The short answer
Many auditors accept our automated penetration test reports, especially for PCI DSS in environments that are not complex. The decision always belongs to your auditor, insurer, or customer, so the safest move is to ask them before you buy. It takes one message, and we wrote it for you further down this page.
What the report contains
Every test ends with two reports you can export from the portal: an executive report for the people who sign things, and a technical report for the people who fix things. Together they include:
- An executive summary in plain language
- Technical detail for each confirmed finding, with proof-of-exploit evidence
- The MITRE ATT&CK tactic and technique behind each finding
- Remediation guidance for each finding
- Retest confirmation, showing that a fix was tested again and held
What auditors look for
Auditors rarely care which tool ran the test. They check a short list, and this is how the test answers each item.
- An independent tester. Clone Systems is an outside company with no stake in your systems. We have done security testing since 1998 and have been a PCI Approved Scanning Vendor since 2007.
- A real attempt to break in. The test safely attempts real exploitation, credential reuse, and privilege escalation. It does not stop at listing possible weaknesses.
- A defined scope. You set the targets, the exclusions, and the testing window in the portal before the test starts.
- A recognized method. Every finding is mapped to MITRE ATT&CK, the public framework that describes how real attackers work.
- Proof that fixes worked. You can fix a finding and run the same test again inside your 30-day window. The retest result goes in the report.
A note on PCI DSS
PCI DSS Requirement 11.4 does not require your penetration tester to be a QSA or an ASV. It asks for a qualified tester who is independent of the systems being tested, a documented method, and a repeat test to confirm that what was found has been fixed. Our reports are built to give your assessor that evidence.
Ask your auditor before you buy
Copy this note, fill in the brackets, and send it to your auditor, insurer, or customer.
We plan to meet our penetration testing requirement with an automated penetration test from Clone Systems, an independent security testing company in business since 1998 and a PCI Approved Scanning Vendor since 2007. The test attempts real exploitation of our in-scope systems from [outside, inside, or both]. The report includes an executive summary, technical detail with proof-of-exploit evidence for each confirmed finding, remediation guidance, and retest confirmation after we fix what it finds. Is this acceptable for [SOC 2, PCI DSS 11.4, HIPAA, our policy renewal, your vendor review]? If you need an engineer to perform the test, Clone Systems can provide that as well.
If your auditor wants a person to run the test
You have two options, and neither one means starting over somewhere else.
- Engineer-performed test. One of our engineers runs the test for you on the same platform, as an add-on to your order.
- Managed penetration test. A full engagement led by our testing team and scoped to your environment. This is the right fit for complex environments and for the business logic flaws and creative attack chains that automation cannot find.
For either one, talk to a specialist and tell us what your auditor asked for.
A summary you can forward
Customers and insurers often want proof that a test happened without seeing the technical detail. Copy this summary onto your own letterhead, fill it in from your executive report, and send it. Keep the full report private.
Penetration test summary
Company: [your company name]
Tested by: Clone Systems, Inc., an independent third party
Type of test: [external, internal, or web application] penetration test
Test window: [start date] to [end date]
Scope: [number of systems and a short description]
Result: [number] findings were confirmed exploitable. [All, or number] have been fixed and confirmed closed by retest on [date].
The full technical report is available under a confidentiality agreement.
Signed: [name, title, date]
This page is general information, not legal or audit advice. Your auditor, insurer, or customer decides what they will accept.
See pen test pricing and buy online · Talk to a specialist
Related: penetration test cost, SOC 2, PCI DSS 11.4, cyber insurance, customer questionnaires, the report your SOC 2 auditor checks, a pen test report is evidence
