Scope & methodology
Which service types are covered (web, API, mobile, internal network, external network, cloud, wireless, OT/ICS, hardware/IoT, AI/LLM, social engineering, physical, red team, purple team, threat-led)?
Is testing manual/human-led, automated, or a hybrid, and what is the split?
What testing methodology or standard is followed (e.g. OWASP, PTES, NIST)?
Is business-logic testing included, or only automated/technical coverage?
Are exploitation and post-exploitation in scope, or discovery only?
How is scope defined, and can it be adjusted mid-engagement?
Tester qualifications & delivery model
Are testers employees, contractors, freelancers, or researcher-pool members?
What is the size of the tester pool or team assigned to this engagement?
What certifications do assigned testers hold (OSCP, OSCE, CREST, or similar)?
Are background checks, clearances, or US-person status required and available?
Is the delivery model traditional project-based, PTaaS/on-demand, continuous, researcher-pool/crowdsourced, or autonomous/agentic-AI?
Can the same tester(s) be requested for repeat engagements for continuity?
Reporting & retesting
Are findings available live during testing, or only in a final report?
How quickly is the final report delivered after testing concludes?
Is retesting included, and if so, how many retests and within what window?
Does retesting produce an updated report, or only confirm fixed findings?
Is the report format accepted by the organization's auditors, regulators, or customers as-is?
Can findings be exported via API, CSV, JSON, or pushed directly into a ticketing system?
Regulatory & compliance support
Which regulatory frameworks does the vendor explicitly support (PCI DSS, HIPAA, FedRAMP, DORA, NIS2, TIBER-EU, CBEST, SOC 2, ISO, or other regional frameworks)?
Is threat-led testing (TIBER-EU/CBEST/DORA TLPT-style) available if required?
Does the vendor hold CREST accreditation, and does it apply to the exact legal entity and service being contracted?
Is a FedRAMP-authorized option available if the engagement involves federal systems?
Will the vendor's deliverable be accepted by the organization's specific auditor or regulator without modification?
Data handling & residency
Where are findings, screenshots, credentials, exploit artifacts, and reports stored?
Are tester-location or citizenship restrictions available (e.g. US-only, EU-only)?
From what source countries or regions does testing traffic originate?
How does the vendor handle cross-border data transfer requirements (GDPR, Standard Contractual Clauses, or similar)?
What is the vendor's data retention and deletion policy after engagement close?
Workflow & integration
Is there a published API for findings, scheduling, or reporting?
Which ticketing/ITSM systems are natively supported (Jira, ServiceNow, or similar)?
Can findings be correlated with vulnerability-management or attack-surface-management data already in use?
Is continuous or always-on testing available, or only scheduled engagements?
Are webhooks or automated notifications available for new findings?
Pricing & contracting
Is pricing published, or quote-based per engagement?
What is the estimated cost for a standard engagement of this scope?
What is the estimated total elapsed time from scoping to final report?
Are multi-year or enterprise program pricing models available?
What is included versus billed separately (retesting, report revisions, expedited turnaround)?