Penetration testing is an authorised, simulated attack on a system by security professionals, aiming to find exploitable weaknesses before real attackers do. It differs from automated vulnerability scanning in depth: humans chain findings together the way an actual intruder would.
Mature software vendors pen-test regularly, fix what is found, and can summarise the latest test for customers under NDA. In procurement, the useful questions are how often tests run, who performs them, and whether findings above an agreed severity are contractually required to be fixed within set windows.