GetPentest

Scoping call questions for testers

A scoping call has two jobs: get enough detail to quote days rather than a guess, and find out whether this is a deal at all. Most firms do the first badly and skip the second entirely.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

Thirty to forty-five minutes, and ask about the trigger before you ask about the technology. Who demanded this test, in what words, and by what date decides whether the deal exists, what it must contain, and whether you are competing against a $3,500 CAD scan. Every technical question after that is easier once you know the answer.

30 to 45 min A scoping call that produces a real estimate

The trigger first Before any technical question

Roles and tenancy The two answers that move days most

Open by qualifying, not by scoping

  1. Who asked for this, and can you read me their exact words? "Annual penetration test by a qualified third party" is a different purchase from "evidence of vulnerability scanning". The literal wording decides what you must deliver and often settles the price argument before it starts.
  2. What is the date, and what happens if you miss it? A real deadline is the strongest buying signal in this market. No deadline usually means no budget yet.
  3. Is there a budget, and has it been approved by whoever signs? Ask directly. A range is fine. Discovering at proposal stage that the budget is $5,000 CAD for a $30,000 CAD scope wastes both of you a week.
  4. Have you had a test before, and may I see the previous report or its scope? The single most useful artifact on the call. It tells you the estate, the previous scope, the finding profile and what they are comparing you against.
  5. Who else are you speaking to? Most will tell you. If the list is three boutiques, you are in a real process. If it is you and an automated scanning service, you are being used to price-check, and you should decide whether to spend the effort.

The trigger changes the deliverable, not just the scope

A SOC 2 buyer needs a report and remediation evidence. A customer security review needs an attestation letter more than it needs the report. A PCI DSS buyer needs a methodology statement that maps to requirement 11.4 and, if they are a service provider, segmentation testing every six months. An insurer needs a date and a letter. Asking the trigger question first means you quote the right deliverable rather than adding it in week three.

The technical questions, by surface

What to ask, and how much the answer moves the estimate
SurfaceAskEffect on days
Web applicationHow many distinct user roles, and is it multi-tenantLarge. Two roles adds about 35 percent, three or more about 60
Web applicationRoughly how many distinct screens or workflows, not pagesLarge. This is the scale multiplier
APIEndpoint count, and is there a specification you can shareLarge. A spec saves a day of discovery
APIIs authorisation checked per object or only per endpointModerate, and the answer is often "we are not sure", which is itself informative
External networkHow many live hosts and public IP rangesModerate
Internal networkSites, VLAN count, domain user count, and is it one forestLarge
CloudHow many accounts or subscriptions, and which servicesLarge
MobileOne platform or both, and is the backend in scopeLarge. The second platform adds 40 to 60 percent

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

The readiness questions that stop overruns

These cost you nothing to ask and are the difference between an engagement that runs to plan and one where two testers sit idle on day one.

Test account provisioning is the most common cause of a lost day. Ask who does it, get a name, and put the date in the statement of work. A WAF that nobody thought to mention is the second most common, because a tester spends a day fighting a rate limit and reports coverage they could not achieve. Decide during scoping whether it stays on, and record the decision.

Answers that should change your quote or your mind

What you hear, and what it means for the deal
What they sayWhat to do
"We just need something for the auditor"Quote what satisfies it honestly, and say what it does and does not cover
"We do not know how many endpoints"Time and materials with a cap, or a half-day scoping engagement first
"Can you start Monday"Ask why. Usually a slipped deadline, sometimes a firm that dropped out
"Our last test found nothing"Ask to see it. It was probably a scan, and you are about to look expensive
"We need it under $5,000 CAD"Say what that buys, honestly, or decline. Do not shrink a real scope into it
"The system belongs to our vendor"Stop. Written authorisation from the owner or there is no engagement
"Can you also fix the findings"Possible conflict. Decide your policy before the call, not during

How to close the call

Say back what you heard in four sentences: the surfaces, the scale, the roles, the date. Getting corrected on the call costs a minute and getting corrected after the proposal costs the deal. Then commit to a turnaround, and make it 48 hours for a scoped request.

Send the scope document with the proposal, not just the price. Buyers are advised to send an identical scope to three firms so quotes are comparable, and a firm that supplies the document has framed the comparison in its own terms. The buyer-side version is generated by the scoping questionnaire, and the questions your prospect has been told to ask you are on questions to ask a penetration testing vendor. Read it before your next call. It is the script the buyer is working from.

Be on the shortlist that generates the call

A listing that names your surfaces and turnaround gets you into scoping calls you would not otherwise hear about.

List your firm

Common questions

What should I ask on a penetration test scoping call?

Start with the trigger: who demanded the test, in what exact words, and by what date. Then budget and previous reports. Only then the technical questions, which for applications are the number of user roles and whether it is multi-tenant, and for networks are host, site and domain counts. Finish with readiness: test accounts, WAF, access and who signs.

How long should a scoping call take?

Thirty to forty-five minutes for a typical engagement. Longer than an hour usually means the buyer cannot describe their own environment, which is a signal to propose a short paid scoping engagement or to quote time and materials with a cap rather than a fixed fee against unknowns.

What single question changes the estimate most?

How many distinct user roles there are and whether the application is multi-tenant. Each additional role is another full pass over the authorisation surface, and tenancy determines whether the most valuable class of finding is even in scope. Two roles adds roughly a third to an application engagement and three or more roughly sixty percent.

Should I quote on the call?

Give a range on the call and the number in writing within 48 hours. Buyers with a deadline reward speed and a range costs you nothing if you frame it as dependent on the two or three answers you are still waiting on. Refusing to indicate anything until a formal proposal is a common way to lose to a firm that was merely faster.

What if the prospect cannot describe their environment?

Sell a short scoping engagement, half a day to a day, that produces the asset inventory and the scope document. It is billable, it makes the main engagement accurate, and a prospect who will not pay for it was unlikely to buy the test. The alternative is a fixed fee against unknowns, which is how firms lose money on their own quotes.