9 things a good pentest provider explains before you sign

Youri van der Zwart ·

Choosing a penetration testing provider is not just a procurement decision. It is a trust decision. You are inviting someone to probe your systems, handle sensitive findings, and guide your remediation efforts. Before you sign anything, a genuinely transparent provider should walk you through nine specific things. If they skip these conversations, that tells you something important about how they operate.

What separates a transparent pentest provider from the rest

Transparency in penetration testing is not about sharing every technical detail upfront. It is about making sure you understand exactly what you are buying, who is doing the work, and what happens when the test is complete. Providers who rush past these conversations tend to deliver generic reports that leave your team with more questions than answers.

The nine points below represent the baseline of what any credible provider should explain before a contract is signed. Use them as a checklist during your evaluation process.

1: Scope definition and what it actually covers

Scope is the foundation of any penetration test. A good provider will sit down with you and define precisely which systems, IP ranges, applications, or environments are in play. They will also be explicit about what is excluded and why.

Vague scope definitions lead to two common problems: testers missing critical assets, or clients assuming coverage they never actually had. A transparent provider puts scope boundaries in writing before work begins, so there are no disputes about what the engagement covered.

2: The methodology behind the test

Not all penetration tests follow the same approach. Some providers rely on automated scanning tools with minimal manual validation. Others follow structured frameworks such as OWASP, PTES, or NIST. The methodology determines the depth and reliability of findings.

Ask your provider which frameworks they follow and how much of the work is manual versus automated. A credible answer will include both, with a clear explanation of how they complement each other. Automated tools find common vulnerabilities at scale; skilled testers find the logic flaws and chained attack paths that tools miss.

3: Who will actually conduct the test?

This question catches more providers off guard than it should. Sales conversations often involve senior consultants, but the actual testing work may be delegated to junior staff or subcontractors. You have a right to know who will have access to your environment.

Ask for the experience level and certifications of the testers assigned to your engagement. Relevant credentials include OSCP, CREST, CEH, and similar industry-recognized qualifications. If the provider cannot give you a clear answer, treat that as a warning sign.

4: Rules of engagement and legal authorization

Penetration testing without proper legal authorization is not testing. It is unauthorized access. Before any work begins, your provider should produce a formal rules of engagement document that defines what testers are permitted to do, when they can do it, and how they must behave if they encounter sensitive data.

This document protects both parties. It ensures testers operate within agreed boundaries and gives your organization legal coverage for the activity. Any provider who skips this step is creating unnecessary risk for everyone involved.

5: How findings are classified and prioritized

A list of vulnerabilities without context is not useful. A good provider explains their severity rating system before the engagement begins, so you understand how findings will be classified when the report arrives. Common frameworks include CVSS scoring, but providers often layer their own risk context on top.

Understanding the classification approach in advance helps your team prepare for remediation planning. It also allows you to set expectations internally about what a critical finding means versus a medium- or low-severity issue.

6: What the final report will contain

Ask to see a sample report before you commit. The final deliverable should include an executive summary written for non-technical stakeholders, a detailed technical section for your security and development teams, and clear remediation guidance for each finding.

Reports that consist of raw scanner output with no analysis or context add very little value. The narrative around each finding, including how it was discovered and what an attacker could do with it, is what makes a report actionable.

7: Remediation support after the report

Delivering findings is only part of the job. A strong provider offers some level of support after the report is issued, whether that means answering technical questions from your developers, clarifying findings, or helping you prioritize remediation efforts based on your specific environment.

Some providers include a defined number of post-report consultation hours in their engagement fee. Others charge separately. Either model is acceptable, but you should know the answer before you sign.

8: Confidentiality and data handling practices

During a penetration test, testers may encounter credentials, personal data, financial records, or other sensitive information. Your provider should have clear policies on how that data is handled, stored, and ultimately destroyed after the engagement.

Ask whether a non-disclosure agreement is standard practice and what their data retention policy looks like. In regulated industries or environments subject to GDPR, this question is not optional. It is a compliance requirement.

9: What a retest covers and when it is included

After you remediate findings, you need to verify that your fixes actually work. A retest is the process of re-examining vulnerabilities that were addressed to confirm they are no longer exploitable. Some providers include a retest within a defined window as part of the original engagement fee. Others charge separately.

Understand exactly what a retest covers. Does it include all findings or only critical and high-severity issues? Is there a time limit on when you must complete remediation before the retest window closes? These details matter when you are planning your remediation timeline.

Ask these questions before any contract is signed

A provider who welcomes these questions is one worth working with. A provider who deflects, gives vague answers, or treats your due diligence as an inconvenience is telling you something important about the engagement experience you can expect.

We work with organizations across the Netherlands and the EU to make penetration testing transparent, structured, and genuinely useful. If you are evaluating providers and want a clear conversation about scope, methodology, and deliverables, get in touch with us and we will walk you through exactly what our engagements cover before you commit to anything.

Frequently Asked Questions

Hoe weet ik of een penetratietestprovider echt transparant is?

V: Hoe weet ik of een penetratietestprovider echt transparant is?nA: Een transparante provider beantwoordt al je vragen over scope, methodologie en rapportage zonder te aarzelen en legt alles schriftelijk vast vóór de start van de opdracht. Als een provider vage antwoorden geeft of jouw vragen als lastig beschouwt, is dat een duidelijk signaal dat de samenwerking waarschijnlijk niet soepel zal verlopen.

Wat moet ik doen als de penetratietest kwetsbaarheden aan het licht brengt die ik niet direct kan oplossen?

V: Wat moet ik doen als de penetratietest kwetsbaarheden aan het licht brengt die ik niet direct kan oplossen?nA: Vraag je provider om hulp bij het prioriteren van bevindingen op basis van de werkelijke risico's voor jouw omgeving, zodat je de meest kritieke kwetsbaarheden als eerste aanpakt. Een goede provider biedt na het rapport ondersteuning om je team te begeleiden bij het opstellen van een realistische en gestructureerde herstelplanning.

Waarom is een hertest na het oplossen van kwetsbaarheden zo belangrijk?

V: Waarom is een hertest na het oplossen van kwetsbaarheden zo belangrijk?nA: Een hertest bevestigt dat de aangebrachte fixes daadwerkelijk werken en dat kwetsbaarheden niet langer uitgebuit kunnen worden, wat essentieel is voor een betrouwbare beveiliging. Zonder verificatie loop je het risico dat je denkt dat een probleem is opgelost, terwijl het in de praktijk nog steeds een aanvalsvector vormt voor kwaadwillenden.

Hoe vaak zou ik een penetratietest moeten laten uitvoeren?

V: Hoe vaak zou ik een penetratietest moeten laten uitvoeren?nA: De meeste organisaties voeren minimaal één keer per jaar een penetratietest uit, maar bij grote infrastructuurwijzigingen, nieuwe applicaties of wijzigingen in compliance-vereisten is het verstandig om eerder een nieuwe test in te plannen. De frequentie hangt af van je risicoprofiel, de snelheid waarmee je omgeving verandert en eventuele wettelijke verplichtingen binnen jouw sector.

Related Articles