How to Choose a Penetration Testing Vendor: The 5 Signals That Separate a Test From a Report
Choosing a penetration testing vendor means comparing how each firm would actually test your environment, not how big its brand is. Ask every finalist for scope in writing, sample evidence, named testers, retest terms, and a remediation speed target, then score proposals against each other. The five-signal scorecard in this post does exactly that.
Most organizations shortlist penetration testing vendors the way they compare insurance quotes. They read the marketing site, look at the price, check the references, and sign. Then a few weeks later the report arrives, and nobody on the team can say what was actually tested, or whether the work would survive a second look. In our client conversations the pattern is consistent: the proposal said "external and internal network," but the scan scope listed nine IP ranges nobody had reviewed, and the retest was a one-time event priced in as an option. The vendor delivered exactly what it sold. The organization just bought the wrong thing.
This problem has gotten more expensive to get wrong. In late September 2026, CISA confirmed that threat actors were actively exploiting two Citrix NetScaler zero-days, CVE-2026-88771 and CVE-2026-88772, and added both to its Known Exploited Vulnerabilities catalog [2]. A third flaw, CVE-2026-88779, followed on October 4, 2026, with a federal remediation deadline of October 7 [1]. The vendors whose customers caught those flaws early were the ones with continuous, validated testing in place, not the ones with the best-sounding proposals.
What Does "How to Choose a Penetration Testing Vendor" Actually Ask?
You are not really asking which company is the best at penetration testing. You are asking whether this proposal describes work that would survive contact with your environment, and whether the report you would receive is evidence or just a deliverable. Those are different questions, and most vendor content, including the listicles that dominate this search, never separates them [4].
Why Vendor Listicles Can't Answer It
Search "how to choose a penetration testing vendor" and the top results are all written by vendors. One is a 12-company list where the writing vendor ranks first. Another is a top-ten considerations list that stops at "ask for a sample report" [4]. None of them show you how to score the proposals you are actually holding, because that would be an instruction for comparing their competitor's work against their own.
The Cost of Choosing Wrong
The data on what happens after the choice is blunt. In Cobalt's 2026 State of Pentesting, built from more than 16,500 penetration tests across nearly 3,000 organizations, the half-life of high-risk findings for top-performing teams was 10 days. For the bottom tier, it was 249 days [3]. The gap between those two outcomes is not talent. It is whether the testing program was built to drive remediation, and that is a property of the vendor relationship you are about to sign.
Signal 1: Scope Normalization
A vendor that cannot restate your scope in writing, line by line, will quietly shrink it. The first exchange with every shortlisted firm should be a written scope: the exact IPs, domains, applications, and cloud tenants in play, what is out of bounds, and which credentials the testers will use.
Ask each firm the same three questions:
- Which specific assets and endpoints are included, and which are excluded by name?
- What exactly happens if a finding points at an out-of-scope system, and who do you call before you touch it?
- How many hours of testing does this scope actually take, and is the fixed price tied to that estimate or to the deliverable?
A fixed price against an open-ended scope is how "unlimited retests" becomes "one retest, then a new quote."
Signal 2: Evidence of Work
Methodology names on a proposal, PTES, OWASP, MITRE ATT&CK, are not evidence. Evidence is a redacted sample report from a real engagement in your kind of environment, plus a description of what a tester actually did during the last eight hours of a recent test.
Request one sample report before you sign, not after. Then check it for three things: does each finding include reproduction steps a second engineer could follow, does it show the actual evidence rather than a screenshot of a tool output, and does it state what was not tested, which is where unqualified vendors quietly hide their gaps? A vendor that refuses a redacted sample has something to hide, or nothing to show.
If the sample report reads like a findings dump with no chain of actions, that is the whole engagement in miniature.
Signal 3: Named Testers
The people selling the service and the people doing the test are often different teams, and the gap between the two is where engagements go quiet. Ask for the names of the testers assigned to your engagement, their relevant certifications, and how you can reach them during the test, not after it.
Also ask two practical questions: how many concurrent engagements does each named tester run at a time, and what happens to your test if they leave mid-engagement? A vendor with a bench of two senior testers and a book of forty engagements will not volunteer that on the sales call. You have to ask.
Signal 4: Retest and Fix Validation Terms
A penetration test that ends when the report is delivered measures a snapshot, and the snapshot is already stale by the time you fix anything. The terms that matter are retests: how many, over what window, and what each one validates.
Ask for the retest policy in the SOW, not in a follow-up email. Two specifics separate serious firms from the rest: does every critical and high finding get a free retest to verify the fix, and will the vendor retest your entire scope after a significant change, like a new web app or a cloud migration, or only the systems the original finding touched? A retest that confirms one reported finding on one system is not a retest that confirms the root cause was fixed, and the difference is a whole class of findings that keep coming back next year [5].
Signal 5: Outcome Benchmarks
The strongest signal is the one vendors rarely volunteer: how fast do fixes actually get validated, once the program is running? In the 2026 State of Pentesting data, programmatic organizations resolved 4.5 times more critical findings within three days than compliance-driven teams, and 45 percent of them hit that mark against 10 percent of ad-hoc organizations [3]. A vendor that has run testing as a program, not a project, can state these numbers with a straight face. One that has only done annual compliance tests cannot.
