Three quotes are sitting in your inbox for the same penetration test. The cheapest is a fraction of the most expensive, yet all three promise experienced testers, a proven methodology and a detailed report. Nothing on the surface tells you which firm will put senior people on your systems for two weeks and which will run a scanner on your systems and format the output.
A buyer does not need a preselected brand name. A capable firm can show how it tests, who will do the work and what its reports contain before you sign. Put the same checks to every vendor on your shortlist, including us, and compare the evidence rather than the promises.
If you are still unpacking the acronym, start with our explanation of what VAPT means and what the process includes.
Why this market is hard to buy in
Security testing is difficult to judge from the outside, even after delivery. You cannot watch what is being done, and every report arrives in a confident voice with a severity chart and a wall of technical language, regardless of how it was produced.
Two features of the market make this worse. Certifications are easy to display, but the name of a qualification tells you little about the work the assigned tester has done since earning it. And if a vendor's process is to run an automated tool and reformat the output, the resulting PDF can still look like a penetration test to anyone who has not read many of them. CBN's risk-based cybersecurity framework, the NDPA 2023 and NGX's testing requirements for Trading Licence Holders have all pushed organizations toward regular testing. More firms now sell the service, which makes the evidence you can check before appointment more important.
The six criteria that matter
What the best penetration testing companies in Nigeria have in common is unglamorous: they can show their work before you sign. Six things can be checked at proposal stage.
- A published methodology: Established references exist for this work: PTES for engagement structure, the OWASP Web Security Testing Guide and MASVS for application testing, and NIST SP 800-115 for technical assessment. A serious firm names the references it follows and can explain how they shape the engagement. We publish our own testing methodology.
- Proof of concept in the report: A finding that says access "could potentially" be gained is a guess. A real finding shows the request exploiting the finding, with the screenshot to prove that where necessary. Ask for a redacted sample report and check whether the findings demonstrate impact or merely assert it.
- A retest: Confirming findings are closed after your team fixes the bugs should be included in the work.
- Who actually does the work: The proposal should name the individuals who will test your systems, and they should be senior penetration testers, not the firm's most impressive CVs standing in for whoever is available that month.
- Regulator and assessor acceptance: A report only counts if the body you answer to accepts it. For capital markets operators, the NGX rules require Trading Licence Holders with digital trading applications to use a recognized VAPT assessor. A report from outside that list will not satisfy the Exchange. Our NGX VAPT assessment page explains the submission cycle.
- Scoping: A vendor who quotes without asking scoping questions is guessing, and a guessed price means guessed effort. Application count, user roles, environment access, testing windows and retest expectations all drive the real cost of a VAPT.
The questions to ask every shortlisted vendor
These are the criteria we hold ourselves to at ClarenSec, listed as questions any buyer can ask.
- Which testing standards does your methodology follow, and can we read it before we sign?
- Can we see a redacted sample report from an engagement similar in size and type to ours?
- Will every verified finding in our report include a proof of concept?
- List the people who will test our systems, and what has each of them worked on before?
- Is a retest of fixed findings included?
- Have your reports been accepted before by the body we answer to: NGX, a QSA, an ISO 27001 auditor, an examiner?
- What do you need to know about our environment before you can price this work?
The last question doubles as a trap for the unprepared. A firm that answers "nothing" has just told you the quote was never connected to your environment in the first place.
The red flags that should end the conversation
Most weaknesses show up as thin answers to the questions above. A few patterns deserve a harder response. If a vendor prices the engagement on the first call, before asking anything about your applications or infrastructure, the number is fictional. If the sample report could describe any company once the logo is swapped, you could be looking at reformatted scanner output. If a proposal guarantees a "clean" result, walk away: the outcome was decided before testing began. And if nobody will say who is doing the work, assume the answer would not help them.
We have written separately about the signs that a pentest report came from a vulnerability scan, and about the quieter failure mode where the testing is real but the money is wasted anyway because findings never turn into fixes. Both change what you look for in a sample report.
How to run the comparison fairly
Three quotes are only comparable if they price the same work, so write a one-page scope brief and send the identical document to every vendor: what is in scope, how many applications and roles, what access you will grant, when testing can run, and that you expect a retest.
Then compare sample reports side by side, and resist the instinct that thicker means better. Read one finding from each in full and ask which one you could hand to your own engineer to reproduce the issue and verify the fix. Finally, insist on twenty minutes with the actual testers before you decide. A senior tester talking about your environment sounds different from a salesperson talking about the firm. For a baseline of what the full engagement should include, we have set out what a complete VAPT engagement covers in one place.
Price comes last: read it as information about effort. Once two firms have passed every check above, choosing the cheaper is now sensible. Choosing the cheapest assessor before running the checks is how organizations end up buying the same test twice.
- Proposals are easy to polish, so compare verifiable practice rather than confidence on paper.
- Check the methodology, proof standard, retest terms, named testers, and scoping questions asked before you sign.
- Send the same scope brief to every vendor so the quotes price comparable work.
- Spend twenty minutes with the people assigned to do the testing.
- Read price as information about planned effort after the other checks have passed.
You do not need to be a security specialist to buy this well. You need one page of scope, seven questions, and the patience to hold every vendor to the same standard. Those seven questions are as good a place to start with us as with anyone.