forumNew topic

How many days should a penetration test report take — what should I see in a sample report?

DDamla Ö***MemberCommunity member
Joined
Jan 2022
Message
70
#1

We're about to sign our first professional penetration testing agreement for our B2C e-commerce infrastructure and mobile app. We got quotes from three different firms for a scope covering external network, web app, and API testing. All of them estimated the testing period at an average of 5 business days.

However, when it comes to preparing and delivering the final report after testing wraps up, one firm said 3 business days while another asked for 15 business days. On top of that, they're reluctant to share a sample or redacted report format before signing, citing confidentiality. 15 business days feels way too long to me; I mean, if there's a critical vulnerability, are we supposed to sit around vulnerable for two weeks?

How many business days does it normally take to get a pentest report after testing concludes? Also, before closing a deal, how should we verify exactly what sections are included in a sample report regarding risk scores, proof of exploit, and remediation guidance?

JJale P***MemberCommunity member
Joined
Mar 2024
Message
207
Most Helpful#2

Short answer: In a standard penetration test, the draft report should be delivered within 3 to 5 business days at most after fieldwork ends; if a critical vulnerability is identified, an immediate notification must be sent the very same day without waiting for the report date. Firms requesting 15 business days for a report are usually putting off documenting findings due to heavy workloads.

Here are the three critical sections you should look for in a sample report before signing: 1) Executive Summary: A visual section tailored for non-technical senior management that breaks down identified vulnerabilities by risk severity (critical, high, medium, low, informational) and summarizes the overall security posture. 2) Documented Technical Findings (PoC): For every vulnerability, a universal risk score (CVSS), exact location (URL, parameter, or service), and most importantly, screenshots or HTTP request-response logs proving the flaw is exploitable. Reports merely copying automated scanner text hold zero value. 3) Root Cause and Remediation Guide: Instead of generic advice like 'update the system', specific code snippets or server hardening steps your dev team can implement to patch the vulnerability.

Citing confidentiality as an excuse not to share a sample report is unacceptable. Professional cybersecurity firms are expected to provide prospective clients with template reports where company names, domain names, and IP blocks are fully redacted. You shouldn't sign any contract without seeing their sample report format.

TTuğçe K***New memberCommunity member
Joined
Sep 2026
Message
310
#3

Look closely at the 'PoC' (Proof of Concept) section in the sample report. In a real pentest, once the specialist finds a vulnerability, they must prove they can exfiltrate unauthorized data or execute commands using screenshots. Don't waste your time with firms that don't bother clearing false positives generated by automated scanners.

EElif T***MemberCommunity member
Joined
Apr 2025
Message
343
#4

Make sure to get these clauses written into the service agreement: 1) An interim email notification will be sent within 24 hours whenever critical or high-severity findings are discovered, 2) The draft report will be delivered within 5 business days at most after testing concludes, 3) A one-time free verification test (re-test) will be conducted within 30 days after findings are remediated.

CCaner K***VeteranCommunity member
Joined
May 2023
Message
21
#5

Our mobile and API tests wrapped up last month. Fieldwork finished on a Friday evening, and we had the draft report by Tuesday morning. There were 4 critical flaws; our dev team resolved them in 10 days, and the firm ran the re-test the next day and delivered a clean final report. Waiting 15 business days just for a report freezes your entire patching timeline.

GGürkan A***Member
Job title
Studio Founder
Sector
Software
Organization type
chain store
Joined
Jul 2024
Message
139
#6

Tell the firm asking for 15 business days that you require 'daily interim reporting for critical findings'. If they push back, drop them immediately. If vulnerabilities like database injection or remote code execution turn up during a pentest waiting two weeks without fixing them is commercial suicide.

SSerkan U***Member
Job title
Site Manager
Sector
Education
Organization type
medium-sized business
Joined
May 2025
Message
312
#7

Some vendors promising reports in 3 days aren't actually writing anything as they test; they just hit 'Export to PDF' on an automated scanner and slap your logo on the cover. Just as much as the turnaround time check the sample report to confirm it's hand-written and contains custom analysis tailored to your setup.

OOkan T***VeteranCommunity member
Joined
Jan 2023
Message
7
#8

dont even sit down with a firm that wont share a sample report imo. you cant sign a deal without knowing what youre gonna get. legit firms always keep redacted samples ready with client permission anyway.

OOkan A***Member
Job title
Clinic manager
Sector
Retail
Organization type
sole proprietorship
Joined
Apr 2023
Message
55
#9

Pay close attention to the 're-test' window in the agreement. It'll take time to patch vulnerabilities once the report arrives. Getting a commitment from the firm to re-audit systems for free within at least 30 or 45 days of report delivery is vital for the health of the project.

AAslı B***Expert
Job title
Purchasing manager
Sector
Consulting
Organization type
family business
Joined
Dec 2022
Message
19

Doki · Infrastructure migration · 2023

#10

if testing takes 5 days but the report takes 15, the engineer who ran the test is probably busy breaching another client's server instead of writing your report but if you have a critical bug web bots will discover it long before you find out two weeks later.

ÜÜlkü K***Member
Job title
Board member
Sector
Agriculture
Organization type
cooperative
Joined
Jan 2025
Message
19

Doki · Infrastructure migration · 2025

#11

Absolutely. If I were to add anything: The biggest time-waster for us was not knowing who had the final say.

Solutions that work at a small scale collapse when you grow; I learned this late. Just leaving this note, it might be useful.

BBarış K***Expert
Job title
Corporate IT manager
Joined
Jun 2023
Message
172
#12

Sorry, but this doesn't apply in every case. Having backups accessible on the same network and with the same identity makes them part of the target.

AAlper T***Member
Job title
IT manager
Sector
E-commerce
Organization type
family business
Joined
Oct 2024
Message
239
#13

I have an objection here. When making a decision, first look at what data you have on hand.

When making a decision, first look at what data you have on hand. I'm also curious if anyone does it differently.

PPınar K***MemberCommunity member
Joined
Feb 2026
Message
17
#14

Noted, thanks.

CCengizNew member
Job title
Auto repair
Organization type
20-person company
Joined
Jul 2024
Message
27
#15

Timely topic. The harder it is to reverse a decision, the slower you should make it.

If you have questions, write them; I'll answer as best I can.

DDilara B***Member
Job title
Operations manager
Sector
Furniture manufacturing
Organization type
regional distributor
Joined
Jun 2024
Message
1

Doki · Interface design · 2024

#16

I have a question. People defend habits, not processes. Resistance comes from there.

This is my opinion, I'm not claiming it's absolute truth.

FFurkan M***Member
Job title
Product Manager
Sector
Construction
Organization type
medium-sized business
Joined
Dec 2024
Message
20
#17

you're right. the hader it is to reverse a decision the slower you should make it.

NNecati B***Member
Job title
Content Editor
Sector
Tourism
Organization type
a company within a holding
Joined
May 2023
Message
249

Doki · SEO consulting · 2026

#18

i have a question. if the notification path is long notifications don't arrive; missing notifications mean delayed incident detection.

don't rely on a singe measure; go layer by layer. if you have questions, write them; I'll answer as best I can.

DDoruk Y***ExpertCommunity member
Joined
Feb 2025
Message
99
#19

Thanks a lot, I'll try it today. If you don't write this down from the start, it leads to arguments later.

An automated scan report is not the same as a penetration test. Good luck with that.

KKerem O***Member
Job title
Game studio
Organization type
20-person company
Joined
Feb 2024
Message
98
#20

Great work.

Reply