Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

What evidence should be kept after a penetration test?

Last verified

Keep the signed authorization, scoped report, remediation records, and retest confirmation. Limit who can read exploit detail. Retention follows YOUR framework and counsel — this page does not set YOUR period. This page is not legal advice.

Evidence retention, last verified 10 September 2026 against AICPA Trust Services Criteria evidence expectations, ISO/IEC 27001:2022 Clause 7.5 and A.8.8, PCI DSS v4.0.1 evidence-retention practice, and NIST SP 800-115. Retention periods here are guidance — verify against YOUR framework and legal counsel. Not legal advice.

Evidence, not a souvenir PDF

Audience: a compliance owner. This page is not legal advice. Kind of text: TSC evidence expectations are attestation practice. ISO/IEC 27001:2022 Clause 7.5 (documented information) is normative if you are certified to that ISMS; A.8.8 is technical vulnerability management. PCI DSS evidence-retention rules apply only if PCI applies. NIST SP 800-115 is methodology guidance. ShipReady Metrics recommendation: store artifacts in the evidence library with review, not in a personal drive.

Evidence-inventory checklist

Last verified 10 September 2026. Not YOUR retention schedule. Not legal advice.

Pen-test evidence inventory (guidance; verify retention with counsel; not legal advice)
ArtifactWhy keep itHandling noteKind of text
Authorization / rules of engagementProves the test was lawful and scoped.Legal hold if a dispute or incident follows.Best practice; NIST SP 800-115 planning.
Full report and executive summaryAudit and diligence artifact.Need-to-know; exploit appendices more tightly than the summary.TSC evidence practice; ISO 7.5 if in the ISMS.
Remediation tickets and change recordsShows the control operated, not only that a PDF exists.Link to finding IDs.TSC / ISO documented information.
Retest confirmationIndependent closure.Keep with the original finding IDs.PCI 11.4 if PCI applies; otherwise best practice.
Tester identity and datesProvenance for the auditor.Do not strip the letterhead when you archive.Best practice.

Handling and retention-period note

There is no single global number of years that this page can assign to every company. SOC 2 examiners typically want evidence covering the review period plus enough history to show the testing program operates. ISO/IEC 27001:2022 Clause 7.5 requires documented information to be controlled and retained as the ISMS defines. PCI DSS has its own evidence-retention expectations if PCI applies. Treat any year-count you hear in a hallway as unverified until counsel and the framework owner write it down. Last verified 10 September 2026. Not legal advice.

Sensitive findings are credentials by another name. Encrypt at rest, restrict ACLs, and do not paste exploit steps into a company-wide chat. Over-retention of raw exploit detail after the retest can increase blast radius if that archive is later stolen.

What to do now

Operational steps. Last verified 10 September 2026. Not legal advice.

  • Make the inventory table YOUR packing list before the tester finishes fieldwork.
  • Ask counsel for the retention period that applies to YOUR SOC 2 period, ISO ISMS, PCI program, or litigation hold.
  • If you already have a session: signed-in app → Compliance → Evidence is the durable store with review and met-verdict overlay. The obligation map is not a retention schedule.
  • Open the SOC 2 pen-test page and the SRM evidence-walkthrough on this site when you map artifacts to criteria.

Checklist

Question list. Not legal advice.

  • Do we have authorization, report, tickets, and retest — all four?
  • Who can open the exploit appendix?
  • What written retention period applies, and who approved it?
  • Is the archive included in backup and legal-hold procedures?

Where this shows up in ShipReady Metrics

Evidence collection, review, obligation map, and met-verdict overlay are the durable store for pen-test artifacts. The product does not set YOUR retention period, does not replace counsel, and does not determine that a framework applies to YOU.

Primary sources (last verified 10 September 2026)

AICPA Trust Services Criteria (evidence expectations). ISO/IEC 27001:2022 Clause 7.5 and A.8.8. PCI DSS v4.0.1 evidence-retention practice if PCI applies. NIST SP 800-115. Not legal advice.

Frequently asked questions