forumNew topic

We got a quote for a fixed-price standard penetration test; how does it differ from a comprehensive one?

İİbrahim G***MemberCommunity member
Joined
Mar 2024
Message
3
#1

We are an 18-person tech company based in Riyadh providing B2B logistics software and fleet management solutions. We've reached the contract-signing stage with a major enterprise retail client in Saudi Arabia, and their IT security team is requiring an independent penetration testing report from us.

We received quotes from two different local cybersecurity vendors. The first offered a fixed-rate "standard penetration test" package for 12,000 SAR and stated they could deliver the final report within 3 business days. The second firm reviewed our architecture, API endpoints, and user roles, then quoted 38,000 SAR for a custom scoped assessment requiring at least two weeks.

That's more than a 3x budget difference and a huge gap in delivery timelines. Will the 12,000 SAR standard penetration test be enough to pass the enterprise client's audit, or are these cheap packages just automated, superficial scans that overlook critical vulnerabilities?

ÖÖzge E***Member
Job title
Sales Manager
Sector
Paper
Organization type
workshop
Joined
Jun 2023
Message
50

Doki · Brand identity · 2023

Most Helpful#2

Short answer: A fixed-price standard penetration test is mostly just automated vulnerability scanners dumped into a boilerplate report template; it will not cover custom API workflows, business logic flaws, or privilege escalation scenarios. If your client expects an in-depth technical audit rather than a rubber-stamp compliance certificate, the standard package will likely fail their review and jeopardize the entire contract.

The reason standard packages cost so little is the lack of dedicated engineering hours. In these tests: 1) Only exposed external IPs and primary web pages get scanned automatically, leaving backend microservices and mobile endpoints untested. 2) Logical access controls—like one tenant accessing another tenant's records—are ignored because automated tools don't understand business context. 3) Discovered issues are rarely validated manually, resulting in reports cluttered with noise and false positives.

Look at the scope of the 38,000 SAR proposal; they are likely using a gray-box methodology to manually probe API documentation, authentication flows, and role-based access controls. The testing methodology and asset inventory will be laid out clearly in the final deliverable, and your enterprise client's InfoSec team will spot the difference instantly.

First, review your client's exact vendor security specifications. If their RFP explicitly mandates OWASP compliance or dedicated API penetration testing, the 12,000 SAR standard package will not meet the criteria.

VVeli Ç***New member
Job title
Call center representative
Sector
Machinery manufacturing
Organization type
cooperative
Joined
Jun 2026
Message
387
#3

The biggest danger with standard packages is missing Broken Object Level Authorization (BOLA) flaws entirely. Automated scanners blindly fire payloads at HTTP parameters, but they won't know how to query Company A's waybill using Company B's auth token in a logistics dashboard. Those checks require manual testing.

EEmre G***ExpertCommunity member
Joined
Jul 2024
Message
409
#4

Put these three questions in writing to both vendors: 1) How many hours of manual exploitation are included? 2) Are API endpoints and mobile interfaces fully in scope? 3) Do you provide a complimentary re-test once we patch the findings? Their answers will immediately justify the price difference.

ZZafer D***Member
Job title
Operations manager
Sector
Tourism
Organization type
8-person team
Joined
Nov 2024
Message
15
#5

We went with a 14,000 SAR standard test for a similar deal in Jeddah last year. Out of the 18-page report, 15 pages were generic boilerplate and automated tool exports. The client's security team rejected it on the spot, and we ended up spending another 32,000 SAR to get a proper scoped test done anyway.

OOrhan G***Member
Job title
Courier coordinator
Sector
Livestock
Organization type
workshop
Joined
Feb 2024
Message
173
#6

didn't you ask the cheaper company for thheir scope list? they'll probably just punch in an IP range run an automated tool and hand over a PDF report three days later then if your client's security manager knows their stuff at all, that report will get rejected immediately.

İİlknur G***MemberCommunity member
Joined
May 2025
Message
172
#7

standard ones are basically just point-and-click button tests tbh... if they didnt ask for source code or api docs, theyre just gonna run an automated scan and call it a day, no way a manual test gets done in three days.

EElif B***Member
Job title
Store associate
Sector
Chemistry
Organization type
workshop
Joined
May 2023
Message
55

Doki · SEO consulting · 2024

#8

Send the scoping document to the other party's information security manager beforehand. Do not make any payments to any firm without getting written confirmation on which test methodology they will accept.

FFiliz S***Member
Job title
Software developer
Sector
Printing
Organization type
early-stage startup
Joined
Apr 2026
Message
129
#9

How is the penetration test scope defined in your NDA and service agreement with the client? Are they asking for black box or white box? Also, does your system process payments or store sensitive customer data?

TTolga Ş***Expert
Job title
Production Manager
Sector
Livestock
Organization type
workshop
Joined
May 2023
Message
38
#10

With our first B2B client, we cut corners and bought an off-the-shelf packaged test, then celebrated when the system came back clean. Two months later, the client's accountant realized that simply tweaking a URL parameter let them download a competing firm's shipping invoices. That was the day we learned standard testing is just an illusion.

AAhmet Ö***Member
Job title
Data entry clerk
Sector
Consulting
Organization type
40-person manufacturing company
Joined
May 2023
Message
228
#11

I'd appreciate it if you shared the outcome. Don't hesitate to ask; those who don't ask always pay more.

Processes without records never improve, because you don't know what to fix. If I were you, I'd go this route.

NNagihanMember
Job title
Recruitment Specialist
Organization type
workshop
Joined
May 2024
Message
98
#12

I have a question, don't want to go off-topic though. When making a decision, first look at what data you have on hand.

The answer varies greatly by industry; there is no one-size-fits-all rule. Hope this helps.

OOrhan Ç***Member
Job title
Clinic manager
Sector
Software
Organization type
300-person organization
Joined
Jun 2023
Message
91
#13

i agree.

ÖÖmer C***Member
Job title
Software team lead
Sector
Packaging
Organization type
workshop
Joined
Sep 2025
Message
74
#14

Good call starting this thread.

DDoruk Y***ExpertCommunity member
Joined
Feb 2025
Message
99
#15

There are three things to check when doing this. When you try to change everything at once, nothing settles.

Just leaving this note, it might be useful.

MMetin A***MemberCommunity member
Joined
Jan 2025
Message
160
#16

Correct. btw start with a small trial; don't commit to everything at once.

Good luck with that.

EEmre A***MemberCommunity member
Joined
Nov 2024
Message
1
#17

I went through the same thing two years ago. An untested backup is not a backup.

The real issue isn't the number, but what it's based on.

AAhmet Z***Expert
Job title
Technical service technician
Sector
Food wholesale
Organization type
family business
Joined
Dec 2023
Message
159
#18

I have a question. btw taking notes for two weeks yields better results than a six-month estimate.

Just leaving this note, it might be useful.

ÜÜlkü Ş***MemberCommunity member
Joined
May 2023
Message
346
#19

Following.

EElif C***MemberCommunity member
Joined
Feb 2023
Message
374
#20

Could you elaborate on that? If 2FA is on, a stolen password alone is useless.

If you have questions, write them; I'll answer as best I can.

Reply