Skip to content

Penetration Testing RFP Template: 25 Questions to Ask Vendors

A usable penetration testing RFP template: sections to include, 25 vendor questions grouped by theme, and what a good answer to each looks like.

Invadel TeamSeptember 4, 20269 min read

Penetration testing proposals tend to read alike. Every vendor follows a recognized methodology, has certified testers, and delivers an executive summary. A request for proposal exists to get underneath that language. It lets you compare what each firm will actually do, who will do it, and what you will hold at the end. This template gives you the structure and the 25 questions that separate the answers.

You do not need a forty-page document. A two-page RFP with precise scope and pointed questions gets better responses than a long one. Send it to a shortlist you have already screened using our guide to choosing a penetration testing company, and let the responses decide.

The RFP structure

Five sections cover everything a vendor needs to respond well.

1. Company background

Give the vendor enough context to size the work and judge fit: what your company does, its size, its industry, and the regulatory frameworks that apply. State why you are testing now, whether that is a compliance deadline, a customer requirement, a new product, or a program you are building. Name the internal owner of the engagement and who will receive the report.

2. Scope

This section determines the price and the timeline, so be specific. List each target with the detail a tester needs:

  • Web applications: URL, number of user roles, what the application does, and whether testing is authenticated
  • APIs: number of endpoints, authentication scheme, and whether documentation exists
  • Networks: number of external hosts, and for internal testing the number of hosts, sites, and Active Directory domains
  • Cloud: provider, number of accounts or subscriptions, and the services in use
  • Mobile: platforms, and whether the backend API is included
  • Social engineering or red team: objectives, the people or systems in play, and any constraints

Add the environments available for testing, the testing windows you can accept, and anything explicitly out of scope. If you cannot describe the scope precisely, ask vendors to propose one from a written description. A good firm responds with scoping questions rather than a guess. Our guide to scoping your first penetration test covers what to gather.

3. Requirements

State what a compliant response must include:

  • A named testing team with certifications listed per person
  • A described methodology with reference to a public standard
  • A redacted sample report
  • A fixed price for the stated scope, with any assumptions listed
  • Retest terms in writing
  • Compliance mapping for the framework you name
  • Certificates of insurance and a willingness to sign your NDA and MSA

4. Evaluation criteria

Tell vendors how you will score them, and set the weighting before responses arrive. Otherwise the loudest proposal sets it for you. A sensible order: manual depth and methodology first, reporting and retest terms second, team and continuity third, compliance fit fourth, and price last among the scored items. Treat insurance and legal terms as pass or fail.

5. Timeline and process

List the dates: RFP issued, deadline for vendor questions, response deadline, shortlist interviews, sample report review, decision date, and the testing window you need.

The 25 questions

Each question comes with what a good answer looks like.

Team and credentials

1. Who will perform the testing on our engagement, and what certifications do they hold? A good answer names the individual testers and lists hands-on certifications such as OSCP or OSCE3 per person, not a company-wide summary. Our testers are senior, in-house, and OSCP and OSCE3 certified.

2. Are your testers employees or subcontractors, and where are they located? A good answer states that testers are employees, names where they work from, and commits that the assigned team will not change without notice.

3. How much offensive security experience does the assigned lead have, and in what kinds of environments? A good answer gives a specific figure for the lead and describes environments like yours, rather than an average across the firm.

4. Can you provide references from clients in our industry or under our compliance framework? A good answer offers contactable references, with the client’s permission, and describes comparable engagements without naming clients.

5. Will the same testers be available for our retest and for future engagements? A good answer explains how continuity works, so the person verifying your fixes understands the original findings.

Methodology and manual depth

6. What share of the engagement is manual testing, and what is automated? A good answer states that manual testing is the majority of the effort, with tools used for discovery and coverage. Our breakdown of automated vs manual penetration testing explains what the humans do that the tools cannot.

7. Which methodology do you follow, and will the report show coverage against it? A good answer names public standards such as PTES, the OWASP Web Security Testing Guide, or NIST SP 800-115. It also commits to a coverage section in the report. Our methodology page describes ours.

8. How do you test business logic and access control between user roles? A good answer describes manual testing with one account per role, and checks of every function and object for horizontal and vertical privilege escalation.

