Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

How do you choose a penetration testing company?

Last verified

Choose a pen-test firm with stated criteria — accreditation, methodology, scoping, retest, reporting, and references — not a logo list. This page never ranks providers. Accreditation is not endorsement. CREST, CHECK, and PCI ASV authorize different work. Not legal advice.

Vendor selection, last verified 10 September 2026 against CREST scheme materials, NCSC CHECK, PCI SSC ASV/QSA scope notes, NIST SP 800-115, and OSSTMM. It is an evaluation framework, not a ranking. Accreditation is not endorsement. Not legal advice.

Evaluation framework, not a ranking

Audience: a security buyer. This page is not legal advice. It does not rank providers and does not endorse a firm. Kind of text: CREST and NCSC CHECK are accreditation schemes (industry / government authorization), not a finding that a named firm is “best.” PCI ASV is an authorization to run approved vulnerability scans — it is not a pen-test license. NIST SP 800-115 and OSSTMM are methodology guidance. ShipReady Metrics recommendation: score every bidder on the same criteria table below.

Vendor-criteria framework

Score each bidder. Do not publish a ranked list from this table. Last verified 10 September 2026. Accreditation is not endorsement. Not legal advice.

Vendor-criteria framework (not a ranking; accreditation is not endorsement; not legal advice)
CriterionWhat to verifyWhat it does not meanKind of text
AccreditationCREST company / tester membership for the service offered; NCSC CHECK if you need UK government CHECK testing; other regional schemes if they apply.Accreditation is not endorsement by this site and not a guarantee of YOUR outcome.Scheme rules — industry / government authorization.
PCI ASV vs pen-test scopeIf the bidder is an ASV, that authorizes Approved Scanning Vendor work under PCI 11.3.2, not automatically a Req. 11.4 pen test. QSA is an assessor role, not a tester role.ASV logo is not proof of pen-test quality.PCI SSC program roles — only if PCI applies.
MethodologyNamed method (NIST SP 800-115, PTES, OSSTMM, CREST) and how they handle business logic, not only scanners.A method name on a slide is not fieldwork.Methodology guidance / industry practice.
Scoping qualityThey inventory assets, data classes, roles, and out-of-scope rules before quoting days (NIST SP 800-115).A one-line “web app test” is not a scope.Methodology guidance.
Retest policyWritten window, what is retested, and whether it is a full re-engagement.“We can come back” is not a policy.Industry best practice; PCI 11.4 if PCI applies.
ReportingExecutive summary, methodology, risk-rated findings, evidence, remediation, residual risk.A scanner CSV is not a report.Best practice (NIST / CREST / PTES reporting).
References and independenceRecent work in YOUR stack; no conflict with the team that built the system under test.A logo wall is not a reference call.Buyer diligence — not a ranking.

What CHECK, CREST, and PCI ASV actually authorize

NCSC CHECK authorizes suppliers and individuals to test UK government systems under that scheme. CREST is a not-for-profit accreditation body for security testing companies and individuals; membership is not this site’s endorsement. PCI SSC ASV is a scanning authorization. Those three are different authorizations. Do not treat one logo as covering the others. Last verified 10 September 2026. Not legal advice.

What to do now

Operational steps. Last verified 10 September 2026. Not legal advice.

  • Send the same scope pack (asset list, roles, rules of engagement) to every bidder.
  • Score with the criteria table. Do not publish a ranked “best companies” list from this page.
  • Read a sample redacted report before you sign. Open the report-contents and retest guides on this site.
  • A dedicated auditor/cert-provider buying guide is not on this site yet. Naming it is not a link.

Checklist

Question list for the oral exam with a bidder. Not a ranking. Not legal advice.

  • Which accreditation, if any, covers THIS statement of work — CREST, CHECK, or neither?
  • Are you quoting an ASV scan, a pen test, or both? Do not mix the logos.
  • Who will be on keyboard, and what is their seniority?
  • What is the retest window and residual-risk language?
  • Can we see a redacted report that matches the promised sections?

Where this shows up in ShipReady Metrics

Vendor-neutral. The product does not rank testers, does not broker engagements, and does not replace an independent pen test.

Primary sources (last verified 10 September 2026)

CREST scheme pages (accreditation, not endorsement). NCSC CHECK (UK government scheme). PCI SSC ASV and QSA role pages (scan/assessor authorizations, not pen-test licenses). NIST SP 800-115 and OSSTMM (methodology). Not legal advice.

Frequently asked questions