As someone who does penetration testing, let me first mention the most common misconception in my industry: calling an automated scan report a penetration test.
Automated scanning uses tools to scan for known vulnerabilities and generates a list. It's useful, cheap, and repeatable. But if the tester stops there, most findings in that report are unverified; the false positive rate is high. That's usually the explanation for the five-fold price difference.
Questions to ask to compare quotes:
Are findings manually verified? Meaning, is every item in the report written by demonstrating it's actually exploitable, or is just the tool's output being copied over?
What is the scope and who defines it? Are the addresses, applications, and included/excluded systems written down?
What type of test is it? Will it be done with no information, partial information, or full access? The three produce different durations and different findings.
Is retesting included? After you fix things, who verifies when that the same findings are closed? If it's not included, the report remains incomplete.
Who is the report for? A good report has both an executive summary and technical details; if they're written in the same tone, one of them is useless.
Finally, timing: get the test done before going live. Anything found after launch is more expensive and riskier to fix.