)}
Penetration Testing

How to Evaluate a Penetration Testing Firm

How to compare pentest vendors in India. What to ask about certifications, report quality, retest policies, and red flags for scanner-only firms.

AK
Ashok Kamat
Cybersecify
9 min read

Evaluate a pentesting firm on four things: team certifications (OSCP, CREST, not just CEH), a sample report showing manual testing evidence, a clear retest policy, and named testers assigned to your engagement. Price alone tells you nothing about quality.

You have three pentest quotes on your desk. One is ₹45,000, one is ₹75,000, and one is ₹2,50,000. All three say “penetration testing” in the proposal title. All three promise a report at the end.

They are not the same service. Not even close.

The difference between a good pentest and a bad one is the difference between knowing your real vulnerabilities and having a false sense of security. This guide will help you tell them apart.

1. Ask About Team Certifications (And Verify Them)

The single biggest factor in pentest quality is who does the work. Certifications matter because they indicate hands-on, practical testing ability, not just theoretical knowledge.

Certifications that signal real testing skill:

  • OSCP (Offensive Security Certified Professional): The industry standard for manual exploitation. Requires a 24-hour hands-on exam where you break into multiple machines. You cannot pass this by memorizing a textbook.
  • CREST CRT/CCT: UK-based certification with rigorous practical exams. Widely recognized in enterprise and financial services.
  • CompTIA PenTest+: Covers planning, scoping, and reporting alongside technical testing. Good baseline.
  • CEH (Certified Ethical Hacker): The most common certification. It tests knowledge, not practical skill. A CEH-only team can do basic testing but may miss complex business logic flaws.

What to ask: “Who will actually perform the testing on my engagement? What are their certifications?” If the answer is vague (“our team has various certifications”) or they can’t name the specific tester, that’s a signal. You want to know the person who will be hands-on with your application.

At Cybersecify, every engagement is delivered by our OSCP-certified founder, Rathnakara. Not managed. Delivered.

2. Understand What “Automated Scan + Manual Testing” Actually Means

Almost every pentest proposal includes the phrase “combination of automated scanning and manual testing.” This sounds reasonable. The problem is that at the lower end of pricing the deliverable is often scan output with light manual review. The phrase does not tell you the ratio, so ask for it: what proportion of testing hours are hands-on-keyboard, and who does them.

Here’s what that looks like in practice:

  • Run Nessus or Acunetix against the target
  • Export the findings
  • A junior analyst reviews the output, removes obvious false positives
  • The remaining findings get copied into a branded report template
  • Total human effort: 4 to 8 hours

That is a vulnerability assessment, not a penetration test. The difference matters.

What to ask: “How many hours of manual testing will my engagement include? What tools does your team use for manual testing?” A legitimate pentest firm will mention Burp Suite Professional, custom scripts, manual API testing with tools like Postman or httpx, and they’ll describe their methodology for testing business logic.

Red flag: If the proposal doesn’t specify manual testing hours or methodology, you’re likely buying a scanner report with a nicer cover page.

3. Evaluate Report Quality Before You Buy

The pentest report is the deliverable. It’s what you show your investor, your enterprise client, your auditor. A bad report wastes the entire engagement.

What a good pentest report includes:

  • Executive summary written for non-technical stakeholders (your CEO, your investor)
  • Business impact assessment for each finding, not just CVSS scores but what it means for your company
  • Detailed reproduction steps that your engineering team can follow to verify the issue
  • Fix guidance with specific, actionable remediation advice (not just “apply the latest patch”)
  • Compliance mapping showing which findings affect SOC 2, ISO 27001, or DPDP Act requirements
  • Risk-rated findings using a standard framework (CVSS, OWASP Risk Rating)

What a bad report looks like: Scanner output with boilerplate descriptions, generic remediation advice (“improve input validation”), no business context, and findings sorted by CVSS score with no explanation of actual impact.

What to ask: “Can I see a sample report?” Any firm confident in their work will share one. Here’s ours.

4. Check the Retest Policy

You get the pentest report. Your team fixes the critical and high-severity findings. Now you need verification that the fixes actually work. This is the retest.

Industry reality: Many firms charge extra for retesting, sometimes as a meaningful fraction of the original engagement cost. Others offer a single “verification scan” (automated, not manual) and call it a retest. Ask for the retest price and the retest method in writing.

