Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What should a penetration test report include?
Last verifiedA credible pen-test report states scope, methodology, risk-rated findings with reproduction, remediation guidance, retest status, and an executive summary. A scanner dump is not that report. Weak reports hide method and severity. This page is not legal advice.
Report contents, last verified 10 September 2026 against NIST SP 800-115 reporting guidance, PTES reporting, CREST reporting materials, and FIRST CVSS v4.0 for severity language. Those texts are methodology and industry practice, not a statute that dictates YOUR report template. Not legal advice.
What a report is for
Audience: an auditor or engineering lead judging report quality. This page is not legal advice. Kind of text: NIST SP 800-115, PTES, and CREST reporting notes are guidance / industry practice. CVSS v4.0 (FIRST) is a severity standard, not a finding that YOU must use CVSS. ShipReady Metrics recommendation: attach the full report as evidence and record a met-verdict only after review — the product does not grade the tester.
Report-section checklist
Use this as an acceptance checklist when the PDF arrives. Last verified 10 September 2026. Not legal advice.
| Section | What good looks like | Kind of text |
|---|---|---|
| Executive summary | Audience-plain residual risk, not only a count of highs. | Best practice (NIST SP 800-115 / CREST reporting). |
| Scope and authorization | In-scope assets, out-of-scope, test window, and written authorization. | Methodology guidance; also evidence you will retain. |
| Methodology | Named method, tools, credentialed vs not, and limitations. | NIST SP 800-115 / PTES / CREST. |
| Risk-rated findings | Each finding has impact, likelihood or CVSS vector, affected asset, and evidence. | CVSS v4.0 is a severity language (FIRST), not a legal duty. |
| Reproduction / evidence | Steps or artifacts an engineer can follow without guessing. | Best practice. |
| Remediation guidance | Actionable fix, not only “sanitize input.” | Best practice. |
| Retest status | Not tested / planned / confirmed, with date. | Best practice; PCI 11.4 if PCI applies. |
Red flags in a weak report
Any one of these is a reason to send the report back before you file it as audit evidence. Not legal advice.
- No rules of engagement or asset list — you cannot prove what was tested.
- Severity as “high/medium/low” with no method and no vector.
- Findings that are raw scanner plugin names with no exploitation narrative.
- No reproduction steps and no evidence appendix.
- No residual-risk statement after accepted findings.
- Missing tester identity or dates of fieldwork.
What to do now
Operational steps. Last verified 10 September 2026. Not legal advice.
- Put the section checklist in the statement of work so you are not arguing after delivery.
- On receipt, walk the red-flag list before you share the PDF with an auditor or acquirer.
- Store authorization, report, remediation tickets, and retest confirmation together. Open the evidence-retention guide on this site.
- If you already have a session: signed-in app → Compliance → Evidence is where the artifact can be reviewed with a met-verdict overlay. That overlay is not a certification.
Checklist
Acceptance questions. Not YOUR audit opinion. Not legal advice.
- Can a new engineer reproduce the top findings from the report alone?
- Is scope dated and signed?
- Is retest status explicit for every finding you claim is closed?
- Have you withheld the full exploit appendix from people who do not need it?
Where this shows up in ShipReady Metrics
Evidence review and the met-verdict overlay are where a report attaches as accepted evidence. The product organizes that file; it does not replace the independent test and does not determine that a framework applies to YOU.
Primary sources (last verified 10 September 2026)
NIST SP 800-115 reporting chapter. PTES reporting. CREST reporting guidance (accreditation body practice, not endorsement). FIRST CVSS v4.0 specification. Not legal advice.