A penetration testing company is a provider that specializes in pentests: a team of ethical hackers who, with authorization and a scope agreed in writing, try to break into an organization's systems to show which flaws can be exploited, what impact they would have on the business and how to fix them. Choosing that provider well means comparing how they work (methodology, scope, validation of findings, retesting and reporting), not just how much they charge.
To hire a pentest with good judgment, you need to be clear on four things: how it differs from a vulnerability scan, which seven criteria separate a solid proposal from a superficial one, which testing approach to ask for and what drives the price.
What a penetration testing company does, and what does not count as a pentest
Picture a locksmith you hire to try to get into your warehouse. You give them written permission, tell them which doors they can test and at what times, and at the end they hand you a report: where they got in, how far they made it and which lock you should replace first. A penetration testing company does exactly that with your systems: servers, web and mobile applications, APIs, network and cloud.
What you get from a well-run pentest is confirmed findings, each one with evidence that it can be exploited, the impact explained in business terms and concrete steps to fix it. That last part is what turns the test into a work plan for your IT team.
Knowing what a pentest is matters as much as knowing what it is not:
- It is not a document review. Reviewing written policies and controls is the job of a cybersecurity assessment, which works alongside a pentest and covers different ground.
- It is not a guarantee of total security. A pentest measures your exposure at one point in time and over a defined scope, which is why it gets repeated.
Here is a concrete example. On a Tuesday at 11 a.m., the pentester logs into your customer portal with a test account, changes one number in the browser's address bar and sees another customer's orders. No automated tool flagged it, because technically the page responded correctly. That finding, with the screenshot and the steps to reproduce it, is what you are paying for when you hire a pentest.
Pentest or vulnerability scan: the difference that changes the proposal
Going back to the locksmith, a vulnerability scan is like checking the locks from the sidewalk and writing down which ones are a model with known flaws. A pentest means trying to open them. If the first door gives way, the tester looks for another unlocked door behind it and keeps going until reaching the room where you keep your inventory.
| Aspect | Vulnerability scan | Pentest |
|---|---|---|
| How it is done | An automated tool compares your systems against a database of known flaws. | Specialists combine tools with manual testing and chain flaws together the way an attacker would. |
| What it confirms | Possible flaws, without testing them. | Exploitable flaws, with evidence. |
| Business context | None: it prioritizes by theoretical severity. | Prioritizes by real impact on your operations. |
| Typical timeframe | Hours. | Days or weeks, depending on scope. |
| What it is for | Routine hygiene and monitoring. | In-depth validation and evidence for customers and auditors. |
On a Thursday afternoon, your IT team receives two proposals for the same e-commerce site. One promises a "complete pentest" delivered the next day; the other proposes five days of testing, a results session and a retest. They are quoting different things: the first one describes a scan under another name, and a final report in 24 hours for several applications is the clearest sign.
7 criteria for comparing penetration testing companies
With several proposals on the table, these seven points tell you whether the provider is going to actually try your locks or just look at them.
1. A team with hands-on certifications
What matters most is the people who run the test. Ask for the profiles of the assigned team and look for certifications earned by attacking systems in a lab, such as OSCP (Offensive Security Certified Professional) or eWPT (a web application penetration testing certification), along with general credentials like CEH (Certified Ethical Hacker).
2. A recognized methodology
A serious pentest follows a public method, so the results do not hinge on each consultant's personal style. The most widely used frameworks are PTES (Penetration Testing Execution Standard, which organizes the test from the initial agreement through the report), NIST SP 800-115 (the technical guide to security testing from the US National Institute of Standards and Technology) and OWASP (the community that publishes the guides for testing web applications and APIs).
With those frameworks, the work is divided into penetration testing phases you can follow and audit: reconnaissance, analysis, exploitation, reporting and verification.
3. Scope and rules agreed in writing
The scope states which assets are included in the test (IP addresses, domains, applications, APIs) and which are left out. The rules of engagement are your agreement with the locksmith about which doors they can touch and when: testing windows, emergency contacts and what to do if a system slows down. A provider that quotes without asking for your asset list is guessing.
4. Business logic testing
Tools detect technical flaws, but they do not understand how your operation works. A pentester does check whether a user can check out at a price of zero by tampering with a field, or skip an approval step. They also check whether a regular user can grant themselves higher permissions. If the proposal does not mention business logic, the test will be superficial.
5. Same-day notice when something is critical
A critical finding should not wait weeks for the final report. Ask how, and how quickly, they will notify you when they confirm a serious vulnerability, so your IT team can close it while the test continues.