What to ask: “Is a retest included in the engagement? Is it a full manual retest or an automated re-scan? What’s the validity window?”

At Cybersecify, both our Startup and Growth pentest plans include one full manual retest at no additional cost. If your team fixes the findings and wants verification, you get it. No extra invoice.

5. Business Logic Testing: The Real Test of Quality

This is where the gap between a scanner-driven engagement and a real pentest becomes impossible to hide.

Business logic vulnerabilities are flaws in how your application implements its rules, not in the code’s syntax or known CVE patterns. Scanners cannot find them because they require understanding what your application is supposed to do.

Examples of business logic findings a manual pentest catches:

  • IDOR (Insecure Direct Object Reference): Changing /api/invoice/1234 to /api/invoice/1235 returns another customer’s invoice. The API works perfectly. The authorization check is missing.
  • BOLA (Broken Object-Level Authorization): A user with “viewer” role can access admin API endpoints because the role check only exists in the frontend React code, not on the server.
  • Auth bypass: Password reset flow accepts any email address and sends the reset link, but the token is predictable (sequential, timestamp-based, or short enough to brute-force).
  • Payment logic abuse: Applying a discount code, removing an item from the cart, then re-adding it applies the discount twice.
  • Race conditions: Two simultaneous withdrawal requests against the same account balance both succeed because the balance check isn’t atomic.

What to ask: “Can you share examples of business logic vulnerabilities your team has found in past engagements?” A good firm will have stories. A firm that only runs scanners won’t.

6. Comparison: Freelancer vs Junior-Led Firm vs Senior-Led Firm

Not all pentest providers are structured the same way. Here’s what you’re actually getting at each tier:

FactorFreelancer (₹30K-50K)Junior-Led Firm (₹50K-1L)Senior-Led Firm (₹75K-2L+)
Who testsSingle freelancer, skill variesJunior analysts (0 to 3 years), senior reviews outputOSCP/CREST certified seniors do hands-on testing
MethodologyVaries by individualMostly automated with some manualStructured manual testing, OWASP, PTES
Business logicMaybe, depends on the personRarely tested in depthCore focus of the engagement
Report qualityBasic, often no business contextTemplate-driven, generic remediationBusiness impact, fix guidance, compliance mapping
RetestUsually not includedAutomated re-scan or extra chargeManual retest included
Compliance mappingNoSometimesSOC 2, ISO 27001, DPDP Act mapping included
ConsistencyDepends entirely on the individualVaries by who’s assignedConsistent because seniors do the work
CommunicationDirect but informalAccount manager relays questionsDirect access to the tester

The cheapest option is not always the worst. A skilled freelancer with OSCP can deliver excellent work. But there’s no quality assurance, no retest guarantee, and if they’re unavailable next quarter, you start from scratch with someone new.

The most expensive option is not always the best. Large firms charge ₹3L+ and assign the work to the same junior analysts you’d get at a mid-tier firm. You’re paying for the brand name on the report cover.

The sweet spot for most startups is a senior-led boutique firm with transparent pricing, proven certifications, and included retesting. For a deeper breakdown of what drives pentest pricing at each tier, see our guide to penetration testing cost in India.

7. Red Flags When Evaluating a Pentest Firm

Watch for these signals that the engagement may not deliver what you need:

  • “Contact us for a quote” with no public pricing. Transparency about pricing signals confidence. If a firm won’t tell you what they charge until they’ve had three sales calls, ask yourself why.
  • Rotating analysts. “Your engagement will be assigned to one of our team members.” Which one? If they can’t tell you who will test your application, the work is being commoditized.
  • No retest included. If the firm doesn’t include retesting, they’re optimizing for report delivery, not for actually improving your security.
  • Automated-only “pentest” at suspiciously low prices. A 2-day “pentest” for ₹20,000 is a scanner report. Manual testing takes time. Time costs money.
  • No sample report available. If they won’t show you what the deliverable looks like before you buy, the deliverable is probably not something they’re proud of.
  • Vague methodology descriptions. “We use industry-standard tools and techniques” means nothing. Ask for specifics.
  • No mention of business logic testing. If the proposal only covers OWASP Top 10 without mentioning authorization testing, IDOR, or workflow abuse, you’re getting surface-level coverage.

