You paid for a PDF document that was passed off as a penetration test.
You spent money on a penetration test. All you received was an export from a scanning tool that had the consultant's logo on the report. ðŸŽ
The suit doesn't fit
Essendis hit the nail on the head in their 2026 pricing guide. They state the market is flooded with "cheap engagements that are a vulnerability scan wearing a suit."
That line is stuck in my head. Because that's the one thing founders can actually purchase.
Netragard raised a red flag on this: automated scans in pentest clothing. You push a button on the tool, push print on the report, and push the box on your checklist.
Nobody actually tried to break in.
Why the cheap thing keeps winning
Here comes the part no one likes to talk about. They aren't the ones to blame for this.
According to an analysis in January 2026 from Analogue Computer, the pentesting market is a "market for lemons," and "the market clears not at the price of risk reduction, but at the price of plausible deniability."
Read that twice. Customers are not buying security, they are buying a checkmark on an audit document.
In a more polished way, Lorikeet Security expressed the same idea in the beginning of 2026: "Compliance frameworks reward control presence over control effectiveness." An auditor inquires do you perform penetration testing?, receives a report, and ticks the box.
The vendor offering a scanner and PDF printer at a low price wins over the human chaining exploits.
What SOC 2 actually says (spoiler: not much)
People often assume that SOC 2 requires a pentest but in reality, it doesn't.
The AICPA's SOC 2 framework does not have the words "penetration test" in it. So, auditors have to rely on the coverage of Trust Services Criteria like CC7.1 in the case of detection and monitoring and CC4.1 in the case of monitoring activities and control evaluation.
Theater sneaks in through that gap - if your architecture never requires adversary emulation, why would you pay for it?
PCI DSS version 4.0 is the mature version to follow. Becoming fully mandatory in March 2025, it clearly separates vulnerability scanning (Requirement 11.3) from penetration testing (Requirement 11.4). Additionally, according to 11.4.4 of PCI DSS v4.0, any exploitable vulnerabilities must be corrected and then the testing must be repeated.
The last word is crucial here. Retested implies that the change that fixed the problem had to be confirmed by someone to actually work. A scanner cannot do that.
How to spot the scan in a suit
Essendis provided potential purchasers with the clearest information I have ever come across:
→ "A firm quoting sight-unseen is planning to run a scanner."
→ If the report looks like a raw export with a logo slapped on, you overpaid for a scan.
→ Real testing means manual business-logic probing, privilege escalation, chained exploits.
The price itself can be a pretty good indicator. For example, a legitimate web app pentest in 2026 will cost you somewhere between $5,000 and $30,000. If the quote is well below that range and it shows up before anyone has even seen your application, then you probably have your answer.
In February 2026, Linford & Co put out a manifesto, which they referred to as, "The Penetration Testing Mirage." In it, the firm stated, "running a commercial scanner and printing a PDF is not a penetration test... That is a commodity service that could be performed by an intern on their first day."
Tough, but true.
The takeaway
The problem isn't with the scanner. Scanners do their job well.
The real villain here is deception. The real deception happens when machine-generated content is passed off as the work of a human adversary, and the client is willing to buy into the charade because the box only sees the costume.
I understand the temptation. As a small team, when you're trying to finalize an enterprise deal, the cheapest option that satisfies the requirement seems like a victory. But one day, someone who doesn't just scan passes through your business logic and finds the door that you never tested. 😬
Here's something to think about. If the market recognizes only plausible deniability, the solution is not more intelligent auditors. It's the buyers who should change their question from "did we pass?" to "did anyone really try to break in?"
When you last bought a "pentest," did you check whether a human touched it, or did you just file the PDF and move on?
Top comments (0)