
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.
The specifics that actually separate real testing from a vulnerability scan with a report template — not marketing claims, a real checklist.
"Who's the best penetration testing company" is close to an unanswerable question — the honest answer depends entirely on your environment, your compliance driver, and what you're actually trying to learn. The answerable version of that question is narrower and far more useful: what actually separates a real testing engagement from a vulnerability scan with a report template slapped on it. Here are the specifics worth checking before signing a statement of work, not marketing claims.
Every provider claims "manual testing." Ask what that means in hours, not adjectives — a quote well below market for your stated scope is usually a sign that most of the work is an automated scan with a human skimming the output before it ships. Our own breakdown of manual testing vs. automated vulnerability scanning covers exactly which vulnerability classes only show up under genuine manual review: chained privilege escalation and business logic flaws chief among them.
Generic security certifications are a weak signal on their own — what matters is whether the specific testers assigned to your engagement hold credentials relevant to what you're actually testing (web application, cloud, network, or industry-specific). CREST accreditation at the firm level is a reasonable baseline signal in regulated markets specifically because it audits methodology and tester competency, not just a marketing claim.
A provider confident in their reporting quality will show a redacted sample. What you're checking for: does every finding include a concrete reproduction path and business-impact reasoning, or is it a CVE ID and a CVSS score copy-pasted from a scanner's own database? CVSS score alone is a weak prioritization signal — a report that stops there hasn't actually done the analysis work you're paying for.
Confirming a fix actually closed the gap is part of the value of testing, not an upsell. If retest access isn't included in the base engagement — or is capped at a token one-issue check — that's worth negotiating before the SOW is signed, not discovering after remediation is already underway.
"We map to OWASP Top 10" is table stakes. The differentiator is whether a provider can speak to the specific numbered control your auditor is actually going to cite — PCI DSS Requirement 11.4, SOC 2's CC7.1, NIS2 Article 21, or ISO 27001's Annex A.8.29 — rather than a generic "we help with compliance" pitch that doesn't name the actual requirement.
A report that classifies findings against OWASP alone tells you what's wrong. One that also maps to MITRE ATT&CK tells you what an adversary would actually do with it — a materially different, more useful signal for prioritizing what gets fixed first when you can't fix everything simultaneously.
A three-week silence followed by a single report at the end is a red flag, not a feature. A genuinely collaborative engagement surfaces critical findings the moment they're confirmed — not held for the final readout — so your team can start remediation before the report is even finished.
A newer, genuinely useful differentiator: does the provider factor real, current exploit-probability data (like FIRST.org's EPSS) into how findings get prioritized, or is everything ranked purely on CVSS severity regardless of whether it's actually being exploited in the wild? This is a small detail most providers' marketing pages don't mention at all, and a genuine signal of a technically current program.
None of these eight criteria are about picking "the best" provider in the abstract — they're about confirming a specific provider's engagement will actually produce the evidence and findings you need, for your specific environment and compliance driver. If you want to see how our own Penetration Testing engagements are structured against these exact criteria, get in touch with your scope and we'll walk through it directly rather than asking you to take a claim on faith.
Tell us about your environment and goals — we'll help you scope the right engagement.