A non-ranked list of six Ho Chi Minh City providers publishing website, web app security assessment or penetration-testing services, with a method for separating scope before requesting proposals.
- The six providers appear alphabetically; this is not a ranking and no placement is sponsored.
- Friday Works publishes the article and is included; its current scope is explicitly a web app/API security assessment, not a full penetration-testing or Red Team programme.
- Information was checked against official service pages on 11 August 2026; compare proposals only after every provider receives the same assets, roles, methods, safety limits and deliverables.
Selection method and disclosure
This guide includes six providers with an official information-security assessment, security-assessment or penetration-testing service page and a published Ho Chi Minh City presence. Providers appear alphabetically. The list does not score companies, name a best provider or accept sponsored placement. Descriptions summarise published scope checked on 11 August 2026; buyers must still verify the delivery team, authorisation, methods and contract for their engagement.
Friday Works publishes the guide and is included in it. We disclose that conflict and our current limit instead of assigning ourselves first place: Friday Works provides scoped website, web app and API security assessments, not a full penetration-testing or Red Team programme. When a contract or compliance obligation requires an independent pentest, choose an appropriately capable provider and scope.
- An official page describing a security assessment or testing service.
- A published office, headquarters or operating location in Ho Chi Minh City.
- Enough scope detail to distinguish an assessment from a broader penetration test.
- Google position, reviews and third-party lists are not treated as evidence of quality.
Two security quotations are not comparable when one is a scoped review and the other a deep penetration test. Normalise objectives and deliverables before looking at price.
A quick comparison of published scope
CMC Cyber Security, HPT, IPSIP and Robusta publish penetration testing across surfaces such as web, mobile, APIs, networks or infrastructure. HISSC publishes Hi-Pentest within a broader information-security portfolio. Friday Works publishes scoped website, web app and API security assessment. These services can appear for the same search but are not automatically substitutes.
Define the decision the report must support before shortlisting: a pre-launch baseline, review of authentication or payment, customer assurance, audit evidence or deeper attack simulation. That objective determines the assets, accounts, methods, exploit limits, evidence, executive report, engineering detail and retesting required.
- CMC Cyber Security: published web, mobile, API, network, cloud and IoT/OT penetration testing.
- Friday Works: scoped website, web app and API assessment; not a full pentest or Red Team programme.
- HISSC: Hi-Pentest within monitoring, incident-response and information-security services.
- HPT: web, mobile, API, network, cloud, IoT and source-code security testing.
- IPSIP: website, web app, API, mobile, network and cloud pentest with reports, remediation guidance and retest.
- Robusta: information-security assessment across websites, servers, databases, networks, mobile and social engineering.
CMC Cyber Security
CMC Cyber Security's official service page describes controlled penetration testing for web applications, mobile, APIs, networks, cloud and IoT/OT. Published web scope includes websites, service portals, internal applications, authentication, authorisation and business logic. Its process moves through information collection, threat modelling, analysis and exploitation to reporting, remediation guidance and retesting. The company publishes a Ho Chi Minh City address.
It is worth researching when an organisation needs a programme broader than one website or has infrastructure and compliance requirements. A proposal should still name every system, exploitation depth, environment, responsible specialists, testing window, stop conditions and the evidence that may be retained.
- Separate web, API, mobile, cloud and network into acceptance scopes.
- Confirm manual and business-logic testing versus tool-based work.
- Put retesting, evidence handling and retention periods in the agreement.
Friday Works
Friday Works provides scoped website, web app and API security assessments in Ho Chi Minh City. Work focuses on attack surface, configuration, authentication, authorisation and important business flows. Deliverables include reproducible findings, impact, remediation direction, an engineering walkthrough and retesting within the agreed boundary.
The current service is not described as a full penetration test or Red Team engagement. It is worth researching when a development team needs a focused baseline before launch or after a major change and wants direct collaboration with a web-app team. Requirements for certification, deep infrastructure work, social engineering or an independent pentest report need an appropriately confirmed provider or partner.
- Assess Friday Works with the same scope, report sample and retest criteria as every candidate.
- Require explicit exclusions and safe exploit-validation limits.
- Do not interpret a scoped assessment as proof that a system is absolutely secure.
HISSC
The official QTSC profile for Ho Chi Minh City Information Security Services Corporation publishes Hi-Pentest for identifying vulnerabilities and security risks across networks, applications, servers and connected devices. Its wider portfolio includes monitoring, malware analysis, endpoint protection, training and exercises, and it publishes an address in Quang Trung Software City.
HISSC is worth researching when the requirement belongs to a broader information-security programme or may connect to monitoring and incident response. Ask the proposal to explain how Hi-Pentest applies to the company's exact assets, its references, application-testing depth, reporting, retesting and named responsibility.
- Confirm web app and API scope rather than inferring it from the broader portfolio.
