We are a 14-person software company based in Barcelona developing cloud-based order management software. We've reached the contract stage with a retail enterprise client across Spain for 65,000 Euro annually. However, before signing, their information security department made it mandatory that we provide a penetration test report from an independent third party.
When we started collecting quotes from the market, things got completely confusing. One firm quoted 1,800 Euro just for the web app, while another quoted 8,500 Euro by throwing in network, API, and cloud infrastructure as well. Some say they can finish in two days, others say it takes two weeks.
What is the right scope to satisfy the client during this contract process without driving up unnecessary costs for our company? How should we set boundaries between the web app, API, and server layers, and what standards is the client actually looking for in the report?