Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

What should a penetration test report include?

Last verified

A credible pen-test report states scope, methodology, risk-rated findings with reproduction, remediation guidance, retest status, and an executive summary. A scanner dump is not that report. Weak reports hide method and severity. This page is not legal advice.

Report contents, last verified 10 September 2026 against NIST SP 800-115 reporting guidance, PTES reporting, CREST reporting materials, and FIRST CVSS v4.0 for severity language. Those texts are methodology and industry practice, not a statute that dictates YOUR report template. Not legal advice.

What a report is for

Audience: an auditor or engineering lead judging report quality. This page is not legal advice. Kind of text: NIST SP 800-115, PTES, and CREST reporting notes are guidance / industry practice. CVSS v4.0 (FIRST) is a severity standard, not a finding that YOU must use CVSS. ShipReady Metrics recommendation: attach the full report as evidence and record a met-verdict only after review — the product does not grade the tester.

Report-section checklist

Use this as an acceptance checklist when the PDF arrives. Last verified 10 September 2026. Not legal advice.

Report-section checklist (industry best practice; not a legal form; not legal advice)
SectionWhat good looks likeKind of text
Executive summaryAudience-plain residual risk, not only a count of highs.Best practice (NIST SP 800-115 / CREST reporting).
Scope and authorizationIn-scope assets, out-of-scope, test window, and written authorization.Methodology guidance; also evidence you will retain.
MethodologyNamed method, tools, credentialed vs not, and limitations.NIST SP 800-115 / PTES / CREST.
Risk-rated findingsEach finding has impact, likelihood or CVSS vector, affected asset, and evidence.CVSS v4.0 is a severity language (FIRST), not a legal duty.
Reproduction / evidenceSteps or artifacts an engineer can follow without guessing.Best practice.
Remediation guidanceActionable fix, not only “sanitize input.”Best practice.
Retest statusNot tested / planned / confirmed, with date.Best practice; PCI 11.4 if PCI applies.

Red flags in a weak report

Any one of these is a reason to send the report back before you file it as audit evidence. Not legal advice.

  • No rules of engagement or asset list — you cannot prove what was tested.
  • Severity as “high/medium/low” with no method and no vector.
  • Findings that are raw scanner plugin names with no exploitation narrative.
  • No reproduction steps and no evidence appendix.
  • No residual-risk statement after accepted findings.
  • Missing tester identity or dates of fieldwork.

What to do now

Operational steps. Last verified 10 September 2026. Not legal advice.

  • Put the section checklist in the statement of work so you are not arguing after delivery.
  • On receipt, walk the red-flag list before you share the PDF with an auditor or acquirer.
  • Store authorization, report, remediation tickets, and retest confirmation together. Open the evidence-retention guide on this site.
  • If you already have a session: signed-in app → Compliance → Evidence is where the artifact can be reviewed with a met-verdict overlay. That overlay is not a certification.

Checklist

Acceptance questions. Not YOUR audit opinion. Not legal advice.

  • Can a new engineer reproduce the top findings from the report alone?
  • Is scope dated and signed?
  • Is retest status explicit for every finding you claim is closed?
  • Have you withheld the full exploit appendix from people who do not need it?

Where this shows up in ShipReady Metrics

Evidence review and the met-verdict overlay are where a report attaches as accepted evidence. The product organizes that file; it does not replace the independent test and does not determine that a framework applies to YOU.

Primary sources (last verified 10 September 2026)

NIST SP 800-115 reporting chapter. PTES reporting. CREST reporting guidance (accreditation body practice, not endorsement). FIRST CVSS v4.0 specification. Not legal advice.

Frequently asked questions