Penetration testing is an unregulated market – technically, anyone can call themselves a “pentester”. This guide summarizes what serious sources (BSI, OWASP, CREST) and the industry itself use to evaluate providers – with sources, without a vendor ranking.
A credible pentest is mostly manual work by certified testers (OSCP is the de-facto standard), follows a recognized methodology (OWASP, PTES, BSI), includes a retest, and delivers a readable report with reproduction steps – not just a CVSS list. Automated scans sold as “pentests”, unusually cheap fixed prices without a scoping call, and missing certifications are the most common warning signs.
Compiled from the BSI methodology, OWASP, the CREST standard, and the selection criteria used by credible providers across the DACH region and internationally.
A real pentest is mostly manual work – automated scanning is only the starting point. Business logic flaws, chained attack paths, and access-control gaps are found by humans, not tools. How to check: ask for the manual-vs-automated ratio, request concrete business-logic examples from past engagements, and ask for a redacted sample report with real proof-of-concept evidence, not just a CVSS list.
Since “pentester” isn't a protected title, practical certifications (OSCP, OSEP, OSWE, CRTO, CRTP) are the primary screening criterion – for the people who will actually run your test, not just the company. How to check: ask which certifications the specifically assigned testers hold, and request proof (e.g. via Credly).
Credible providers reference documented standards such as the BSI penetration-testing methodology, OWASP WSTG, PTES, or NIST SP 800-115. A 'methodology' that's really just a tool list (Burp, Nmap, Metasploit) isn't a process – it's marketing. How to check: ask explicitly which framework the proposal is based on.
The rest of the checklist
You're paying for analysis, not automation output. A good report includes an executive summary, technical findings with reproduction steps and screenshots, a risk rating, and prioritized remediation guidance – split by audience (leadership vs. IT). How to check: request an anonymized sample report before signing.
A pentest without a retest is a diagnosis without a follow-up check – whether a finding was actually fixed remains unproven otherwise. How to check: clarify upfront whether the retest is included or billed separately (market rate, if separate: roughly 20–30% of the project value).
Test targets, exclusions, testing windows, and escalation paths need to be documented in writing before testing starts – without documented authorization (“permission to attack”), a test sits on legally thin ice. How to check: a credible provider insists on a scoping call. No scoping call before a quote is a warning sign.
Demonstrable security research, publications, or reference clients of comparable size/industry signal real reputation in the community. How to check: ask specifically for case studies or published advisories, and whether a reference exists in your industry.
Intrusive testing can unintentionally affect production systems – professional liability insurance with an explicit pentest clause covers that risk. A minimum coverage of roughly €5 million is common in the market. How to check: request proof of insurance with a clause covering offensive security activities.
Who actually runs the test – employees, or anonymous subcontractors? For GDPR, NIS2, and DORA, where data is stored and processed matters. How to check: ask about the testers' employment status, any subcontractors, and where data is stored (ideally the EU).
A provider that also sells security products has a structural conflict of interest when assessing your risk. How to check: ask whether the provider sells hardware or software it might “recommend” as part of the test.
Web/API, Active Directory, cloud, mobile, or OT/ICS each require different expertise – a generalist is rarely equally strong everywhere. How to check: ask for evidence of experience with your specific tech stack and industry.
Depending on your industry, NIS2, DORA/TLPT, KRITIS (§8a BSIG), TISAX, or ISO 27001 may require specific evidence – not every provider fits every regulatory context. How to check: verify the provider's experience with your specific framework, and whether they're BSI-listed or CREST-accredited.
A credible quote is a binding fixed price following a scoping call, broken down by testing days. Pricing per IP address or per scan result usually signals automated-scanner billing. How to check: request a transparent breakdown instead of a lump sum.
A rough tiering by hands-on rigor – not exhaustive, but a useful first filter when a provider names certifications.
Demonstrate foundational knowledge, some with a heavy multiple-choice component (CEH). On their own, not strong proof of hands-on compromise capability.
OSCP is the industry's de-facto standard – a 24-hour hands-on exam followed by a report. CRTO/CRTP are the common entry points into red teaming. Most frequently required in pentester job postings.
Advanced specializations (advanced evasion, web whitebox, exploit development) with multi-day hands-on exams. CREST certifications are additionally tied to an ISO 27001/9001 company accreditation.
Note: CISSP is widely regarded in the field as weak evidence for hands-on pentesting – it's a management certification with no mandatory practical exam.
None of these signals is disqualifying on its own – but in combination, they're worth asking about directly.
Physical penetration testing is even less standardized than cyber pentesting – different criteria, a different certification landscape, different law.
Go to the physical pentest buyer's guide →Orientation values compiled from multiple market sources (see sources below) – actual cost depends heavily on scope and testing depth. Quotes significantly below these ranges are a reason to ask more questions (see red flags).
Sources include market surveys and provider disclosures, see sources below. Not a substitute for an individual quote following a scoping call.
Depending on your industry and size, a provider's specific certification or experience can be a requirement rather than a nice-to-have:
NIS2 obligates affected companies to conduct regular security reviews. DORA/TLPT requires accredited, experienced red-team providers for threat-led penetration testing at regulated financial entities. KRITIS operators (§8a BSIG) need to provide evidence to the BSI. TISAX is relevant for suppliers in the automotive industry. ISO 27001 (control A.8.8) requires regular technical vulnerability management, which pentests can satisfy.
OSCP is the industry's de-facto standard and the most frequently required certification in pentester job postings, because it's a 24-hour hands-on exam with real system-compromise proof – not a multiple-choice test. But it's not the only relevant certification: CRTO/CRTP are more common for red teaming, OSWE for web applications. What matters more than any single certification is whether the specifically assigned testers hold hands-on credentials at all.
A pentest shows vulnerabilities at a single point in time – whether your fixes actually work is only confirmed by a retest. Whether it's included is a matter of negotiation; what matters is clarifying it upfront instead of being surprised by it as an add-on cost later. If billed separately, roughly 20–30% of the original project value is common.
A vulnerability scan is an automated tool that detects known issues via signatures – fast, but shallow. A pentest combines that with manual analysis: testers chain smaller vulnerabilities into real attack paths and examine business logic that no scanner understands. When a plain scan is sold as a 'pentest', this manual component is usually missing – often visible in a report that only lists CVSS scores without proof-of-concept.
Because scope, testing depth, and constraints directly determine the effort involved – a credible fixed-price quote without that conversation is either a rough guess or, in reality, covers only an automated scan. The scoping call is also where rules of engagement and exclusions get clarified before any testing begins.
Not necessarily, but a price significantly below the market ranges (see pricing above) is a signal to ask more questions: how much of the work is manual, what certifications do the testers hold, is a retest included? Unusually low prices are often the result of heavy automation or inexperienced testers rather than genuine efficiency gains.
Legally, usually not required, but practically relevant for GDPR, NIS2, and DORA: where is test data and findings stored and processed, and who exactly runs the test – employees, or anonymous subcontractors in third countries? For regulated industries (KRITIS, financial sector), a transparent, EU-based provider is usually the simpler choice.
If you'd like to check these criteria against a concrete quote – including our own – reach out. No pressure, no sales pitch.
Book a free consultationThis guide was compiled from publicly available industry sources. Where possible, we link to primary sources rather than competitor blogs.