How to Make Your Decision

Here’s a simple evaluation checklist:

  1. Ask who will do the testing. Get a name and certifications.
  2. Ask for a sample report. Read the executive summary and fix guidance sections.
  3. Ask how many hours of manual testing are included.
  4. Ask if retesting is included and whether it’s manual or automated.
  5. Ask about business logic testing methodology.
  6. Compare the total cost, including retesting and compliance mapping, not just the headline price.

A ₹75,000 pentest with senior testers, included retesting, and compliance mapping is more valuable than a ₹45,000 engagement that misses your critical vulnerabilities and charges ₹30,000 for a retest.

One more tip: ask for references. A firm that has tested products similar to yours (SaaS, fintech, healthtech, whatever your vertical) will ramp up faster and find more relevant issues. Domain knowledge matters in security testing just as it does in engineering.


Community: Cybersecify was a Community Partner for BSides Bangalore 2026, with co-founder Ashok Kamat on the Core Team. Bengaluru’s flagship community-driven cybersecurity conference (July 9, Sheraton Grand), where Ashok presented original OSINT research and joined a panel on deepfakes.

Our Approach

Our Startup Pentest plan is ₹74,999 for one scope with 5 business days of testing and a full manual retest within one month of the v1.0 report. Every engagement is delivered by our OSCP-certified founder, Rathnakara. Not supervised. Delivered.

Want to see the quality before you commit? View our sample report or run your domain through Open EASD for a free external attack surface snapshot.

If you’re not sure whether you need a pentest or something else entirely, book a free 30-min discovery call with the founders. We will scope the right next step for your situation.

See our web application pentest, API pentest, cloud pentest, Android application pentest, and iOS application pentest service pages for full scope details and what each engagement includes.

The right pentest firm won’t just hand you a report. They’ll make your product meaningfully harder to break.

Corrections

  • 2026-08-09: Removed the unsourced “90% automated and 10% manual” split attributed to lower-priced firms, and the unsourced “25 to 50%” retest price. Both are now written as questions to ask the vendor.

Frequently Asked Questions

What certifications should a penetration testing firm have?

Look at the certifications of the person who will actually be hands on with your application, not the badge collection on the firm's website. OSCP is the meaningful baseline for manual exploitation because it is a hands on exam against live machines rather than a multiple choice paper. CREST CRT and CCT carry similar weight and are widely recognised in enterprise and financial services. CompTIA PenTest+ covers planning, scoping and reporting alongside technical testing and is a reasonable baseline. CEH tests knowledge rather than practical exploitation, so a CEH only team can run standard checks but is unlikely to find business logic flaws. Two follow ups make the answer useful. Ask for the certification number so you can verify it, which is normal and any legitimate tester will provide. Then ask whether that named person performs the testing or reviews someone else's output, because those are very different engagements at similar prices.

How do I know if a pentest firm is running scanners instead of manual testing?

Ask three questions and read the answers for specificity. How many tester days per scope are hands on keyboard, and who spends them? What tools beyond automated scanners does the testing use? Can you describe a business logic vulnerability your team found in a past engagement, without naming the client? A firm doing real manual work answers with Burp Suite Professional, custom scripts, manual API testing, and a method for authorisation and workflow testing, and it has stories. A firm reselling scanner output stays generic, cannot name the tester, and describes coverage as industry standard tools and techniques. The timing gives it away too. A scan of a web application completes in hours, while manual testing of a single application scope takes about five business days. If a proposal offers a full pentest of a complex product in two days, the arithmetic has answered your question already.

Should I ask for a sample pentest report before buying?

Yes, and treat a refusal as the answer. Any firm confident in its deliverable shares one, and ours is published in full. When you read a sample, check five things. Is the executive summary written so a non technical founder or investor can follow it, or is it a chart of CVSS scores? Can you follow the reproduction steps for a finding without being a security engineer? Is the remediation guidance specific to a stack, or generic advice like improve input validation that could appear in any report? Is there compliance mapping to SOC 2 Trust Services Criteria or ISO 27001 Annex A controls if you have an audit coming? Most importantly, is there at least one finding that required understanding the product, such as an authorisation bypass between two accounts or a workflow abused out of order? If every finding is a header, a TLS setting or a library version, you are reading a vulnerability scan.

