Judge an audit firm on evidence you can verify yourself: read two or three of their published reports in full, confirm who will actually be assigned, check whether clients corroborate the work on their own domains, and see whether the firm pushes back during scoping.
Contests are good at breadth and at finding what many eyes can find quickly. Private audits are better at deep protocol-specific logic, at systems that cannot be made public, and at continuity. Serious protocols increasingly use both, in that order: private audit first, contest after.
Audit pricing is driven by auditor-days, and auditor-days are driven by complexity rather than line count. A self-contained token and a cross-chain lending market of the same size are not comparable work. Expect scoping to depend on SLoC, composability, test coverage, documentation quality and how many auditors the system warrants.
Ask who specifically will be assigned and whether they are employees; how the firm prevents a team from converging on the same findings; what happens if you are exploited after the audit; and what the firm's methodology does not cover. The last one is the most revealing.
A smart contract audit reviews onchain code for logic and economic flaws. A web3 penetration test attacks the surrounding systems — backends, APIs, key management, infrastructure and frontends. A protocol needs both, because most systems are not purely onchain and the boundary between them is rarely anyone's responsibility.
We are happy to be on the list you are comparing. Ask us the hard questions above.