NODUM

A customer asks you for a pentest: what to do

A large customer, a public body or a bank asks you for a pentest before signing, or sends you a security questionnaire with that question inside. This is worth knowing before you commission one.

What they are really asking for

They almost never want a certificate. They want evidence that someone independent has tried to attack what you are going to give them (an application, a portal, an API) and that you have fixed what came up.

The request often comes from their own obligations. NIS2 asks the companies it covers to look after the security of their supply chain, and DORA (Regulation (EU) 2022/2554, Article 28) asks banks, insurers and other financial entities to manage the risk of their technology providers. The questionnaire is how they do it.

What to ask them before commissioning it

Five questions that save you from commissioning a test that turns out to be useless to them:

Which systems they want tested: only what they will use, or everything you expose to the internet.

What kind of test they expect: from outside without credentials, or with a user inside the application.

How old the report may be at most.

Whether they also want the fixes checked, which is called a retest.

Whether they need the full report or a summary is enough.

What goes into the scope

The sensible start is what the customer will touch: the application or portal you will give them, with its permissions and its API. If they also ask about what you expose to the internet, the external perimeter test is added.

The scope is agreed in writing before starting, with the authorisation of the owner of the systems. If the application runs on a cloud or hosting provider, its terms for security testing also need checking.

What you show them at the end

The report describes how your system could be attacked, so it should not travel further than necessary. Ask whether a summary is enough: what was tested, when, what was found and what is fixed.

If there were vulnerabilities, what reassures a customer most is seeing them closed. That is why it makes sense to plan the retest from the start.

What it is not

A pentest is not a certification and does not prove compliance with any standard. It is a dated technical test: it says what was found at that moment and within that scope. If your customer asks for a certification, such as ISO 27001 or the ENS, it is issued by a certification body, and we are not one.