forumNew topic

A major client wants a pre-contract penetration test, how should we define the scope?

EEceMember
Job title
Legal Counsel
Joined
Feb 2024
Message
98

Doki · Backup setup · 2023

#1

We are a 14-person software company based in Barcelona developing cloud-based order management software. We've reached the contract stage with a retail enterprise client across Spain for 65,000 Euro annually. However, before signing, their information security department made it mandatory that we provide a penetration test report from an independent third party.

When we started collecting quotes from the market, things got completely confusing. One firm quoted 1,800 Euro just for the web app, while another quoted 8,500 Euro by throwing in network, API, and cloud infrastructure as well. Some say they can finish in two days, others say it takes two weeks.

What is the right scope to satisfy the client during this contract process without driving up unnecessary costs for our company? How should we set boundaries between the web app, API, and server layers, and what standards is the client actually looking for in the report?

LLevent Ö***Veteran
Job title
Production planning
Sector
Textile
Organization type
a company within a holding
Joined
Jan 2023
Message
13
Most Helpful#2

Short answer: The only way to set the right scope that satisfies your client is to get written confirmation of the target asset boundaries directly from their info sec team. If you define the scope based on your own assumptions, either it won't be enough and you'll have to rerun the test, or you'll include unnecessary components and pay double.

First, officially ask your client this: 'Would a gray-box web application test covering the web application and the API endpoints consumed by this application within the scope of our contract be sufficient?' Enterprise clients usually want to audit the application layer where their data will actually live and the authentication mechanisms. A full-scope internal network or office infrastructure test is rarely requested.

Follow these steps when getting quotes and managing your budget: 1) Pre-list the exact number of dynamic pages and API endpoints to be tested and hand that to the security firms to prevent variable pricing. 2) Require that the test isn't just an automated vulnerability scanner, but includes guided manual test scenarios (aligned with OWASP principles). 3) Make sure your contract includes one free retest for critical and high findings; the client won't just want a list of findings, they'll want a signed final report proving they've been remediated.

For a 14-person SaaS, 1,800 Euro quotes are most likely just automated tool outputs run for a few hours, and there's a high chance enterprise compliance will reject it. A decent web app and API test takes on average 3 to 5 business days and typically lands around 3,000 to 5,000 Euro when conducted by independent certified professionals.

LLeventVeteran
Job title
Digital transformation consultant
Organization type
two-branch business
Joined
Jul 2023
Message
208
#3

Corporate auditors spot automated scanner dumps right away. If the report doesn't start with an executive summary, a methodology reference, and remediation sign-off dates showing how vulnerabilities were resolved, the client won't accept it. Don't cheap out and risk losing the deal.

MMustafa C***MemberCommunity member
Joined
Jan 2026
Message
96
#4

Request a written copy of the security specification document from your client. In most corporate structures, security requirements are defined via a standard checklist. Getting hold of this document and sharing it with the security firms you're sourcing quotes from will prevent out-of-scope costs.

UUfuk A***ExpertCommunity member
Joined
Dec 2024
Message
410
#5

To nail down the scope, you need to clearly provide these three parameters to the firms: 1) The number of user roles in the system (admin, vendor, standard user). 2) The number of public-facing API endpoints. 3) Whether the test will be run in production or on an exact staging replica.

LLeylaMember
Job title
Purchasing
Joined
Apr 2024
Message
86
#6

We're also an 18-person team in Valencia. A similar client accepted a pentest we had done for around 4,000 Euro. The test took 4 days and turned up 2 high-severity vulnerabilities. Our team patched them in 10 days and the security firm provided a retest report for free. The client signed the contract two days later.

CCaner A***Member
Job title
Technical service technician
Sector
Agriculture
Organization type
sole proprietorship
Joined
Nov 2022
Message
157
#7

The ones quoting 8,500 Euro probably bundled your entire cloud architecture and internal office network into the scope. Why would you test your corporate office network where no client data is stored? Whatever the sales contract covers, the test should be strictly limited to that specific data flow.

PPınar K***New memberCommunity member
Joined
Aug 2026
Message
410
#8

Definitely do not run the test against your production database. Spin up a dedicated staging environment that mirrors prod identically but is filled with dummy data. Security testing can trigger DB deadlocks or unexpected drops, you don't want your live operations grinding to a halt.

OOkan T***VeteranCommunity member
Joined
Jan 2023
Message
7
#9

stay away from firms promising to wrap it up in two days imo. they just run an automated scanner and hand you a pdf. an enterprise client will see right through that and make you redo it from scratch.

edit: I wrote something wrong above, sorry about that.

SSerapNew member
Job title
Private tutoring
Joined
Nov 2024
Message
30
#10

65,000 Euro annually is a fantastic contract, congrats. 3,000-4,000 Euro is a totally reasonable security investment for a deal of this size. Plus once you have that report in hand you can showcase it as a trust factor to other prospective enterprise clients down the road.

AAslı A***MemberCommunity member
Joined
Oct 2023
Message
19
#11

There's also a measurement aspect to this. When you try to change everything at once, nothing settles.

Good luck with that.

FFerhat Ş***Member
Job title
General coordinator
Sector
Law
Organization type
family business
Joined
Jul 2023
Message
13
#12

Exactly, and not many people know this. Forgotten test environments are more often the entry point than live systems.

The real issue isn't the number, but what it's based on.

YYiğit A***VeteranCommunity member
Joined
Jan 2025
Message
2
#13

I'm curious too.

AAv. Kemal U***Expert
Job title
Lawyer · IT
Organization type
300-person organization
Joined
Sep 2023
Message
168
#14

This thread is archived.

FFerhat A***ExpertCommunity member
Joined
Mar 2026
Message
124
#15

Let's separate the concepts, they're getting mixed up. Everything goes well for the first three months; problems arise in the fourth.

Processes without records never improve, because you don't know what to fix.

İİremNew member
Job title
Intern · marketing
Joined
Jan 2025
Message
30
#16

great work. any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

hope this helps.

FFeyza S***Member
Job title
Front office accounting
Sector
Furniture manufacturing
Organization type
sole proprietorship
Joined
Dec 2023
Message
414
#17

We got stuck at the same point for a while. Having backups accessible on the same network and with the same identity makes them part of the target.

Payment information changes are never verified through the channel they came from.

JJale Ç***MemberCommunity member
Joined
Nov 2024
Message
199
#18

I have a question. If you scold false alarms, nobody will report again.

Hope this helps.

KKemal S***Member
Job title
Field sales representative
Sector
Machinery manufacturing
Organization type
two-branch business
Joined
Jun 2023
Message
62
#19

The opposite happened to me, that's why I'm writing. Trying to do this alone is the most expensive way.

Everything goes well for the first three months; problems arise in the fourth. Just leaving this note it might be useful.

BBarış Ç***Member
Job title
Customer Relations Manager
Sector
Furniture manufacturing
Organization type
two-branch business
Joined
Oct 2023
Message
12
#20

Let me clarify the technical side. If you don't write this down from the start, it leads to arguments later.

Reply