Hiring the right penetration testing provider is one of the most consequential decisions a security-conscious organisation can make. A well-executed pen test exposes real vulnerabilities before attackers find them. A poorly executed one gives you false confidence and a report that collects dust. To help you separate the two, here are nine questions every organisation should ask before signing an engagement.
What separates a reliable pen test provider
Not all penetration testing providers operate at the same standard. The gap between a credible firm and a checkbox exercise often comes down to methodology, personnel, and transparency. Asking the right questions upfront gives you a clear signal of how a provider thinks about security, and whether their approach will produce findings you can actually act on.
The nine questions below cover the areas that matter most: qualifications, process, communication, and accountability. Use them as a structured checklist in any provider conversation.
1: What certifications do your testers hold?
Certifications are not a guarantee of quality, but they are a meaningful baseline. Look for testers who hold recognised credentials such as OSCP (Offensive Security Certified Professional), CREST, CEH, or GPEN. These qualifications demonstrate that the individual has been tested against a defined standard of offensive security knowledge.
Ask specifically whether the testers assigned to your engagement hold these certifications, not just someone in the organisation. A firm may list credentials on its website that belong to senior staff who never touch client work. Clarifying this upfront protects you from a mismatch between what was sold and what is delivered.
2: What methodology do you follow?
A structured methodology ensures the test is repeatable, comprehensive, and defensible. Established frameworks such as PTES (Penetration Testing Execution Standard), OWASP (for web application testing), or NIST guidelines provide the backbone for a professional engagement. Ask the provider to describe their process from scoping through to reporting.
Providers who cannot clearly articulate their methodology, or who rely entirely on automated scanning tools, are unlikely to surface the nuanced, logic-based vulnerabilities that skilled attackers exploit. Manual testing combined with a recognised framework is the standard to hold them to.
3: Who exactly will perform the test?
This question is more important than it might seem. Sales teams and senior consultants often present the engagement, while junior staff or subcontractors carry it out. You have every right to know who will have hands-on access to your systems.
Ask for the names and experience profiles of the testers assigned to your project. Confirm whether the firm uses subcontractors, and if so, what vetting process those individuals go through. The answer tells you a great deal about how the provider manages quality and accountability.
4: What does your reporting include?
A penetration test is only as useful as its report. A strong deliverable includes an executive summary for leadership, a technical breakdown of each finding, evidence of exploitation, a clear severity rating, and actionable remediation guidance. Ask to see a sample report; any reputable provider should be able to share a redacted example.
Pay attention to the remediation guidance in particular. Generic advice such as “apply patches” adds little value. Specific, prioritised steps tied to your environment are what enable your team to act quickly and effectively after the engagement.
5: Do you offer retesting after remediation?
Identifying vulnerabilities is only half the work. Retesting confirms that your fixes actually closed the gaps the test uncovered. Without it, you cannot be certain that remediation was successful rather than merely attempted.
Ask whether retesting is included in the engagement price or billed separately. Some providers offer a defined retesting window as part of the standard package; others treat it as an add-on. Understanding this upfront prevents budget surprises and ensures the engagement produces a verified outcome rather than just a list of findings.
6: What is your experience in our industry?
Penetration testing in a healthcare environment carries different considerations from testing a financial services platform or a manufacturing network. Industry-specific experience matters because testers who understand your regulatory context, your technology stack, and your threat landscape will ask better questions and find more relevant vulnerabilities.
Ask for examples of engagements in your sector. A provider with genuine experience will reference common attack patterns, relevant compliance requirements such as NIS2, ISO 27001, or sector-specific standards, and the types of systems they have tested in similar environments.
7: How do you handle sensitive data during testing?
During a penetration test, testers will inevitably encounter sensitive information: credentials, personal data, financial records, or proprietary systems. How a provider handles this data is a direct reflection of their professionalism and your legal exposure.
Ask for a clear data handling policy. This should cover how data is stored during the engagement, who has access to it, how long it is retained after the test concludes, and how it is securely destroyed. Providers should also be willing to sign a non-disclosure agreement before the engagement begins.
8: What is included in scope, and what is not?
Scope definition is one of the most critical steps in any penetration testing engagement. A vague scope leads to missed coverage, unexpected costs, or worse, accidental disruption to production systems. Before signing anything, make sure both parties have a written agreement on exactly what is in scope and what is excluded.
Common scoping questions include whether cloud environments are included, whether social engineering is part of the test, and whether physical security falls within the engagement. Clarifying boundaries protects you legally and operationally, and it ensures the test focuses effort where your actual risk exposure lies.
9: Can you provide references from past clients?
References from past clients offer direct evidence of how a provider performs in practice. Ask for contacts at organisations of similar size and complexity to your own, ideally in a comparable industry. A provider who hesitates to provide references, or who can only offer testimonials rather than direct contacts, is worth treating with caution.
When you speak to references, ask specifically about the quality of the reporting, the responsiveness of the team during the engagement, and whether the findings led to meaningful security improvements. These practical details reveal far more than any sales presentation.
Choose a provider that delivers real security value
Penetration testing is an investment in understanding your real security posture, not a compliance checkbox. The questions above help you evaluate whether a provider will deliver findings that strengthen your defences or simply hand you a document that satisfies an audit requirement.
We work with organisations across the Netherlands and the EU to provide independent, expert-led security assessments with clear, actionable reporting. If you want guidance on selecting the right approach for your environment, get in touch with us and we will help you find the right fit.
Frequently Asked Questions
Wat is het verschil tussen een pentest en een vulnerability scan?
V: Wat is het verschil tussen een pentest en een vulnerability scan?nA: Een vulnerability scan detecteert automatisch bekende zwakheden in systemen, maar simuleert geen echte aanval. Een penetratietest gaat verder: een ethische hacker exploiteert kwetsbaarheden actief om te bepalen welke schade een aanvaller werkelijk kan aanrichten, waardoor je een veel realistischer beeld krijgt van je werkelijke beveiligingsrisico's.
Hoe vaak moet een organisatie een penetratietest laten uitvoeren?
V: Hoe vaak moet een organisatie een penetratietest laten uitvoeren?nA: De meeste organisaties voeren minimaal één keer per jaar een penetratietest uit, maar na grote infrastructuurwijzigingen, nieuwe applicaties of beveiligingsincidenten is een extra test sterk aan te raden. Regelmatig testen zorgt ervoor dat nieuwe kwetsbaarheden tijdig worden ontdekt voordat aanvallers er misbruik van kunnen maken.
Waarom is een duidelijke scope zo belangrijk voordat de test begint?
V: Waarom is een duidelijke scope zo belangrijk voordat de test begint?nA: Een onduidelijke scope kan leiden tot onverwachte verstoringen van productiesystemen, juridische risico's en gemiste kwetsbaarheden in kritieke onderdelen van je infrastructuur. Door vooraf schriftelijk vast te leggen welke systemen, omgevingen en testmethoden zijn toegestaan, bescherm je zowel je organisatie als de testprovider en zorg je voor gerichte, effectieve resultaten.
Hoe weet ik of de bevindingen uit het rapport daadwerkelijk zijn opgelost?
V: Hoe weet ik of de bevindingen uit het rapport daadwerkelijk zijn opgelost?nA: De enige betrouwbare manier om dit te bevestigen is via een hertest, waarbij de provider de eerder gevonden kwetsbaarheden opnieuw controleert na jouw remediatiemaatregelen. Zonder hertest weet je niet zeker of de oplossingen correct zijn geïmplementeerd, waardoor schijnzekerheid ontstaat die gevaarlijker kan zijn dan geen test uitvoeren.