Blog · C.19 · Buyer Trigger

Your customer wants a pentest report — what they actually need

A prospect or enterprise customer has made a penetration test report a condition of the deal. Before you panic or overspend, here is exactly what they are asking for, what counts as acceptable, what to share, and how to get one without stalling the contract.

Vendor SecuritySales EnablementSOC 2AttestationSaaS
Vendor Security: Independent Third Party · Manual Testing · Recent (<12 mo) · Findings Remediated · Shareable Summary / Attestation Vendor Security: Independent Third Party · Manual Testing · Recent (<12 mo) · Findings Remediated · Shareable Summary / Attestation
// TL;DR

When an enterprise customer asks for your penetration test report, they want proof — from an independent third party, based on manual testing against a recognised methodology, recent (usually within 12 months), showing that findings were remediated. A raw vulnerability scan or an internal self-assessment usually will not satisfy them. You generally do not hand over the full technical report; you share a summary or attestation letter (often under NDA) that states the scope, dates, tester and remediation status. A standard test takes one to three weeks plus reporting, so if a deal is waiting, scope tightly to what the customer cares about and ask your provider for a shareable summary the moment testing and critical-issue remediation finish.

// 01 Why your customer is asking for this

Your customer is not being difficult — they are managing their own risk. Every enterprise, and especially every regulated one, is responsible for the security of the vendors it depends on. If your software touches their data or connects to their systems, you are part of their attack surface, and their security, procurement or compliance team has to be able to show their auditors that they vetted you. A penetration test report is the standard, widely accepted evidence that closes that question.

The request usually arrives through one of three doors: a vendor security questionnaire with a line item for "most recent penetration test," a procurement gate before contract signature, or a customer's own SOC 2 or ISO 27001 programme that requires them to assess critical suppliers. Recognising which door it came through tells you how formal the answer needs to be — but the underlying ask is the same.

// 02 What counts as an acceptable report

Not every document labelled "security report" will pass. Enterprise reviewers are looking for a specific set of signals, and a report that misses them gets bounced back — costing you the very time you were trying to save. An acceptable report generally meets all of these:

SignalWhat they checkWhy
IndependenceThird-party testerA self-run test lacks objectivity; they want an external firm
Manual methodologyReal testing, not a scanAligned to OWASP, PTES or NIST — proves depth
RecencyUsually within 12 monthsSecurity changes; an old test proves little about today
Relevant scopeThe systems that serve themA test of an unrelated app doesn't reassure them
RemediationFindings fixed / plannedOpen criticals are a red flag; evidence of closure is the goal
Named providerA credible testing firmRecognisable methodology and credentials build trust

// 03 What they don't want (and common mistakes)

Just as important is knowing what will not work, because sending the wrong thing wastes a review cycle. The recurring mistakes:

RejectedScan

An automated vulnerability scan

A Nessus or scanner PDF is not a penetration test. Reviewers know the difference, and increasingly the questionnaire says "penetration test" explicitly.

RejectedInternal

An internal self-assessment

A test your own team ran on your own systems lacks the independence enterprise buyers require.

RejectedStale

A two-year-old report

Recency matters. Most programmes want a test within the last 12 months, tied to your current architecture.

RiskyOversharing

The full raw technical report

Handing over detailed exploitation steps and unremediated criticals is a security risk in itself. Share a summary instead.

// 04 What to actually send them

Here is where many vendors get nervous, and needlessly. You are not expected to email a stranger a document that maps every exploitable weakness in your product. The professional norm is to share a summary report or an attestation letter, usually under NDA. That document confirms the essentials the reviewer needs: that an independent test was performed, by whom, when, over what scope, using what methodology, and that findings were remediated or are on a dated remediation plan — without exposing the step-by-step detail an attacker would want.

A good testing partner produces both artefacts from one engagement: the detailed technical report for your engineers, and a clean, shareable summary or attestation you can hand to customers and drop into your security-questionnaire responses. If your provider only gives you a raw findings dump, you will end up writing the summary yourself — so ask about the shareable deliverable before you book.

// 05 How fast can you get one — without derailing the deal

A standard external or application penetration test takes roughly one to three weeks of elapsed time, plus a few days for reporting — so realistically you can have a shareable result inside a month, and faster if the scope is tight. When a contract is genuinely waiting on it, three moves keep things moving: scope narrowly to the specific systems the customer cares about rather than your whole estate; tell your provider a deal depends on it so testing is prioritised; and ask for an interim attestation summary the moment testing and critical-issue remediation are complete, rather than waiting for the polished final report.

The one thing not to do is buy the cheapest scan to tick the box — because if the customer's reviewer rejects it, you have spent money and lost a review cycle, and now you are commissioning a real test under even more time pressure. Do it once, properly. Our cost guide covers what a right-sized test runs, and our guide to reading a pentest report helps you understand what you will receive.

// 06 Frequently asked questions

Why is my customer asking for a penetration test report?

Their vendor-security or procurement process requires evidence that you test for vulnerabilities. You are part of their attack surface, and a recent independent test is the accepted proof.

What kind of report will they accept?

An independent third-party test, manual and methodology-based, recent (usually under 12 months), with findings remediated or planned. A raw scan usually will not do.

Should I send the full technical report?

Usually not. Share a summary or attestation letter, often under NDA, that states scope, dates, tester and remediation status.

How fast can I get one?

One to three weeks plus reporting. Scope tightly, prioritise, and ask for an attestation summary as soon as testing and critical remediation are done.

UG

Usama Gul

Founder & Penetration Testing Lead, CyberFortify

Helps SaaS and fintech vendors turn a customer's security demand into a closed deal — with right-scoped testing and shareable attestation reports built for procurement review.

Deal waiting on a pentest report?

Tell us which systems your customer cares about and your timeline. We'll scope tightly, prioritise the test, and give you a shareable attestation summary alongside the technical report — retest included.

Get testing scheduled → See the cost →