We're about to sign our first professional penetration testing agreement for our B2C e-commerce infrastructure and mobile app. We got quotes from three different firms for a scope covering external network, web app, and API testing. All of them estimated the testing period at an average of 5 business days.
However, when it comes to preparing and delivering the final report after testing wraps up, one firm said 3 business days while another asked for 15 business days. On top of that, they're reluctant to share a sample or redacted report format before signing, citing confidentiality. 15 business days feels way too long to me; I mean, if there's a critical vulnerability, are we supposed to sit around vulnerable for two weeks?
How many business days does it normally take to get a pentest report after testing concludes? Also, before closing a deal, how should we verify exactly what sections are included in a sample report regarding risk scores, proof of exploit, and remediation guidance?