How to choose a penetration testing company
Rankings and “top 10” lists won’t tell you whether a penetration testing company will actually find your real vulnerabilities. These are the checkable, specific facts that will — before you sign anything or pay a cent.
The bait-and-switch to watch for: an automated scan wearing a pentest label
This is the single most common way small businesses get burned when hiring a penetration testing company. A tool runs a set of known-vulnerability checks against your site, a template generates a PDF with a red/yellow/green dashboard, and it gets sold to you as a “penetration test” — at pentest prices, with none of the actual hands-on work.
What a real manual penetration test actually involves
A human tester logs in as a real user would, pokes at your login flow, tries to see other customers’ data by changing an ID in the URL, tests whether your contact form can be abused to send spam, checks if an admin panel is reachable, and chains small, individually low-severity issues together the way an actual attacker would. Automated tools are part of the process, but a human interprets every result, throws out the false positives, and manually tries the things a scanner can’t. This is why the work takes real hours, not minutes.
How to catch a rebranded scanner in a sales call
Ask direct questions: “Which parts of my site did a human manually test, versus what a scanner flagged automatically?” “Can you walk me through one finding a tester caught recently that a scanner would have missed?” “How many hours of testing am I paying for?” Vague answers, or a report that arrives within an hour of the engagement starting, are the tell. See manual vs automated penetration testing for a full side-by-side.
The report is the product — what a real one contains
You’re not paying for the hours a tester spends poking at your site. You’re paying for the document that comes out the other end, and it should be something your developer can act on the same afternoon.
Evidence for every finding, not just a severity score
A real finding includes a screenshot, the actual request and response involved, and the exact steps to reproduce it. If a report just lists “SQL Injection — High” with a generic description and no proof it was actually tried against your site, you have no way to verify the finding is real, let alone that it’s been fixed later.
Exact fix steps, written for whoever maintains your site
Compare “improve access control on your admin endpoints” to “the /export endpoint doesn’t check the logged-in user’s role before returning data — add a capability check before the query runs.” The second version is something a developer can implement in an hour. Before you hire anyone, ask what a fix step actually looks like in their reports — not whether they include remediation guidance, but whether you can see one.
Ask to see a sample report before you pay anything
A legitimate provider should have no problem showing you a real (or realistically anonymized) example of their finished work before you commit. Bug Circuit publishes one at /sample-report — findings, severity, evidence, and fix steps, in the same format every customer actually receives.
Who’s actually doing the testing
A named human tester, not a ticket number
You should know the name of the person testing your site, and you should be able to get on a call with them — not just a salesperson — to ask about a specific finding or push back on a severity rating. This matters most after delivery, when your developer has a question about how to reproduce something or whether a proposed fix actually closes the gap.
Retesting after you fix things — included, or extra?
Finding a vulnerability and confirming a fix actually closed it are two different jobs. Without a retest, you’re trusting that whoever patched the issue got it right, with no independent check. Ask explicitly whether retesting is included in the price or billed as a separate engagement later — the answer changes the real cost of “getting fixed,” not just “getting a report.”
Money, scope, and paperwork most companies bury
- Transparent pricing, not “contact sales.” Published pricing signals a repeatable, well-understood process rather than a custom-negotiated deal every time.
- Scope defined in writing before you pay. Which domain, which flows are in bounds, and what’s explicitly excluded — agreed before, not after, money changes hands.
- A real Authorization to Test, signed and recorded. Without it, what’s being done to your site is legally indistinguishable from an unauthorized intrusion.
- A committed turnaround time. 3–10 business days is realistic for a small business site — ask for a real number, not an estimate.
Bug Circuit publishes its own pricing at /pricing: $49 for a one-time Circuit audit, $299 for Signal, which adds the team fixing issues with you, a retest, and three months of monitoring.
Common questions
Should I just pick from a "top 10 penetration testing companies" list?
Does it matter if I hire a penetration testing company "near me," or can this be done remotely?
How much does a penetration test cost for a small business?
What’s the difference between a vulnerability scan and a real penetration test?
What should be included in a penetration testing report?
Is retesting after I fix the issues included, or is that a separate cost?
How long does a penetration test take from start to finish?
What is an Authorization to Test, and why do I need to sign one?
Keep reading
See what a real manual audit report looks like before you decide anything
Check the sample report and the published pricing, then book the $49 Circuit audit — a named engineer, real evidence, and a fix list your developer can actually use.