New ยท Release 2026.04, Multi-tenant audit exports & SLA dashboards now live See changelog โ†’
Security & Compliance

How to Choose a Penetration Testing Company

The canonical vendor-selection guide for penetration testing in 2026 โ€” decoding certifications, proving methodology, vetting sample reports, retest and escalation policy, pricing, red flags, and the questions every buyer should ask before signing.

ShareLinkedInX

Penetration testing is a market where the quality difference between providers is enormous. Some companies run automated scans and call it a manual pen test; others employ world-class testers with OSCP, CREST, and GPEN certifications who conduct genuine adversarial testing. With the penetration testing market reaching USD 1.98 billion in 2025 and growing at 14.2 percent CAGR, buyer demand is outpacing the supply of genuinely qualified testers โ€” creating a real risk of paying for testing that provides a false sense of security rather than genuine risk reduction. Evaluate companies on six factors: tester certifications and experience, methodology documentation, report quality and format, retest policy, how they handle critical findings during active engagements, and how their pricing maps to human tester days.

Criterion 1

Tester certifications and qualifications

The certifications your testers hold are the clearest signal of skill โ€” but only if you know what each one actually proves. Ask every provider: who specifically will perform the testing on your engagement, and what certifications do they hold? Then decode the answer, because the credentials are not interchangeable.

OSCP is the practical baseline: it is validated by a proctored 24-hour live exam against real systems, so a holder has demonstrably compromised machines under time pressure, not answered multiple-choice questions. OSWE and OSEP, from the same certification body, indicate advanced web application and evasion skill. CEH is a knowledge-level entry credential โ€” broad and widely recognised in compliance contexts, but it is not proof of hands-on exploitation ability, so treat 'our testers are CEH certified' as a starting point for questions rather than an answer. GPEN and GWAPT (SANS/GIAC) validate network and web application testing skill respectively through rigorous curricula, and BSCP demonstrates practical web testing ability.

CREST works at two levels and is worth checking separately: CREST accredits firms (their processes, data handling and complaint routes), while CRT and CCT certify individual testers. A CREST-accredited firm employing non-CREST juniors is common โ€” which is why the question is always about the named individuals on your engagement, not the company letterhead. For Indian regulated entities, one more check outranks all of these: filings with RBI, SEBI and several sector regulators must come from a CERT-In empanelled auditing organisation, so confirm empanelment in writing before you sign. Our VAPT certification guide decodes the full landscape.

  • OSCP โ€” hands-on exploitation skill; the gold standard, validated by a 24-hour live exam against real systems
  • OSWE / OSEP โ€” advanced application-security and defence-evasion skill beyond OSCP
  • CEH โ€” broad knowledge of attack techniques; more theoretical, widely recognised for compliance
  • CREST โ€” firm-level accreditation, plus CRT/CCT for individual testers
  • GPEN โ€” network penetration testing skill validated by SANS; GWAPT and BSCP for web applications
  • CERT-In empanelment โ€” mandatory for many Indian regulated filings; verify the certificate, not the claim
  • Red flag: a provider who cannot name the specific individuals who will test your environment, or describes testers as 'certified' without specifying which certifications

Criterion 2

Methodology and framework alignment

Ask the provider what methodology they follow. A credible answer references PTES (Penetration Testing Execution Standard), the OWASP Testing Guide v4.2, NIST SP 800-115, or MITRE ATT&CK for red-team engagements โ€” by name, unprompted.

Then ask for proof, because naming a framework costs nothing. Proof looks like: a proposal whose sections map to the framework's phases (compare it against the 8-phase engagement structure); a scope and rules-of-engagement template they can show you; and, for web engagements, the ability to say which OWASP test categories will be covered and which are out of scope. A provider who can walk you through their process phase by phase โ€” what happens, what you receive, what they need from you โ€” has a process. One who cannot is improvising at your expense.

Red flag: a provider who describes their methodology as 'industry standard' without naming a specific framework, or who cannot describe their testing process phase by phase.

Criterion 3

Report quality: the sample-report checklist

The report is the primary deliverable that justifies the cost, and a redacted sample tells you more about a provider than any sales call. Ask for one before engaging โ€” refusal is itself an answer. Then read the sample against this checklist:

  • Executive summary a non-technical leader could act on โ€” overall risk rating, what an attacker could realistically achieve, and the three to five priorities that matter most
  • Methodology and scope section describing what was tested, what was excluded, and which framework was followed โ€” the section your auditor reads first
  • Finding-by-finding documentation with CVSS score, affected systems, step-by-step reproduction instructions, and specific remediation guidance rather than 'apply vendor patches'
  • Proof-of-concept evidence โ€” screenshots or command output โ€” for every exploited finding; findings without evidence are opinions
  • An attack narrative showing how findings chained together, not just an isolated list
  • Evidence of testing coverage โ€” what was tested and found clean, not only what was found broken
  • Remediation priority matrix sorted by severity, and a retest confirmation section
  • Red flag: a report that is primarily automated scanner output without manual analysis, or lists findings without proof-of-concept evidence

Criterion 4

Retest policy

After your team remediates, you need confirmation the fixes held. Ask: is a retest included in the engagement price, or billed separately? A provider that bills separately for retests creates a disincentive to validate remediation properly. Quality providers include at least one retest cycle within scope.

