How to Choose a Penetration Testing Provider

Every provider says they are the best. Here are the things that actually differ between them, and how to check each one before you sign.

Key check
Company-level accreditation
Ask for
A redacted sample report
Watch for
Scan output sold as testing
Confirm
Retest included or extra

Why this page does not claim we are the best

Every penetration testing company on the internet describes itself as leading, trusted or best-in-class. None of it is verifiable and none of it helps you choose.

What follows is what genuinely differs between providers, how to check each thing, and where we stand on it. Use it on us and on whoever else you are considering.

1. Accreditation — and at what level

What good looks like: the company is accredited, not just an individual who works there. CREST company accreditation means methodology, reporting standards, data handling, insurance and staff competence have been independently audited against the CREST Penetration Testing Accreditation Standard.

How to check: search the provider on the CREST marketplace. If they are not listed, they do not hold company accreditation regardless of what the proposal implies. Watch for phrasing like "CREST-certified consultants" or "CREST-qualified team", which describes individual certifications and is a materially weaker claim.

Why it matters: many public sector frameworks and enterprise procurement requirements mandate it, insurers use it to judge whether an engagement met an acceptable standard, and after an incident it is the difference between "we used an accredited provider" and "we used a consultant".

Us: CREST accredited at company level, verifiable on the marketplace.

2. Who actually does the testing

What good looks like: you know the name and qualifications of the person testing your systems before you sign, and that person is the one who turns up.

How to check: ask directly. "Who will run this test, what do they hold, and will I speak to them during the engagement?" A provider that cannot answer, or answers with "one of our qualified team", is telling you something.

Why it matters: the gap between a strong tester and a weak one is enormous, and it does not show up in the proposal. Large firms commonly sell on senior expertise and staff with juniors, because that is how the economics work.

Us: every engagement is delivered personally by a CREST-qualified tester. You speak to them before, during and after.

3. Manual testing versus automated scanning

What good looks like: a stated methodology, days of genuine manual testing, and findings that show real exploitation rather than tool output.

How to check: compare the day count, not the total price. A quote dramatically below the others is usually a scan with a report template around it. Ask what proportion of the engagement is manual, and ask for an example of a finding no scanner would have found.

Why it matters: the findings that cause real breaches — broken access control, business logic flaws, chained attack paths — are precisely the ones automated tooling cannot find. A scanner will not work out that your booking system lets one customer read another's records because the object reference is predictable.

Us: manual, expert-led testing aligned to CREST, OWASP and NCSC guidance. Automated tooling is used for coverage, not as the test.

4. Report quality

What good looks like: two audiences served in one document. An executive summary a non-technical director can act on, and technical detail with reproduction steps and evidence that your engineers can work straight from.

How to check: ask for a redacted sample report before you commit. Any competent provider has one. If they will not share it, that is your answer.

Why it matters: the report is the deliverable. A 200-page scanner export with severity inflation is worse than useless, because your team will spend days triaging noise and lose confidence in the process.

Us: ask and we will send a redacted sample.

5. Retesting

What good looks like: retest of remediated findings included as standard, with an updated report reflecting closed items.

How to check: read the quote. It is frequently a separate line item, or absent entirely and quoted later at full day rate.

Why it matters: fixing the findings is the entire point, and your client, insurer or auditor wants to see them closed rather than merely identified.

Us: retesting is included as standard.

6. Scoping honesty

What good looks like: a provider who tells you when you need less than you asked for, or when a penetration test is not the right next step at all.

How to check: describe your situation and see what they recommend. If you have no multi-factor authentication, unsupported operating systems in production or untested backups, a good provider will say so rather than sell you a test that confirms what you already suspect.

Why it matters: a test of a fundamentally unhardened environment produces a report full of findings you could have predicted, at a cost better spent fixing them.

Us: scoping conversations are free and we will tell you when the answer is Cyber Essentials rather than a penetration test.

7. Communication during the engagement

What good looks like: a direct channel to the tester, critical findings reported the moment they are confirmed, and no surprises in the final report.

How to check: ask what happens if they find something critical on day one.

Why it matters: if a provider finds a live, exploitable path into your systems, you want to know that afternoon — not in a document three weeks later.

8. Cost, and what actually drives it

What good looks like: a provider who explains what moves the day count and quotes a fixed price for a defined scope.

How to check: ask what would make the estimate go up or down. A provider who cannot explain their own pricing is either padding it or guessing.

We set out the drivers in detail on our pricing page, including how to compare two quotes properly.

A checklist you can use

  • Is the company accredited, and can you verify it independently?
  • Who is the named tester, and what do they hold?
  • How many days of manual testing, excluding reporting?
  • Can you see a redacted sample report?
  • Is retesting included or extra?
  • What happens if they find something critical mid-test?
  • Will they tell you if you do not need the test?

Common questions

What is the most important thing to check?

Company-level accreditation, because it is the only claim on this list that is independently verifiable in thirty seconds. Everything else relies on the provider's own account of how they work — accreditation you can confirm yourself on the CREST marketplace.

Is a bigger provider safer?

Not necessarily. Larger firms bring bench depth, formal processes and the reassurance of a recognisable name, which genuinely matters at enterprise scale. They also have higher overheads and commonly staff engagements with junior testers. For a small or mid-sized organisation the trade often runs the other way.

How do I compare two quotes that are very different?

Compare days of testing rather than total price, then check what is included. A cheaper quote is usually a smaller quote — fewer days, reporting time counted as testing time, retest excluded. Once you normalise for those, the gap frequently disappears.

Should I ask for references?

Yes, though expect confidentiality limits — most security clients do not want to be named. A provider should be able to describe comparable engagements in general terms, and many can arrange a reference call even where they cannot publish a case study.

What are the warning signs?

A quote far below the others. Reluctance to share a sample report. Inability to name who will test. Vague accreditation wording that implies company status without holding it. Guaranteeing they will find vulnerabilities, or guaranteeing they will not. And any provider that does not ask enough questions to scope properly before quoting.

Does CREST accreditation guarantee a good test?

No. It sets a floor — audited methodology, reporting standards and data handling — which rules out the worst outcomes. It does not guarantee the individual tester is excellent. Use it as a filter, then assess the specific people.

Related

Ready to talk?

Scoping conversations are free and there is no sales team to get past. Tell us what you're dealing with and we'll tell you honestly what you need.