Penetration Testing Services: How to Choose, and When to Choose Someone Else
Most pages like this one tell you every buyer should pick the vendor who wrote the page. This one does not. Matproof Sentinel is an AI penetration testing platform. It runs ten agents and a ValidatorAgent that stamps every finding VALIDATED, UNVERIFIED or FALSE_POSITIVE. It has no human penetration tester behind it, and Matproof holds no CREST membership, no NCSC CHECK approval and no FedRAMP 3PAO accreditation. That rules us out of some work, and we would rather tell you now than after you have paid. Below: which requirement actually applies to you, what to ask any provider, and where a platform beats a consultancy.
Choosing a provider: five questions that decide it
Start with the contract, not the vendor. Read your customer's security schedule, your tender documents and your regulator's text before you shop, because they usually name the answer. If a scheme is named, buy from someone accredited under that scheme and stop reading comparison pages. If nothing is named, you are free to choose on merit, and merit comes down to five questions. First: does the provider prove each finding, or forward scanner output? A finding without proof wastes your engineers' time. Second: does the report map to the controls your auditor checks, or must you translate it? Third: how current will the evidence be? The NCSC is blunt that a penetration test validates known issues on the day of the test, and notes that a year or more often passes between tests. Fourth: is the re-test after remediation in the price, or billed again? This single question moves budgets more than any other. Fifth: can you get a price without a sales call? Most cannot publish one, because they price by day against a custom scope. That is a fair reason, but it still costs you weeks. Match the answer to the job. A platform is the right buy for web, API and external testing that has to run all year. A human team is the right buy for social engineering, physical entry, red teaming, and anything that needs a person to improvise.
- Read the contract first. If it names CREST, CHECK, CBEST, ASSURE or a 3PAO, that decides your shortlist before merit does.
- Ask for proof of exploit per finding. Scanner output dressed up as a pentest is the most common way buyers get short-changed.
- Ask whether the report maps to your framework. An unmapped technical PDF is homework, not evidence.
- Ask whether the re-test is included. Many firms bill it a second time, and it is rarely in the headline price.
- Ask about lead time. Weeks of scheduling means the report describes a build you have already replaced.
- Check who does the work and what they hold. Certificates sit with people, not with the company logo.
- Check insurance. A test is a controlled attack on live systems. Ask what covers you if something breaks.
What Matproof Sentinel covers
- Recon: nmap, amass and httpx map the attack surface before anything is probed.
- Web: OWASP Top 10 coverage with nuclei, sqlmap and OWASP ZAP.
- API: REST and GraphQL against the OWASP API Security Top 10.
- Infrastructure: exposed services, edge devices, TLS and DNS with testssl.sh.
- Cloud: configuration and IAM checks with Prowler, on Growth and above.
- Mobile: iOS and Android packages with MobSF, on Growth and above.
- Source code and supply chain: Semgrep, Gitleaks and Trivy read the repositories you connect.
- Validation: a ValidatorAgent re-runs every finding and stamps it VALIDATED, UNVERIFIED or FALSE_POSITIVE.
- Reporting: PDF, JSON and SARIF 2.1.0, mapped to ISO 27001, SOC 2, NIS2, DORA, PCI DSS and HIPAA controls.
- Domain ownership is confirmed by DNS TXT or an HTTP file challenge before any traffic is sent.
Sample finding
The honest comparison, both ways
A traditional firm gives you a named tester, an accreditation you can show a customer, and the ability to improvise against your business logic. It also gives you a scoping call, a wait of weeks, a report describing one day, and often a second invoice for the re-test. A platform gives you a price up front, a report in about half an hour, testing that runs all year, and machine-readable output your pipeline can consume. It does not give you a human, an accreditation, social engineering or zero-day research. Neither is better in the abstract. They answer different questions. 'Can I show a client a signed report from an accredited firm' is one question. 'Is the build I shipped this morning clean' is a different one.
Fix: Work out which question you are being asked, and by whom. If it comes from a procurement team, a tender or a regulator naming a scheme, buy the accreditation. If it comes from your own engineers or an auditor asking for evidence across a period, buy continuous testing. If both are being asked, buy both: one accredited engagement a year for the signature, continuous automated testing for the evidence in between. That is what most mature teams end up doing, and it usually costs less than two annual engagements.
