Network penetration testing companies all look the same from the outside, so most MSPs shortlist on technical skill. Wrong filter. Almost every firm on your list can find vulnerabilities. The ones that cost you an account are the ones that won't show you a full report before you sign, or won't put a non-solicit in the MSA. MSP Pentesting is channel-only: we run the testing and write the report under your brand, and there's no end-client sales team here to route your account to.
So you're not really buying a pentest. You're buying something you'll put your logo on, defend in a client QBR, and live with for the next twelve months.
That changes the criteria.
The first filter: does the vendor sell direct?
Ask it on the first call, in those words. Do you sell directly to end clients?
Most firms say they do both. Both is the answer that should worry you.
Here's how it plays out. The vendor tests your client. Their tester emails the client contact for scoping details. Their brand appears somewhere in the deliverable, maybe just a footer.
Then the findings come back, a few of them serious, and the client wants remediation help. The vendor happens to have a services team with availability. Twelve months later that client has a direct relationship with a security firm doing exactly the work you were planning to sell.
Nobody has to behave badly for that to cost you an account. It just happens.
Channel-only means something specific and checkable. No direct sales team. No end-client marketing list. No case studies naming companies that are somebody else's clients. No pricing page written for the buyer you're protecting.
Ask about all four and watch how fast the answers come back.
Then get it in writing. A serious pentest partner will hand you these clauses without being asked.
- Non-solicit that survives termination. Covering any client introduced during the relationship, for a defined period after the last engagement closes.
- Confidentiality that covers client identity. Not just findings. The fact that a named company is your client is commercially sensitive on its own.
- Brand control on deliverables. Your logo, your colors, your cover page. The vendor's name appears only where you decide it appears.
- Communication routing. What happens when the client emails the tester directly. The right answer is that it gets forwarded to you, every time, no exceptions for convenience.
A vendor who hesitates on any of those has just told you what the plan is.
The report is the product
Your client will never watch anyone test anything. The report is the entire deliverable as far as they're concerned, and it's the artifact with your logo on the front.
So read one before you sign. Not a two-page sample chapter. A full redacted engagement report, cover to appendix.
Here's what separates a good one.
- An executive summary a non-technical owner can read. No CVSS scores in the first paragraph. What was tested, what an attacker could do with it, what to fix first.
- Findings with evidence. Screenshots, command output, the exact host, the exact path. If you can't hand a finding to an engineer and have them reproduce it, it isn't a finding. It's an opinion.
- An attack narrative. The story of how the tester got from nothing to Domain Admin, in order. This is the section that sells remediation work, because it shows a chain instead of a list of unrelated issues.
- Remediation that fits the environment. Apply vendor patch isn't remediation guidance. What to change, in what order, and what it'll break on the way.
- An explicit scope statement. What was tested, what was excluded, which dates, which IP ranges. This is the section that protects you when a client asks why an untested system got hit.
If you need a baseline to compare vendor samples against, our pentest report template shows the structure we deliver and what each section is for.

Who runs the engagement
Ask for a name. Then ask for that person's background.
You want a named tester with hands-on network experience, certifications that carry a genuine hands-on component, and confirmed availability inside your client's window.
Be precise about what those certifications prove, because they aren't interchangeable. OSCP is the strongest signal: a 24-hour practical exploitation exam with a reporting window after it. GPEN is a roughly three-hour proctored exam, mostly multiple choice, with a small set of hands-on CyberLive lab questions, so it evidences methodology rather than sustained exploitation. CREST is the one to ask about where your client has UK exposure.
The answer that should slow you down is we assign from a pool. Quality then varies by whoever's free that week, and you find out which one you got when the report lands.
Three follow-ups worth asking on the same call:
- Is any part of this subcontracted, and to whom? Not disqualifying by itself. Discovering it later is.
- Which methodology do you follow? NIST SP 800-115 and PTES are the names you'll hear, though both are dated and PTES hasn't been meaningfully maintained since around 2014. What matters more is whether they can walk you through their own documented process, with OWASP testing guidance where web interfaces sit in scope. A vendor who can't name anything is improvising.
- How do you approach an internal test against Active Directory? A tester who can't talk fluently about credential relaying, Kerberos abuse, or the route from a standard user account to Domain Admin is running a scanner and writing it up.
How to spot a scan dressed up as a pentest
Vulnerability scanning is genuinely useful. Run it monthly, feed it into patching, sell it as its own service. It just isn't a penetration test, and some vendors resell it as one because the margin is excellent when nobody opens the file.
Four questions that expose it.
- How many hours of human testing are in this price? A real quote has a number. A scan resale gets vague immediately.
- What did you remove from the raw tool output before writing the report? Manual validation means false positives got deleted. If the finding count matches the scanner's count, nobody validated anything.
- Show me a finding a scanner could not have produced. Chained privilege escalation, an authentication bypass in a business workflow, segmentation that failed between two VLANs that were supposed to be isolated. Any real report has several.
- What happens if you find nothing serious? The honest answer is that it happens occasionally and the report says so plainly. The bad answer is a padded list of informational items assembled to justify the invoice. You'll know it when you see it: fourteen findings, not one of them exploitable.

