Q-Sec Blog

External Penetration Testing Companies: How to Choose

Written by Q-Sec Security Operations Center | 07 Oct, 2026

Technical review by Volodymyr Garbar, CISO & Tech Lead
Updated: 6 October 2026

External penetration testing companies test the systems your organization exposes to the internet to find out where an outside attacker could get in. Depending on the scope, that can include public IP addresses, servers, VPNs, remote access services, web applications, APIs, cloud infrastructure, and other externally reachable assets.

Finding a company that offers this service is easy. Figuring out what you will actually get from the test is harder.

Two proposals can both say “external penetration test” and describe quite different work. One may focus mainly on network infrastructure. Another may include web applications and APIs. Some providers combine automated discovery with substantial manual testing. Others sell continuous or AI-assisted testing alongside traditional engagements.

The useful comparison is not whose website has the longest list of certifications. It is whether the company can test the attack surface you actually have and give your team findings they can act on.

Free playbook

Preparing for a PCI DSS penetration test?

The Q-Sec PCI DSS Penetration Testing Playbook covers scope, testing domains, readiness, and the evidence expected from the engagement.

Get the PCI DSS Penetration Testing Playbook

What is external penetration testing?

External penetration testing examines systems that can be reached from outside the organization's trusted network, usually from the perspective of an attacker who does not already have internal access.

That can start with reconnaissance: what domains, IP addresses, services, applications, and other assets are visible from the internet? Testers then investigate potential weaknesses and, within the agreed rules of engagement, try to exploit them and determine what access they provide.

The scope matters here. “External” does not automatically mean “scan our public IP addresses.”

A public-facing application or API may be one of the most important ways into the organization. Cloud services and remote-access infrastructure can also form part of the external attack surface. Before comparing quotes, check what each provider actually includes when it uses the term.

For a broader explanation of the different testing scopes, Q-Sec's guide to types of penetration testing covers external and internal networks, web applications, APIs, cloud environments, social engineering, and adversary simulation.

What should an external penetration testing company actually test?

There is no useful universal list of ten things that every external test must contain. Scope depends on the environment.

For a company with a small public perimeter, a focused infrastructure test may be reasonable. A SaaS business with several applications, APIs, cloud services, and customer-facing authentication has a very different external surface.

Before requesting proposals, map the systems an attacker can reach without already being inside your network. That gives you something concrete to discuss with providers.

Depending on the environment, an external engagement can cover:

  • Public IP addresses and exposed network services;
  • Firewalls, VPNs, and remote-access infrastructure;
  • Internet-facing servers and administrative interfaces;
  • Web applications and APIs;
  • Cloud-hosted services exposed to the internet;
  • Authentication and account-related weaknesses;
  • Misconfigurations and known vulnerabilities on public systems.

The test should also establish what happens after a weakness is found. A scanner can tell you that a service appears vulnerable. A penetration tester should be able to investigate whether that weakness is exploitable and, where the scope permits, what an attacker could reach from there.

That distinction is worth checking when comparing penetration testing companies. Some providers now mix traditional manual testing, automated vulnerability assessment, continuous testing, and AI-based testing under fairly similar product language.

How to compare external penetration testing companies

Price matters, but comparing quotes before comparing scope is a good way to buy the cheaper version of a different service.

I would check these areas first.

What is actually in scope?

Ask the provider to name the asset types covered by the proposal.

If you have a public application and APIs but the quote covers only IP addresses and network services, you have not necessarily found a cheap pentest. You may simply be buying a narrower one.

The proposal should also make exclusions visible. Nobody benefits from discovering halfway through the engagement that a critical customer portal was never included.

How much of the work is manual?

Automated tools belong in penetration testing. They are useful for discovery and for finding known weaknesses quickly.

The question is what happens next.

Ask whether testers manually validate findings, attempt controlled exploitation, investigate attack chains, and remove false positives before reporting. If the provider uses AI-assisted or automated penetration testing, ask the same thing in a slightly different form: which parts are automated, which involve human review, and what evidence is produced for a successful exploit?

Who will perform the test?

Company credentials are useful, but you are hiring the people who will work on your systems.

Ask about the experience of the assigned testers with your technology. Someone testing a conventional external network does not need exactly the same background as someone assessing a complex cloud environment or a large API estate.

You can also ask which methodology they work from. Q-Sec, for example, states that its testing uses recognized references, including the OWASP Testing Guide, PTES, NIST SP 800-115, and MITRE ATT&CK, depending on the engagement.

What will the report look like?

Ask for a sanitized sample.

It is one of the quickest ways to see what you are buying.

A useful report should tell the technical team what was found, where it was found, why it matters, how the finding was validated, and what needs to change. Someone outside the security team should also be able to understand the important risks without reading thirty pages of exploit output.

