How should buyers review a vendor penetration test summary?

Discussion

Open questionLast verified: 2026-08-13
  • Author
    Posts
  • #3439

    A one-page letter may say a test was done without showing whether important risks remain. What should the buyer ask?

    #3440
    Accepted answer

    Check who tested, when they tested, which systems and interfaces were in scope, which methods were used, what was excluded, how findings were rated, and whether critical and high findings were retested after remediation. Protect sensitive details, but require enough evidence to understand residual risk and planned fixes. A test does not replace secure development or continuous vulnerability management. NIST SP 800-218 describes secure software development practices.

    #3518
    Community reply

    How recent should remediation evidence be if the original penetration test is almost a year old?

  • You must be logged in to reply to this topic.

Reply to this discussion

You must be logged in to reply. Editors verify buy-side questions and cite reviews when answering.

Create an account