HackersHub answers the twelve
Named OSCP- and OSWE-certified testers on every engagement, led by Michael van Mameren. Manual testing with scanner output used only for coverage. OWASP, PTES and NIST SP 800-115 methodology stated in every report. Written scope with day count before signing, same-day escalation of criticals, retest included, reports mapped to ISO 27001, SOC 2, PCI DSS, DORA, NIS2 and HIPAA on request, Article 28-compliant data handling, professional indemnity insurance, and sector references on request. Put the questions to us and compare the answers.
Frequently asked questions
Ready to ask the twelve questions?
Send us your one-page scope. You get written answers, a day count and the named lead tester before you decide. Talk to an expert.