Is that a penetration test or a scan with a report?
Six questions about the proposal in front of you, then a verdict with the specific signals that decided it and the questions to put back to the vendor before you sign.
Both products are sold under the same three words. One is a licensed scanner run against your address range with the output exported to a template. The other is a person spending days inside your application, chaining findings a tool cannot chain, and writing up what they reached. The price difference is large and the wording in the two proposals is often identical.
Answer six questions about the proposal you were sent and this tells you which one you are being offered, which signals decided it, and what to ask before you sign. The verdict appears on this page. Nothing is emailed anywhere unless you ask for it at the end.
On its way
Check your inbox shortly.
Why these six questions
Each one is hard to fake in writing. A scanning product cannot describe role comparison in your own application because it has never seen your roles. A firm selling two hours of analyst time cannot offer you a named tester and a findings walkthrough without the economics falling apart. So the answers correlate tightly with what is actually being sold, in a way that the methodology page on a website does not.
Tester days are the strongest single signal. Divide the quoted figure by about $2,000 CAD, the middle of the $1,500 to $2,800 CAD Canadian day rate band, and you have the number of days the firm can afford to spend including writing the report. Two days does not cover somebody learning your product, getting credentials working, and comparing what two accounts can reach.
None of this makes a scan worthless. Authenticated vulnerability scanning on a schedule is a sensible control and it is cheaper than a test for a reason. The problem is only ever paying test money for scan work, or handing an auditor a scan when the requirement said test. The difference is set out on vulnerability assessment versus penetration test.
What to do with the answer
If the verdict comes back as a scan and you wanted a scan, you are fine. Check the price against scanning rather than against testing. If you wanted a test, do not argue about the label. Send the same written scope to two or three more firms and compare what comes back, which is what the scoping questionnaire is for, and put the vendor questions from questions to ask a vendor in the same email.
Common questions
Is it wrong for a penetration test to use scanners?
No. Every competent tester runs tooling, because there is no reason to find a missing patch by hand. The question is what happens next. On a test, the tool output is the first hour and the input to the thinking. On a scan with a report, the tool output is the deliverable.
Our auditor accepted a scan last year. Does this matter?
It matters the next time. Auditors and enterprise customers have both tightened on this, and the usual failure is a customer security review asking for scope, methodology and a named signer, none of which a scan export carries. Ask what your customer contract actually requires before you buy either product.
The proposal says manual testing. Is that enough?
On its own, no. The phrase appears in nearly every proposal in this market. What tells you something is the sentence after it: which manual activities, against which parts of your system, and for how many days. If those three answers are absent, treat the phrase as marketing.
Does a low verdict mean the firm is dishonest?
Usually not. Plenty of firms sell an honest scanning service and the buyer supplies the word pentest on their own. The confusion is as often created on the buying side as the selling side, which is why writing the scope down first removes most of it.
How do we make several quotes comparable?
Send every firm the same written scope, and ask each one for the tester days and the retest terms as separate line items. Most of the spread buyers report between quotes comes from firms answering different questions rather than from anyone overcharging. More on why quotes differ.