// buying guide

Choosing a penetration testing company is harder than it should be. The websites all look alike, every quote claims the same methodology, and the thing you are buying, the quality of a tester's judgement over a few weeks, is invisible until the report lands. By then the money is spent.

This guide is the checklist we would want a friend to use. It covers the five things that genuinely separate a good provider from an expensive scanner run, the questions that expose the difference in a single call, and the red flags that should end a conversation early. It applies whether you are a Sydney fintech facing a SOC 2 audit, a Melbourne SaaS team answering an enterprise security questionnaire, or a Brisbane manufacturer who has simply never been tested.

What you are actually buying

Strip the marketing away and a penetration test is senior specialist time applied with judgement. The deliverable is a report, but the value is in the thinking that produced it: a person reading your application the way an attacker would, chaining small weaknesses into a real compromise, and explaining it so your engineers can fix it. Tools help with coverage; they do not produce that judgement.

That framing matters because it tells you what to evaluate. You are not comparing feature lists. You are comparing who will do the work, how they will do it, and whether you can trust what they hand you at the end. Everything below follows from those three questions.

The five things that separate good from bad

1. Method: manual-first, mapped to a standard

Ask how much of the engagement is automated and what happens after the scanner finishes. A credible answer describes scanners as a mapping tool and manual testing as the main event, with findings verified by a person and chained where possible. The methodology should be mapped to a recognised framework: OWASP (Top 10, ASVS, MASVS, API Top 10) for applications, PTES or NIST SP 800-115 for engagements overall. If the provider cannot name the framework without checking, that is your answer.

2. People: who is actually on the keyboard

Many firms are sold by a senior and delivered by whoever is free. Ask for the name and background of the tester assigned to your engagement, not the company's collective credentials. Certifications like OSCP, OSWE, CREST CRT or CCT are useful signals, but years of hands-on application or infrastructure testing matter more. A senior tester finds in day two what a junior finds in day six, or never.

3. Report: written to be acted on

Ask for a redacted sample report before you sign anything. Look for an executive summary a non-technical director can follow, findings rated with CVSS plus a contextual rating for your environment, and per-finding evidence with exact reproduction steps and a concrete fix. If the sample reads like tool output with a cover page, the engagement will too. Our guide to what a penetration test involves covers the warning signs in more detail.

4. Retesting: included, or an invoice

Finding problems and then charging extra to confirm you fixed them is common and worth avoiding. Ask whether retesting is included, how many rounds, and whether you receive an updated report and an attestation letter you can share with customers and auditors. The answer changes the real price of the engagement more than most line items.

5. Evidence: references, samples, and straight answers

Good providers are happy to show a sample report, offer a reference in your industry, and explain their process in plain English on a call. Evasiveness about any of the three is a signal. So is a quote that arrives before anyone has asked about your user roles, environments or deadlines.

15 questions to ask before you sign

Use these on the scoping call. The point is not to trip anyone up; it is that good providers answer all fifteen easily and poor ones cannot.

About the testing

  1. What proportion of the engagement is manual testing, and what does the tester do after the scanner finishes?
  2. Which standard is the methodology mapped to, and can you show me the mapping?
  3. Will you test authenticated, with an account for every user role we give you?
  4. Do you test business logic, or only the categories a scanner recognises?
  5. How do you handle production environments, and what are the rules of engagement?

About the people

  1. Who exactly will be testing our systems, and what is their background?
  2. How many engagements like ours has that person delivered in the last year?
  3. Is the work done onshore, and where will our data and findings be stored?

About the report and what happens after

  1. Can we see a redacted sample report before we commit?
  2. How are findings rated, and do you adjust severity for our business context?
  3. Does every finding include reproduction steps and a specific fix?
  4. Is retesting included, and do we get an updated report and attestation letter?
  5. Will you alert us the same day if you find something critical?

About the commercials

  1. Is the quote fixed, and exactly what is excluded from it?
  2. What do you need from us to start, and how quickly can you begin?

Red flags that should end the conversation

  • A quote with no scoping questions. Nobody can price a test without knowing roles, environments and targets.
  • A refusal to show a sample report, or a sample that is clearly scanner output.
  • Vague answers about who does the testing, or a team that changes between the sale and the kickoff.
  • Testing offshore without telling you, especially if you handle personal or regulated data under the Privacy Act or APRA CPS 234.
  • Suspiciously fast timelines for the size of the target. Two days for a multi-role application is not a pentest.
  • Retesting quoted as a separate line item at a price close to the original test.

Comparing quotes fairly

When one quote says $7,000 and another says $22,000 for what looks like the same application, you are almost never comparing the same work. The usual differences are the share of automation, the seniority of the tester, what is quietly excluded (extra roles, the API, retesting) and the quality of the report. Our Australian pentest pricing guide breaks down typical ranges and the levers behind them, so you can tell a lean quote from a hollow one.

A practical approach: write down your scope once (targets, roles, environments, deadline, what the report must prove) and send the identical brief to every provider. Quotes against the same brief are comparable. Quotes against five different understandings of your scope are not.

Making the decision

Score each provider one to five on the five criteria above: method, people, report, retest and evidence. Then weigh price. A provider that scores well on all five and costs more is usually the cheaper option over a year, because you fix the right things once instead of paying twice for a test that missed them.

If you want to see how we answer these questions ourselves, our methodology page walks through the full process, and the services pages describe what is included in each engagement type. We are also happy to be one of the providers you send that identical brief to.