Pin down the mechanics as well as the principle: the retest window (30โ€“90 days after report delivery is typical โ€” long enough to fix, short enough that the environment has not drifted), what the retest covers (every reported finding, not a sample), and what you receive at the end. The closing artefact should be a retest attestation โ€” a signed statement of which findings were verified fixed โ€” because that letter, not the original report, is what actually closes the engagement for your auditor and your enterprise customers.

Criterion 5

Critical-finding escalation, communication and data handling

Ask what happens if a Critical vulnerability is discovered mid-engagement. The correct answer: immediate notification to named contacts in the rules of engagement document, with documentation and a recommendation on whether to pause or continue testing that vector. A quality company also spends significant time on scoping, producing a written rules-of-engagement document covering in-scope and out-of-scope systems, permitted techniques, active testing hours, escalation contacts, and liability terms.

Communication cadence during the engagement matters almost as much as the escalation path: agree up front how often you hear from the testers (a short written status at least weekly on multi-week engagements), through which channel, and who on your side receives it. Silence for three weeks followed by a PDF is how surprises happen.

Finally, remember that a penetration test report is a working map of your weaknesses โ€” treat the provider's data handling as part of the evaluation. Ask where findings and evidence are stored, who can access them, how long they are retained after the engagement closes, and how deletion is confirmed. A provider who has no ready answer for protecting your report should not be trusted to write it.

Red flag: a provider who sends a simple questionnaire and starts testing without a signed rules-of-engagement document.

Criterion 6

What a quality engagement costs

In India, a focused web application penetration test typically costs โ‚น1.5โ€“4 lakh (USD 2,000โ€“5,000). A combined network + web application VAPT for a mid-size environment runs โ‚น5โ€“15 lakh (USD 6,000โ€“18,000), and large multi-scope programmes covering cloud, API and mobile go beyond โ‚น25 lakh (USD 30,000+). US/EU-market engagements for comparable scope typically price two to three times higher. The final number depends on scope, asset count and whether a remediation retest is included.

Compare quotes on human tester days, not headline price: ask each shortlisted provider how many tester days the number buys and what seniority those days carry. Two quotes of โ‚น3 lakh are not equivalent if one is eight days of an OSCP-certified tester and the other is two days of scanner time with a report template. If a subscription model fits your release cadence better than an annual project, PTaaS pricing and trade-offs are covered in our companion guide.

At a glance

Vendor evaluation checklist

Use this as a scoring sheet across your shortlist โ€” a provider should clear every row, not most of them.

Vendor evaluation checklist: what good looks like vs red flags

CriterionWhat good looks likeRed flag
Tester credentialsNamed testers with OSCP/CREST/GPEN; CVs and certificates shared on request'Certified team' with no names or specific certifications
MethodologyProposal mapped phase-by-phase to PTES, OWASP or NIST SP 800-115'Industry standard' with no framework named
Sample reportRedacted sample with proof-of-concept evidence for every findingScanner output rebadged; findings without evidence
ScopingWritten rules-of-engagement signed before any testing startsQuote issued without asking about scope or environment size
RetestAt least one retest cycle in scope, closing with an attestation letterRetest billed separately or not offered
Critical findingsImmediate escalation to named contacts, documented in the RoENo defined mid-engagement escalation process
PricingPriced on scope and stated human tester daysWell below market with no explanation; 'VAPT' priced like a scan
Data handlingDefined storage, access, retention and deletion terms for your evidenceNo answer on where your report and evidence live

Questions to ask every penetration testing company

Put these to every shortlisted provider in writing, and keep the answers with the contract โ€” they become your acceptance criteria for the engagement.

  • Who will perform the testing on my engagement, and can you provide their CVs and certifications?
  • How many human tester days does this quote include, and at what seniority?
  • Will testing be performed by your employees or subcontracted, and if subcontracted, to whom?
  • What methodology do you follow, and can you walk me through your process phase by phase?
  • Can I see a redacted sample report from a comparable engagement?
  • Is a retest included in the scope, what window does it cover, and do we receive a retest attestation?
  • What is your process if you discover a Critical finding during active testing?
  • How often will we receive status updates during the engagement, and from whom?
  • What happens to my data and evidence after the engagement closes, and how long is it retained?
  • Are you CERT-In empanelled (required for many Indian regulated filings)?
  • Have you tested environments similar to ours in size and technology stack, and can you share two references?
  • What does your scoping process look like, and what documents are produced before testing begins?

