Build a penetration test scope you can take to a tester

Eleven questions. A draft scope you can copy, print or download. Nothing leaves your browser unless you send it.

Sorami Consulting uses PTES pre-engagement and NIST SP 800-115 to organise this draft scope. Answer eleven questions to record targets and exclusions. The draft includes access, rules of engagement and deliverables. Add asset names before seeking authorisation. Only a scope matching the published baseline shows A$7,500 ex GST. Wider scopes need a custom quote.

Your testing brief

Choose your answers and watch the draft take shape. Nothing is assumed until you select it.

Targets and coverage

Start with the boundary of your test.

01 What needs testing?

The target type decides the method and who can test it. A web app, a cloud account and an internal network need different skills.

02 How many separate applications?

Each application has its own code paths and access model. Two apps sharing a login are still two apps to test.

03 Roughly how many API endpoints?

Endpoint count helps define coverage. List methods, roles and business workflows as well as paths.

04 How many user roles?

Different roles may read different objects and call different functions. Name the role pairs the tester should compare.

05 Cloud accounts in scope?

Testing cloud configuration and identity is separate work from testing the application that runs there.

Access and timing

Plan safe access before testing begins.

06 How do users sign in?

The sign-in method decides which test identities you must create. MFA and SSO need identities that do not rely on a staff phone.

07 Which environment?

Production gives the truest result and the most risk. Staging is safer if it mirrors production code and configuration.

08 When can testing run?

Your operations team needs to know when alerts are expected, and who to call if something breaks.

Evidence and reporting

Tell us what the result needs to demonstrate.

09 Why are you testing?

The driver decides what the report must show. A PCI DSS assessor and a customer questionnaire ask for different evidence.

10 Do you need a retest?

A retest shows the fixes worked. Many requesters want that evidence as well as the original findings.

11 Who reads the report?

Engineers need reproduction steps. A customer or auditor may want a short letter they can file.

Assets and final details

Add what you know. Anything missing stays marked for confirmation.

List exact URLs or account names and exclusions. Add business-critical workflows and owner approval. Record dates with timezone and the stop-test contact. Specify evidence retention or deletion requirements. Do not enter passwords, tokens or customer data. These details stay in this page unless you submit the enquiry.

Live preview

Your draft scope

Updates as you choose. A draft for discussion, not authorisation to test.

Not started. Choose your first answer.

Price basis

Complete all eleven questions to check the published price basis. This is not a quote.

Private by default. No saved answers or system scans.

Where the price comes from

Published prices only.

The only price this page shows is our published one. A targeted web app or cloud test starts at A$7,500 ex GST. That covers one web application with its API and two user roles, or one cloud account. It includes five testing days, the report and a retest of critical and high findings. The pricing page describes that baseline. Wider or ambiguous scopes need a custom quote, not a formula.

Mobile apps, internal networks and more than two roles have no published price, so the builder shows none. The figure is indicative and not a quote. The fee is fixed in writing once scope is agreed.

Why each section is there

What a tester needs before day one.

In scope and out of scope

The written boundary of the test. The PTES pre-engagement section calls scope one of the most overlooked parts of a test.

Assumptions

What both sides take as given. A common one is a staging copy that matches production.

Access needed

Test accounts for each role. Without two accounts per role a tester cannot check that one user is kept out of another user's data.

Rules of engagement

The testing window and source IPs. Also the stop-test contacts and how urgent findings are raised. NIST SP 800-115 treats these as part of test planning.

Deliverables

The report and who it is written for. Also whether a retest of fixed findings is included.

For web and API targets the method usually follows the OWASP Web Security Testing Guide. If PCI DSS is the driver, requirement 11.4 of PCI DSS v4.0.1 sets the testing requirements and your assessor decides what is accepted. The ASD Essential Eight is a maturity model rather than a testing standard. A test can support that evidence, and Sorami is not an IRAP assessor.

What this is not

The limits of a draft scope

  • A starting point for discussion, not a contract.
  • Not authorisation to test. That needs a signature from the system owner.
  • Not a quote. The fee is fixed in writing after scoping.
  • Not a test. Nothing here touches your systems.

Your answers stay in this page. Nothing is sent until you submit the enquiry form below.

Send it to us

Send the draft with an enquiry.

The draft above is attached when you submit. We reply within one business day.

Your enquiry

Request a quote

Your draft scope is attached. Only your email is required. Please do not include credentials.

An enquiry, not an instant quote or a booking. We reply within one business day. We use your details only to reply. Our Privacy notice names every processor.

Questions before you book

Practical answers.

How do you scope a penetration test?

List the systems in scope and what is excluded. Name the roles, environments and testing window, and record the access the tester needs. Then agree the rules of engagement and the deliverables in writing. PTES calls this pre-engagement, and NIST SP 800-115 treats it as test planning.

What should a penetration test scope document include?

Six parts. In scope and out of scope assets come first. Then the assumptions and the access or test accounts needed. Then the rules of engagement, such as the testing window and the stop-test contact. Last come the deliverables and any retest. The builder above drafts each part from your answers.

How much does a penetration test cost in Australia?

Sorami publishes a starting price of A$7,500 ex GST for one web application with its API and two user roles, or one cloud account. That covers five testing days, the report and a retest of critical and high findings. Other scopes are quoted after a scoping call.

Is a scope document the same as authorisation to test?

No. A scope says what will be tested. Authorisation is a signed statement from someone with authority over every system in scope that permits the test. Testing should not start without both.

The long version of this checklist is how to scope a penetration test. What you should get back is set out in what a penetration test report should contain. If you are unsure whether you need a test or a configuration review, read cloud security review against penetration test. For APIs, the OWASP API Security Top 10 self-check shows which categories to prioritise. The engagement itself is on penetration testing, and every free tool is on resources.

Last reviewed: