Questions to ask a pentest vendor
You cannot judge testing skill from a proposal, but you can judge it from how a firm answers questions about method, staffing and evidence. These are the ones that produce different answers from different firms, which is the whole point of asking.
Ask every firm the same twenty questions in the same order and score the answers side by side. Most of the information you need is not in the proposal, because proposals are written to survive comparison. The five questions that discriminate hardest are who does the testing, what proportion of findings came from a tool, whether you can see a redacted report, what happens on retest, and what the firm would refuse to do. Everything else is confirmation.
20 Questions, about 40 minutes on a call
1 redacted report The single most informative thing to request
$1,500 to $2,800 Canadian tester day rate to check quotes against, CAD
Send the same scope first
These questions only produce comparable answers if every firm is quoting the same thing. Build the scope document before the calls, not after, using the scoping questionnaire or the method on how to write a penetration test scope. Three quotes against three different interpretations of your environment tell you nothing about the firms.
Who actually does the testing
- Who specifically will be on this engagement, and how long have they been at your firm? You want names and tenure. The answer you do not want is that it will be assigned from a pool nearer the date, because it means the person who scoped it is not the person who tests it.
- Will any of the work be subcontracted? Subcontracting is normal and not disqualifying. Undisclosed subcontracting is. Ask whether the same background checks and confidentiality terms flow down.
- Where will the testers be located while testing, and where will the evidence be stored? This is the one Canadian buyers forget to ask, and it matters for public sector work and for anything under Quebec's Law 25. See data residency during a penetration test.
- What certifications do the assigned testers hold? OSCP, OSWE, CRTO, GPEN, GWAPT and GXPN are practical, hands-on qualifications. CISSP is a management credential and tells you nothing about whether somebody can test. If you are selling into the UK or the EU, CREST is the accreditation your customer is likely to recognise, and it is held by the firm rather than only by the individual. How much weight each one deserves is on CREST, OSCP and pentest certifications.
How to check the answers
What a good answer includes. The names and certifications of the testers who will be on your engagement (OSCP, OSWE, OSEP, CREST or equivalent), whether any of the work is subcontracted, and a sample report redacted from a real engagement.
How to verify. OffSec and CREST certifications can be checked against the issuer. Ask to speak to the lead tester for fifteen minutes before you sign; a firm that will not allow it is selling you a scanner run.
Common mistakes. Accepting the firm's credentials as the tester's, and not asking whether juniors do the work while a senior signs the report.
Canadian note. Canada has no licence for penetration testers. Some public sector and financial buyers ask for testers cleared through the federal Contract Security Program, so check the buyer's requirements before you shortlist.
Method, and how much of it is a person
- Which methodology do you follow, and can you name the sections? A firm that says PTES, OWASP WSTG, OWASP MASTG for mobile, or NIST SP 800-115 and can say which parts apply to your surface is telling the truth. A firm that names all of them and can say nothing further is reading a marketing page.
- Roughly what proportion of findings in a typical report of this type came from automated tooling? There is no correct number and every tester uses tools. Listen for whether they can answer at all, and whether they can describe a finding from your kind of system that no scanner would have produced.
- Give me an example of an authorisation flaw you found recently in an application like ours. Broken object-level authorisation is the most common serious finding in web and API testing and it cannot be found by a scanner, because a scanner does not know that order 1043 belongs to a different customer. A firm that cannot tell this story is selling you a scan, which is the argument on vulnerability assessment against penetration test.
- How many tester days are you allocating, and how are they split between testing and reporting? Days times rate is the whole quote. If a firm will not give you days, you cannot compare their number to anyone else's. Check the arithmetic against penetration testing cost in Canada.
- What would you refuse to do on this engagement? The best answer is specific: no denial of service, no testing of the payment provider's systems, no pretexting staff without HR sign-off. A firm that would refuse nothing has not thought about your environment.
How to check the answers
What a good answer includes. A named methodology (OWASP WSTG for web, PTES or NIST SP 800-115 generally), how many tester days are manual versus automated, and how they handle authenticated testing, business logic and access control between tenants.
Typical time. A small web application with an API usually needs five to ten tester days. A one-day quote for the same scope is mostly automated scanning.
Common mistakes. Buying a test scoped by page count or IP count instead of by roles and functions, and skipping authenticated testing because credentials were not ready.
Tip. Give the testers two accounts in each role, including two tenants if you are multi-tenant. Tenant isolation is where the serious findings usually are.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
The report and what comes after
- May I see a redacted report from a similar engagement? Ask before you sign. Almost every established firm has a sanitised sample and will send it under NDA. What to look for once you have it is on how to read a penetration test report.
- Who owns the report, and may I give it to a customer? You want ownership and the right to share under NDA. A licence-to-view arrangement means the report cannot do the job you bought it for.
- Do you provide an attestation letter, and is it included? This is the document most customers and insurers actually want, and it should be a named deliverable rather than a favour. See report against attestation letter.
- Is a retest included, what does it cover, and how long is the window? Included, all findings, 90 days is the good answer. Included, high and critical only, 30 days is common and workable. Not included is a $1,500 to $6,000 CAD line item you will pay later. The terms are on retest and remediation verification.
- How are severities assigned, and will every finding carry a CVSS vector string? A number with no vector cannot be checked. Ask which version, and see CVSS v3.1 against v4.0 for why the answer should be written into the scope.
