Buyer's Guide · Last updated: August 31, 2026

What to actually look for when choosing a penetration testing provider

Penetration testing is an unregulated market – technically, anyone can call themselves a “pentester”. This guide summarizes what serious sources (BSI, OWASP, CREST) and the industry itself use to evaluate providers – with sources, without a vendor ranking.

13 selection criteria Certification tiers Fully sourced
TL;DR

A credible pentest is mostly manual work by certified testers (OSCP is the de-facto standard), follows a recognized methodology (OWASP, PTES, BSI), includes a retest, and delivers a readable report with reproduction steps – not just a CVSS list. Automated scans sold as “pentests”, unusually cheap fixed prices without a scoping call, and missing certifications are the most common warning signs.

The Criteria

13 things that actually matter

Compiled from the BSI methodology, OWASP, the CREST standard, and the selection criteria used by credible providers across the DACH region and internationally.

Non-negotiable

Manual testing depth, not just a scanner

A real pentest is mostly manual work – automated scanning is only the starting point. Business logic flaws, chained attack paths, and access-control gaps are found by humans, not tools. How to check: ask for the manual-vs-automated ratio, request concrete business-logic examples from past engagements, and ask for a redacted sample report with real proof-of-concept evidence, not just a CVSS list.

Non-negotiable

Certifications of the actual testers

Since “pentester” isn't a protected title, practical certifications (OSCP, OSEP, OSWE, CRTO, CRTP) are the primary screening criterion – for the people who will actually run your test, not just the company. How to check: ask which certifications the specifically assigned testers hold, and request proof (e.g. via Credly).

Non-negotiable

Recognized methodology, not a tool list

Credible providers reference documented standards such as the BSI penetration-testing methodology, OWASP WSTG, PTES, or NIST SP 800-115. A 'methodology' that's really just a tool list (Burp, Nmap, Metasploit) isn't a process – it's marketing. How to check: ask explicitly which framework the proposal is based on.

The rest of the checklist

04

Report quality

You're paying for analysis, not automation output. A good report includes an executive summary, technical findings with reproduction steps and screenshots, a risk rating, and prioritized remediation guidance – split by audience (leadership vs. IT). How to check: request an anonymized sample report before signing.

05

Included retest

A pentest without a retest is a diagnosis without a follow-up check – whether a finding was actually fixed remains unproven otherwise. How to check: clarify upfront whether the retest is included or billed separately (market rate, if separate: roughly 20–30% of the project value).

06

Clear scoping & rules of engagement

Test targets, exclusions, testing windows, and escalation paths need to be documented in writing before testing starts – without documented authorization (“permission to attack”), a test sits on legally thin ice. How to check: a credible provider insists on a scoping call. No scoping call before a quote is a warning sign.

07

References & track record

Demonstrable security research, publications, or reference clients of comparable size/industry signal real reputation in the community. How to check: ask specifically for case studies or published advisories, and whether a reference exists in your industry.

08

Professional / cyber liability insurance

Intrusive testing can unintentionally affect production systems – professional liability insurance with an explicit pentest clause covers that risk. A minimum coverage of roughly €5 million is common in the market. How to check: request proof of insurance with a clause covering offensive security activities.

09

Data location & no offshore subcontracting

Who actually runs the test – employees, or anonymous subcontractors? For GDPR, NIS2, and DORA, where data is stored and processed matters. How to check: ask about the testers' employment status, any subcontractors, and where data is stored (ideally the EU).

10

Independence

A provider that also sells security products has a structural conflict of interest when assessing your risk. How to check: ask whether the provider sells hardware or software it might “recommend” as part of the test.

11

Domain specialization

Web/API, Active Directory, cloud, mobile, or OT/ICS each require different expertise – a generalist is rarely equally strong everywhere. How to check: ask for evidence of experience with your specific tech stack and industry.

12

Regulatory fit

Depending on your industry, NIS2, DORA/TLPT, KRITIS (§8a BSIG), TISAX, or ISO 27001 may require specific evidence – not every provider fits every regulatory context. How to check: verify the provider's experience with your specific framework, and whether they're BSI-listed or CREST-accredited.

13

Price transparency

A credible quote is a binding fixed price following a scoping call, broken down by testing days. Pricing per IP address or per scan result usually signals automated-scanner billing. How to check: request a transparent breakdown instead of a lump sum.

Certification Tiers

Which pentester certifications actually matter?

A rough tiering by hands-on rigor – not exhaustive, but a useful first filter when a provider names certifications.

Entry level
CEH · CompTIA PenTest+ · eJPT

Demonstrate foundational knowledge, some with a heavy multiple-choice component (CEH). On their own, not strong proof of hands-on compromise capability.