Three kinds of vendor, side by side
| Channel-only partner | Firm that sells both ways | Scan and ship shop | |
|---|---|---|---|
| Who owns the client | You, structurally | Contested from day one | You, until they read the report |
| Brand on the deliverable | Yours | Co-branded at best | Whatever the tool prints |
| After the findings | Remediation work routes to you | Their services team pitches | Nobody follows up |
| Non-solicit | Standard in the MSA | Negotiable, narrowly | Not offered |
| Manual hours quoted | Explicit | Varies by account size | Effectively zero |
| What you're buying | Capacity under your brand | A competitor's capacity | A PDF |
The middle column is where most MSPs get hurt, because those firms are usually the most technically impressive on the call. Capability isn't the problem. Alignment is.
What should disqualify a vendor on the spot
The walk-away column in the checklist above covers what you'll catch in the first meeting. Two more are worth spelling out, because MSPs underrate both.
The first is any vendor who promises your client will pass an audit. Nobody can promise that. A vendor who says it is telling you they'll shape findings to fit the outcome, and you're the one who has to defend that report when somebody finally reads it properly.
The second is retesting quoted separately with no fixed window. That one costs more than you'd think. Findings get fixed, the client wants proof for their insurer or their auditor, and now you're selling a second engagement to prove the first one worked. Get the retest into the contract with a deadline attached.
Run one paid engagement before you commit
Shortlist three. Buy one small real engagement from your top choice, ideally against your own network or a friendly client who knows exactly what you're doing and why.
You're not testing whether they can find vulnerabilities. Most competent firms can. You're testing the things that only show up during delivery.
- How fast they respond when scope changes mid-engagement, because it will.
- Whether status updates arrive without you chasing them.
- Whether the report needed rewriting before you could send it to a client.
- Whether they held the schedule when the client contact went quiet for a week.
- Whether they told you about a critical finding immediately or saved it for the report.
That last behavior is the single best predictor of how the relationship goes. A partner calls you the same day. A subcontractor writes it up on page 34.
Frequently asked questions
What is the difference between a white label pentest partner and a subcontractor?
A subcontractor does the work and hands you a file. A partner writes the deliverable to be resold, joins a client call under your brand when you want technical backup, and contractually stays out of your accounts. The testing itself looks similar. The commercial structure around it doesn't, and that structure is what you're really selecting for.
How many network penetration testing companies should I evaluate?
Three. One isn't a comparison. Past four the differences stop being informative and the process stalls for a quarter. Score them on report quality, channel terms and delivery discipline. Price comes fourth, and if it comes first you'll end up with a scanner subscription.
Should my client ever talk to the tester directly?
Sometimes, and it's your call rather than the vendor's. A technical clarification call with you on the bridge is efficient and makes you look well connected. What should never happen is the tester and your client scheduling something between themselves.
Do certifications matter?
They matter as a floor, not as a ranking, and they don't all prove the same thing. OSCP is a 24-hour hands-on exam, so it confirms the person has genuinely exploited something under time pressure. GPEN is a knowledge exam with some hands-on lab questions, so treat it as evidence of methodology, not of exploitation under pressure. Neither tells you whether that person writes a report a business owner can act on. The sample report tells you that.
How should I price a resold network pentest?
Price the outcome, not the day rate. Your client is buying an answer to a board question, an insurance requirement or a customer security review, plus your interpretation and your remediation plan. Quote cost plus a percentage and you've positioned yourself as a reseller, which is exactly the position you get squeezed out of at renewal.
Where to start this week
Pick your three. Ask the direct sales question first, because it's the only one where a wrong answer costs you a client rather than a bad document.
Then read the reports. All of them, all the way through, including the appendices nobody reads. That's where the real difference lives.
If you want a scoped price plus a full sample report to benchmark the other two against, get a pentest quote and we'll send both.



.avif)
.png)
.png)
.png)

