✓ OSCP · OSWE · OSEP certified | Joost performs every test himself — no juniors | Response within 1 business day | Based in Haarlem

How Do You Choose a Pentest Company? 7 Questions to Ask

How Do You Choose a Pentest Company? 7 Questions to Ask

The penetration testing market is large and hard to navigate. From big consultancy firms to one-person operations — everyone calls themselves a pentester. How do you choose a trustworthy partner that genuinely fits your situation? These are the 7 questions you need to ask.

1. What certifications do your pentesters hold?

Look for recognised, hands-on certifications — not just paper qualifications. Relevant certifications include:

  • OSCP (Offensive Security Certified Professional) — hands-on, widely recognised
  • CEH (Certified Ethical Hacker) — broad, more theoretical
  • CREST — used in UK/EU government engagements
  • eWPT / eCPPT — practical web/infrastructure specialisations

Ask specifically who will carry out the test — not just which certifications the company claims to have.

2. Do you carry out the test manually, or only with tools?

Automated scanners quickly find known vulnerabilities, but miss logic flaws, business-layer vulnerabilities and creative attack scenarios. A serious penetration test is always a combination: tools for efficiency, manual work for depth. Ask about the ratio.

3. What exactly is in the report?

A good pentest report includes:

  • A management summary for a non-technical audience
  • Technical findings with reproduction steps and screenshots
  • CVSS scores or comparable risk classes
  • Concrete remediation advice per finding

Ask for an anonymised sample report. If a company can’t provide one, that’s a red flag.

4. Do you have experience in my sector or with my type of systems?

A pentest on a healthcare application requires different knowledge than a test on a SaaS platform or a government website. Specific sector experience (healthcare, government, fintech) leads to more efficient tests and better risk interpretation.

5. How do you handle sensitive data you encounter during the test?

During a pentest, the tester may gain access to production data, customer information or internal documents. Ask about:

  • Data handling protocol (what data is stored, for how long, how secured?)
  • An NDA and confidentiality agreement before the test begins
  • A data processing agreement (GDPR) where applicable

6. Is a retest included?

After a pentest, you’ll want to fix vulnerabilities and verify that it worked. Ask whether a targeted retest is included or priced separately. A retest doesn’t need to be a full re-test — a focused check on the items found is usually sufficient.

7. What’s the communication like during the test?

Good pentesters communicate proactively. If they find a critical vulnerability, they report it the same day — not just in the final report three weeks later. Ask about the escalation protocol for critical findings.

What makes MonkeysICT different?

MonkeysICT is a specialised pentest company based in Haarlem. We work with certified pentesters, always deliver a manually performed test, and report transparently — including a management summary and remediation advice. Our approach is direct, personal and focused on your situation.

Request a quote or read more about our approach on the penetration testing page.

Related articles and services

Scroll to Top