Skip to content

Choosing a Penetration Testing Provider

 

Learn about vendor qualifications, tester certifications like OSCP and CREST, internal vs external testing, vetting questions, sample reports, and much more, through the Frequently Asked Questions (FAQs) below. Please schedule a consultation if you are looking for Penetration Testing for compliance or regulatory requirements or to comply with a global security standard.. 

Table of Contents

What qualifications should I look for in a penetration testing firm? 

 

Summary: Evaluating a penetration testing firm requires assessing methodology, tester credentials, industry experience, report quality, and professional accreditation, not just price. 

When selecting a penetration testing firm, organizations should evaluate the following: the firm’s stated methodology (look for PTES, NIST SP 800-115, or OWASP alignment, generic or absent methodology descriptions are a red flag), the certifications held by the specific testers who will conduct the engagement (OSCP, GPEN, GWAPT, CREST, or equivalent), the firm’s experience in the specific industry (healthcare, financial services, government) and with relevant compliance frameworks (PCI DSS, HIPAA, SOC 2, CMMC), professional accreditation (CREST accreditation in the UK/international context; A2LA accreditation for FedRAMP-authorized 3PAOs), references from clients with similar risk profiles, a sample redacted report to evaluate documentation quality, clear communication about what is manual vs. automated in the engagement, and the firm’s policy on retesting and ongoing support after report delivery. Organizational independence is also important; the firm should have no conflicts of interest with the systems it is testing. 

 

What certifications should a penetration tester hold? 

 

Professional penetration testers should hold certifications that validate their hands-on technical skills and knowledge of security testing methodology. The most respected certifications in the industry are: OSCP (Offensive Security Certified Professional), widely considered the gold standard for penetration testing, requiring candidates to compromise multiple machines in a 24-hour hands-on exam; GPEN (GIAC Penetration Tester), validates network penetration testing skills including exploitation frameworks and password attacks; GWAPT (GIAC Web Application Penetration Tester), validates web application security testing competency; CEH (Certified Ethical Hacker), a knowledge-based certification from EC-Council covering ethical hacking concepts, considered less rigorous than hands-on certifications; CREST CRT (CREST Certified Tester), a UK-origin practical examination; and PNPT (Practical Network Penetration Tester), a newer practical certification from TCM Security gaining significant industry recognition. Senior testers may also hold CISSP (Certified Information Systems Security Professional), which validates broad security management and architecture knowledge. When evaluating a vendor, ask which specific certifications the testers assigned to your engagement hold, not just what certifications the firm claims as an organization. 

 

What is the difference between OSCP, CEH, GPEN, and other pen testing certifications? 

 

Summary: Penetration testing certifications differ significantly in format, rigor, and practical relevance, understanding these differences helps organizations evaluate tester qualifications accurately. 

OSCP (Offensive Security Certified Professional) is a hands-on, performance-based certification that requires candidates to compromise a defined number of vulnerable machines in a 24-hour practical exam, then submit a professional penetration test report. It is universally recognized as the most rigorous and practically relevant entry-level certification in the field. GPEN (GIAC Penetration Tester) is a knowledge and practical-skills certification from GIAC that covers network penetration testing methodology, exploitation frameworks, and post-exploitation techniques, highly respected by enterprise employers. CEH (Certified Ethical Hacker) from EC-Council is primarily a knowledge-based multiple-choice examination rather than a practical skills test, it provides broad foundational knowledge but is less valued by technical practitioners than hands-on certifications. CREST CRT (CREST Certified Tester) is a rigorous UK-origin examination widely required for UK government and financial sector testing. PNPT (Practical Network Penetration Tester) is a newer, practical certification from TCM Security that requires a complete Active Directory penetration test and professional report, gaining strong recognition for its hands-on format at an accessible price point.

 

What is CREST accreditation and why does it matter? 

 

CREST (Council of Registered Ethical Security Testers) is an international, not-for-profit accreditation body that sets professional standards for penetration testing, threat intelligence, incident response, and security operations services. CREST accreditation for an organization means that the firm has been assessed against rigorous standards for the qualifications and technical competence of its testers, the quality of its methodology and processes, its legal and professional conduct standards, and its information security practices for handling client data. CREST accreditation matters because it is required by UK government and many financial sector procurement frameworks, it is increasingly recognized in the U.S. and internationally as evidence of professional quality, and it provides clients with independently verified assurance that the testing firm meets professional standards. CREST offers individual certifications (CRT, CCT) as well as organizational membership and accreditation. For organizations in highly regulated industries seeking the highest level of assurance from their penetration testing provider, CREST accreditation is a meaningful differentiator.

