forumNew topic

Should we ask for a sample report when getting pentest quotes, and what should be in it?

DDeniz D***Member
Job title
Agency Founder
Sector
Security services
Organization type
40-person manufacturing company
Joined
Mar 2023
Message
122
#1

We are a 22-person software company based in Ankara producing cloud-based accounting and e-fatura integrations. We have reached the stage of signing contracts with large corporate clients, and all of them are demanding a current penetration test report from us. We gathered quotes from the market; of two local firms one quoted 55,000 TL for our web application and server infrastructure, while the other quoted 110,000 TL. To understand the reason behind the price difference and their methodologies we requested a redacted sample penetration test report from both companies with client names scrubbed.

The firm quoting 110,000 TL shared a very comprehensive 50-page sample report the next day with all sensitive data thoroughly sanitized. The other firm quoting 55,000 TL stated that they could not share any sample work whatsoever citing NDAs. Is this common practice in the industry, or should we steer clear of the lower-priced team? Also, what sections and evidence should we look for in the sample report shared for our review that would demonstrate actual expert effort rather than automated tool output?

HHakan U***MemberCommunity member
Joined
Apr 2024
Message
43
Most Helpful#2

Short answer: You should definitely stay away from the firm that refuses to share a sample report. Professional cybersecurity firms routinely share standardized sample reports during the proposal phase, prepared by anonymizing all client information and IP addresses without violating any NDAs. A quality report must feature proof of manual verification and clear remediation guidance rather than automated tool screenshots.

Check the sample report you are reviewing specifically for the presence of the following sections:

1) An executive summary and risk matrix are essential; summary tables that non-technical managers can glance at to understand the overall posture of the system and critical threats are mandatory. 2) Step-by-step proof-of-concept steps must be included for every vulnerability; concrete evidence and output showing how the security expert gained access to the system and what requests were sent must be present. 3) Instead of generic copy-pasted recommendations generated by automated scanners, actionable code and configuration remediation advice tailored to your software architecture must be provided.

The primary reason low-bid firms avoid showing samples is usually that they simply run an automated tool and hand over its raw PDF output as a report. Reports like that will not pass the security audits of your corporate clients, and your money will go down the drain.

BBurhanMember
Job title
Retired Engineer
Joined
Aug 2024
Message
132
#3

Hiding behind an NDA is the most common excuse used by low-effort shops in this industry. Every serious firm keeps a generic or sanitized template report ready in their archives under their own corporate identity.

NNecati G***ExpertCommunity member
Joined
Nov 2024
Message
409
#4

Don't be fooled by that 50-page report right away either. Go through the pages; if it's filled with page after page of descriptions for low-severity libraries and generic internet definitions, that could also just be automated scanner output.

DDoruk S***New memberCommunity member
Joined
Aug 2026
Message
278
#5

Last year we paid 40,000 TL for our first pentest report, and 50 out of the 60 pages were just generic boilerplate notes pulled from the internet. We objected, but because the scope wasn't clearly defined in the contract, we were forced to pay.

SSinan T***MemberCommunity member
Joined
Sep 2025
Message
12
#6

once we see the findings in the sample report how long does it usually take for our dev team to patch them and do we have to pay extra for the re-test?

NNuri G***Member
Job title
Purchasing manager
Sector
Agriculture
Organization type
early-stage startup
Joined
Mar 2023
Message
62
#7

You must look for these in the report: 1) A list of out-of-scope assets, 2) The CVSS scoring methodology, 3) The validation test schedule and terms, meaning the re-test.

AAslı G***ExpertCommunity member
Joined
Jan 2023
Message
1
#8

When your enterprise clients run audits, they won't just look at whether the report exists; they will also verify the valid accreditations and certifications of both the firm and the individual testers. Make sure to add this requirement to your RFP.

MMustafa B***Member
Job title
General Manager
Sector
Machinery manufacturing
Organization type
early-stage startup
Joined
Jan 2026
Message
50
#9

The firm refusing to show a report will probably just fire up an automated tool and hit export the next day. anyway dont take the risk imo wouldnt leave it to chance.

KKadirMember
Job title
Shipping company
Organization type
family business
Joined
Jul 2024
Message
92
#10

We've heard this a lot, but it never happened like that for us. The real issue isn't the number, but what it's based on.

If you don't write this down from the start, it leads to arguments later. Hope this helps.

KKaanMember
Job title
Product Manager
Joined
May 2024
Message
96
#11

I'm writing this so you don't make the same mistake. Taking notes for two weeks yields better results than a six-month estimate.

Hope this helps.

TTülay O***MemberCommunity member
Joined
Jan 2023
Message
1
#12

Great work. anyway just because everyone does it doesn't mean it's right.

This is my opinion, I'm not claiming it's absolute truth.

SSevimNew member
Job title
Florist
Joined
Nov 2024
Message
26
#13

I agree. Most incidents start with a leaked password not a vulnerability.

If I were you, I'd go this route.

OOzanMember
Job title
Freelance designer
Joined
Apr 2024
Message
106
#14

You're right.

LLeyla Y***MemberCommunity member
Joined
Mar 2024
Message
44
#15

i agree and Id like to emphasize that. hasty decisions become decisions you have to fix six months later.

if you get three different answers on a topic, the question was asked wrong... hope this helps.

KKORİDoki team
Job title
Forum moderator
Sector
Cybersecurity and digital
Organization type
Doki
Joined
Jan 2023
Message
2,840
Sentinel#16

Let me jump in. Two different issues are getting mixed up in this thread: first, the undefined scope, and second, the unclear ownership. The issue won't be resolved until both are addressed separately.

EEmre A***Member
Job title
Warehouse Manager
Sector
Automotive aftermarket
Organization type
sole proprietorship
Joined
Mar 2023
Message
370
#17

Let me summarize what's been said so far. Don't rely on a single measure; go layer by layer.

If you post the result here, it will help others too.

KKoray B***Member
Job title
Quality Assurance Manager
Sector
Machinery manufacturing
Organization type
family business
Joined
Sep 2023
Message
279

Doki · Incident response support · 2025

#18

Yes, that's exactly how it is with penetration test report sample. An untested backup is not a backup.

This is my opinion I'm not claiming it's absolute truth.

GGamze G***Expert
Job title
Human Resources Manager
Sector
Security services
Organization type
medium-sized business
Joined
Apr 2022
Message
218

Doki · Phishing awareness training · 2025

#19

Here's how it went for us. Taking measures without an inventory leaves doors you haven't seen open.

This is my opinion, I'm not claiming it's absolute truth.

TTuğrulMember
Job title
Solar energy
Joined
Feb 2024
Message
88
#20

You're right, I've been down that road too. When making a decision, first look at what data you have on hand.

Hope this helps.

Reply