Skip to content
← Field Notes

What Does a Penetration Test Report Look Like?

What Does a Penetration Test Report Look Like?

A penetration test report is a written document with four core parts: an executive summary in plain English, the scope and method of the test, a list of every finding ranked by how exploitable it really is with proof for each one, and a prioritized fix list your IT team can work through. If the report you paid for is missing any of those, you bought a scan, not a test. This guide walks through each section, what a good one looks like, and what you actually hand to your insurance carrier or client when they ask for evidence, written for the business owner buying the test, not the engineer reading it.

The report matters more than most buyers realize. The test itself is invisible to you; the report is the entire deliverable. It is the thing your carrier asks about, the thing your client’s security questionnaire references, and the thing that decides whether the next month of IT work is focused or wasted. So it is worth knowing what you should get before you sign anything.

The five parts of a good penetration test report

Different firms use different templates, but a report worth paying for covers the same ground. Formal testing guides like NIST SP 800-115 and the Penetration Testing Execution Standard both treat reporting as its own phase of the engagement, not an afterthought, and both land on a similar structure.

SectionWhat it tells youWho reads it
Executive summaryWhere you stand, in plain English, on one or two pagesYou, your leadership, your insurer
Scope and methodologyWhat was tested, when, and howAuditors, carriers, your IT provider
Findings, rankedEach weakness, how serious it really is, and proofYour IT team or MSP
Fix listWhat to fix first, second, and thirdYour IT team or MSP
Retest resultsWhich fixes held when we checked your workEveryone, it closes the loop

The executive summary is the part you will actually read

This is the section written for you. It should say, in language you would use over coffee, what the tester could and could not do: whether an outsider could get in, what they could reach if they did, and how the overall picture compares to what a business your size should expect. No acronym soup. If the executive summary of a sample report reads like it was generated by a tool, that tells you how the rest of the engagement will go.

Scope and methodology, or what was actually tested

This section records what was in bounds, the dates of testing, and the approach used. It sounds like paperwork, and it partly is, but it is the paperwork that makes the report usable as evidence. An insurance carrier or an auditor wants to see that the test covered the systems that matter and that it happened recently, not three years ago. It is also your protection: a test scoped in writing is what separates authorized testing from someone poking at your network.

Findings, ranked by what is actually exploitable

The heart of the report. Each finding should have a name, a severity, a plain-English explanation of what it means for your business, proof it is real, and a specific fix. Two honest notes on severity, because this is where reports mislead people:

  • A raw scanner score is not a risk ranking. Automated tools assign severity from a database, with no idea whether the weakness is reachable in your environment. A human tester ranks findings by what an attacker could actually do with them, which is sometimes lower than the scanner says and sometimes much higher.
  • Chains matter more than single findings. Most real intrusions are not one critical flaw. They are three medium ones combined: a reused password, an over-shared drive, a system nobody patched because nobody knew it existed. A good report shows the chain, not just the links.

And one more, because we believe it enough to put it on every page of this site: something being reachable from the internet is not, by itself, a finding. Your VPN and your email server are supposed to be there. The findings that count are about patching, configuration, and missing multi-factor authentication, not about existing.

How to spot a bad report before you pay for one

Ask any firm you are evaluating for a sanitized sample report. What comes back tells you nearly everything:

  1. Length used as a substitute for quality. A 200-page PDF that is 190 pages of raw scanner output is a doorstop with a logo. Volume is easy; judgment is the product.
  2. No proof. Every real finding should come with evidence, a screenshot, a captured response, a demonstrated path. “Trust us” is not a finding.
  3. No prioritization. If everything is critical, nothing is. You should be able to read the fix list and know what Monday morning looks like.
  4. No retest. A report that ends at the findings leaves the loop open. Ours includes a retest of your fixed findings on every tier, because a finding is not closed until someone checks the fix held. If you are comparing quotes, our guide to what a penetration test costs covers what should be included at each price, and the pricing page has our numbers published.

If the sample fails those checks, the difference you are looking at is the one we wrote about in penetration test vs vulnerability scan: an automated scan dressed up as a test.

The attestation letter: what you show your insurer or client

Here is the part almost nobody explains to first-time buyers. The full report is a map of your weaknesses, with proof. You should treat it like the sensitive document it is, and you usually should not hand it to third parties at all.

What carriers and clients generally want is an attestation letter: a short document from the testing firm stating that a penetration test was performed, the dates, what was in scope, the methodology in a sentence or two, and a high-level summary of the outcome, often including confirmation that findings were remediated and retested. It proves you were tested without publishing the details of how to break into your business.

In practice it works like this:

  • Cyber insurance questionnaire asks “have you had a penetration test?” You answer yes and provide the attestation letter or the executive summary if asked. Our cyber-insurance guide covers what carriers actually ask for.
  • A client or prime contractor wants evidence. Same answer. Serious security teams know better than to ask for your full findings; an attestation with scope and dates is the professional norm.
  • Someone insists on the full report. It happens occasionally. Share the least detail that satisfies the requirement, ideally after the retest confirms the findings are closed, and send it through a secure channel, not a reply-all email thread.

When we finish an engagement, the readiness package includes the report and the attestation, so you are not left improvising when the questionnaire shows up.

What happens after the report lands

A report nobody acts on is worthless, so the engagement should not end when the PDF arrives. The pattern that works: your IT team or MSP takes the fix list and works it top to bottom, we stay available to explain any finding in plain language, and once the fixes are in, we retest and issue updated results showing what held. That final state, tested, fixed, retested, dated, is what turns a security exercise into a document with real shelf life for insurers, clients, and auditors. Most engagements go from scoping to report inside a couple of weeks; the honest breakdown is in how long a penetration test takes.

Frequently asked questions

What is included in a penetration test report?

A good report includes an executive summary in plain English, the scope and dates of the test, every finding ranked by how exploitable it really is, proof for each finding, and a prioritized fix list. After remediation, a retest section or updated report confirms which fixes held.

What is a penetration test attestation letter?

A short letter from the testing firm stating that a test was performed, when, what was in scope, and a high-level summary of the outcome. It exists so you can prove you were tested without handing your full findings, which are a map of your weaknesses, to a third party.

Should I send my full penetration test report to my insurance carrier?

Usually you do not need to. Most carriers and clients accept an attestation letter or the executive summary. If one insists on more, share the least detail that satisfies them, send it through a secure channel, and confirm the findings are fixed and retested first.

What if the report finds nothing serious?

That is a good outcome, not a wasted test. The report still documents what was tested and what held up, which is exactly the evidence an insurer, client, or auditor wants to see. A clean, dated report proving your controls stood up to a real attempt has real value.

The bottom line on what a penetration test report looks like

A penetration test report should leave you clearer than you were before it arrived: an executive summary you can actually read, findings ranked by real-world exploitability with proof, a fix list with an obvious Monday-morning starting point, and a retest that closes the loop. If you are evaluating testers, ask for a sample report first and judge them on it, because the report is the product.

Want to see where your business stands and get a report written to be used, not filed? Tell us a little about your business and what is prompting the test, and we will come back with a fair, fixed quote. Request a quote.

Want to know where you stand?

Tell us a little about your business and what is prompting the test. We will come back with a fair, fixed quote.

Request a quote