I think it greatly depends on the kind of pentesting. A military network is different from a bank, or an AWS site, or a social network.
It's a guess, but I would suspect the market is saturated -- by opportunists, not talent -- leading to necessarily high-touch sales and high barrier to entry, but not oversupply.
What sorts of barriers to entry? Purely the fact that there is a lot of noise vs. signal in terms of low-grade operators? Or is it more to do with learning the requisite skills?
It's a guess, but I would suspect the market is saturated -- by opportunists, not talent -- leading to necessarily high-touch sales and high barrier to entry, but not oversupply.