5 October 2026 · 8 min read · By Michael van Mameren, Lead Penetration Tester (OSCP)
Penetration Testing RFP and Quote Checklist: What to Send, What to Require Back
The quality of a penetration testing quote is decided by the request. Send a vague request and you get a vague number. Send this checklist and every firm answers the same questions, so you can compare them in an afternoon.
Why the request decides the quote
A penetration testing quote is consultant-days multiplied by a day rate. The day count comes from what you ask to test and how deep. If the request does not say how many applications, hosts, roles and APIs are in scope, each firm guesses differently, and the quotes you receive are not comparable. Most procurement frustration with penetration testing comes from this single gap.
The checklist below is what we ask every prospective client for, and what we would ask any firm if we were buying. It works for a formal RFP and for a two-paragraph email.
Part 1: what to send with the request
One page is enough. The more of this you include, the fewer assumptions a firm has to make.
- Why you are testing: audit (ISO 27001, SOC 2, PCI DSS, DORA, NIS2, HIPAA), customer requirement, product launch, post-incident, or a regular cycle
- What is in scope, listed: applications with URLs, APIs with endpoint counts or documentation, IP ranges or host counts, cloud accounts, mobile apps per platform
- User roles per application and whether you will provide test accounts (grey box) or expect discovery from zero (black box)
- Test positions: external from the internet, internal assumed-breach from the network, authenticated user, partner or tenant
- Environment: production, staging or both, and any restrictions on timing, rate limiting or destructive tests
- Deadline: when the report must be in hand and why (audit date, customer deadline)
- Report requirements: executive summary, compliance mapping, evidence format, language
- Retest expectation: included or separate, and the remediation window you plan
- Constraints: data residency, NDA, background checks, on-site requirements, security clearance
Part 2: what to require in every quote
Ask each firm to answer these in writing alongside the price. A quote missing any of them is not comparable with one that has them.
- Written scope restating what will be tested, with exclusions
- Number of consultant-days and the day rate, not only the total
- Named lead tester and team members, with certifications (OSCP, OSWE, CREST or equivalent)
- Methodology referenced (OWASP Testing Guide, PTES, NIST SP 800-115) and the share of manual testing
- Testing window, daily communication method and the escalation path for critical findings
- Report contents: executive summary, scope statement, findings with reproducible evidence and CVSS severity, remediation plan, compliance mapping
- Retest terms: included or priced, and the window
- Data handling: where evidence is stored, who has access, retention and deletion, GDPR Article 28 terms
- Insurance: professional indemnity and cyber liability, with limits
- Two references in a comparable sector
Scoring the quotes
A simple weighted score keeps the comparison honest and defensible to your management.
| Criterion | Weight | What scores high |
|---|---|---|
| Tester quality | 30% | Named, certified individuals; relevant sector experience |
| Scope match | 25% | Written scope matches your request, exclusions explicit |
| Methodology and manual depth | 15% | Recognised methodology, examples of logic findings, sample report |
| Report and compliance fit | 15% | Deliverables mapped to your framework, usable by engineers and auditors |
| Retest and support | 10% | Retest included within a stated window, same-day critical escalation |
| Price per consultant-day | 5% | In the published market range for the seniority offered |
The three mistakes that produce bad quotes
First: sending a URL and asking for a price. Without roles, APIs and the reason for testing, the firm either pads the estimate or quotes a scan. Second: asking for a fixed price before a scoping call. Serious firms will want twenty minutes with you; the ones that quote instantly are selling a product, not a test. Third: comparing totals instead of day counts. A lower total with fewer days is less testing, not a better deal.
How to request a quote from HackersHub
Send the Part 1 checklist, or as much of it as you have, through the penetration testing page. We book a short scoping call with the lead tester, then return a written scope, the day count, named testers, deliverables, retest terms and insurance details, so your Part 2 is answered before you ask. No price list, every engagement scoped on what you actually need to test.
Frequently asked questions
Ready to request a quote?
Send us your scope. You get a written proposal with day count, named testers, deliverables and retest terms within two working days. Talk to an expert.