What should a pentest report include?
A good penetration test report lets a manager grasp the risk in a few minutes and lets a developer reproduce and fix each finding on their own. Automated scan output on its own is not a report.
- 01
The short answer
A pentest report should contain at least: an executive summary, the scope and method tested, a risk table ordered by severity, and for each finding the evidence, step-by-step reproduction notes, an explanation of the impact and a recommended fix. The test dates, the limits of the work and the retest result should be stated too. If one of these is missing, the report falls short for either the manager or the developer.
- 02
Executive summary
It is written for non-technical readers and should not run past a page or two. It sets out in plain language the overall risk picture, the few most critical findings, their possible impact on the business and the priority actions. It should focus on saying clearly which risk must be closed first, not on making the number of findings look large.
- 03
Scope and method
It states which domains, IP addresses and applications were tested, on which dates and with which approach, black-box or grey-box. Systems left out of scope and attempts that were not made, such as tests that could interrupt the service, are also stated clearly. This section draws the report's boundary: no conclusion that a system is “secure” can be drawn for anything the report does not cover.
- 04
The entry for each finding
Each finding should be written up as a separate entry: a short title, the affected address or component, a severity (critical, high, medium, low), evidence showing how it was found, step-by-step reproduction notes and an explanation of its real impact. The basis for the severity should be stated as well; CVSS is one common measure, but the impact specific to your business should also be taken into account.
- 05
Fix recommendations and priority
Each finding should come with a fix you can act on: not a general line such as “validate input”, but what needs to change and where. The report should also say which item to tackle first; a critical weakness and a low-risk configuration gap do not share the same priority. When a temporary mitigation and the permanent fix are written separately, your team can reduce the risk quickly and plan the lasting work.
- 06
Retest and closure
A finding is closed by the result of an independent retest, not by the word of whoever made the fix. After the retest, the report gets a new version and the status of each finding is recorded: closed, partly closed, open or risk accepted. Accepting a risk should also be done in writing, with a record of who accepted it and why.
- 07
How to judge a report
At the quote stage, ask for an anonymised sample report or a report template and check: are the findings backed by evidence, can they be reproduced, are the fixes concrete, or has automated tool output been pasted in as it is? In our penetration testing service, the report consists of an executive summary, a risk table, step-by-step reproduction notes and fix recommendations, and findings are verified by hand before they reach you. If you want help closing the weaknesses, our remediation service works together with the retest.
Related pages
Articles that complete this topic, plus the matching service page.
Let's talk about your project.
Tell us what you need; we will define the scope together.