Pentest
Penetration Test Readiness & Scoping Checklist
A pre-engagement checklist for scoping, rules of engagement, environments, and remediating findings.
- Estimated time
- 2–6 Weeks Pre-Test
- Audience
- Security, Engineering, and Vendor-Management Teams
- Last updated
Operational reference for commissioning a pentest. The tester’s report is independent; this site does not perform testing.
Progress is saved in this browser only. Nothing is sent to a server.
Phase 1: Scope
Phase 2: Readiness
Phase 3: During
Phase 4: After
FAQ
Black box vs grey box?+–
Grey/white box with authenticated roles finds authorization bugs that black box misses.
How often?+–
Annually plus after major releases is common for SOC 2.
Is a bug bounty a pentest?+–
It is complementary. Auditors often still want a scoped pentest report.
Who should perform it?+–
An independent firm with a clear ROE. Internal red team is extra, not a replacement for independence when customers ask.
Related field notes
The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer