Testing is a way of asking questions
A penetration test answers a specific question: could someone with this access reach that asset? Framed that way, it is much easier to choose scope and judge results.
Scope matters more than tools
The most useful tests are scoped around what you cannot afford to lose: customer data, payment flows, admin access. Agree those targets in writing before anyone runs a scan.
Findings are the start
A report is only valuable if it leads to fixes. Ask for findings ranked by business impact, reproduction steps your developers can follow, and a retest to confirm they are closed.
Do it on a rhythm
Systems change, so test after major releases and at least once a year. Treat it as maintenance, not a one-off project.