9. Do you attempt exploitation and chain findings, or stop at identification? A good answer confirms exploitation to demonstrate real impact within agreed rules of engagement. Chained findings should be reported as an attack path, not a list of separate items.

10. How do you handle a critical finding discovered during testing? A good answer names a notification window, a contact on the vendor side, and the rule for pausing testing if something dangerous is found.

Scope and pricing model

11. Is the price fixed, hourly, or credit-based, and what could change it? A good answer is a fixed price, agreed in writing before work starts. The scope statement should be specific enough that only a scope change you request can move it. That is how we price every engagement; starting prices are on the pricing page.

12. What does the price include? A good answer itemizes it: testing, the executive and technical reports, a findings platform, a readout call, the retest, and an attestation letter. Anything sold separately should be listed with its price.

13. How do you size an engagement, and what do you need from us to do it? A good answer describes a scoping questionnaire or call covering applications, roles, endpoints, hosts, and environments, and gives a turnaround for the proposal.

14. What is your lead time to start, and how long will testing run for our scope? A good answer gives a start date tied to your access being ready and a duration tied to your scope. A generic promise that applies to every client is not an answer.

15. Can you test in production, staging, or both, and what safeguards apply? A good answer describes testing windows, rate limits, excluded actions, and how the tester coordinates with your team when something unexpected happens.

Reporting and retest

16. Can we see a redacted sample report before we decide? A good answer is yes, without conditions. You can request ours and hold every other response to the same standard.

17. What does the report contain, and is there a separate executive summary? A good answer describes an executive report for leadership and auditors, plus a technical report with reproduction steps, evidence, severity ratings, and stack-specific remediation guidance. Our guide to what a penetration testing report should contain lists every section to check.

18. Is a retest included, what is the window, and does the final report reflect the fixes? A good answer includes the retest, states a reasonable window, and commits to an updated report showing each finding closed. Ours is free on every engagement, with phishing as the exception, since a phishing campaign produces no findings to remediate.

19. How are findings delivered: a PDF only, or a platform where we can track remediation and request retests? A good answer offers both, with the platform included rather than licensed per seat.

Compliance mapping

20. Will the report map findings to our framework? A good answer names the frameworks the firm maps to, such as SOC 2, PCI DSS, HIPAA, ISO 27001, NYDFS 23 NYCRR 500, or CMMC. It should also describe experience with the evidence auditors under your framework expect.

21. Do you provide an attestation letter we can share with customers and auditors? A good answer is yes, as a standard deliverable: a short letter confirming scope, dates, methodology, and outcome without technical detail.

22. Are your testers independent of any systems we run, and will you confirm that in writing? A good answer confirms the firm does not manage, host, or build anything in scope, and offers an independence statement for your auditor.

23. What professional liability, errors and omissions, and cyber liability insurance do you carry? A good answer offers a certificate of insurance on request and confirms the limits meet the requirements in your vendor contracts.

24. Will you sign our NDA and master services agreement, and what are your authorization terms? A good answer accepts a mutual NDA, provides its own agreement for comparison, and requires written authorization before any testing begins.

25. How is our data handled during and after the engagement? A good answer describes where evidence and credentials are stored, who can access them, how they are encrypted, and when they are destroyed after the retest.

Scoring the responses

Score each question against the rubric from your evaluation criteria and total the themes, not the individual questions. A response that is strong on methodology and reporting but weak on price is usually the better buy. A response that is cheapest and vague on questions 6, 9, 16, and 18 is usually a scan with a cover page. For named vendors and how their models compare, our comparison pages put Invadel next to platforms, crowdsourced programs, scanners, and other testing firms.

Frequently asked questions

Do we need a formal RFP for a penetration test? Not always. A short request for information with the 25 questions above works for a single engagement. A formal RFP makes sense when procurement requires it or when you are selecting a firm for a multi-year program.

What if a vendor will not answer a question? Treat it as the answer. Every question above has a straightforward response from a firm doing the work properly.

Want to see how we respond to all 25? Scope your assessment and we will return a fixed-scope proposal that answers them, or request a sample report and start with the deliverable.

Written by

Invadel Team

Senior penetration testers writing from real engagements, the same team that scopes, tests, and reports for our clients. About Invadel →

Find out what an attacker sees.

Tell us what to test and see your fixed price.

Prefer the full scoping questionnaire? 
Start the conversation