Getting started · 24 Jul 2026

How to Prepare for Your First Penetration Test

Most delays and scope confusion in a first engagement come from the same handful of missing pieces. Have these ready before the scoping call and testing starts on time.

Before the scoping call

1. Know what's actually in scope

A URL or IP range is a start, but the more precise you can be, the more accurate your quote and timeline will be: which environment (staging or production), which subdomains or services, how many user roles exist, and whether an API is included. If you're not sure, that's fine — the scoping call is exactly where this gets nailed down together.

2. Have written authorization ready

Every legitimate engagement requires documented authorization to test — either you own the systems outright, or you have explicit written sign-off from whoever does (this matters especially for cloud infrastructure, where the cloud provider's own terms of service govern what testing is permitted). This gets formalized in the rules-of-engagement document before testing starts, but knowing who needs to sign it in advance saves time.

3. Decide on your testing window

Is there a maintenance window you'd prefer, or a hard deadline (an audit date, a release date) the engagement needs to work around? Flag it early — timelines get built around real constraints, not assumed ones.

4. Identify who gets the report

Reports are written for two audiences at once — an executive summary for leadership, a technical section for engineers — but knowing who specifically will read and act on each half helps tailor emphasis. If a compliance auditor needs to see it too, say so; the report format can be adjusted to match what they expect.

What happens on the call itself

A free 30-minute conversation about your environment, goals, and any compliance drivers — no commitment, no pressure. It ends with enough information to send a written proposal within 24 hours: exact scope, fixed price, and timeline.

During testing

You'll get progress updates through the engagement, not silence until the final report. If something high-severity and actively exploitable turns up, you hear about it immediately — not two weeks later in the write-up.

After the report lands

The report ships with a live debrief walkthrough, not just a PDF in your inbox — a call to go through findings, answer questions, and make sure the remediation roadmap is actually actionable for your team. A re-test after remediation is available to confirm fixes hold.

Ready to scope yours? Book a call or see what's covered in a specific service first.

Bring what you have — we'll fill in the rest on the call

Free scoping call, fixed-price proposal within 24 hours.

See pricing