What should I ask a vendor to be sure the testing is real pentesters and not a Nessus scan dressed up as a PDF?

Ask five questions. One: who personally performs the testing, and what are their certifications (OSCP and CompTIA PenTest+ signal hands-on manual skill; CEH alone does not)? Two: how many hours of manual testing are included, and what tools beyond scanners do you use (a real answer names Burp Suite Professional, custom scripts, and a business logic methodology)? Three: can I see a sample report, and does it show business logic findings like BOLA, IDOR, and payment-flow abuse that a scanner cannot detect? Four: is a retest included, and is it manual or an automated re-scan? Five: can you describe a business logic vulnerability your team found in a past engagement? A vendor selling a Nessus or Acunetix export will be vague on manual hours, cannot name the specific tester, shows a findings list sorted only by CVSS with no business context, and has no business logic stories. At Cybersecify every engagement is delivered (not just supervised) by our OSCP-certified founder, Rathnakara, with manual exploitation and 1 free retest included.

What are the signs of a bad pentesting vendor?

Seven signs. One: no public pricing, with a quote offered only after several sales calls. Two: rotating or unnamed analysts, so they cannot tell you who will test your application. Three: no retest included, or a retest charged at full engagement price. Four: a suspiciously low price for a 2-day pentest of a complex application, which almost always means a scanner report. Five: no sample report available before you buy. Six: vague methodology (industry-standard tools and techniques) with no named framework like OWASP WSTG v4.2 or PTES. Seven: no mention of business logic, authorization, IDOR, or workflow abuse testing, meaning coverage stops at surface-level scanner findings. A report that is pure scanner output with a branded cover page, identical wording across findings, or generic remediation like improve input validation is the clearest tell. Real manual pentesting takes 5 to 15 days per scope; automated scans finish in hours.

Does it matter if the pentest firm is in a different country from us?

For most SaaS products it does not change the testing, but three practical things are worth settling before you sign. Data handling: agree in writing what the tester may access, whether any real customer data is in scope, where evidence is stored and when it is destroyed. If you fall under GDPR or India's DPDP Act, that belongs in the contract rather than in an email thread. Jurisdiction: the NDA and the written authorisation to test should name a governing law both sides accept. Working hours: agree the testing window and a channel where a Critical finding reaches you quickly, because a finding sitting unread overnight is the real cost of a timezone gap, not the timezone itself. What does not change is the standard the report is held to. An auditor or an enterprise reviewer reads methodology, tester credentials, findings and remediation evidence, not the address on the cover.

What should be agreed in writing before testing starts?

Six items. A signed scope document listing every target, every exclusion and the testing window. Written authorisation to test, which your cloud or hosting provider may also require and which protects the tester legally. A mutual NDA covering the findings, since a pentest report is a working description of how to attack your product. Data handling terms: what the tester may access, whether real customer data is in scope, how evidence is stored and when it is destroyed. An escalation path with a named contact for anything Critical found mid test. And a deliverables list spelling out the report format, whether a retest is included and its validity window, and whether a letter of attestation is provided. A firm willing to start testing on a purchase order and a friendly email will bring that same informality to the report.

How do we compare pentest quotes that are priced differently?

Normalise them to two numbers: tester days per scope, and the total cost of everything you will actually need. Firms quote per scope, per day or per application, and the headline price hides the differences that matter. Build a short table with a row for each of these: how many scopes are covered, how many hands on tester days per scope, who performs the testing and their certifications, whether a retest is included and whether it is manual, whether compliance mapping is included if you have an audit coming, and whether a letter of attestation is provided. A cheaper quote that excludes the retest and charges for it separately often lands higher than the one that looked expensive, and the retest is the artefact your auditor asks for. Then check the arithmetic on time. A full application pentest priced at two days is not the same product as one priced at five, whatever both proposals are titled.

Security questions, worries, or not sure what to use?

Cybersecify is a founder-led penetration testing firm for AI and SaaS startups. Tell us what you are weighing and we will give you a straight answer. Ask the team or book a free 30-minute call.

Share this article
pentestvendor selectionOSCPCRESTsecurity assessmenthow to choose penetration testing companypentest vendor India

Spotted something wrong on this page? Facts change and we get things wrong. Tell us and we will check it. We publish corrections on the page rather than editing quietly.