Ask each finalist to describe, in plain terms, what the first 90 days look like after the report: who owns remediation tracking on your side, which findings get priority, and when the first retest happens. If the answer starts with "that depends on your internal team," the vendor has not thought about what happens after the PDF.
The Clone Systems 5-Signal Penetration Test Vendor Scorecard
This is the scorecard we use when we review our own vendor relationships, and we will hand it to you to use on us. Score each finalist one to five on all five signals, and do not proceed with any vendor below a three on any one of them.
- Scope normalization. Restates the written scope asset by asset, with out-of-bounds behavior defined in the SOW.
- Evidence of work. Provides a redacted sample report with reproducible findings, and describes actual tester activity.
- Named testers. Assigns named, certified testers with a named backup, reachable during the test window.
- Retest terms. Free retests to validate every critical and high fix, plus scope retesting after significant changes, all written into the SOW.
- Outcome benchmarks. Can state a remediation-speed benchmark from its own program data, and commits to a 90-day cadence.
Run This on Your Next Two Quotes
Take the two quotes you are already holding, and answer three questions for each, without looking at the vendor's website:
- Can the vendor name the exact assets in scope, and tell you what is excluded by name?
- Will it send a redacted sample report this week, and can you find the reproduction steps in it?
- Is the retest window and the retest count written into the SOW as it stands today?
If a quote cannot pass all three without a sales call, the vendor's margin is in the ambiguity, and you are about to buy it.
How Clone Systems Can Help
We run manual, continuous, and automated penetration testing, and we score our own proposals against the five signals above, so you can hold us to them. For compliance-driven engagements, our reports are built to survive assessor review, the same standard we laid out in SOC 2 Penetration Testing: The Report Your Auditor Checks, and we build every report to the bar in Your Penetration Test Report Is Evidence, Not a Findings List. If you want to see the difference before you commit, schedule a demo and we will walk through a redacted sample report with you, findings, evidence, and all.
Frequently Asked Questions
How do I choose a penetration testing vendor? Compare proposals line by line on scope, evidence, named testers, retest terms, and outcome benchmarks, rather than on brand or price alone. Score each finalist one to five on each signal, and do not proceed with any vendor that scores below three on any one of them.
What questions should I ask a penetration testing company before signing? Ask for the written scope, a redacted sample report, the names of the assigned testers, the retest policy, and a remediation-speed benchmark from their own program data. If a vendor cannot answer all five without a sales call, treat that as the answer.
What should be in a penetration test proposal? It should list the assets in scope and out of scope, the methodology, the named testers, the retest terms, and the deliverables, including the report format. A proposal that describes the deliverable but not the scope, the testers, or the retests is describing a report, not a test.
How do I compare penetration test quotes? Normalize the scopes first, then compare the price per unit of tested scope, not the total. A lower quote against a narrower scope is usually more expensive per tested asset, not less, and the gap is invisible until you line the two scopes up.
What is the difference between penetration testing and vulnerability scanning? Scanning inventories known weaknesses automatically, while penetration testing validates what an attacker could actually exploit and chain from those weaknesses. You need both on a cadence, and a scanning program is not a substitute for testing, or vice versa (Penetration Testing vs Vulnerability Scanning).
Conclusion
The Citrix NetScaler zero-days of September and October 2026 [1][2] were not a failure of patching discipline. They were a reminder that the organizations that get hit are rarely the ones without a security program. They are the ones whose program stopped at a report. Choose the vendor that measures its work in validated fixes, not delivered PDFs, and use the five-signal scorecard above to make sure the proposal in front of you actually promises that. clone-systems.com
References
[1] CISA, Known Exploited Vulnerabilities Catalog, CVE-2026-88779 entry, added 2026-10-04, BOD 26-04 due date 2026-10-07. https://www.cisa.gov/known-exploited-vulnerabilities-catalog [2] CISA, "Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway," alert, 2026-09-27. https://www.cisa.gov/news-events/alerts/2026-09-27/critical-zero-day-vulnerabilities-exploited-citrix-netscaler-adc-gateway [3] Cobalt, "State of Pentesting Report 2026," 2026. https://resource.cobalt.io/state-of-pentesting-2026 [4] SERP for "how to choose a penetration testing vendor," retrieved 2026-10-09: https://deepstrike.io/blog/penetration-testing-vendors, https://www.ciso.inc/blog-posts/top-10-considerations-for-choosing-a-penetration-testing-vendor, https://underdefense.com/blog/penetration-testing-services [5] Clone Systems, "Why Passing a Penetration Test Retest Isn't the Same as Fixing the Root Cause." https://www.clone-systems.com/blog/why-passing-a-penetration-test-retest-isnt-the-same-as-fixing-the-root-cause [6] Clone Systems, "Penetration Testing vs Vulnerability Scanning: Why the Difference Matters." https://www.clone-systems.com/blog/penetration-testing-vs-vulnerability-scanning [7] Clone Systems, "SOC 2 Penetration Testing: The Report Your Auditor Checks." https://www.clone-systems.com/blog/soc-2-penetration-testing-the-report-your-auditor-checks [8] Clone Systems, "Your Penetration Test Report Is Evidence, Not a Findings List." https://www.clone-systems.com/blog/penetration-test-report-is-evidence-not-a-findings-list [9] Clone Systems, Managed Penetration Testing Services. https://www.clone-systems.com/managed-penetration-testing-services/ [10] Clone Systems, Schedule a Demo. https://www.clone-systems.com/schedule-a-demo
