How to check a tester's certifications and reputation
Verify a penetration tester's certifications, check registers, call references, and request sample reports. Here's what to check and ask before hiring.
You're about to hand someone access to your systems to deliberately break in. The difference between a skilled tester who surfaces real vulnerabilities and a careless one who costs you time and money—or worse, introduces new risks—comes down to credentials, track record, and who will vouch for them.
Verification isn't paranoia. It's the only reason to commission a test at all.
Search the registers
Start with the International Information Systems Security Certification Consortium. Search their registry at isc2.org for Certified Ethical Hacker (CEH), Offensive Security Web Expert (OSWE), or Offensive Security Certified Professional (OSCP) holders. The first two are administered by Ec-Council; the OSCP is Offensive Security's own credential and widely respected. Enter the tester's name and confirm the certification is active and hasn't lapsed. A valid entry isn't everything, but its absence is a red flag.
Ask the tester for their SANS certifications if they mention them—GIAC Security Essentials (GSEC), GIAC Penetration Tester (GPEN), or GIAC Web Application Penetration Tester (GWAPT) are genuine. You can verify these at giac.org. Similarly, CompTIA Security+ is entry-level but legitimate; check comptia.org.
If they work for a firm, that firm may hold industry accredences: ISO 27001 certification or CREST (Council of Registered Ethical Security Testers) listing in countries where CREST operates, or similar bodies. These don't guarantee individual competence but signal an organisation under scrutiny.
In South Africa, ask whether they're registered with the Professional Institute of the Public Service (PIPS), or if they're a solo operator, whether they hold a PSIRA security licence if they're positioning themselves as a security provider. Not all penetration testers will hold a PSIRA licence—the register applies mainly to guarding and investigative work—but if they claim security credentials, ask about their professional registration with any relevant body.
Request proof of work and references
Credentials prove someone sat an exam. References prove they did the job. Ask for the contact details of three organisations they've tested in the past two years—ideally in your sector or with similar scale. Call those references directly. Don't email; call. Ask: Did the tester deliver the test on schedule? Were the findings clear and actionable? Did they identify vulnerabilities you didn't know about? Would you use them again?
Ask the tester to describe a past engagement anonymously—not confidential findings, but the scope, approach, and outcome. A good tester should walk you through how they'd have approached your systems, what they'd look for first, and why. Red flags: vague answers, claims they find vulnerabilities in "almost every test," or refusal to discuss method.
Request samples of their report format—not real findings, but a template. A solid penetration test report includes an executive summary, a breakdown of findings by severity, proof of exploitation, remediation advice, and a clear methodology. If their template is thin or unstructured, the test itself probably will be too.
Ask about their test approach
A tester should ask *you* detailed questions before they start: What systems are in scope? Who are your users? What's your tolerance for downtime? Are there areas you've already tested? These questions show they're tailoring the engagement, not running a generic scan.
Watch how they describe methodology. Do they mention reconnaissance, social engineering, vulnerability discovery, and exploitation? Do they explain the tools they use and why? Generic answers like "we use industry best practice" are filler. Specificity counts.
If they're testing web applications, ask about coverage of the OWASP Top 10 and how they test for business logic flaws—not just SQL injection. If it's infrastructure, ask how they handle segmentation and multi-factor authentication testing. Their depth here reveals whether they think or just click.
Verify liability and scope in writing
Before signing, confirm they carry professional indemnity insurance and ask to see the certificate. A tester without insurance who damages your systems leaves you holding the bill. Agree on scope in writing—which systems, which user accounts they can use, which testing methods are off-limits (load testing, DoS simulation, etc.). Get a clear statement of what they will and won't do. This protects both of you.
A tester who resists questions, hides behind "it's confidential," or dismisses your concerns isn't hiding expertise—they're hiding gaps. When you're ready to move forward, Strove lets you compare testers side by side, see verified ratings and past client reviews, and message them directly before you commit.
Common questions
- What certifications should a penetration tester have?
- Look for CEH, OSCP, OSWE, GIAC certifications (GPEN, GWAPT), or SANS credentials. The OSCP (Offensive Security Certified Professional) and GIAC Penetration Tester are particularly well-regarded. You can verify most of these on the issuing body's website; ask the tester for their certificate number or entry ID.
- How do I verify a tester's credentials?
- Search the registry at isc2.org for Ec-Council credentials, giac.org for SANS certifications, and comptia.org for CompTIA certificates. Ask for the tester's certification number and verify it's active. Always call references directly—don't rely on email, and ask specific questions about past work.
- What questions should I ask their references?
- Ask: Did they deliver on time? Were findings clear and actionable? Did they identify vulnerabilities you weren't aware of? Would you hire them again? Also ask whether they tested similar systems and what the tester's approach was.
- What should a penetration test report include?
- A credible report contains an executive summary, findings ranked by severity with proof of exploitation, clear remediation steps, and a transparent methodology. Ask to see a sample report template before you hire; a thin or poorly structured template signals a weak engagement.
Find a verified provider on Strove
Compare vetted penetration testing providers, check their credentials, and book or request a quote — all in one place.
Find a Business