We are an 11-person team providing HR software to enterprise clients in the UK. One of our enterprise clients requested an up-to-date penetration testing report and an independent audit sign-off as part of their annual contract renewal.
We got a quote from an external security firm; they want 5,500 GBP for the web app and server infrastructure in scope. Meanwhile, our in-house developer suggests paying a 1,200 GBP annual license fee for a popular automated pentesting tool and running all the scans ourselves, pointing out that these tools detect vulnerabilities and generate reports anyway.
Honestly, saving 4,300 GBP sounds tempting, but how credible is it on the enterprise side to run these tools internally and hand the report to the client? Are there technical or legal risks to DIY testing that we aren't seeing?