A penetration test is an authorised, time-boxed attempt to reach a stated objective by the means a real attacker might use. That definition carries three constraints people routinely forget.
Time-boxed
A tester has days; an attacker has as long as they like. A clean report means "nobody found a way in within the time and scope agreed", not "there is no way in". Treat the absence of findings as weak evidence, and ask what the tester did not get to.
Objective-driven
"Test everything" produces shallow coverage. A good objective is concrete: reach customer records from an unauthenticated position, move from a developer laptop to production, or obtain domain administrator. The objective decides the technique, and makes the result meaningful to people who do not read security reports.
Authorised
Scope, timing, data handling and contacts are agreed in writing before anything starts. Without that, the activity is indistinguishable from an intrusion — legally as well as operationally.
What it is not
It is not a vulnerability scan. A scan enumerates known weaknesses across many hosts; a test chains a few of them into an outcome. Both are useful and they answer different questions.
It is not an assessment of your controls either. A test tells you whether a path exists today. A control assessment tells you whether the practices that would close such paths are working, which is why mature programmes run both.
It is not a substitute for fixing what you already know about. If your last three reports share findings, another test is not what you need.