10 questions to ask before hiring a pentest (and the answers that disqualify a vendor)
Pentest proposals look identical on paper and range from $5k to $60k. These ten questions separate manual testing from a scanner with a logo, and keep you from paying for a report your auditor will reject.

Why pentest proposals are hard to compare
Three proposals, three prices, all promising a "comprehensive penetration test aligned with OWASP". The difference between $5k and $60k is almost never in the PDF — it is in who executes, how much time they spend, and what they deliver when it ends. These ten questions expose that difference before you sign.
1. Who will run the test, by name?
Ask for names, certifications (OSCP, OSWE, OSEP, CRTO, BSCP) and public track record (CVEs, bug bounty, talks). Disqualifies: "our certified team" with no names, or a salesperson who cannot answer. A pentest is a service delivered by people, not by a brand.
2. How many hours or days of manual testing are in scope?
A mid-size web app needs 5 to 15 days of one expert. Disqualifies: "2 days" for an application with 40 screens and an API — that is a scanner with a quick review.
3. Which methodology, and how does it show up in the report?
OWASP WSTG, ASVS, PTES, NIST SP 800-115, OWASP LLM Top 10 for AI. Disqualifies: citing the methodology only in the proposal; the report must show the phases covered and what was not tested.
4. Black, grey or white-box — and why?
For most applications, grey-box (with regular and admin credentials) finds more in less time. Pure black-box is usually requested by people who want to "simulate an attacker" but end up paying for recon they could skip. Disqualifies: the vendor not asking what you want to prove.
5. What happens when something critical is found mid-test?
Right answer: alert within 24 hours, with a PoC, without waiting for the final report. Disqualifies: "everything goes in the report at the end".
6. Can I see a sample (anonymized) report?
Look for: an executive summary a board can read, findings with reproducible evidence (request/response, steps), CVSS and business risk, remediation with references. Disqualifies: refusing to show one, or the sample being formatted tool output.
7. Is the retest included? Within what window?
Market standard: retest included, within 60 to 90 days, with a final attestation. Disqualifies: charging for the retest as a separate service without saying so upfront — that is where the real cost shows up.
8. How do you handle AI, APIs and mobile in the same scope?
If the application has a chatbot, an agent or a public API, a "web" pentest does not cover it. Ask whether they test prompt injection, tool abuse, BOLA in APIs, and whether that is in the price. Disqualifies: "we run the same tools".
9. What confidentiality guarantees, and how is data handled?
NDA before scoping, evidence stored encrypted and deleted after a defined period, access restricted to the project team. Disqualifies: no process.
10. Does the report work for PCI DSS, SOC 2 or ISO 27001?
If you will use the pentest in an audit, the report needs the structure the auditor expects (methodology, scope, segmentation when applicable, documented retest). Disqualifies: the vendor not knowing what PCI requirement 11.4 asks for.
Bonus: what to bring to the conversation
A list of URLs/APIs, a simplified diagram, technologies, whether there is AI, the audit or customer deadline driving the test, and what happened in the last pentest. The clearer the scope, the more accurate the proposal — and the lower the chance of surprises.
How Pentest Machine answers these questions
Names and certifications in the proposal, explicit manual-testing days, named methodology in the report, critical alerts within 24h, sample report under NDA, retest included within 90 days, AI/LLM and API coverage in the same engagement, and an audit-ready structure. Send the scope and get a proposal within one business day.