Choosing a penetration testing company is really about spotting the difference between a firm that will genuinely stress-test your systems and one that hands you a repackaged vulnerability scan with a nice cover page. The fastest way to tell them apart is to ask direct questions before you sign anything. Who exactly will test my systems? Can I see a sample report? What methodology will you use? What happens after you find something?

Most IT managers buy a penetration test once a year at most. So it’s easy to feel out of your depth when three quotes land on the desk at wildly different prices for what looks like the same service. Yet it usually isn’t the same service. So here are the questions that expose the difference.
Table of Contents
Who is CREST or CHECK accredited, and does it matter for us?
CREST accreditation means an independent body has checked the company’s governance, methodology and data handling. It isn’t just taking their word for it. CREST says accredited firms must run robust governance and security controls, employ technically competent staff, and follow proven methodologies. They face regular reassessment to keep that status.
If you’re a public sector organisation, or part of UK critical national infrastructure, ask specifically about CHECK, the scheme run directly by the NCSC. CHECK team leaders must hold Security Testing Title credentials at Principal level. Everyone on the engagement needs at least SC clearance. Most private-sector buyers don’t need CHECK. But choosing a penetration testing company that also holds CHECK status is still a useful signal of consistently high standards.
Which specific people will be testing our systems?
Choosing a penetration testing company on accreditation alone misses this. A company’s accreditation doesn’t guarantee who turns up to do the work. Ask for the names and qualifications of the actual testers, not a generic “our team holds CREST certifications” line. Look for CREST Registered Tester (CRT), CREST Certified Tester (CCT) or OSCP against named individuals. Ask about their experience with systems like yours. If a salesperson can’t answer this without checking, that tells you something too.
Can I see a sample report before I commit?
This is the single most useful question you can ask. It’s also the one weaker providers dodge. A penetration test report worth paying for explains findings in business terms. It includes evidence and clear steps to reproduce each issue. It uses a consistent severity scale, usually CVSS. And it gives fixes specific to your stack, not boilerplate advice lifted from a knowledge base.
If a company refuses, or only offers a marketing one-pager instead of a real, redacted example, assume the actual deliverable won’t hold up either.
What methodology will you follow, and why?
NCSC guidance is clear that a penetration test only validates against known issues on the day it runs. Think of it more like a financial audit than a permanent guarantee. Ask whether the test will be open box, where testers get full system detail, closed box, which better simulates a real external attacker, or scenario-based, focused on a specific risk like a stolen laptop or a compromised account. There’s no single “best” answer here. What matters is whether the provider can justify the choice against what you’re trying to learn, and set it out in a clear testing methodology, rather than defaulting to whatever’s quickest to deliver.
What exactly is in scope, and what happens if you find more?
NCSC guidance recommends scoping as a joint exercise between risk owners, technical staff and testers. That covers systems, IP ranges, authenticated versus unauthenticated testing, and anything explicitly excluded. If a provider quotes you a price before that conversation happens, ask what assumptions they made. Testers who find unexpected attack surface once they start should flag it. They shouldn’t quietly leave it untested, or bill you extra without warning you first.
How do the quotes actually differ?
Once scope is genuinely equal across providers, ask how many tester-days each has allowed and why. A quote that undercuts the others for the same scope is usually buying fewer days, more junior staff, or both. If you want a general sense of what to budget for a penetration test before quotes start arriving, it’s worth reading up first. It’s a fair question to ask outright. A confident provider will answer it without getting defensive.
What support do we get after the report lands?
Ask whether remediation guidance and retesting are included, or billed separately. Ask what the retest turnaround looks like. Ask how findings and any data captured during testing are stored and eventually destroyed, particularly if the job touches personal data under GDPR.
What’s actually in the contract?
So read the terms before you sign, not after. Check for a clear confidentiality clause covering how your data and findings are handled. Check for professional indemnity insurance, and ask what it actually covers. Check the cancellation and rescheduling terms too, since testing dates sometimes need to move around business priorities. None of this is exciting reading, but it’s exactly where problems surface later if it’s skipped now.
Can you give me a reference I can actually call?
Case studies on a website are marketing copy, so ask for something more direct. A reasonable provider can offer at least one past client, ideally in a similar industry, who’s willing to talk about how the engagement actually went. Because most testing work sits under an NDA, expect them to check with that client first before sharing contact details. If a provider has been trading for several years but can’t produce a single reference, ask why.
This single step often does more to separate the strong choices from the weak ones than anything else on this list, since a real client will tell you things a sales page never will: whether the testers were responsive, whether the report needed chasing, and whether the quote matched what was actually delivered. Choosing a penetration testing company on the strength of one honest phone call beats choosing one on a glossy brochure every time.
Choosing a penetration testing company: answers that should make you walk away
- “We’ll find everything and make you fully secure.” No test can promise that. NCSC guidance is explicit that testing only covers known issues on the day it runs.
- Vague or evasive answers about who is actually doing the testing.
- No written confidentiality or data handling terms.
- A firm quote before any scoping discussion has happened.
- Reluctance to share a sample report, redacted or otherwise.
We’re Aardwolf Security, a CREST-accredited UK penetration testing firm. We’d genuinely rather you put these questions to every company you’re considering, us included, than take a glossy proposal at face value. Our penetration testing service page covers how we scope and report. Our contact page is the quickest way to get a straight answer to any of the questions above.
Frequently asked questions
Is it rude to ask for a sample report?
No. A reputable provider expects it, and usually has a redacted example ready to send. It’s a standard part of choosing a penetration testing company, not an unusual demand.
Do smaller providers ever beat the bigger, accredited firms?
Yes. Plenty of smaller CREST-accredited firms do excellent work. Accreditation and named tester qualifications matter more than company size.
What if a provider can’t answer the methodology question clearly?
Treat it as a warning sign. A tester who can explain, in plain terms, why they’d recommend open box over closed box testing for your systems almost always does better work than one who can’t.
Should the report format be agreed in advance?
Yes. Ask what severity scale they use, whether an executive summary is included, and how findings map to any compliance framework you need to satisfy, such as Cyber Essentials or PCI DSS.
How many providers should I get quotes from?
Three is usually enough. It lets you compare scope, methodology and named testers without dragging out the process of choosing a penetration testing company for weeks.
Subscribe to our newsletter
Honest updates, straight to your inbox. Unsubscribe any time.