Penetration testing
What's in a Penetration Test Report (and How to Read One)
A section-by-section guide to pentest reports (executive summary, scope, severity ratings, findings and retests) and how to turn one into a fix plan.
· 5 min read
// Compliance Pentest
A penetration test scoped and reported the way auditors expect, so it counts as evidence for SOC 2, ISO 27001, PCI DSS and customer security reviews.
Most compliance frameworks either require or strongly expect independent penetration testing: SOC 2 auditors look for it as evidence of control effectiveness, ISO 27001 expects technical vulnerability management, and PCI DSS explicitly requires it.
A compliance-ready test is the same rigorous testing, scoped against the systems your auditor cares about and documented so the evidence is accepted first time.
Read the full testing methodology.
// Process
A short call to agree targets, test type, dates and rules of engagement. You get a quote for that scope, then written authorization is signed before any testing starts.
Hands-on, tool-assisted testing aligned to OWASP and PTES, with every finding verified. Anything critical is reported to you immediately, not saved for the report.
A clear report: executive summary, then every finding with severity, evidence, reproduction steps and a specific fix. Followed by a readout call.
Once fixes are in, we verify each one and issue an updated report and an attestation letter you can share with customers and auditors.
// FAQ
Yes. Auditors look for a qualified tester who is organizationally independent from the systems being tested, a documented methodology, and evidence of remediation. All three are in the report.
No. Quarterly external ASV scans (PCI DSS Req. 11.3.2) must come from an ASV. Penetration testing (Req. 11.4) does not require an ASV and is what this service covers.
// Further reading
Penetration testing
A section-by-section guide to pentest reports (executive summary, scope, severity ratings, findings and retests) and how to turn one into a fix plan.
· 5 min read
Penetration testing
What penetration tests cost in 2026 by test type, how quotes are built from days and day rates, what drives the price, and how to spot a scan sold as a pentest.
· 5 min read
Compliance
What SOC 2, ISO 27001 and PCI DSS v4.0.1 actually say about penetration testing: which require it, how often, who may test, and the evidence auditors ask for.
· 6 min read
// Also available
An authenticated test of your web application against the OWASP Top 10 and the business-logic flaws scanners never find.
Testing of REST and GraphQL APIs for broken object-level authorization, auth flaws, mass assignment and data over-exposure.
External testing of everything you expose to the internet, and internal testing of what an attacker could reach once inside.