Warning signs

Red flags that signal a low-quality provider

Any one of these is a reason to slow down; two or more is a reason to walk away, whatever the price.

  • Provides a quote without asking about scope, environment size, or requirements
  • Cannot name or provide CVs for the testers who will conduct the engagement
  • Prices a 'VAPT' similar to a standalone vulnerability scan
  • Promises a completed 'penetration test' of a complex environment in one or two days
  • Cannot provide a sample report or reference engagements
  • Does not mention a rules-of-engagement document or written scope agreement
  • Offers significantly below-market pricing without a clear explanation
  • Guarantees zero findings, or conversely guarantees Critical findings, before scoping
  • Delivers findings in automated scanner output format with minimal manual analysis

Infronest

Conclusion

If you are delivering penetration testing engagements yourself or managing multiple VAPT programmes across clients, Infronest's Security and VAPT module provides the platform infrastructure you need: structured engagement management, finding documentation, CVSS scoring, evidence storage, peer review workflows, and audit-ready PDF report generation in one tenant-isolated workspace โ€” the operational backbone behind every criterion this guide tells buyers to check.

Start your 14-day free trial at infronest.com โ€” no credit card required.

Manage engagements, evidence, peer review and audit-ready reports in one workspace. 14-day free trial, no credit card required.

Explore Infronest VAPT services

Sources

Every figure and methodology reference in this article comes from the following published standards and reports. We cite them so you can verify the claims rather than take them on trust.

Frequently Asked Questions

How much should a penetration test cost from a quality provider?
In India, a focused web application penetration test typically costs โ‚น1.5โ€“4 lakh (USD 2,000โ€“5,000). A combined network + web application VAPT for a mid-size environment runs โ‚น5โ€“15 lakh (USD 6,000โ€“18,000), and large multi-scope programmes covering cloud, API and mobile go beyond โ‚น25 lakh (USD 30,000+). US/EU-market engagements for comparable scope typically price two to three times higher. The final number depends on scope, asset count and whether a remediation retest is included.
What certifications should a penetration testing company have?
Look for OSCP as the practical baseline for hands-on testers, with OSWE/OSEP, GPEN, GWAPT or BSCP indicating deeper specialisation, and CREST CRT/CCT as widely respected individual credentials. CEH alone signals knowledge rather than proven exploitation skill. In India, regulated filings frequently require a CERT-In empanelled auditing organisation, so verify empanelment separately from individual certifications.
Should I choose a large firm or a specialist boutique provider?
Both can deliver quality engagements. Large firms offer consistency and brand recognition for compliance reporting; specialist boutiques often provide deeper expertise in specific areas and more experienced testers per engagement. Individual tester credentials matter more than firm size.
What questions should I ask before hiring a penetration testing company?
The four that filter fastest: who exactly will test our environment and what do they hold; how many human tester days does the quote buy; can we see a redacted sample report; and is a retest with attestation included. A provider who answers all four crisply and in writing is usually safe to shortlist โ€” the full question list in this guide extends from there.
How do I verify a sample penetration test report is genuine quality?
Check three things: every exploited finding carries proof-of-concept evidence (screenshots or command output), there is a methodology and scope section naming a recognised framework, and the executive summary is readable by a non-technical leader. A sample that is mostly scanner output, or lists findings without evidence, predicts exactly what your report will look like.
What is CERT-In empanelment and do I need it?
CERT-In, India's national incident response agency, maintains a list of empanelled auditing organisations approved to perform security audits for government and regulated entities. If you file with RBI, SEBI or several sector regulators, the audit typically must be signed off by an empanelled firm โ€” so confirm empanelment in writing before engaging. Purely private engagements do not require it, but it remains a useful quality signal.
Can I use a penetration testing company overseas for a UK or EU engagement?
Yes, but confirm the provider is subject to appropriate data-protection requirements, particularly for evidence handling under GDPR. Ask where engagement data is stored, who has access, and how it is deleted after the engagement closes.

About the Author

Infronest

Infronest Security Research Team

Certified security professionals (CEH, OSCP, CISM, ISO 27001 Lead Auditor) with 10+ years of hands-on delivery. Content reviewed against PTES, the OWASP Testing Guide v4.2, NIST SP 800-115, and CREST standards.

Written by the Infronest Security Research Team โ€” certified security professionals (CEH, OSCP, CISM, ISO 27001 Lead Auditor) with 10+ years of hands-on delivery. Reviewed against PTES, OWASP Testing Guide v4.2, NIST SP 800-115, and CREST assessment standards.

Ready to see where you are exposed?

Talk through your scope with an Infronest security engineer โ€” targets, timelines and what a report for your environment looks like.