Hiring a penetration testing company without the right criteria is one of the most expensive mistakes an organization can make in cybersecurity—not because of the cost of the service itself, but because of the cost of trusting an assessment that failed to uncover what it should have. A poorly executed penetration test creates a false sense of security that can last for months, until a real incident reveals what the test failed to detect.
The offensive security market has grown rapidly in recent years, and with it, the number of vendors offering “penetration testing” as a service. Knowing how to distinguish a serious technical assessment from an automated scan with a polished report is what allows you to make this decision based on objective criteria.
Why Penetration Testing Requires Careful Evaluation
Unlike other IT services, the results of a penetration test cannot be immediately verified by the company hiring it. The organization receives a report, but without technical expertise, it has no way of knowing whether that document truly reflects what was tested or whether there were attack vectors the tester simply did not explore.
This creates an information asymmetry that benefits providers with weaker technical standards, as long as the final report appears comprehensive. The seven criteria below are intended to reduce this asymmetry and give organizations concrete parameters for evaluating proposals.
The 7 Technical Criteria for Choosing a Penetration Testing Company
Before evaluating any proposal, it is important to understand what these criteria measure. They are not simply about credentials or reputation, but indicators of how the assessment will be conducted and the depth of analysis that will be delivered.
1. Certifications of the Professionals Performing the Test
Certifications such as OSCP, CEH, eJPT, and EC-Council certifications indicate that the professional has completed practical offensive security assessments. The key point here is to ask specifically who will perform the test—not just which certifications the company lists in its overall portfolio. It is common for companies to showcase the certifications of partners or executives while the actual testing is performed by analysts without the same qualifications.
2. Documented and Recognized Methodology
A reputable penetration testing company follows internationally recognized methodologies such as OWASP for web applications, the PTES (Penetration Testing Execution Standard), or NIST guidelines for infrastructure testing. More important than simply mentioning the methodology is being able to clearly explain the phases of the assessment and what is evaluated in each stage. A vague proposal in this area is a warning sign that the assessment may lack the structure needed to cover the most relevant attack vectors in your environment.
3. Clearly Defined Scope Before Signing the Contract
The scope of the penetration test—including which systems, networks, applications, and access points are included—must be clearly defined before the agreement is signed. A poorly defined scope allows the provider to deliver a superficial assessment without technically breaching the contract, since anything not tested simply was not included. The most critical vulnerabilities are often found in areas no one mapped beforehand, and a vague scope is exactly what ensures they remain untested.
4. Clear Distinction Between Manual Penetration Testing and Automated Scanning
Automated vulnerability scanners identify known and documented vulnerabilities. A high-quality penetration test goes beyond that: it involves professionals who chain together attack vectors, explore combinations that automated tools cannot identify on their own, and test the system’s logic—not just the presence of known CVEs. Ask the provider what percentage of the assessment is performed manually and request examples of vulnerabilities discovered in previous engagements that would not have been detected through automated scanning alone.
5. Report with Traceability and Remediation Guidance
The final report is the tangible deliverable of a penetration test. It should document every vulnerability found, including the exploitation method used, the technical evidence supporting the finding, the severity classification based on recognized metrics such as CVSS, and specific remediation guidance for each issue. A report that merely lists vulnerabilities without showing how they were exploited or how they should be fixed has limited technical value. A report structured to be understood by both technical teams and executive leadership is what transforms findings into actionable security decisions.
6. Experience with the Type of Environment Being Tested
Penetration testing for network infrastructure differs from testing web applications, which in turn differs from testing cloud environments or APIs. A company whose experience is concentrated in infrastructure may not have the same technical depth required to assess a complex SaaS application. Ask the provider for references or examples of assessments performed in environments similar to yours, and evaluate whether the team has experience with the technologies that make up your infrastructure.
7. Ethical Standards and Confidentiality Agreement
During a penetration test, professionals gain access to sensitive company systems, data, and information. Before authorizing any testing, there must be a contract clearly defining what can and cannot be accessed, how discovered data will be handled, and what confidentiality obligations remain after the engagement ends. Companies that resist formalizing these terms or propose vague contractual language in this area deserve additional scrutiny before being granted access to your environment.
How to Evaluate the Proposal Before Making a Decision
With these criteria in hand, you can ask objective questions of any provider and compare their answers in a structured way. Who will perform the assessment? Which methodology will be followed? What is—and is not—included in the scope? How will the findings be documented?
The answers to these questions reveal far more about the quality of the service than any sales presentation. A penetration testing company with strong technical standards will answer each one precisely. A company that relies more on appearances than expertise will resort to generalities.
The decision to invest in a penetration test already represents an important step in any organization’s security maturity. It is worth ensuring that the assessment truly delivers the insights needed to make informed technical decisions—not just a report that creates the impression that the work has been done.
STWBrasil conducts annual penetration tests with internationally certified professionals, using recognized methodologies and delivering fully traceable reports for both technical teams and executive leadership. Contact our team to learn how our testing approach can be tailored to your organization’s environment.




