Experiencing a security incident? Emergency Response

Resources

Before requesting a pentest quote: a short guide to scoping it right

2026-07-15 · 7 min read

The biggest reason penetration test proposals cannot be compared is not price, it is scope ambiguity. The same phrase "web application test" can mean a 3-day automated scan at one firm and 15 days of manual testing at another. This guide collects the questions to settle internally before requesting proposals.

1. What exactly is being tested?

"Everything" is not a scope. Count your assets: how many web applications, APIs, mobile apps, external IPs, internal network segments? If you don't know, your first need may not be a pentest but external attack surface discovery.

2. From which perspective?

Black box (no information), grey box (a user account), or white box (source code and architecture)? Grey box is the most efficient balance for most organizations: it simulates the attacker's most likely position, someone who got in or already has some access.

3. Production or a test environment?

Testing production is realistic but demands continuity rules: a test window, prohibited techniques, an emergency contact. A test environment allows more freedom, but results are only as valid as the environment is identical to production. Put the differences in writing.

4. What is your measure of success?

Do you want compliance evidence or a real risk picture? Both are legitimate, but they are different jobs. A compliance-driven test produces documentation in the auditor's format. A risk-driven test hunts for attack paths to your critical assets. Saying this upfront lets the proposal be built correctly.

5. What happens after the findings?

Is retesting included? Is closure verification charged separately? In what format do findings arrive, and who walks you through them? A good proposal answers these. Our standard: a two-layer technical and executive report, a findings presentation meeting, and verification retesting included after remediation.

6. Who is actually testing?

Who signs the report, what are their certifications, who will actually do the work? "Our team is experienced" is not an answer. You have the right to ask for names; we state them without being asked.


You can download our fillable scoping form (in Turkish) that makes these questions systematic. When you send it back filled in, our proposal contains calculation, not guesswork.

Let's build your defense together.

Whether a single penetration test or an end-to-end security program, let's clarify your needs in a 30-minute introductory call.