Why penetration test proposals lose
Firms losing on price usually are not. They are losing because the buyer could not tell three quotes apart and picked the cheapest, which is a different failure with a different fix.
The most common reason a penetration testing proposal loses is that it did not show tester days. A buyer holding three quotes at $4,000, $14,000 and $26,000 CAD with no days in any of them has no basis for a decision except price, and will take the cheap one or the middle one for reasons that have nothing to do with you. Put the days in and the comparison changes shape.
Days, not price The line most losing proposals omit
Within 24 hours How fast a sample report request should be answered
2 to 4 pages A proposal a technical buyer will read
The seven reasons, in order of how often they are the real one
- The quote is not comparable. No days, no split between testing and reporting, no statement of what is out of scope. Fix: a table showing days per surface, reporting days, retest days, rate, total.
- You quoted a different thing than the competitor did. You priced authenticated multi-role testing, they priced an unauthenticated scan, and the buyer thinks those are the same product at different prices. Fix: state what you are including that a cheaper quote will not, in one short paragraph, without naming anyone.
- No sample report, or a slow one. Buyers are told to ask. A firm that takes a week or asks why is out. Fix: have a redacted report ready to send under NDA the same day.
- The proposal is about you. Four pages of company history and certifications before anything about their environment. Fix: their environment, your understanding of it, the days, then credentials.
- You did not answer the trigger. They are buying because an auditor or a customer asked. If the proposal never mentions the framework or the customer requirement, it does not look like it was written for them. Fix: name the trigger in the first paragraph.
- Retest and the letter were absent or priced separately. The buyer reads separate pricing as a lever. Fix: include both, cap the retest window, and say so.
- You were slow. Compliance-driven buyers have a date. A proposal on day nine loses to an adequate one on day two. Fix: a 48-hour turnaround for a scoped request, even if the answer is a range.
Price is the reason buyers give, not usually the reason
When a buyer says the other firm was cheaper, they are reporting the only difference they could see. If your proposal had made the difference visible, price would have been one input among several. Treat every "we went with a lower quote" as a message about your document, not your rate. The fix for the first is free.
A proposal structure that survives comparison
| Section | Length | Job it does |
|---|---|---|
| What you are buying and why | One paragraph | Names their trigger. Proves you listened on the call |
| Scope, as a list of assets | Half a page | Hostnames, applications, roles, cloud accounts. Makes quotes comparable |
| Out of scope | Five lines | Prevents the change-order argument and signals experience |
| Days and price table | One table | The section that wins or loses it |
| Method, named | One short paragraph | PTES, OWASP WSTG or MASTG, NIST SP 800-115, with the sections that apply. The glossary has what each covers |
| Deliverables | A list | Report, attestation letter, retest with window, live readout |
| Team | Four lines | Named testers with real qualifications. Not the whole company |
| Dates | Two lines | Start, report, retest deadline. Buyers have a compliance date |
The days figure comes from a defensible base by surface, which is what pricing a penetration test sets out, and the answers that feed it come off the call, which is scoping call questions.
Two to four pages. A twenty-page proposal signals a firm that sells rather than tests, and the technical buyer who has to approve it will not read past page three. Put the credentials at the back where a procurement reviewer can find them.
The one table that changes outcomes
| Component | Tester days | CAD |
|---|---|---|
| Web application, authenticated, three roles, two tenants | 9 | $18,000 |
| REST API, 60 endpoints, object-level authorisation | 5 | $10,000 |
| Reporting and quality review | 2 | $4,000 |
| Retest within 90 days of report | 1 | Included |
| Total, at $2,000 CAD a day | 17 | $32,000 |
A buyer holding this beside a $4,000 CAD quote can see that the other proposal is two days of work. You have not disparaged anybody and you have not defended your rate. You have made the market legible, which the buyer wanted and could not do alone. To have them reach that conclusion without you arguing it, send them vulnerability assessment against penetration test, which makes the case from a source that is not bidding.
Losing well
Ask what the winning proposal did differently, and ask the buyer rather than your own team. Most will tell you, particularly if you ask once, briefly, with no attempt to reopen. The answers cluster: they included a retest, they named the testers, they came back in two days, they sent a sample report. Each of those is something the buyer was told to ask for on questions to ask a penetration testing vendor, which is worth reading as the script your prospect is working from.
Then stay in the file. Compliance testing is annual. A firm that lost gracefully, sent something useful six months later and was available when the incumbent slipped a date wins the second year often enough to justify the discipline. Put a reminder in for eleven months.
When not to bid
Firms bid too often. Skip it when the buyer will not do a scoping call, when the requirement is written so that only an automated service can meet the price, when the deadline is inside your lead time and you would have to staff it badly, or when the scope includes a surface you have never tested and there is no budget to bring in a specialist. Say why you are declining and what would change your answer. That message converts to future work more often than a rushed bid does.
Get in front of buyers before the bid
Most proposals lose before they are written, when the buyer builds a shortlist you were not on.
List your firmCommon questions
Why do we keep losing penetration testing bids on price?
Usually because the proposals were not comparable, so price was the only visible difference. Show tester days per component, the reporting split and the retest, and the buyer can see that the cheap quote is a day and a half of work. Price becomes one input rather than the whole decision.
How long should a penetration test proposal be?
Two to four pages. The technical buyer who approves it will not read twenty, and length reads as selling rather than testing. Lead with their environment and the trigger that made them buy, put the days and price table in the middle, and leave credentials and boilerplate for the back.
Should we include a sample report with the proposal?
Offer it in the proposal and send it the same day it is requested, under NDA. It is the artifact that separates you from a scan reseller and buyers are explicitly advised to ask for one. A firm that takes a week to produce one has usually lost by the time it arrives.
Is it worth asking why we lost?
Yes, once, briefly, with no attempt to reopen the decision. Most buyers answer, and the answers repeat: a retest was included, the testers were named, the response was faster, a sample report arrived. Then diarise eleven months out, because compliance testing renews and incumbents slip dates.
Should we ever decline to bid?
Yes. Decline when there is no scoping call, when the budget only fits an automated service, when the deadline forces you to staff it badly, or when the scope needs a specialism you do not have and cannot subcontract. Say what would change your answer. That note produces more future work than a rushed proposal.