Back to Blog
Security Testing
4 min read

Choosing a Penetration Testing Vendor: Scope, Evidence and Reporting

The sample report tells you almost everything. What to look for in it, and the scoping discipline that makes bids comparable.

GuardsArm Team

Security Experts

September 25, 2026

Choosing a penetration testing vendor

Penetration testing quality varies more than almost any other security service, and the variation is hard to see from a proposal. Two firms quoting similar prices can deliver work of entirely different value, and you generally find out only after you have paid.

One artefact predicts quality better than anything else in the process: the redacted sample report.

The sample report predicts quality
Ask for one before discussing price
Reproduction steps are the signal
Findings engineers cannot reproduce get ignored
Careless scoping means careless testing
Watch how they behave before quoting

Reading the sample report

Ask every vendor for one. A firm that will not provide a redacted sample is telling you something.

What to look for in a sample reportReproduction steps, an attack narrative and plain-language business impact are the decisive signals. Severity rationale, specific remediation advice and stated exclusions follow.Reproduction steps for every findingThe strongest single quality signalAn attack narrative, not just a tableEvidence a human did the workBusiness impact in plain languageSeparates consultants from techniciansClear severity rationaleNot just a copied CVSS scoreRemediation advice specific to youNot generic vendor documentationExplicit statement of what was excludedKnown unknowns, stated honestly
Fifteen minutes with a sample report beats an hour of proposal reading.

Reproduction steps are the single best quality signal. A finding you cannot reproduce is a finding your engineers will argue with and eventually ignore. A good report lets a developer reproduce the issue in minutes.

The attack narrative is the second. A findings table sorted by CVSS is scanner output with formatting. A narrative describing how the tester moved from initial access to the objective is what a human produced, and it is the part that changes how you think about your estate.

Business context separates consultants from technicians. "This SQL injection allows retrieval of the full patient table" is more useful than "SQL injection, CVSS 9.8".


Who actually does the work

AskWhy
Names and certifications of the assigned testersSales engineers are not always the testers
Will these specific people do the work?Bait and switch is common
How much is subcontracted?You may be buying a broker
What proportion of the engagement is manual?The difference between a test and a scan
How many similar engagements has this tester run?Sector familiarity shortens ramp-up

Certifications are an imperfect but useful signal. Practical, hands-on certifications carry more weight than multiple-choice ones, and a tester with public research, tooling or disclosures behind them is usually a good sign.


Scoping discipline

A vendor who scopes carelessly will test carelessly. Watch how they behave during scoping — a good firm asks awkward questions before quoting:

  • What are you actually worried about?
  • What would a successful attack look like for your business?
  • What is out of bounds, and why?
  • What is the state of your vulnerability management — should we expect to spend the first days on known issues?
  • Are there systems where testing could affect safety or continuity?

A vendor who quotes from a one-line request without asking any of these will deliver a generic engagement, because that is what they scoped.

A vendor who does not ask awkward questions will not find awkward problems
Good scoping conversations are uncomfortable: what are you actually afraid of, what is out of bounds, what will we waste time on. A firm that quotes from a one-line request has scoped a generic engagement, and that is what will arrive.

The terms to fix in writing

  1. Scope — exact ranges, URLs, roles, and exclusions
  2. Methodology referenced explicitly
  3. Testing window, and constraints around it
  4. Escalation path if something breaks, or if a critical finding emerges mid-test
  5. Immediate notification for critical findings, rather than waiting for the report
  6. Retesting — included, and for how long afterwards
  7. Deliverables — report, executive summary, attestation letter if your customers need one
  8. Data handling — what they collect, where it is stored, when it is destroyed

Point five matters more than it looks. If a tester finds a critical vulnerability on day two, you want to know on day two, not in the report three weeks later.

The penetration testing RFP template sets these out in a form vendors can bid against consistently, which is what makes prices comparable. See also what a test should cost.


Red flags

  • A quote without scoping questions
  • Pricing far below the market — you are buying a scan
  • No sample report available
  • Certifications advertised for the firm rather than the testers
  • Findings promised in advance — "we always find X"
  • No retest included, and reluctance to discuss it

Where to start

Request a redacted sample report from three vendors before discussing price. Fifteen minutes with each tells you more about what you will receive than any amount of proposal reading, and it reframes the conversation from cost to quality.

GuardsArm provides sample reports on request and scopes against a written specification. See security testing or book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on this topic

Talk to the GuardsArm team about how these services apply to your environment.