- Clarify the relationship among pentest, monitoring, response and bundled services.
- Request a sanitised report sample and closure criteria for findings.
HPT
HPT publishes penetration testing for public-facing web, mobile, APIs and email, together with networks, servers, Active Directory, cloud, IoT, automation systems and source-code security testing. Its service page describes findings with exploitation steps, impact, remediation and severity, and HPT publishes a Ho Chi Minh City headquarters.
That breadth is worth researching when application, infrastructure or source review must be combined. Require the proposal to separate every surface, method and user role, then explain how duplicate signals across scanners, manual validation, source review and network testing are consolidated.
- Require a matrix of assets, methods, accounts and testing depth.
- Confirm executive and engineering reporting for the relevant audiences.
- Agree retest, response times and escalation when a test creates operational risk.
IPSIP
IPSIP publishes pentest services for websites, web applications, mobile, APIs, networks, servers, cloud, wireless and IoT. Its service page distinguishes vulnerability assessment from pentest, describes tools plus manual testing, and lists executive and technical reports, severity, evidence, remediation advice and retest options. It publishes a Ho Chi Minh City address.
IPSIP is worth researching for a multi-surface pentest or when security operations services may also be required. The proposal should name assets, roles, business-logic depth, references, impact limits and retesting rather than relying on a generic package name.
- Compare equivalent asset types and exploit-validation depth.
- Confirm the delivery team, testing window and emergency stop contact.
- Separate penetration testing, retesting and ongoing operational services in the price.
Robusta
Robusta publishes penetration testing that combines manual work with supporting tools to verify weaknesses and reduce false positives. Its assessment portfolio covers websites, servers, databases, networks, mobile applications, social engineering and broader information-security posture. The same official page publishes its Ho Chi Minh City headquarters.
It is worth researching when scope extends across applications, infrastructure or people. Because social engineering and active testing carry different legal and operational risks from a web review, separate authorisation, targets, timing, prohibited actions, permitted data collection and incident handling for every component.
- Do not combine social engineering and web pentest under one ambiguous scope.
- Ask for evidence of manual validation and false-positive handling.
- Agree rules of engagement, data protection and retest criteria before work begins.
Turn six providers into three comparable proposals
Choose three candidates by the decision you need to make, not position in this guide. Send one brief listing domains, applications, APIs, environments, roles, sensitive data, high-consequence flows, recent changes, the testing window and prohibited actions. State whether the report supports engineers, customers, auditors or the board.
Normalise proposals into objective, assets, accounts, methodology, manual testing, exploit validation, business logic, safety limits, references, reports, evidence, walkthrough, retest, data protection and exclusions. Compare price only when scope and responsibility are equivalent; a cheaper quote that omits APIs or administrator roles is not the same service.
- Shortlist three providers whose published scope best matches the requirement.
- Send one brief, one asset set and allow equivalent question time.
- Request a sanitised report sample and sample rules of engagement.
- Score evidence, testing safety, remediation usefulness and retesting.
FAQ
Frequently asked questions
Which is the best website security assessment provider in Ho Chi Minh City?
No provider is best for every scope. A focused assessment, web app pentest, network pentest, source review and Red Team programme require different capabilities and rules of engagement. Shortlist three suitable providers and score evidence, testing safety, reporting, remediation support and retesting.
Is this a ranking of penetration-testing companies?
No. The six providers appear alphabetically, receive no score and have no sponsored placement. Some publish broad pentest services, while Friday Works publishes scoped web app/API assessment; this guide does not treat those scopes as equivalent.
Does Friday Works provide a full pentest or Red Team programme?
It is not currently advertised that way. Friday Works provides scoped website, web app and API security assessment with agreed evidence, remediation guidance and retesting. Full pentest or Red Team requirements need separate confirmation of capability, partners, authorisation and responsibility.
How many security proposals should a company request?
Three proposals are usually enough when every candidate receives the same assets, roles, objectives, depth, safety limits, deliverables and retest requirement. More quotations with different scopes do not create a valid comparison.
When was the shortlist information checked?
Published service scope and Ho Chi Minh City presence were checked against official pages on 11 August 2026. Services, teams and locations can change, so verify directly before contracting.
References
Sources used in this guide
We prioritise official guidance and primary technical sources. Visit each source for full context and the latest updates.
- Dịch vụ Tấn công kiểm thử lỗ hổng bảo mật (Pentest)CMC Cyber Security ↗
- Dịch vụ đánh giá bảo mật website, web app và APIFriday Works ↗
- Công ty Cổ phần Dịch vụ An toàn Thông tin Thành phố Hồ Chí MinhQTSC / HISSC ↗
- Dịch vụ kiểm thử xâm nhậpHPT ↗
- Dịch vụ đánh giá xâm nhập hệ thống PENTESTIPSIP ↗
- Tư vấn & triển khai giải pháp bảo mậtRobusta ↗
