Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
How do you choose a penetration testing company?
Last verifiedChoose a pen-test firm with stated criteria — accreditation, methodology, scoping, retest, reporting, and references — not a logo list. This page never ranks providers. Accreditation is not endorsement. CREST, CHECK, and PCI ASV authorize different work. Not legal advice.
Vendor selection, last verified 10 September 2026 against CREST scheme materials, NCSC CHECK, PCI SSC ASV/QSA scope notes, NIST SP 800-115, and OSSTMM. It is an evaluation framework, not a ranking. Accreditation is not endorsement. Not legal advice.
Evaluation framework, not a ranking
Audience: a security buyer. This page is not legal advice. It does not rank providers and does not endorse a firm. Kind of text: CREST and NCSC CHECK are accreditation schemes (industry / government authorization), not a finding that a named firm is “best.” PCI ASV is an authorization to run approved vulnerability scans — it is not a pen-test license. NIST SP 800-115 and OSSTMM are methodology guidance. ShipReady Metrics recommendation: score every bidder on the same criteria table below.
Vendor-criteria framework
Score each bidder. Do not publish a ranked list from this table. Last verified 10 September 2026. Accreditation is not endorsement. Not legal advice.
| Criterion | What to verify | What it does not mean | Kind of text |
|---|---|---|---|
| Accreditation | CREST company / tester membership for the service offered; NCSC CHECK if you need UK government CHECK testing; other regional schemes if they apply. | Accreditation is not endorsement by this site and not a guarantee of YOUR outcome. | Scheme rules — industry / government authorization. |
| PCI ASV vs pen-test scope | If the bidder is an ASV, that authorizes Approved Scanning Vendor work under PCI 11.3.2, not automatically a Req. 11.4 pen test. QSA is an assessor role, not a tester role. | ASV logo is not proof of pen-test quality. | PCI SSC program roles — only if PCI applies. |
| Methodology | Named method (NIST SP 800-115, PTES, OSSTMM, CREST) and how they handle business logic, not only scanners. | A method name on a slide is not fieldwork. | Methodology guidance / industry practice. |
| Scoping quality | They inventory assets, data classes, roles, and out-of-scope rules before quoting days (NIST SP 800-115). | A one-line “web app test” is not a scope. | Methodology guidance. |
| Retest policy | Written window, what is retested, and whether it is a full re-engagement. | “We can come back” is not a policy. | Industry best practice; PCI 11.4 if PCI applies. |
| Reporting | Executive summary, methodology, risk-rated findings, evidence, remediation, residual risk. | A scanner CSV is not a report. | Best practice (NIST / CREST / PTES reporting). |
| References and independence | Recent work in YOUR stack; no conflict with the team that built the system under test. | A logo wall is not a reference call. | Buyer diligence — not a ranking. |
What to do now
Operational steps. Last verified 10 September 2026. Not legal advice.
- Send the same scope pack (asset list, roles, rules of engagement) to every bidder.
- Score with the criteria table. Do not publish a ranked “best companies” list from this page.
- Read a sample redacted report before you sign. Open the report-contents and retest guides on this site.
- A dedicated auditor/cert-provider buying guide is not on this site yet. Naming it is not a link.
Checklist
Question list for the oral exam with a bidder. Not a ranking. Not legal advice.
- Which accreditation, if any, covers THIS statement of work — CREST, CHECK, or neither?
- Are you quoting an ASV scan, a pen test, or both? Do not mix the logos.
- Who will be on keyboard, and what is their seniority?
- What is the retest window and residual-risk language?
- Can we see a redacted report that matches the promised sections?
Where this shows up in ShipReady Metrics
Vendor-neutral. The product does not rank testers, does not broker engagements, and does not replace an independent pen test.
Primary sources (last verified 10 September 2026)
CREST scheme pages (accreditation, not endorsement). NCSC CHECK (UK government scheme). PCI SSC ASV and QSA role pages (scan/assessor authorizations, not pen-test licenses). NIST SP 800-115 and OSSTMM (methodology). Not legal advice.