 

Should I use an internal team or an external third party for penetration testing? 

 

The decision between using an internal team or an external third-party penetration testing firm depends on the organization’s security maturity, compliance requirements, budget, and objectives. Internal teams offer advantages including detailed knowledge of the organization’s environment, ongoing availability for ad-hoc testing, and cost efficiency over time if the team is large enough to sustain a dedicated penetration testing function. However, internal teams face “insider blindness”, testers who built or maintain the systems they are testing may unconsciously avoid certain attack paths or fail to identify vulnerabilities that an outsider would immediately notice. External penetration testing firms bring independence, broader exposure to diverse attack techniques, specialized expertise, and an unbiased perspective. Many compliance frameworks, including PCI DSS Requirement 11.4.2, which requires organizational independence, effectively mandate external testers for annual assessments even if internal testing is conducted more frequently. Best practice for most organizations: use internal teams for ongoing, continuous testing and frequent application-level assessments, and engage qualified external firms for formal annual compliance-driven assessments. 

 

What questions should I ask a penetration testing vendor before hiring them? 

 

Organizations should ask prospective penetration testing vendors the following questions before signing a contract: What specific methodology do you follow (PTES, NIST SP 800-115, OWASP WSTG)? What percentage of the engagement is manual testing versus automated scanning? Who specifically will conduct the test, and what certifications do they hold? Can you provide a redacted sample report from a similar engagement? What is your process for reporting critical findings discovered during testing? Is a retest included in the quoted price, and what does it cover? What data will you collect from our environment, how will it be stored, and how will it be destroyed after the engagement? Do you have experience with our specific industry and compliance frameworks? What is your escalation process if a system is accidentally disrupted during testing? Do you carry professional liability (errors and omissions) insurance? How do you ensure the confidentiality of findings and the final report? These questions distinguish professional, process-driven firms from vendors who are simply running automated tools and repackaging output as a penetration test. 

 

What is a sample penetration test report and why should I ask for one? 

 

A sample penetration test report is a redacted version of an actual report from a previous engagement, with client identifying information, specific IP addresses, and sensitive vulnerability details removed, that a penetration testing firm provides to prospective clients to demonstrate the quality, format, and depth of their reporting. Requesting a sample report is one of the most effective ways to evaluate a penetration testing vendor before hiring, because the report is the primary tangible deliverable of the engagement. A high-quality sample report should include a well-structured executive summary written in accessible language, detailed technical findings with evidence (screenshots, command outputs), clearly articulated business impact statements for each finding, specific and actionable remediation recommendations, and CVSS scores or equivalent severity ratings. Red flags in a sample report include vague remediation recommendations, findings that are clearly generated by automated tools without manual validation, absence of proof-of-concept evidence, and generic language that could apply to any organization. If a vendor refuses to provide a sample report, that itself is a red flag. 

 

How do I verify that a penetration testing firm is legitimate? 

 

Verifying the legitimacy of a penetration testing firm requires going beyond the vendor’s own marketing claims. Practical verification steps include checking for professional accreditation through bodies such as CREST (searchable at crest-approved.org), A2LA (for FedRAMP 3PAO status), or GIAC (for individual tester certification verification); requesting proof of the certifications of the specific testers assigned to the engagement, since individual certifications can often be verified directly through the issuing body’s online registry; requesting references from current clients in a similar industry and following up with those references; reviewing the firm’s professional liability (errors and omissions) insurance coverage; confirming the firm has a clear, documented methodology and can articulate their testing process in technical detail; and checking for any professional or legal complaints through state attorney general offices or industry forums. Legitimate penetration testing firms will welcome scrutiny and be able to provide verification for their claims, firms that are evasive or unable to provide third-party verification should be disqualified from consideration. 

 

What is the difference between a penetration testing firm and a bug bounty program? 

