- Job title
- Agency Founder
- Sector
- Security services
- Organization type
- 40-person manufacturing company
- Joined
- Mar 2023
- Message
- 122
We are a 22-person software company based in Ankara producing cloud-based accounting and e-fatura integrations. We have reached the stage of signing contracts with large corporate clients, and all of them are demanding a current penetration test report from us. We gathered quotes from the market; of two local firms one quoted 55,000 TL for our web application and server infrastructure, while the other quoted 110,000 TL. To understand the reason behind the price difference and their methodologies we requested a redacted sample penetration test report from both companies with client names scrubbed.
The firm quoting 110,000 TL shared a very comprehensive 50-page sample report the next day with all sensitive data thoroughly sanitized. The other firm quoting 55,000 TL stated that they could not share any sample work whatsoever citing NDAs. Is this common practice in the industry, or should we steer clear of the lower-priced team? Also, what sections and evidence should we look for in the sample report shared for our review that would demonstrate actual expert effort rather than automated tool output?