Guide — hiring a pentest provider

How to choose a penetration testing company

Rankings and “top 10” lists won’t tell you whether a penetration testing company will actually find your real vulnerabilities. These are the checkable, specific facts that will — before you sign anything or pay a cent.

A penetration testing company is worth hiring if it clears seven checkable facts before you pay: testing is done by hand by a named human, not just run through an automated scanner and repackaged as a “pentest”; the report shows evidence for every finding, plus exact fix steps, not just a risk score; retesting after you fix issues is included, not a paid add-on; pricing is published up front instead of hidden behind a “request a quote” form; the scope is written down before you pay; there’s a signed Authorization to Test; and turnaround time is stated before you commit, typically 3–10 business days for a small business site. Ask to see a real sample report and the tester’s name before signing anything.

The bait-and-switch to watch for: an automated scan wearing a pentest label

This is the single most common way small businesses get burned when hiring a penetration testing company. A tool runs a set of known-vulnerability checks against your site, a template generates a PDF with a red/yellow/green dashboard, and it gets sold to you as a “penetration test” — at pentest prices, with none of the actual hands-on work.

What a real manual penetration test actually involves

A human tester logs in as a real user would, pokes at your login flow, tries to see other customers’ data by changing an ID in the URL, tests whether your contact form can be abused to send spam, checks if an admin panel is reachable, and chains small, individually low-severity issues together the way an actual attacker would. Automated tools are part of the process, but a human interprets every result, throws out the false positives, and manually tries the things a scanner can’t. This is why the work takes real hours, not minutes.

How to catch a rebranded scanner in a sales call

Ask direct questions: “Which parts of my site did a human manually test, versus what a scanner flagged automatically?” “Can you walk me through one finding a tester caught recently that a scanner would have missed?” “How many hours of testing am I paying for?” Vague answers, or a report that arrives within an hour of the engagement starting, are the tell. See manual vs automated penetration testing for a full side-by-side.

The report is the product — what a real one contains

You’re not paying for the hours a tester spends poking at your site. You’re paying for the document that comes out the other end, and it should be something your developer can act on the same afternoon.

Evidence for every finding, not just a severity score

A real finding includes a screenshot, the actual request and response involved, and the exact steps to reproduce it. If a report just lists “SQL Injection — High” with a generic description and no proof it was actually tried against your site, you have no way to verify the finding is real, let alone that it’s been fixed later.

Exact fix steps, written for whoever maintains your site

Compare “improve access control on your admin endpoints” to “the /export endpoint doesn’t check the logged-in user’s role before returning data — add a capability check before the query runs.” The second version is something a developer can implement in an hour. Before you hire anyone, ask what a fix step actually looks like in their reports — not whether they include remediation guidance, but whether you can see one.

Ask to see a sample report before you pay anything

A legitimate provider should have no problem showing you a real (or realistically anonymized) example of their finished work before you commit. Bug Circuit publishes one at /sample-report — findings, severity, evidence, and fix steps, in the same format every customer actually receives.

Who’s actually doing the testing

A named human tester, not a ticket number

You should know the name of the person testing your site, and you should be able to get on a call with them — not just a salesperson — to ask about a specific finding or push back on a severity rating. This matters most after delivery, when your developer has a question about how to reproduce something or whether a proposed fix actually closes the gap.

Retesting after you fix things — included, or extra?

Finding a vulnerability and confirming a fix actually closed it are two different jobs. Without a retest, you’re trusting that whoever patched the issue got it right, with no independent check. Ask explicitly whether retesting is included in the price or billed as a separate engagement later — the answer changes the real cost of “getting fixed,” not just “getting a report.”

Money, scope, and paperwork most companies bury

  • Transparent pricing, not “contact sales.” Published pricing signals a repeatable, well-understood process rather than a custom-negotiated deal every time.
  • Scope defined in writing before you pay. Which domain, which flows are in bounds, and what’s explicitly excluded — agreed before, not after, money changes hands.
  • A real Authorization to Test, signed and recorded. Without it, what’s being done to your site is legally indistinguishable from an unauthorized intrusion.
  • A committed turnaround time. 3–10 business days is realistic for a small business site — ask for a real number, not an estimate.

Bug Circuit publishes its own pricing at /pricing: $49 for a one-time Circuit audit, $299 for Signal, which adds the team fixing issues with you, a retest, and three months of monitoring.

Common questions

Should I just pick from a "top 10 penetration testing companies" list?
Treat those lists as a starting point for research, not a substitute for due diligence. Most are built from SEO placements, directory submissions, or a vendor’s own marketing spend, not independently verified testing quality — a company ranked first on one list can still be reselling an automated scan with a sales team on top. Use the criteria in this guide to vet whoever you’re actually considering, ranked or not.
Does it matter if I hire a penetration testing company "near me," or can this be done remotely?
Location doesn’t affect testing quality — a competent tester probes your website over the internet the same way an attacker would, wherever they’re sitting. What actually matters is time zone overlap for the scoping call and debrief, and clarity on which jurisdiction’s contract terms apply. Bug Circuit is Sri Lanka-based and works with customers worldwide on USD pricing, scheduling around the customer’s time zone rather than requiring a local office.
How much does a penetration test cost for a small business?
Manual, human-led testing for a small business site typically runs from a few hundred to a few thousand dollars depending on scope and depth. Bug Circuit publishes its pricing rather than gating it behind a quote form: $49 for the one-time Circuit audit, $299 for Signal (audit plus the team fixing high/critical issues with you, a retest, and three months of monitoring, currently discounted from launch pricing).
What’s the difference between a vulnerability scan and a real penetration test?
A vulnerability scan is automated software checking your site against a list of known signatures in minutes; a penetration test is a human deliberately trying to break into your specific site, chaining small issues together the way a real attacker would. Reports that arrive within minutes or hours of "testing" starting, with no human hours logged against them, are almost always a scan wearing a pentest label.
What should be included in a penetration testing report?
A real report includes evidence for every finding — screenshots, the actual request and response, steps to reproduce — plus a severity rating grounded in what the issue actually lets an attacker do, and exact fix steps written for whoever maintains the site. A generic risk score or a list of CVE numbers with no evidence attached is a sign the "testing" wasn’t hands-on.
Is retesting after I fix the issues included, or is that a separate cost?
Ask this explicitly — finding a vulnerability and confirming a fix actually closed it are two different jobs, and without a retest you’re trusting that your developer’s patch worked with no verification. Some engagements price retesting as a separate line item; Bug Circuit’s Signal tier builds retesting and three months of ongoing monitoring into the price rather than billing it later.
How long does a penetration test take from start to finish?
For a small business website, realistic manual testing runs 3-10 business days from kickoff to the delivered report, depending on how much surface area there is to cover. Be wary of either extreme: a report delivered same-day almost certainly wasn’t hand-tested, and a vague "we’ll get back to you" with no committed timeframe usually predicts a slow, disorganized engagement.
What is an Authorization to Test, and why do I need to sign one?
It’s a signed, recorded document confirming you own or control the domain being tested and are explicitly authorizing the company to attempt to break into it — without it, what the tester is doing is legally indistinguishable from an unauthorized intrusion. A legitimate provider verifies domain ownership and gets this signed before any live testing starts.

Keep reading

See what a real manual audit report looks like before you decide anything

Check the sample report and the published pricing, then book the $49 Circuit audit — a named engineer, real evidence, and a fix list your developer can actually use.

Passive recon only. No login, and no impact on your site. Deeper testing needs domain verification.

Ready for the full manual audit? See transparent pricing →