Is retesting included?

A finding marked “fixed” in Jira has not necessarily been fixed.

Ask whether the provider will retest remediated findings, whether that is included in the original price, and what documentation you receive afterward. This becomes particularly important when the report is being used as compliance or customer-assurance evidence.

For PCI DSS environments, external and internal penetration testing have specific roles under Requirement 11.4. Q-Sec's PCI DSS Penetration Testing Guide goes into the testing and retesting requirements in more detail.

External penetration testing companies to consider

External penetration testing companies to consider include Q-Sec, Cobalt, BreachLock, Pentest-Tools.com, and Intruder, among others. These providers offer different models, from consultant-led penetration testing and PTaaS to continuous security testing and automated assessment.

There is no single provider that makes sense for every organization. A small SaaS company looking for fast application testing has a different buying problem from a European financial entity that needs a wider infrastructure engagement and compliance evidence.

So rather than ranking companies from “best” to “worst,” the useful comparison is what each provider is set up to do.

Company External testing model What stands out Worth considering if
Cobalt Pentest as a Service (PTaaS) with a platform and pentester community External network testing combines reconnaissance, scanning, and manual exploitation, real-time findings, and retesting You want pentesting delivered through a mature PTaaS model and need to run engagements regularly
Q-Sec Consultant-led penetration testing with manual and automated testing Broad scope across external networks, web/API, cloud, Microsoft 365, AD, and adversary simulation; strong EU compliance focus You are a European organization that needs technical testing alongside NIS2, DORA, PCI DSS, ISO 27001, or similar compliance work
BreachLock PTaaS plus expert-led and autonomous testing options Covers external/internal networks, applications, APIs, cloud, IoT, and red teaming, with findings managed through its platform You want a broader offensive-security platform rather than only a traditional point-in-time pentest
Pentest-Tools Security testing platform plus full-service manual pentesting Strong emphasis on exploit validation and tooling that can also be used directly by internal security teams Your security team wants both access to pentesting tooling and the option to bring in human testers
Intruder Automated vulnerability management with manual testing options Combines continuous external scanning with managed services and manual assessments You want frequent external vulnerability monitoring alongside periodic human-led testing

These companies are not interchangeable, and that is the point.

For example, Cobalt structures external network testing around its PTaaS platform. Its published methodology includes reconnaissance, vulnerability scanning, manual assessment, reporting, triage, and retesting.

BreachLock also uses a PTaaS model, but its current offering extends across application, API, network, cloud, IoT, and red-team testing. It now also offers autonomous penetration testing alongside its human-led services.

Pentest-Tools comes from a slightly different direction. It provides tooling for security teams and professional testers, including exploit validation, but also offers full-service manual network penetration testing when a company does not want to run the assessment itself.

Intruder is useful to include because it illustrates another buying model. Its offering spans automated external vulnerability scanning, managed services, and manual assessment rather than treating every security check as a traditional consultant-led pentest. Its own guidance distinguishes these service levels.

And Q-Sec sits closer to the consultant-led end of the spectrum. Its current penetration testing scope covers external and internal networks as well as web/API, cloud, Microsoft 365, Active Directory, social engineering, and adversary simulation. It also explicitly maps engagements to European requirements, including NIS2 and DORA, alongside PCI DSS, ISO 27001, and SOC 2.

The company names matter less than this difference in delivery model. Before comparing prices, decide whether you need a one-off expert assessment, recurring human-led testing, continuous automated visibility, or some combination of the three.

Which external penetration testing company is right for your organization?

Start with what you need tested. It sounds obvious, but it removes a surprising number of bad-fit proposals.

If your main concern is a small set of public IP ranges, you may not need a provider with a huge application security platform. If your external attack surface includes APIs, several cloud environments, SaaS infrastructure, and customer-facing applications, a narrow network assessment is unlikely to tell you enough.

The second question is how often you need testing.

A project-based engagement can make sense before an audit, after a significant infrastructure change, or when an organization wants an independent assessment of a defined environment. Companies with frequent releases or a rapidly changing external attack surface may get more value from a PTaaS or continuous-testing model.

There is also a fairly practical compliance question.

If the penetration test will become part of your PCI DSS, DORA, NIS2, ISO 27001, or customer assurance evidence, tell the provider before the scope is agreed. You may need specific systems covered, evidence retained, tester independence documented, or remediation and retesting recorded.

For European organizations, Q-Sec's Penetration Testing Service is built around both technical testing and these compliance-driven engagements, including NIS2, DORA, PCI DSS, and ISO 27001.

Do you need a penetration testing company near you?

In most cases, a penetration testing company does not need to be physically located near your office. External networks, web applications, APIs, cloud environments, and many internal environments can be tested remotely when the provider has secure access to the agreed systems.

