A penetration testing methodology is the documented process a security firm follows to plan, run and report a test. It’s built on recognised standards such as PTES, the OWASP Testing Guide or NIST SP 800-115. If you’re an IT manager or business owner choosing a provider, the methodology matters more than the sales pitch. It’s often the best clue to what you’re actually buying. That could be a genuinely rigorous test. Or it could be a repackaged vulnerability scan with a nicer cover page.

This guide builds on what penetration testing actually involves. It focuses on how to judge a provider’s penetration testing methodology. It also covers how to spot a weak one during a sales call, and what a properly run test looks like from the inside.
Table of Contents
Why the Methodology Should Be Part of Your Buying Decision
Most buyers compare quotes on price and scope. Few ask how the work will actually be carried out. That’s a mistake. Two providers quoting for the same scope can still deliver very different depth of testing. The gap usually comes down to the penetration testing methodology behind the number. A vague answer to “what’s your methodology?” is one of the clearest early warning signs that a test will be shallow.
The NCSC’s own guidance puts it plainly: a penetration test should use “the same tools and techniques as an adversary might.” It should also validate your existing security processes, not just hunt for low-hanging fruit. A firm without a documented methodology can’t reliably promise either.
What a Proper Penetration Testing Methodology Includes
Look for these building blocks when you ask a provider to describe their process:
- A named standard. Most credible firms map their approach to PTES, the OWASP Testing Guide, NIST SP 800-115, or a documented blend of these, according to OWASP’s summary of established methodologies.
- A clear scoping process that sets out targets, boundaries, timing and emergency contacts before testing starts.
- Manual testing, not just scanning. Automated tools find known issues. Skilled testers find the logic flaws and chained weaknesses that tools miss.
- A defined escalation path for anything critical found mid-test, instead of waiting weeks for a scheduled report.
- A structured report with evidence, business-relevant severity ratings and practical remediation steps, along the lines of what a good penetration test report looks like.
- A retest to confirm fixes actually close the gap, not just that a ticket got marked resolved.
How the Phases Play Out in a Real Engagement
Once a scope is agreed, testers move through a broadly consistent sequence. Reconnaissance maps what’s exposed. Vulnerability analysis finds weaknesses. Exploitation proves real impact, safely. Post-exploitation shows how far an attacker could reach. Then comes reporting. Each stage builds on the last, so rushing scoping or reconnaissance weakens everything that follows, even when the exploitation work itself is skilled.
How much information testers start with also matters, and a good provider will discuss this with you rather than assume. The NCSC describes a spectrum here. At one end sits a transparent “open box” test, where information is shared upfront to check internal controls thoroughly. At the other sits an opaque “closed box” test, which models a real external attacker starting from nothing. Many buyers land on a grey box middle ground instead, giving testers a standard user account to reflect what a genuine attacker could plausibly obtain.
Red Flags That Suggest a Weak Methodology
A few signs are worth watching for when you’re comparing quotes. They line up closely with our broader guide on how to choose a penetration testing company:
- The quote is priced almost entirely on scan output rather than tester time.
- The provider can’t name the standard their process is based on.
- Sample reports read like raw scanner output with little manual analysis or business context.
- There’s no mention of a retest, or it’s an expensive add-on rather than part of the process.
- Nobody can explain how findings would be escalated if something critical turned up on day one.
None of these alone is disqualifying. But two or three together usually mean the “penetration testing methodology” on the sales page is a marketing phrase, not a real process.
What Methodology Depth Does to Timescales and Cost
A properly run methodology takes longer than a scan-and-report exercise, and that shows up in both the timeline and the price. Reconnaissance and scoping alone can take a day or more before active testing even begins. Manual exploitation of a promising lead can eat hours that automated tools would never spend. A well-written report with business context takes real time to draft too. A quote that looks unusually fast or cheap for a broad scope should raise a question. Ask directly how the provider fits proper reconnaissance, manual testing and reporting into that timeframe. Often the honest answer is that one of those stages got compressed or skipped.
That doesn’t mean the priciest quote is automatically the most rigorous one. Price should track scope and depth, not brand name. A clear penetration testing methodology lets you compare quotes on a like-for-like basis. Two providers testing the same scope, to the same standard, with similar manual effort, should land in a similar price range. A big gap either way is worth a direct question.
Accreditation as a Shortcut to Trust
In the UK, CREST accreditation offers a useful shortcut. It means a firm’s penetration testing methodology, its testers and its quality controls have passed an independent check, not just a self-assessment. It doesn’t replace asking your own questions. But it narrows the field to firms whose process has already been checked by someone else.
Aardwolf Security runs every engagement to a documented methodology built on these established standards, tailored to your environment rather than a generic script. If you’d like to see how our process would apply to your organisation, take a look at our penetration testing service, or get in touch and we’ll talk you through it before you commit to anything.
Frequently Asked Questions
What questions should I ask about a provider’s methodology?
Ask which named standard they follow. Find out who performs the technical work, and their qualifications. Then ask how critical findings are escalated mid-test, and whether a retest is included in the price.
Is a cheaper quote ever a red flag?
It can be, if the low price reflects mostly automated scanning with little manual testing. Ask specifically how much of the work is manual versus tool-driven before you compare quotes on price alone.
Does a bigger firm always have a better methodology?
Not necessarily. Size doesn’t guarantee rigour, so a documented, standards-based process and CREST accreditation are more reliable signals than company size alone.
How long should a properly run test take?
It depends heavily on scope. But a methodology with real reconnaissance, manual analysis and a retest simply takes longer than a scan-and-report job, so be wary of very short timelines for a broad scope.
Should the methodology differ for a small business versus an enterprise?
The underlying standard usually stays the same. A good provider instead adapts depth and emphasis to your risk profile and budget, rather than applying identical treatment regardless of size.
What should I expect in a scoping call before the test starts?
A provider with a real methodology will ask detailed questions. What’s genuinely in scope? Which systems are off-limits? What’s your testing window, and who should they contact if something urgent turns up? A scoping call that feels rushed or generic is usually a preview of how the rest of the engagement will go.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.