Ask who will actually perform the test
Sales credentials and company logos do not tell you who will touch your environment. Ask about the practitioner’s experience with the technology and attack surface in scope.
Ask how findings are validated
Look for a clear explanation of how automated discoveries become confirmed findings, how false positives are handled, and whether the team safely demonstrates exploitability.
Review a sample report
The report should work for two audiences: leaders need business impact and priorities; technical teams need evidence, reproduction detail, and remediation guidance.
Ask about retesting
A provider should have a clear process for verifying remediated findings and documenting closure.
Related next step
Use this resource as a starting point, then adapt it to the systems, business constraints, and threat model that actually apply to your organization.