When an enterprise customer asks for your penetration test report, they want proof — from an independent third party, based on manual testing against a recognised methodology, recent (usually within 12 months), showing that findings were remediated. A raw vulnerability scan or an internal self-assessment usually will not satisfy them. You generally do not hand over the full technical report; you share a summary or attestation letter (often under NDA) that states the scope, dates, tester and remediation status. A standard test takes one to three weeks plus reporting, so if a deal is waiting, scope tightly to what the customer cares about and ask your provider for a shareable summary the moment testing and critical-issue remediation finish.
// 01 Why your customer is asking for this
Your customer is not being difficult — they are managing their own risk. Every enterprise, and especially every regulated one, is responsible for the security of the vendors it depends on. If your software touches their data or connects to their systems, you are part of their attack surface, and their security, procurement or compliance team has to be able to show their auditors that they vetted you. A penetration test report is the standard, widely accepted evidence that closes that question.
The request usually arrives through one of three doors: a vendor security questionnaire with a line item for "most recent penetration test," a procurement gate before contract signature, or a customer's own SOC 2 or ISO 27001 programme that requires them to assess critical suppliers. Recognising which door it came through tells you how formal the answer needs to be — but the underlying ask is the same.
// 02 What counts as an acceptable report
Not every document labelled "security report" will pass. Enterprise reviewers are looking for a specific set of signals, and a report that misses them gets bounced back — costing you the very time you were trying to save. An acceptable report generally meets all of these:
| Signal | What they check | Why |
|---|---|---|
| Independence | Third-party tester | A self-run test lacks objectivity; they want an external firm |
| Manual methodology | Real testing, not a scan | Aligned to OWASP, PTES or NIST — proves depth |
| Recency | Usually within 12 months | Security changes; an old test proves little about today |
| Relevant scope | The systems that serve them | A test of an unrelated app doesn't reassure them |
| Remediation | Findings fixed / planned | Open criticals are a red flag; evidence of closure is the goal |
| Named provider | A credible testing firm | Recognisable methodology and credentials build trust |
// 03 What they don't want (and common mistakes)
Just as important is knowing what will not work, because sending the wrong thing wastes a review cycle. The recurring mistakes:
An automated vulnerability scan
A Nessus or scanner PDF is not a penetration test. Reviewers know the difference, and increasingly the questionnaire says "penetration test" explicitly.
An internal self-assessment
A test your own team ran on your own systems lacks the independence enterprise buyers require.
A two-year-old report
Recency matters. Most programmes want a test within the last 12 months, tied to your current architecture.
The full raw technical report
Handing over detailed exploitation steps and unremediated criticals is a security risk in itself. Share a summary instead.
// 04 What to actually send them
Here is where many vendors get nervous, and needlessly. You are not expected to email a stranger a document that maps every exploitable weakness in your product. The professional norm is to share a summary report or an attestation letter, usually under NDA. That document confirms the essentials the reviewer needs: that an independent test was performed, by whom, when, over what scope, using what methodology, and that findings were remediated or are on a dated remediation plan — without exposing the step-by-step detail an attacker would want.
A good testing partner produces both artefacts from one engagement: the detailed technical report for your engineers, and a clean, shareable summary or attestation you can hand to customers and drop into your security-questionnaire responses. If your provider only gives you a raw findings dump, you will end up writing the summary yourself — so ask about the shareable deliverable before you book.
// 05 How fast can you get one — without derailing the deal
A standard external or application penetration test takes roughly one to three weeks of elapsed time, plus a few days for reporting — so realistically you can have a shareable result inside a month, and faster if the scope is tight. When a contract is genuinely waiting on it, three moves keep things moving: scope narrowly to the specific systems the customer cares about rather than your whole estate; tell your provider a deal depends on it so testing is prioritised; and ask for an interim attestation summary the moment testing and critical-issue remediation are complete, rather than waiting for the polished final report.
The one thing not to do is buy the cheapest scan to tick the box — because if the customer's reviewer rejects it, you have spent money and lost a review cycle, and now you are commissioning a real test under even more time pressure. Do it once, properly. Our cost guide covers what a right-sized test runs, and our guide to reading a pentest report helps you understand what you will receive.
// 06 Frequently asked questions
Why is my customer asking for a penetration test report?
Their vendor-security or procurement process requires evidence that you test for vulnerabilities. You are part of their attack surface, and a recent independent test is the accepted proof.
What kind of report will they accept?
An independent third-party test, manual and methodology-based, recent (usually under 12 months), with findings remediated or planned. A raw scan usually will not do.
Should I send the full technical report?
Usually not. Share a summary or attestation letter, often under NDA, that states scope, dates, tester and remediation status.
How fast can I get one?
One to three weeks plus reporting. Scope tightly, prioritise, and ask for an attestation summary as soon as testing and critical remediation are done.