All resources
// Resources

How to Choose a Penetration Testing Vendor: A Buyer's Guide

Published June 8, 2026

Vendor proposals can look similar while defining different coverage and delivery. Ask how much work is manual, whether you can see a sample report, whether retesting is included in your written scope, and whether requested standards mapping is supported. This guide gives you those buyer questions and the red flags to watch for.

If you’re comparing providers — and in Indonesia alone there are more than twenty — this is how to look past the brochure.

The core test: is it actually a pentest, or a scan in disguise?

This is the single most important distinction, and it’s where the price gap usually comes from. A vulnerability scan is an automated tool that matches your application against a database of known issues and outputs a list of potential findings, complete with false positives and no proof. Some vendors run that scan, reformat the output, and sell it as a “penetration test.”

A real penetration test is performed by a person. They validate every finding by exploiting it, chain small weaknesses into serious breaches, and — crucially — find the access-control and business-logic flaws that scanners structurally cannot detect (we cover why in web application penetration testing). Those are the highest-impact issues in real breaches, so a test that can’t find them isn’t protecting you.

The tell is the report. A real pentest documents each issue with a reproducible proof of concept — the exact steps to make it happen. A dressed-up scan gives you a severity list and CVE references with nothing behind them. Which is why the first thing to ask for is a sample.

The questions that reveal quality

Ask these before you sign anything. The answers separate real vendors from resellers fast.

  • “Which methodology do you follow?” A credible vendor works to a recognized standard — the OWASP Web Security Testing Guide (WSTG) for web, MASVS for mobile, PTES for the overall process — so coverage is consistent and nothing important is skipped. “We use our own approach” with no detail is a warning.
  • “Which activities are manual versus automated in our scope?” Ask the vendor to list hands-on and tool-assisted activities in writing, including exclusions and coverage limits.
  • “Can I see a redacted sample report?” Ask whether a sanitized example is available. If one is provided, check whether findings include reproducible evidence and clear remediation rather than only scanner output.
  • “Is retesting included in our scope?” Ask whether retesting is included, separately priced, limited to specified findings, or subject to a time window. Record the answer in the written engagement scope.
  • “How is scope and pricing determined?” Quality vendors price on the size and complexity of the attack surface, not a flat rate — see our pricing guide. A fixed price quoted before anyone understands your system is a sign of a one-size-fits-all scan.
  • “Will you flag critical findings during the test, or only at the end?” A serious tester tells you immediately if they find something that’s actively dangerous, rather than sitting on it for the final report.
  • “How is our data handled?” You’re giving a vendor access to sensitive systems. Ask about NDAs, how test data is stored and destroyed, and who on their side has access.
  • “Can you map findings to the standards we report against?” If you answer to OJK, UU PDP, ISO 27001, or SPBE/BSSN, the report needs to speak those frameworks’ language so it stands up to an auditor — not just to your engineers.

Red flags

Some signals should make you walk away:

  • “We guarantee your system will be 100% secure.” No one can. Security is risk reduction, not a guarantee, and anyone promising perfection is selling.
  • A flat price with no scoping. It means the same canned test for every client regardless of size — almost always an automated scan.
  • No sample report, or a sample that’s clearly scanner output. If they won’t show their work, assume the work isn’t there.
  • No retest offered. Suggests low confidence, or that fixing isn’t really their concern.
  • Selling purely on price or a wall of certification logos, with nothing said about how they actually test. Credentials are a signal, but they’re not the work.

What actually matters

Strip it back and the question is simple: will a skilled human genuinely try to break this system, prove what they find, and help you fix it? Methodology, manual depth, an honest report you can read before you buy, a retest to close the loop, and findings mapped to your obligations — those are the things that determine whether a pentest protects you or just produces a certificate. The right vendor is happy to be judged on exactly those points; see how we structure an engagement in our methodology and what we cover across our services. For how access level shapes coverage, see types of penetration testing.

The bottom line

Every vendor’s brochure looks the same, so don’t buy the brochure — buy the delivery. Ask for the methodology, the manual/automated split, a sample report, a retest, transparent scoping, and standards mapping. The vendor who answers all of those clearly is the one doing real work; the one selling on price and promises is selling you a scan. Choose on what’s actually delivered, and you’ll get security instead of a checkbox.

Want a straight answer to all of those questions for your project? Get in touch and we’ll walk you through exactly how we’d test your system.

Frequently asked questions

How do I choose a good penetration testing vendor?

Ask each vendor which methodology applies, which work is manual or automated, whether a redacted sample report is available, whether retesting is included in your written scope, how pricing follows scope, and whether requested standards mapping is supported. Compare their documented answers rather than assuming any item is included.

What's the difference between a real pentest and a vulnerability scan sold as one?

A vulnerability scan is an automated tool that outputs a list of potential issues with false positives and no proof. Some vendors run that scan, format the output, and sell it as a 'penetration test.' A real pentest is performed by a person who validates each issue by exploiting it, chains weaknesses into serious attacks, and finds the access-control and business-logic flaws scanners structurally cannot detect. The giveaway is the report: a real pentest contains reproducible proof of concepts, not just a scanner's severity list.

Should I just pick the cheapest pentest?

Price alone does not show coverage. Compare the written scope, manual and automated activities, methodology, report format, exclusions, and whether retesting is included or separately priced. Choose the proposal whose documented delivery matches your risk and assurance needs.

What questions should I ask a penetration testing vendor before hiring them?

Ask: Which methodology do you follow? How much of the test is manual versus automated? Can I see a redacted sample report? Is a retest to confirm fixes included? How is scope and pricing determined? Will you tell us about critical findings during the test or only at the end? How is our data handled and protected? And can you map findings to the standards we report against — OWASP, ISO 27001, UU PDP, OJK, or SPBE/BSSN? The answers reveal quality fast.

Have a system that needs testing?