Risk & policies
What is a penetration test report?
Short answer
A penetration test report is the deliverable from a pen test: it documents the scope and methodology, lists the vulnerabilities found with a severity rating and evidence for each, gives remediation guidance, and often records a retest confirming fixes. Buyers and auditors ask for it as proof you actively test your security, not just scan.
What the report contains
A pen test report typically includes an executive summary, the scope and rules of engagement, the methodology used, and a findings section that lists each vulnerability with a severity rating (often critical, high, medium, low), evidence or steps to reproduce, and remediation guidance. Many reports also include a retest section confirming which findings were fixed.
A pen test is not a vulnerability scan
A vulnerability scan is automated and lists known weaknesses; a penetration test adds skilled humans who chain issues together to see what an attacker could actually achieve. The report reflects that: it is about demonstrated impact, not just a list of scanner output.
How it is used
Buyers and auditors ask for a recent pen test report (or a summary/attestation letter, since the full report is sensitive) as evidence you test your defenses. Frameworks like SOC 2 and ISO 27001 expect regular testing, and the report plus your remediation is the proof.
FAQ
-
How is a pen test report different from a vulnerability scan report?
- A scan is automated and lists known vulnerabilities. A penetration test adds human testers who exploit and chain issues to show real impact, so its report reflects demonstrated risk, not just scanner findings.
-
Do we share the full pen test report with customers?
- Usually not in full, because it contains sensitive detail. Many companies share a summary or an attestation letter from the testing firm, and provide the full report only under NDA.
Next step
Get audit-ready with Keel
The AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.