Buyer's guide

Choosing a penetration testing company in South Africa

South Africa has a genuinely strong security industry, from long-established consultancies to newer platform providers. The hard part is not finding one. It is working out which model fits what you actually need, and asking the questions that separate a real test from a scan with a cover page.

We build one of these products, so treat this as an informed but interested source. The questions below are the ones we would want asked of us.

Three delivery models

Most providers are a variation on one of these. Each has a real trade-off.

Traditional consultancy

A team of testers scopes and runs a fixed engagement, usually annually or before an audit. Deep, human-led, and the right answer for complex business logic, chained exploitation and red-team work.

Trade-off: Priced per engagement (commonly R50 000 to R150 000), booked weeks out, and accurate for the date it ran. Your next release is untested until the next engagement.

Platform / PTaaS

Testing runs continuously from a platform you start on demand, with findings tracked between runs. Suits teams shipping regularly who need a current answer rather than an annual snapshot.

Trade-off: Automated depth is excellent on well-understood classes and weaker on novel business logic. Ask what the platform does NOT test, and whether human testing is available alongside it.

Freelance and bug bounty

Individual testers or a crowd, paid per engagement or per finding. Can surface creative findings a methodology misses, and the economics are attractive at small scale.

Trade-off: Coverage is not guaranteed and reporting quality varies. Rarely sufficient on its own where an auditor or a customer questionnaire expects a structured, dated report.

Six questions to ask any provider

Ask every shortlisted provider the same six and compare the answers. The differences that matter rarely appear on a pricing page.

01

What exactly is in scope, and what is explicitly out?

Get the target list in writing: domains, IP ranges, APIs, cloud accounts. Ambiguous scope is the most common cause of a disappointing report.

02

Is the testing authenticated?

Most real risk sits behind a login. A test that only sees the logged-out surface will miss access-control flaws entirely, which are the findings that matter most.

03

Will you test with more than one user identity?

Proving that user A can reach user B's data requires two accounts. Without a second identity, cross-user authorization simply cannot be assessed, and a report that stays silent on it is not the same as a clean result.

04

How do you distinguish a proven finding from a suspected one?

Ask how evidence is graded and what a report row actually contains. A list of possible issues with no evidence attached is a scan, whatever it is called.

05

What happens after the report?

Ask about retesting: is it included, does it cost extra, and how long do you have. A finding is not closed until someone has confirmed the fix.

06

Where is our data stored, and for how long?

Findings describe your weaknesses, so the report is sensitive. Under POPIA you need to know where it lives, who can read it, and when it is deleted.

POPIA, and where your report lives

A penetration test report is a catalogue of your weaknesses, and often contains personal information encountered during testing. Under POPIA that makes it sensitive in its own right. Ask where findings are stored, who inside the provider can read them, how long they are retained, and whether any of it leaves South Africa. A provider who has not thought about the security of their own report storage is telling you something.

Penetration testing and POPIA

Where PentestMe fits

We are the platform model. Testing runs on demand across web, API, network, cloud, email and VoIP, findings are graded by the strength of the evidence behind them, reports arrive the same day, and pricing is published in Rand rather than quoted. Our team holds OSCP and CEH certifications, and manual engagements are available where a scope needs a human tester.

Where we are not the right fit

  • You need CREST accreditation. Some enterprise and public-sector procurement mandates it. We hold OSCP and CEH, not CREST. If your tender requires it, you need a CREST-accredited provider.
  • You need a full red-team exercise. Multi-week adversary simulation with physical and social-engineering components is consultancy work, not platform work.
  • Your application is deeply bespoke. Highly unusual business logic benefits from a human tester who can spend days understanding the domain. Our manual engagements cover this; the platform alone will not.

Frequently asked questions

How much does a penetration test cost in South Africa?

A traditional consultancy engagement typically runs R50 000 to R150 000 for a single assessment, depending on scope and depth. Platform subscriptions are lower and continuous: PentestMe plans start at R3 449 a month for two pentests. See our cost breakdown for the full comparison.

What certifications should a penetration tester have?

OSCP is the most widely recognised hands-on qualification; CEH is common and more theoretical; CREST is an organisational accreditation some enterprise and government buyers require. Ask which certifications the people testing your systems actually hold, not just what the company website lists.

Does POPIA require a penetration test?

POPIA does not name penetration testing specifically. It requires appropriate, reasonable technical and organisational measures to secure personal information, and expects them to be kept current. Testing is the usual way an organisation demonstrates it has identified and addressed risks to that information.

How long does a penetration test take?

A consultancy engagement usually runs one to three weeks of testing plus a reporting period, and is booked in advance. Platform-based tests typically complete the same day they are started.

Should I shortlist more than one provider?

Yes. Ask each the same scope and evidence questions and compare the answers rather than the brochures. The differences that matter — authenticated testing, multiple identities, how evidence is graded, whether retesting is included — rarely appear on a pricing page.

Judge the report, not the brochure

Run a real, validated pentest on your own target before you pay anything, and compare what comes back against anyone else you are considering. No credit card.

Start your free pentest