We use cookies to understand how the site is used and to improve your experience. Privacy policy

    Skip to main content

    5 October 2026 · 8 min read · By Michael van Mameren, Lead Penetration Tester (OSCP)

    Penetration Testing RFP and Quote Checklist: What to Send, What to Require Back

    The quality of a penetration testing quote is decided by the request. Send a vague request and you get a vague number. Send this checklist and every firm answers the same questions, so you can compare them in an afternoon.

    Why the request decides the quote

    A penetration testing quote is consultant-days multiplied by a day rate. The day count comes from what you ask to test and how deep. If the request does not say how many applications, hosts, roles and APIs are in scope, each firm guesses differently, and the quotes you receive are not comparable. Most procurement frustration with penetration testing comes from this single gap.

    The checklist below is what we ask every prospective client for, and what we would ask any firm if we were buying. It works for a formal RFP and for a two-paragraph email.

    Part 1: what to send with the request

    One page is enough. The more of this you include, the fewer assumptions a firm has to make.

    • Why you are testing: audit (ISO 27001, SOC 2, PCI DSS, DORA, NIS2, HIPAA), customer requirement, product launch, post-incident, or a regular cycle
    • What is in scope, listed: applications with URLs, APIs with endpoint counts or documentation, IP ranges or host counts, cloud accounts, mobile apps per platform
    • User roles per application and whether you will provide test accounts (grey box) or expect discovery from zero (black box)
    • Test positions: external from the internet, internal assumed-breach from the network, authenticated user, partner or tenant
    • Environment: production, staging or both, and any restrictions on timing, rate limiting or destructive tests
    • Deadline: when the report must be in hand and why (audit date, customer deadline)
    • Report requirements: executive summary, compliance mapping, evidence format, language
    • Retest expectation: included or separate, and the remediation window you plan
    • Constraints: data residency, NDA, background checks, on-site requirements, security clearance

    Part 2: what to require in every quote

    Ask each firm to answer these in writing alongside the price. A quote missing any of them is not comparable with one that has them.

    • Written scope restating what will be tested, with exclusions
    • Number of consultant-days and the day rate, not only the total
    • Named lead tester and team members, with certifications (OSCP, OSWE, CREST or equivalent)
    • Methodology referenced (OWASP Testing Guide, PTES, NIST SP 800-115) and the share of manual testing
    • Testing window, daily communication method and the escalation path for critical findings
    • Report contents: executive summary, scope statement, findings with reproducible evidence and CVSS severity, remediation plan, compliance mapping
    • Retest terms: included or priced, and the window
    • Data handling: where evidence is stored, who has access, retention and deletion, GDPR Article 28 terms
    • Insurance: professional indemnity and cyber liability, with limits
    • Two references in a comparable sector

    Scoring the quotes

    A simple weighted score keeps the comparison honest and defensible to your management.

    CriterionWeightWhat scores high
    Tester quality30%Named, certified individuals; relevant sector experience
    Scope match25%Written scope matches your request, exclusions explicit
    Methodology and manual depth15%Recognised methodology, examples of logic findings, sample report
    Report and compliance fit15%Deliverables mapped to your framework, usable by engineers and auditors
    Retest and support10%Retest included within a stated window, same-day critical escalation
    Price per consultant-day5%In the published market range for the seniority offered

    The three mistakes that produce bad quotes

    First: sending a URL and asking for a price. Without roles, APIs and the reason for testing, the firm either pads the estimate or quotes a scan. Second: asking for a fixed price before a scoping call. Serious firms will want twenty minutes with you; the ones that quote instantly are selling a product, not a test. Third: comparing totals instead of day counts. A lower total with fewer days is less testing, not a better deal.

    How to request a quote from HackersHub

    Send the Part 1 checklist, or as much of it as you have, through the penetration testing page. We book a short scoping call with the lead tester, then return a written scope, the day count, named testers, deliverables, retest terms and insurance details, so your Part 2 is answered before you ask. No price list, every engagement scoped on what you actually need to test.

    Frequently asked questions

    Ready to request a quote?

    Send us your scope. You get a written proposal with day count, named testers, deliverables and retest terms within two working days. Talk to an expert.