6. Retesting included
The retest is the locksmith's second visit after you changed the lock: the provider tests each finding again to confirm the fix works. Without it, you have no evidence that you closed what was found, which is exactly what an auditor asks for. We explain how it works in our guide to retesting in penetration testing.
7. A report with two levels
The deliverable has to serve two readers. Leadership needs an executive summary in business language: how exposed the company is and what it will take to fix it. Your technical team needs each finding with its evidence, the steps to reproduce it and the exact way to remediate it, without hundreds of pages of unconfirmed alerts.
On a Monday at 9 a.m., your CFO and your IT lead read the same report. The CFO needs to understand on a single page how much risk there is and what it would cost to reduce it; your team needs to know what to close first and how. If the report only works for one of them, it is incomplete.
Black box, gray box or white box: which approach to ask for
The approach defines how much information the team receives before starting. In locksmith terms: they show up with no keys, with the key to the front door or with the building's floor plans.
| Approach | What the team receives | What it simulates | When it makes sense |
|---|---|---|---|
| Black box | No information up front. | An external attacker starting from the internet. | Measuring your public exposure. |
| Gray box | Partial access, such as a user account and basic documentation. | A customer, supplier or employee whose basic access has been compromised. | A first formal test: it offers the best balance between depth and time. |
| White box | Full knowledge: architecture, credentials and sometimes source code. | An insider threat or an exhaustive review. | Critical systems, audits and regulated industries. |
Beyond the approach, the target changes too: there are different types of pentesting for web applications, networks, cloud, APIs and mobile apps, and a single proposal can combine several of them.
For example, a logistics company that has never had a pentest and needs to show evidence to a corporate customer within six weeks usually starts with a gray box test of its customer portal and its office network.
How much does a pentest cost, and what drives the price?
A pentest is priced according to its scope. Four variables define it:
- Number and type of assets: how many IP addresses, domains, applications, APIs or network segments are tested.
- Complexity: an informational web page can be assessed quickly; a platform with transactions, several user roles and integrations requires much more manual work.
- Approach: black box usually needs more reconnaissance hours than gray box.
- What is included: whether the retest and the results session are part of the price or quoted separately.
When you compare, put the proposals on the same footing: same scope, same approach and same deliverable. In our penetration testing service for businesses, we quote based on your asset list, with the retest and a letter of attestation already included.
On a Friday at noon, you compare two quotes that are 40% apart. Once you line them up, you find that the cheaper one covers three of your eight applications and does not include a retest: the price gap was really a scope gap.
Frequently asked questions about penetration testing companies
They are related, but they are not identical. Ethical hacking is the broader discipline of using attack techniques with permission and for defensive purposes; pentesting is a specific project within it, with a scope, dates, a methodology and a formal report. We go deeper in pentesting vs. ethical hacking.
A pentest takes an in-depth look at a defined scope over a short period. A Red Team simulates a real adversary for weeks, combining technical intrusion, social engineering and control evasion to put the whole organization to the test. For most companies, regular pentesting is the step that comes first.
At least once a year and after every major change: a cloud migration, a new internet-facing application, a merger or a security incident.
It depends on your industry and your customers. PCI DSS (the Payment Card Industry Data Security Standard) requires periodic penetration testing for anyone who processes card payments, ISO 27001 calls for managing technical vulnerabilities and, in financial services, the Safeguards Rule under the Gramm-Leach-Bliley Act (GLBA) treats it as part of sound technology risk management. Outside of regulation, more and more corporate customers ask for a recent pentest report before signing a contract.
It depends on the scope and the approach. A narrowly scoped web application can be covered in a few days; several applications, APIs and the internal network can take weeks. On top of the testing schedule, add the time your IT team needs to fix the findings and the retest.
Either one. Production shows the real risk, which is why the work happens in agreed windows with a direct channel to pause the test if a system slows down. A test environment lowers operational risk, but it is only useful if it faithfully mirrors the production configuration. The decision is made when the scope is defined.
During a pentest the team may see sensitive data, so how that information is handled must be put in writing before the work begins: a confidentiality agreement, who has access to the evidence, where it is stored and when it is deleted. If the provider subcontracts part of the work, they should also tell you to whom.
Gustavo Sánchez
Microsoft Cloud and Cybersecurity expert with more than a decade of experience in the technology industry. He is recognized for his extensive knowledge in implementing cloud-based solutions and protecting data and systems against cyber threats. As a leader and speaker, Gustavo continues to share his knowledge and best practices at technology events and training programs.