Inclusion & corrections

Submit a company or request an update

We add or change a listing when the evidence checks out against a primary source. Here is exactly what that means, and why one particular link matters more than everything else you could send.

Last updated: September 2026

Read this first

Submitting information does not guarantee inclusion, a particular position, or a response by any deadline. This page has no backend: there is no form, no database and no automated acknowledgement. It is an email route with a documented evidence standard, and the address below is a placeholder until the domain mailbox is live.

What to send

  1. Company legal name and official domain. The registered entity name, not only the trading name — registers list the former and buyers search the latter, and the mismatch is a recurring source of error.
  2. UAE office address or entity registration, if you have one. This matters more than it might seem: several profiles on this site currently cannot establish whether "Middle East coverage" means a UAE presence or remote delivery from another country, and that is a real question for a buyer weighing timezone, escalation and where test data sits.
  3. Every accreditation you claim, each with a direct link to the issuing body's own register entry. A CREST claim should link to your profile on the CREST Marketplace. A Dubai Cyber Force claim should link to, or quote, your entry on DESC's certified-provider list, with the certificate reference and expiry date.
  4. Services relevant to external penetration testing specifically — external network, web, API, cloud or mobile scope — and whether testing is manual, automated, or a stated mix.
  5. Whether a retest of fixed critical and high findings is inside your base statement of work or billed separately. This is one of our five criteria and the answer is rarely on a vendor website.
  6. Any publicly shareable evidence of delivery: a published case study, a named client reference, dated press coverage, or a redacted sample report.

Why we insist on register links

Because the alternative does not work. Several companies in our research pool state an accreditation on their own marketing pages that we could not find on the certifying body's register — see the flagged entries on the PentestME and Wattlecorp profiles for the two current examples. In both cases a single register link would settle the question immediately, in the company's favour if the accreditation is current.

Two distinctions we ask you to be precise about, because vendor marketing routinely blurs them:

  • Company accreditation is not individual certification. A team holding CREST individual certificates is a genuine credential and a different claim from the company being CREST-accredited. Tell us which one you mean and we will publish that one.
  • A logo is not a register entry. A DESC or CREST mark on a website establishes that a company has the image file. We check the register.

What happens next

We cross-check what you send against the primary source before anything changes. Unverifiable claims are not published as fact even when they come directly from the company they concern — they are either left out or shown with an explicit "not independently confirmed" note, which is how every other profile on this site is handled. If your evidence moves a claim from flagged to confirmed, the profile is updated and the page carries a new updated date.

If we decline to add a company, it is usually one of three reasons: the services fall outside our scope of external penetration testing, no source outside the company's own marketing could be found, or the register did not corroborate the accreditation the positioning depends on.

Requesting a removal or a correction

Listed companies use this same route to correct their own profiles, including asking us to remove a flag once the underlying evidence exists. If you believe a characterisation is unfair rather than factually wrong, say which sentence and what the accurate version is — we will assess it against the same standard and, where we got it wrong, fix it and date the change.

Where to send it

listings [at] best-external-penetration-testing-companies.com — placeholder until the domain mailbox is live.

Please put the company's legal name in the subject line. For anything that is not a listing matter, use the contact page instead. Our evidence standard is set out in full in the editorial policy, and the criteria that decide position are on the methodology page.