There are exceptions. Location matters more when the engagement requires physical access, on-site testing, or work that cannot be performed through an approved remote connection. Procurement rules, data-handling requirements, time zones, and the ability to work with your internal teams can also influence the choice.

For European organizations, I would look beyond physical distance. A provider's experience with European regulatory requirements, contractual expectations, data handling, and your technology stack is usually more useful than finding an office in the same city.

So if you search for “penetration testing companies near me,” the closest provider is not necessarily the most suitable one. Compare the scope, tester expertise, testing approach, reporting, retesting, and location requirements of the engagement first.

For a more detailed procurement checklist, see our Penetration Testing Vendor Evaluation guide.

How much do external penetration testing companies charge?

An external penetration test typically costs around €3,000–€15,000 in Europe, although small scopes can cost less and complex environments can go well beyond these ranges. The final price depends on the number of internet-facing assets, testing depth, applications and APIs in scope, reporting requirements, and whether remediation support and retesting are included.

There is no useful standard price for an external penetration test without a scope.

The number of public IPs or hosts matters, but it is not the whole quote. Applications, APIs, cloud infrastructure, authentication, testing depth, retesting, reporting requirements, and the amount of manual work can all change the effort involved.

Even providers scope the work differently. Cobalt, for example, asks customers to specify the number of active IP addresses for an external network pentest, while other types of assets use different scoping parameters.

This is why a quote of €4,000 and another of €8,000 do not tell you that one provider is twice as expensive until you know what both companies intend to test.

Ask for a written scope. Then compare the quotes line by line.

What should you include in an RFP or request for a pentest quote?

You do not need to write a miniature security policy to get a useful proposal.

Give providers enough information to understand the environment: the assets or IP ranges in scope, relevant applications and APIs, cloud services where applicable, your reason for testing, any regulatory requirements, expected timing, and whether you need remediation support or retesting.

Mention production constraints early too. If a system cannot tolerate particular testing techniques or there are strict testing windows, that belongs in the conversation before the engagement starts.

A provider may need more information during scoping. That is normal. In fact, a quote produced without much interest in what you actually run is something I would question.

For a PCI DSS engagement, the Q-Sec PCI DSS Penetration Testing Playbook gives teams a more detailed starting point for defining scope and preparing for the assessment.

External penetration testing company or automated testing platform?

This distinction has become less tidy than it used to be.

There are traditional consulting engagements, PTaaS providers, vulnerability-management platforms, autonomous pentesting products, and companies that combine several of them. BreachLock, for example, currently offers both expert-led PTaaS and autonomous testing, while Pentest-Tools.com combines security testing software with manual pentesting services.

Automation is useful. External attack surfaces change, and running automated checks more frequently than a yearly pentest can catch exposures between formal assessments.

But make sure you know what the product is doing.

An external vulnerability scan that identifies possible weaknesses is not automatically equivalent to a penetration test where testers validate exploitability and investigate what an attacker can do next. Intruder's own explanation of external pentesting describes manual investigation of scanner output, exploit validation, and chaining weaknesses as important differences between the two.

If you need both, buying both is perfectly reasonable. Just don't let similar product names hide the difference.

Final thoughts: before you choose a provider

Get the scope in writing. Ask who will do the work. Ask how findings are validated and what the report looks like. Check whether retesting is included.

And give the provider enough context to tell you when your proposed scope is wrong.

That last one is easy to overlook. You are paying for security expertise, not only for someone to execute the list of IP addresses you sent them.

FAQ

What does an external penetration testing company do?

It assesses internet-facing systems from an external attacker's perspective. Testing can include reconnaissance, vulnerability discovery, controlled exploitation, impact analysis, reporting, remediation guidance, and retesting, depending on the agreed scope.

What is included in an external penetration test?

The scope can include public IPs, servers, network services, VPNs, firewalls, web applications, APIs, and other internet-facing assets. The exact coverage should be agreed upon before testing begins.

How do I choose an external penetration testing company?

Compare the actual scope, manual testing depth, tester experience, methodology, reporting, remediation support, retesting, and experience with your technology and compliance requirements. Do not compare prices until you know the proposals cover equivalent work.

Is external penetration testing the same as vulnerability scanning?

No. Scanning identifies potential vulnerabilities at scale. Penetration testing adds human investigation and controlled exploitation to determine whether weaknesses are exploitable and what an attacker could achieve.

How often should external penetration testing be performed?

The appropriate frequency depends on risk, infrastructure changes, customer requirements, and applicable standards or regulations. Some organizations test annually, while others also test after significant changes or use continuous testing between formal engagements.

Can external penetration testing be automated?

Parts of it can. Automated tools can discover assets, scan for vulnerabilities, and increasingly validate some exploits. Human-led testing remains useful where judgment, complex attack paths, business logic, or unusual environments are involved.