Most commonly required Advanced
OSCP · CRTO · CRTP · CPTS · GPEN

OSCP is the industry's de-facto standard – a 24-hour hands-on exam followed by a report. CRTO/CRTP are the common entry points into red teaming. Most frequently required in pentester job postings.

Elite
OSEP · OSWE · OSCE3 · OSEE · CREST CCT

Advanced specializations (advanced evasion, web whitebox, exploit development) with multi-day hands-on exams. CREST certifications are additionally tied to an ISO 27001/9001 company accreditation.

Note: CISSP is widely regarded in the field as weak evidence for hands-on pentesting – it's a management certification with no mandatory practical exam.

Warning Signs

6 red flags when choosing a provider

None of these signals is disqualifying on its own – but in combination, they're worth asking about directly.

  • An automated scan sold as a “pentest”: no proof-of-concept, no screenshots in the report, just a CVSS list without context.
  • A fixed-price quote with no prior scoping call, often paired with an unrealistically short turnaround (24 hours for a full test).
  • Pricing per IP address or per scan result – a typical pattern for automated tool operation rather than manual work.
  • No sample report available on request – you'd be buying a deliverable you've never seen before signing.
  • A price unusually low compared to the market average – often a sign of heavy automation or inexperienced testers.
  • No findable reputation in the security community – no research publications, no conference talks, no references.

Looking specifically for a physical penetration testing provider?

Physical penetration testing is even less standardized than cyber pentesting – different criteria, a different certification landscape, different law.

Go to the physical pentest buyer's guide →
Price Ranges

What a pentest realistically costs (DACH, 2025/2026)

Orientation values compiled from multiple market sources (see sources below) – actual cost depends heavily on scope and testing depth. Quotes significantly below these ranges are a reason to ask more questions (see red flags).

Web app pentestapprox. €3,000 – €10,000
Infrastructure/network pentestapprox. €3,000 – €20,000
Certified pentester day rateapprox. €1,200 – €2,000
Red team engagementfrom approx. €30,000
DORA TLPT cycle (regulated financial entities)approx. €200,000 – €620,000

Sources include market surveys and provider disclosures, see sources below. Not a substitute for an individual quote following a scoping call.

Regulation

When which framework becomes relevant

Depending on your industry and size, a provider's specific certification or experience can be a requirement rather than a nice-to-have:

NIS2 obligates affected companies to conduct regular security reviews. DORA/TLPT requires accredited, experienced red-team providers for threat-led penetration testing at regulated financial entities. KRITIS operators (§8a BSIG) need to provide evidence to the BSI. TISAX is relevant for suppliers in the automotive industry. ISO 27001 (control A.8.8) requires regular technical vulnerability management, which pentests can satisfy.

FAQ

Frequently asked questions about choosing a provider

OSCP is the industry's de-facto standard and the most frequently required certification in pentester job postings, because it's a 24-hour hands-on exam with real system-compromise proof – not a multiple-choice test. But it's not the only relevant certification: CRTO/CRTP are more common for red teaming, OSWE for web applications. What matters more than any single certification is whether the specifically assigned testers hold hands-on credentials at all.

A pentest shows vulnerabilities at a single point in time – whether your fixes actually work is only confirmed by a retest. Whether it's included is a matter of negotiation; what matters is clarifying it upfront instead of being surprised by it as an add-on cost later. If billed separately, roughly 20–30% of the original project value is common.

A vulnerability scan is an automated tool that detects known issues via signatures – fast, but shallow. A pentest combines that with manual analysis: testers chain smaller vulnerabilities into real attack paths and examine business logic that no scanner understands. When a plain scan is sold as a 'pentest', this manual component is usually missing – often visible in a report that only lists CVSS scores without proof-of-concept.

Because scope, testing depth, and constraints directly determine the effort involved – a credible fixed-price quote without that conversation is either a rough guess or, in reality, covers only an automated scan. The scoping call is also where rules of engagement and exclusions get clarified before any testing begins.

Not necessarily, but a price significantly below the market ranges (see pricing above) is a signal to ask more questions: how much of the work is manual, what certifications do the testers hold, is a retest included? Unusually low prices are often the result of heavy automation or inexperienced testers rather than genuine efficiency gains.

Legally, usually not required, but practically relevant for GDPR, NIS2, and DORA: where is test data and findings stored and processed, and who exactly runs the test – employees, or anonymous subcontractors in third countries? For regulated industries (KRITIS, financial sector), a transparent, EU-based provider is usually the simpler choice.

Still have questions about your selection?

If you'd like to check these criteria against a concrete quote – including our own – reach out. No pressure, no sales pitch.

Book a free consultation
Sources

What this guide is based on

This guide was compiled from publicly available industry sources. Where possible, we link to primary sources rather than competitor blogs.

Buyer's Guide · Last updated: August 31, 2026