Skip to content

Pentest

Penetration Test Readiness & Scoping Checklist

A pre-engagement checklist for scoping, rules of engagement, environments, and remediating findings.

Estimated time
2–6 Weeks Pre-Test
Audience
Security, Engineering, and Vendor-Management Teams
Last updated

Operational reference for commissioning a pentest. The tester’s report is independent; this site does not perform testing.

Progress0% Completed

Progress is saved in this browser only. Nothing is sent to a server.

Phase 1: Scope

Phase 2: Readiness

Phase 3: During

Phase 4: After

FAQ

Black box vs grey box?+

Grey/white box with authenticated roles finds authorization bugs that black box misses.

How often?+

Annually plus after major releases is common for SOC 2.

Is a bug bounty a pentest?+

It is complementary. Auditors often still want a scoped pentest report.

Who should perform it?+

An independent firm with a clear ROE. Internal red team is extra, not a replacement for independence when customers ask.

Related field notes

The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer