Compare the testing hypothesis

Look for an explanation of what the testers will attempt to prove, which threat perspectives they will use and how the approach relates to your architecture.

Separate coverage from depth

More targets can dilute attention. Check the assumed application roles, APIs, environments, network ranges and test accounts, then see whether the allocated effort is credible.

Inspect the reporting promise

Confirm that the deliverable includes reproducible evidence, risk context, prioritised fixes, an executive view and a method for handling urgent findings during testing.

Make remediation support visible

Ask who can discuss findings with engineers, how questions are handled and what the included retest covers. These details determine whether a report becomes action.

Score confidence, not page count

The winning proposal should leave you confident that important attack paths will be explored safely and the resulting decisions will be easier—not merely that a long PDF will arrive.

Planning a penetration test?

Share your concern, system or deadline and we’ll help shape a focused scope.

Start a conversation →