Reference: NCSC penetration testing guidance (reviewed 10 January 2022) · NCSC CHECK · PCI DSS v4.0 requirement 11.4 · Matproof pricing at matproof.com/pricing
Free scan, Matproof Sentinel, and a traditional firm
| — | Free scan | Matproof Sentinel | Traditional consultancy |
|---|---|---|---|
| Price published before a sales call | ✓ | ✓ €149 / €299 / €1,490 / Custom | Rare |
| Human penetration tester | ✗ | ✗ AI agents only | ✓ |
| CREST, CHECK or 3PAO accreditation | ✗ | ✗ Matproof holds none | Available from accredited firms |
| Proof of exploit per finding | ✗ | ✓ ValidatorAgent re-runs each one | ✓ |
| Findings labelled VALIDATED / UNVERIFIED / FALSE_POSITIVE | ✗ | ✓ On every finding | ✗ Usually severity only |
| Social engineering, phishing, physical entry | ✗ | ✗ Out of scope | ✓ On a red team engagement |
| Zero-day research | ✗ | ✗ Out of scope | ✓ At the top end |
| Testing between annual engagements | ✗ | ✓ Continuous | ✗ Point in time |
| Findings raised in your issue tracker | ✗ | ✓ GitHub issues, deduped across re-tests | |
| Machine-readable output | ✗ | ✓ SARIF 2.1.0 and JSON | Usually PDF only |
| Published method | n/a | ✓ docs.matproof.com, including what it will not do | Varies |
Which requirement actually applies to you
Market: United Kingdom and United States · Figures checked on 19 August 2026. Every row links to the page the number comes from.
| Scope | Published price | What it covers | Source |
|---|---|---|---|
| UK public sector or CNI, systems at OFFICIAL and above | NCSC CHECK company | NCSC says such systems should be assessed by a CHECK-assured company | NCSC, using a CHECK provider |
| UK private sector, no contractual demand | No scheme required | The NCSC does not tell private organisations to use CHECK | NCSC, CHECK penetration testing |
| UK systemically important financial firms and FMIs | CBEST accredited provider | Bank of England framework, run with the PRA and FCA | Bank of England, CBEST threat intelligence-led assessments implementation guide |
| UK Cyber Essentials Plus | IASME-accredited certification body | CREST is not the gate. IASME sets the assessor qualification | IASME, Cyber Essentials |
| Card data environments under PCI DSS v4.0 | Internal and external test every 12 months | Req. 11.4.2 and 11.4.3. No certification named. Asks for a qualified party and organizational independence | PCI Security Standards Council, PCI DSS v4.0 SAQ D for Merchants |
| New York covered financial entities | Penetration test at least annually | 23 NYCRR 500.5(a)(1), inside and outside the boundary, by a qualified party | NYDFS, Second Amendment to 23 NYCRR Part 500 |
| US defense contractors at CMMC Level 3 | Penetration test at least annually | 32 CFR 170.14. Level 1 and Level 2 do not require one | 32 CFR 170.14, CMMC Level 3 requirements |
| US federal cloud services under FedRAMP | Accredited 3PAO | 3PAOs are accredited by A2LA against ISO/IEC 17020 | FedRAMP, penetration test guidance version 3 |
| US healthcare under HIPAA | No penetration test required today | 45 CFR 164.308(a)(8) asks for a periodic evaluation. The word penetration does not appear | 45 CFR 164.308, HIPAA Security Rule administrative safeguards |
| SOC 2 audits | No penetration test required by the framework | The Trust Services Criteria do not name it. Auditors and buyers usually ask anyway | PCI Security Standards Council, PCI DSS v4.0 SAQ D for Merchants |
Read this before you shop. Buyers routinely pay for an accreditation that nothing in their world asks for, and skip the one their contract does ask for. Every row links to the body that runs the scheme.
Sources
- NCSC, CHECK penetration testing — No date shown on page
- NCSC, using a CHECK provider — No date shown on page
- NCSC, penetration testing guidance — Published 8 August 2017, last reviewed 10 January 2022
- CREST — No date shown on page
- CREST, CHECK membership requirements — No date shown on page. States deadlines of 31 March 2025 and 31 March 2026
- Bank of England, CBEST threat intelligence-led assessments implementation guide — No date shown on page
- IASME, Cyber Essentials — No date shown on page
- PCI Security Standards Council, PCI DSS v4.0 SAQ D for Merchants — Publication date April 2022
- NYDFS, Second Amendment to 23 NYCRR Part 500 — Dated 1 November 2023. Section 500.5 compliance date 1 May 2025
- 32 CFR 170.14, CMMC Level 3 requirements — Current text as published by Cornell LII
- 45 CFR 164.308, HIPAA Security Rule administrative safeguards — 68 FR 8376 (20 February 2003), amended 78 FR 5694 (25 January 2013)
- FedRAMP, penetration test guidance version 3 — Dated 30 June 2022
- A2LA, FedRAMP 3PAO accreditation — No date shown on page
- Precursor Security, penetration testing rate card — Page marked updated August 2026
- Synack, platform pricing — No date shown on page
Matproof Sentinel pricing (public, no quote required)
- 10 specialised AI agents + ValidatorAgent
- Web + API + Infra + DNS/TLS coverage
- Up to 50 target URLs per scan
- PDF + SARIF 2.1.0 + JSON export
- SOC 2 / ISO 27001 / DORA / NIS2 mapping
- Open methodology (docs.matproof.com)
- 3 full Sentinel pentests per month
- All 10 agents (Web / API / Infra / Source-Code)
- GitHub App + auto-created GitHub Issues
- Up to 50 target URLs per scan
- Remediation-diff metric across re-tests
- SOC 2 / ISO 27001 / DORA / NIS2 evidence
- 20 Sentinel pentests per month
- Additional scans at €149 each
- All 10 agents incl. Cloud (Prowler) + Mobile (MobSF)
- Continuous schedules — hourly / daily / weekly
- Authenticated scanning (session cookies, bearer tokens)
- Webhook delivery + priority support
- Everything in Growth + unlimited targets
- SupplyChain agent on (Trivy: deps + containers + IaC)
- SSO / SAML, role-based access
- Custom compliance mapping (PCI DSS, HIPAA, BaFin MaRisk, NEN 7510)
- Dedicated success manager + SLA
- Private deployment options
Frequently asked questions about penetration testing services
What should I look for in a penetration testing company?