- Will there be a live readout with the engineers who have to fix this? An hour of the tester's time explaining findings to the people who will remediate them is worth more than another ten pages of report.
How to check the answers
What a good answer includes. An executive summary, findings rated with a stated method (CVSS or the firm's own scale explained), reproduction steps, remediation advice specific to your stack, and a retest of fixed findings with a letter you can share.
Typical time. The report usually arrives one to two weeks after testing ends. Retests are booked once fixes ship, often within 30 to 90 days.
Common mistakes. Forgetting to include a retest in the quote, and sharing the full report with customers when an attestation letter would do.
For SOC 2 and ISO 27001. Auditors want the report, your remediation tickets and evidence the retest closed them. A test with open high findings and no plan becomes an exception.
Commercial and contractual
- What is in the rules of engagement, and can I see the template? Read it before signing anything. The clauses to refuse are listed on penetration test rules of engagement.
- What insurance do you carry? Professional liability and cyber liability, with amounts. Ask for the certificate.
- How long do you retain evidence and findings, and when are they destroyed? A stated period with a deletion commitment. "Indefinitely for quality purposes" means your credentials live on their file share.
- What would make this quote go up after we sign? Honest answers exist: a scope that grows, an environment that is not ready, a discovered second application. Getting them on the call prevents the change order argument.
- What is your lead time, and what happens if we slip? Good firms are booked four to eight weeks out. A firm available on Monday is either very new, very large, or has just lost a client.
How to check the answers
What a good answer includes. A fixed fee for a defined scope, the retest price, the rules of engagement, testing windows, who to call if something breaks, insurance, and how long they keep your data.
Contract points. Get written authorization signed by someone entitled to give it, and check your cloud provider's testing policy. AWS, Azure and Google Cloud allow most testing without prior approval, with listed exceptions.
Common mistakes. Letting the firm keep report copies indefinitely, and not naming a contact on your side who can stop testing if production slows.
Canadian note. Ask whether test data and reports stay in Canada. Findings often include screenshots of personal information, which you remain accountable for under PIPEDA when a vendor holds it.
Answers that should end the call
| What they say | What it means |
|---|---|
| "We can start tomorrow" | Nobody is booked, or the work is a scan that needs no scheduling |
| "We can do it for $2,500 CAD" | That is roughly one tester day plus reporting. It is a scan |
| "We do not share sample reports" | Universal firms redact and share. This is unusual and unexplained |
| "Our platform finds everything a manual test would" | It does not, and a firm claiming so is not testing authorisation |
| "The report is licensed, not owned" | You cannot give it to the customer who asked for it |
| "We guarantee you will pass your audit" | Nobody can guarantee an auditor's conclusion |
| "Retest is quoted separately after the report" | Fine if priced now, a lever if priced later |
The counter-case: when the cheap quote is the right one
If what you need is quarterly external scanning of a small perimeter to satisfy a questionnaire, an automated service at $2,000 to $5,000 CAD a year is the correct purchase and a $20,000 CAD manual engagement is money set on fire. The failure is not buying a scan. It is buying a scan believing it is a test, then handing the output to a customer who asked for a penetration test. Decide which you need first using which test do you need, then ask the questions that fit.
Scoring the answers
Write the twenty answers into one table with a column per firm before you form an opinion, because the firm you spoke to most recently always sounds best. Weight the five discriminating questions double. If two firms tie, take the one whose sample report reasons about impact in your context rather than pasting a vendor advisory, and whose quote shows tester days rather than a single number.
Price is the last tiebreak, not the first filter. The spread between the cheapest and dearest comparable quote in Canada is usually explained by tester days, and the day rate itself varies far less than buyers expect. Where the spread is not explained by days, you are looking at two different services with the same name on them.
Put one scope in front of several firms
Tell us what needs testing and who asked for it. The same scope goes to Canadian firms so the answers are comparable.
Get matchedCommon questions
What should I ask a penetration testing company before hiring them?
Who specifically will test, how many tester days are allocated and how they split between testing and reporting, whether you can see a redacted sample report, what the retest includes and how long the window runs, and what they would refuse to do. Those five separate firms faster than anything else, because the answers genuinely differ.
Should I ask for CREST or OSCP?
OSCP and its siblings are individual, hands-on qualifications and are a reasonable proxy for whether a tester can test. CREST is a firm-level accreditation and is the mark UK and EU buyers recognise, so it matters if your customer is over there or if you are bidding into a process that names it. For a Canadian buyer with Canadian and US customers, neither is mandatory. A redacted report tells you more than either.
Is it rude to ask a firm what proportion of findings came from a tool?
No, and the good firms enjoy the question. Every competent tester uses automation for coverage and then spends the bulk of the engagement on the things automation cannot reach. What you are testing is whether they can describe that split honestly and give you an example of a finding no scanner would have produced.
How many firms should I ask?
Three. Two gives you no sense of the range and five costs you more calendar time than the decision is worth. Send all three the identical scope document, ask the identical questions, and give them the same deadline.
What if a firm will not answer some of these?
Some refusals are reasonable: they cannot name the exact tester eight weeks out, or a sample report needs an NDA first. An unexplained refusal on report ownership, retest terms, tester days or evidence retention is different, because those are commercial terms you are about to be bound by and there is no confidentiality reason to withhold them.