What the questionnaire is asking
Standard questionnaires such as the SIG and the CAIQ, and most custom ones, ask the same things:
- Has an independent third party tested your systems in the last 12 months?
- What was in scope?
- Were the findings fixed?
- Can you share a summary?
What a good report shows
- The date and the scope of the test
- That an independent party ran it
- The method used
- Findings ranked by severity, with proof
- Evidence that fixes were retested
Get it this week
- Standard external penetration test, $3,495 for a 30-day window: 10 external IPs or domains, with authenticated web application testing included. This is the usual fit for a software company.
- Starter external penetration test, $1,995 for a 30-day window: 1 external IP or domain.
Buy online, start the same day, fix what it finds, retest inside the window, then send your customer the executive summary instead of the full technical detail.
If the customer asks for a human-led test
Some enterprise customers specify a test led by a named engineer. Our managed penetration testing team does that.
See pen test pricing and buy online · Talk to a specialist
Related: SOC 2, HIPAA, ISO 27001, PCI DSS 11.4, penetration test cost
