We are an 18-person tech company based in Riyadh providing B2B logistics software and fleet management solutions. We've reached the contract-signing stage with a major enterprise retail client in Saudi Arabia, and their IT security team is requiring an independent penetration testing report from us.
We received quotes from two different local cybersecurity vendors. The first offered a fixed-rate "standard penetration test" package for 12,000 SAR and stated they could deliver the final report within 3 business days. The second firm reviewed our architecture, API endpoints, and user roles, then quoted 38,000 SAR for a custom scoped assessment requiring at least two weeks.
That's more than a 3x budget difference and a huge gap in delivery timelines. Will the 12,000 SAR standard penetration test be enough to pass the enterprise client's audit, or are these cheap packages just automated, superficial scans that overlook critical vulnerabilities?