How to Choose a Penetration Testing Company in 2026: 7 Criteria That Actually Matter
Penetration testing companies sell wildly different things under the same name: a EUR 300 automated scan and a EUR 50,000 consulting engagement both get called a pentest. The seven criteria below separate vendors that deliver auditor-accepted manual testing from the rest, with the exact question to ask for each. Work through them and any shortlist sorts itself in an afternoon.
The 7 Criteria
1. Certifications of the actual testers
OSCP is the baseline for hands-on offensive work, OSWE signals advanced web depth, CREST matters in UK and enterprise procurement. The trap: companies advertise certifications the sales team's colleagues hold. Ask directly: which certification does the tester assigned to MY engagement hold? A vendor that cannot answer with a named credential falls off the list.
2. Manual testing, not a rebranded scan
The cheapest 'pentests' on the market are automated scans with a logo on the report. Scanners find known CVEs; they miss broken access control, business logic flaws, and chained attacks, which is where real breaches happen. Ask: does a human tester work through my application, and what share of the engagement is manual? For compliance evidence, auditors accept manual testing only.
3. A redacted sample report
The report is the product. A professional one contains reproduction steps, exploitation screenshots, CVSS risk ratings, business impact per finding, and concrete remediation guidance. Ask every candidate for a redacted sample before you sign. If the sample looks like scanner output or the vendor refuses to share one, you have your answer.
4. A named methodology
Serious vendors test against published methodologies: OWASP Testing Guide for applications, PTES for engagements end to end. A named methodology makes coverage verifiable: you can check what was tested against what should have been tested. 'Our proprietary approach' with no reference framework is a red flag.
5. Transparent pricing
You should see a day rate or a total price without sitting through multiple sales calls. Rates for certified manual testing run EUR 800 to 1,500 per day in 2026; a standard web application test takes 4 to 6 days. Quotes without a day count hide either padding or a scan. If a vendor needs three meetings before showing a number, you are paying for those meetings.
6. Real dates: start and delivery
Traditional firms quote six to twelve weeks before testing starts, which matters when an auditor or enterprise customer is waiting. Ask for the actual start date and the report delivery date, in writing. Self-serve platforms start within days; some, including Budget Security, assign a tester within 24 to 48 hours.
7. Compliance mapping and retest policy
If the test is for SOC 2, ISO 27001, PCI DSS, HIPAA, or NIS2, the report must be structured for your auditor: control mapping, evidence trail, and a retest after remediation that confirms fixes. Ask what a retest costs and how it is booked. Vendors that treat the retest as a fresh engagement double your real price.
The Three Vendor Types You Will Meet
| Vendor type | Who tests | Time to start | Typical price | Compliance-ready |
|---|---|---|---|---|
| Automated scan service | Software | Instant | EUR 200 to 500 | No |
| Traditional consultancy | Certified specialists | 6 to 12 weeks | EUR 5,000 to 50,000+ | Yes |
| Self-serve platform (Budget Security) | OSCP and OSWE testers | 24 to 48 hours | From EUR 849/day | Yes |
The test quality between a good consultancy and a good self-serve platform is the same: certified humans following OWASP and PTES. The difference is the delivery model, which is where the weeks and the overhead cost live. What each scope costs in practice is covered in the penetration testing cost guide.
Five Red Flags That End the Conversation
- No named tester certification. "Our team is highly experienced" is not a credential.
- No sample report. If they will not show the product, do not buy it.
- A price with no day count. You cannot compare quotes without knowing the effort behind them.
- Guaranteed-clean results. A vendor promising few findings sells compliance theater, not security.
- Pressure to buy a retainer first. A pentest is a standalone engagement; recurring work should be your choice after seeing the quality.
Hold Us to the Same Seven Criteria
OSCP and OSWE certified testers, manual testing on OWASP and PTES, a sample report on request, a public day rate from EUR 849, a tester assigned within 24 to 48 hours, and auditor-ready reports with one-click retests. Judge for yourself.
Explore our penetration testing services