Five things. Proof of exploit on every finding, not scanner output. A report mapped to the controls your auditor checks. Short lead time and a cadence that matches how often you ship. Re-tests included rather than billed again. A price you can get without a sales call. Before any of that, read your contract: if it names a scheme, that decides your shortlist.
Do I need a CREST-accredited provider?
Only when something asks for it. No UK law requires CREST. CREST is a private accreditation body and a delivery partner for NCSC CHECK, Bank of England CBEST, Cabinet Office GBEST and UK CAA ASSURE. For UK public sector and CNI systems at OFFICIAL and above, the NCSC guidance points to CHECK. If you are not public sector or CNI, the NCSC does not tell you to use CHECK. Your customer's security schedule might, so read it first.
What is the difference between CREST and CHECK?
CHECK is the NCSC's own assurance scheme, and it exists so that public sector and CNI systems are tested by assured companies. CREST is an independent accreditation body that operates internationally and acts as a delivery partner for CHECK and other UK schemes. CHECK is scoped to UK public work. CREST is a market signal that also underpins several regulated schemes.
Is there a US equivalent of CHECK?
Not for general commercial work. The closest is FedRAMP 3PAO accreditation, which applies only to federal cloud services and is granted by A2LA against ISO/IEC 17020. In the US, OSCP, GIAC GPEN and CREST are market signals. No US rule we checked names a certification. PCI DSS asks for a qualified party with organizational independence, and NYDFS asks for a qualified internal or external party.
Does Matproof hold CREST or CHECK?
No. Matproof holds no CREST membership, no NCSC CHECK approval and no FedRAMP 3PAO accreditation, and we employ no human penetration tester. Sentinel is an AI platform: ten agents plus a ValidatorAgent that stamps each finding VALIDATED, UNVERIFIED or FALSE_POSITIVE. If your buyer needs a CREST-signed report for a contract, hire an accredited firm. We would rather say that than sell you the wrong thing.
Are automated penetration testing services credible?
For web applications, APIs and external infrastructure, a platform that proves each finding covers the ground most audits check, and it runs all year rather than once. It is not credible as a substitute for social engineering, physical entry, red teaming or bespoke legacy work, and we do not claim it is. Judge a platform on whether it validates findings and publishes its method. Ours is public at docs.matproof.com, including the list of what it will not do.
Will this help us pass an ISO 27001 or SOC 2 audit?
It gives you evidence, not a pass. Reports map to ISO 27001 A.8.8 and A.8.29, SOC 2 CC4.1 and CC7.1, NIS2 Art. 21 and DORA Art. 24, with proof of exploit, CVSS ratings and re-test verification. Continuous testing also evidences that a programme ran throughout a period, which is what surveillance and Type 2 audits look for. Note that the SOC 2 Trust Services Criteria do not actually name penetration testing. Your auditor's request list is what matters.
Do you provide penetration testing services in the UK and US?
Yes, in the sense that Sentinel is a platform and has no geographic scheduling constraint. Reports map to UK, EU and US frameworks. Pricing is published in euros only: €149 per run, €299 per month, €1,490 per month, and Custom. We do not publish a USD or GBP price list.
When not to buy Matproof Sentinel
Sentinel is an AI penetration testing platform and nothing more. Ten agents test, and a ValidatorAgent re-runs every finding before it ships. There is no human penetration tester behind it, and Matproof holds no accreditation of its own. Several kinds of work are therefore out of our reach, and we will point you elsewhere rather than take the order.
- No human penetration tester. AI agents find the issues. Another AI agent checks them.
- No CREST membership, no NCSC CHECK approval, no FedRAMP 3PAO accreditation. We cannot sign a report as an accredited assessor.
- No social engineering, no phishing simulation, no physical intrusion.
- No zero-day research and no improvised business-logic red teaming.
- Buy from an accredited firm if a customer contract, a tender, or a scheme such as CHECK, CBEST, GBEST or ASSURE names one.
- Buy from an accredited 3PAO if you are in a FedRAMP process.
- Ask your QSA before relying on an AI-only test for PCI DSS 11.4. PCI names no certification, but your QSA decides what qualified means.
- Hire a human team for OT and SCADA estates, mainframes, and anything that needs a person on site.
Start with a free scan, then decide who you need
Run a free scan to see your exposed surface and the report format. A full report costs €149. Continuous testing costs €299 a month. If it turns out you need a CREST-signed or 3PAO-signed report, we will tell you to hire an accredited firm.
Run free scan