 

A penetration testing firm and a bug bounty program are both mechanisms for identifying security vulnerabilities, but they differ fundamentally in structure, scope, control, and output. A penetration testing firm is hired on a contractual basis to conduct a defined, time-boxed assessment of a specific scope with a guaranteed deliverable, a professional report with all findings, regardless of severity. The testing is conducted by a known, vetted team under a signed legal agreement with a Letter of Authorization and NDA. A bug bounty program is an ongoing public or private program that invites independent security researchers to discover and report vulnerabilities in exchange for financial rewards based on severity. Bug bounty programs leverage the creativity of a large, distributed researcher community but provide no guaranteed output, no defined scope testing depth, and no professional report deliverable. Organizations typically use bug bounty programs to complement penetration testing, not replace it, because auditors and compliance frameworks require the structured documentation of a formal penetration test, not ad-hoc vulnerability reports.

 

What are the risks of using an unqualified or inexperienced penetration tester? 

 

Using an unqualified or inexperienced penetration tester creates significant security, legal, financial, and compliance risks. Security risk: an inadequate tester will miss vulnerabilities, providing a false sense of security and potentially leaving critical exposures undiscovered that a real attacker would find. Legal risk: an inexperienced tester may operate outside the agreed scope, cause system disruptions, accidentally compromise data, or fail to follow proper legal documentation procedures, creating liability for both the tester and the client organization. Compliance risk: a test conducted by an unqualified tester that fails to meet the methodology standards of PCI DSS, HIPAA, or CMMC may be rejected by auditors, leaving the organization without compliant security testing documentation. Operational risk: inexperienced testers may use exploits that cause system crashes, data corruption, or service outages without the skills to avoid or recover from them. The money saved by hiring a cheap, unqualified vendor is easily exceeded by the cost of any one of these consequences. 

 

Explore Blogs, Webinars and other Resources

Trusted by Reputed Companies

pVerify, Inc.
Electronic Data Solutions
Bernard Robinson & Company
Avance Care
iCliniq
Botsplash
Logically
Mr.Internet Systems
Vision Radiology
Tangible Solutions
Tangible Solutions
WorkSmart
Triyam
Med First Primary and Urgent Care
Arizona State Radiology
DataCaliper
Dose Spot Company Logo
DoseSpot
Forsyte I.T. Solutions
Tego Data

Accreditations and Associations

* Disclaimer: This list of accreditations is held by our team of employees and consultants.

What Our Clients Say

We used databrackets (formerly EHR 2.0) in our small medical practice for our risk analysis assessment to be in compliance with meaningful use. Their response was fast, the final report is detailed but simple and easy to follow. They were always available to answer our questions.
E. Compres
Pulmonary and Sleep Center of the Valley
I never miss the opportunity to learn something new …that’s why I am always registering to all free seminars offered on the web. databrackets (formerly EHR 2.0) happened to be the friendliest, comprehensive and up-to- date source of HIPAA Privacy and Security updates.
Alexandra V.
Community Healthcare Network
Today’s presentation was great! Thank you for sending the slides. My only feedback is that it would be fabulous to have the slides ahead of time so I could print them and take notes on the slides.Thanks for your time and knowledge today!
T.B., PM
Community Health Network
Particularly interesting was the flow chart on Administrative Simplification. I utilize all of the Security subcategories you list under the Security tile and appreciate knowing that I am hitting all of the relevant topics during my employee training.
Jessica B.
JD, CHC
I have re-worked our original risk assessment….We are using databrackets' (formerly EHR 2.0) Meaningful Use Security Risk Analysis Toolkit and it meets our needs. It was easy to use and I believe that it very beneficial to our meeting meaningful use.
Bill Curtis
Neurosurgical Associates Of Texarkana, TX
Information (webinars) presented by databrackets (formerly EHR 2.0) highlights some of today’s most demanding healthcare topics. The webinars help to direct those operating in today’s rapidly changing environment in the right direction.
Candace M.
Privacy and Security Officer, Springhill Medical Center

Our Growing List of Credentials

0 +
Assessments
0 +
Clients
0 +
Assessment Libraries
0 +
Years of Experience
0 +
No. of Staff Trained
0 +
HIPAA
0 +
SOC 2 Readiness
0 +
Pen Testing
0 +
ISO 27001 Certifications
0 +
Dollars Saved in Compliance Penalties