Cybersecurity / Buyer's Guide
How to choose a penetration testing vendor
Eight criteria, the questions to ask, and the red flags to walk away from — the checklist we'd use ourselves, including to evaluate us against anyone else.
Why this choice is hard
Penetration testing is difficult to buy well because the thing you're paying for — the depth and honesty of the work — is invisible until the engagement is over. Proposals look alike. A rebadged vulnerability scan and a genuine manual test can carry the same service name, similar language, and very different prices, and the difference often only becomes clear when the report lands: one is a scanner export with a cover page, the other is evidence someone thought their way through your system.
The good news: you can tell them apart before you sign, if you know what to ask. What follows is the checklist we'd use if we were the buyer. It applies to every vendor you're evaluating — including us.
Eight things to evaluate
- 01
Methodology transparency
- What good looks like
- A written methodology the vendor will show you, mapped to recognized frameworks — the OWASP Testing Guide, PTES, NIST SP 800-115. You should be able to read how they test before anyone touches your systems.
- What to ask
- “Which published frameworks is your methodology aligned to — and can we see the methodology document itself?”
- Red flag
- A “proprietary methodology” with nothing published or shareable. If a vendor can't show you how they test, you can't verify that they test at all.
- 02
A sample report — before you sign
- What good looks like
- The report is the product: it's what your engineers remediate from, what your auditor reads, and what your customers may ask to see. A serious vendor shares a sanitized sample early, so you can judge reporting depth, severity reasoning, and remediation detail up front.
- What to ask
- “Can we see a redacted sample report before we contract?”
- Red flag
- Refusing to show any sample until you've signed. Treat that as a walk-away signal — you'd be buying a deliverable you've never seen.
- 03
Tester qualifications — the actual team
- What good looks like
- The credentials that matter belong to the people assigned to your engagement, not to the sales deck. A good vendor tells you at scoping who will do the work, what those individuals hold, and who leads the engagement.
- What to ask
- “Who specifically will be on our engagement, and what are their individual qualifications? Can the lead tester join the scoping call?”
- Red flag
- Senior faces in the sales cycle, but no named lead tester until after kickoff — the classic switch to a junior bench you never met.
- 04
Retest policy
- What good looks like
- Remediation verification is part of the engagement, committed in writing: after you fix, the vendor tests again and updates the report, so the version your auditor or customer sees reflects closure rather than open risk.
- What to ask
- “Is retest included in the quoted price, and within what window? Please put it in the statement of work.”
- Red flag
- Retest surfacing as a separate line item after findings land, or a vague “we can retest” with no written commitment.
- 05
Scoping rigor
- What good looks like
- Before quoting, the vendor asks detailed questions about your environment — applications and APIs in scope, roles and tenancy, environments, constraints, and what evidence you need out of the test. Effort follows attack surface, so a real quote requires understanding yours.
- What to ask
- “What do you need to know about our environment before you can price this work?”
- Red flag
- A fixed price after a five-minute conversation. A vendor that quotes without asking detailed questions is pricing a scan, not a test.
- 06
Independence
- What good looks like
- Findings that aren't shaped by what the tester sells. A tester that also sells you the products — or the remediation work — its findings recommend carries a conflict of interest on every finding. Good vendors either avoid that conflict structurally or disclose exactly how they manage it.
- What to ask
- “Do you resell any products you might recommend, or bid on the remediation work your findings create? If so, how is that separated from testing?”
- Red flag
- Findings that funnel neatly into the vendor's own product catalog, with no acknowledgement that a conflict exists.
- 07
Data handling
- What good looks like
- Your findings are a map of your weaknesses. The vendor can tell you where reports and evidence are stored, who can access them, how long they're retained, and how they're destroyed — and will commit to those terms in the contract.
- What to ask
- “Where will our findings live, who can see them, what is the retention period, and how is destruction handled?”
- Red flag
- No clear answer on retention or destruction, or findings passed around through ad-hoc channels nobody controls.
- 08
Verifiable reputation
- What good looks like
- Claims you can check for yourself: references you're allowed to call, testimonials attached to named people, case studies with technical substance, published research. Independent signals beat logo walls.
- What to ask
- “Can you give us references from comparable engagements — and may we contact them directly?”
- Red flag
- Anonymous logos and unverifiable superlatives, with no reference you're actually permitted to speak to.
How we answer these
Held to our own checklist. Each answer below links to where the fact is published — nothing here is claimed that isn't already on this site.
- Methodology transparency
- Our methodology is published at /methodology/: testing aligned to the OWASP Testing Guide, PTES, and NIST SP 800-115, with the engagement flow spelled out step by step.
- Sample report
- A redacted sample penetration-test report is a direct download — no form, no contract, no call required. Judge our reporting before you ever talk to us — our section-by-section walkthrough of that sample shows you what to look for in ours or anyone else’s.
- Tester qualifications
- 63% of our engineers hold industry certifications (CISSP, CEH, eCPPT, ISTQB, AWS), and the people who scope your engagement are the people who run it — the scoping call is with the testers themselves, not a sales team. Company facts are on the trust page.
- Retest policy
- Retest is included as standard: remediation is verified on retest and the report updated to “remediated and retested.” That policy is published on our methodology and trust pages, and we'll commit it in your statement of work.
- Scoping rigor
- Every engagement starts with a scoping call with the testers themselves — targets, rules of engagement, and what evidence you need out — before any price is final. See how PTaaS engagements run — and use our vendor-neutral pentest scoping checklist to assemble your answers before you talk to any vendor, including us.
- Independence
- We don't build what we test, and we don't resell what we recommend — no tool-resale commissions influence findings. That independence statement is published on the trust page.
- Data handling
- Findings and reports are shared only through the channels agreed at scoping and retained only for the period needed to deliver and support the engagement; storage, encryption, retention, and destruction specifics are set in your service agreement. Engineers who handle client data sign NDAs and undergo background checks. Details on the trust page.
- Verifiable reputation
- We publish named client testimonials and case studies, and references from comparable engagements are provided during vendor due diligence — ask for them, and call them.
Where we don't have the proof point yet
Two things this checklist asks for, we can't fully show today — and we'd rather tell you than talk around it. On organizational certification: we hold no organizational certification today and do not claim otherwise. ISO 27001 certification for VirtuesTech is planned (stated July 2026) — milestones will be published on the trust page when they are reached, not before. On third-party review platforms: we don't point to any today; what we offer instead are named testimonials, case studies, and references you can actually call. We publish only what we can prove — if a fact isn't on our trust page or linked from it, we probably can't prove it.
Ready to scope the work?
A 30-minute call with the engineers who will do the testing — not a sales gate.