How to hire a pentest: a practical guide for businesses

By Kike Gandia · Co-Founder & CEO, OSCP

Hiring a pentest is a critical security decision, not a formality. Choosing the wrong provider can give you a false sense of security: an automated scan packaged as a pentest won't find the flaws a real attacker would exploit. This guide helps you hire the right service, ask the right questions and get the most value from the report.

When does your company need a pentest?

There are moments when a pentest goes from advisable to essential: before launching an application or platform to production, after a significant change in infrastructure or architecture, when an enterprise client, investor or external auditor requires it as a condition, to comply with NIS2, DORA, PCI-DSS, ISO 27001 or the National Security Framework, and annually as preventive maintenance. It's also the logical step if it's been more than a year since a formal test or if you have well-founded suspicions that something may be wrong.

Define the scope before asking for a quote

The scope determines the price, duration and value of the pentest. Before contacting a provider, answer: what exactly do I want to audit? (URLs, IPs, mobile apps, internal network, Active Directory, cloud). How many environments are there? (production, staging, dev). What access does the auditor have? (black, grey or white box). How many users, roles or APIs are in scope? Without this information, you'll get generic quotes that can't be compared.

What to ask the provider before hiring

What certifications does the team have? (OSCP, CEH, CRTO — prioritize OSCP as a sign of real technical quality). Do you use automated scanners or manual exploitation? (the honest answer always includes both, but manual exploitation is what sets a real pentest apart). Can I see a sample report? Does it include a closing meeting to explain the findings? Do you offer a re-test to verify we've fixed the critical issues? Who is assigned to my project?

What a professional pentest proposal should include

A serious proposal should detail: exact scope (not generic), methodology used (OWASP, PTES, OSSTMM), team composition and relevant certifications, an execution schedule with phases, concrete deliverables (executive + technical report, closing meeting), confidentiality policy and non-disclosure agreement (NDA), and whether or not it includes a re-test. Be wary of proposals that don't specify the team or the methodology.

Executive report vs technical report: what to demand

A quality pentest delivers two documents. The executive report summarizes the risk in business terms: what could the company lose if each vulnerability is exploited? It's aimed at management, the CISO and the board. The technical report details each finding with evidence (screenshots, payloads, reproduction steps), severity classification (CVSS), and concrete step-by-step recommendations. Both documents are needed to justify the remediation investment internally.

How to get the most from the report

The report isn't the end of the process, it's the beginning. To maximize value: prioritize Critical and High findings before tackling medium and low ones, assign a remediation owner to each vulnerability with a concrete deadline, request a technical walkthrough session with your development team, and schedule the re-test to confirm the critical flaws are closed. Companies that treat the report as a formality repeat the same mistakes the following year.

FAQ

How much does it cost to hire a pentest in Spain?

It depends on scope: we break it down in detail, by pentest type, in our pricing guide. As a quick reference, a standard web pentest (one application, grey box) typically runs €1,500 to €5,000. The initial call to define your scope is free and with no obligation.

How long does it take to hire and run a pentest?

The full process from first contact to report delivery is usually 2 to 4 weeks. The scope agreement and proposal take 2-5 days. The technical execution lasts between 3 and 10 business days depending on scope. The report is delivered 2-3 days after the technical phase ends.

Do I need to sign any document before starting?

Yes. Before any testing, a scope agreement (Rules of Engagement) is signed defining exactly which systems are audited, from which IPs the team operates and which actions are allowed or excluded. An NDA (Non-Disclosure Agreement) is also usually signed. These documents protect both parties and are standard with any serious provider.

Related service

pentesting service for businesses

Related content

Sources

Request a pentest quote