In scope and out of scope
The written boundary of the test. The PTES pre-engagement section calls scope one of the most overlooked parts of a test.
Eleven questions. A draft scope you can copy, print or download. Nothing leaves your browser unless you send it.
Sorami Consulting uses PTES pre-engagement and NIST SP 800-115 to organise this draft scope. Answer eleven questions to record targets and exclusions. The draft includes access, rules of engagement and deliverables. Add asset names before seeking authorisation. Only a scope matching the published baseline shows A$7,500 ex GST. Wider scopes need a custom quote.
Your testing brief
Choose your answers and watch the draft take shape. Nothing is assumed until you select it.
Start with the boundary of your test.
Plan safe access before testing begins.
Tell us what the result needs to demonstrate.
Add what you know. Anything missing stays marked for confirmation.
List exact URLs or account names and exclusions. Add business-critical workflows and owner approval. Record dates with timezone and the stop-test contact. Specify evidence retention or deletion requirements. Do not enter passwords, tokens or customer data. These details stay in this page unless you submit the enquiry.
Live preview
Updates as you choose. A draft for discussion, not authorisation to test.
Not started. Choose your first answer.
Complete all eleven questions to check the published price basis. This is not a quote.
Private by default. No saved answers or system scans.
The only price this page shows is our published one. A targeted web app or cloud test starts at A$7,500 ex GST. That covers one web application with its API and two user roles, or one cloud account. It includes five testing days, the report and a retest of critical and high findings. The pricing page describes that baseline. Wider or ambiguous scopes need a custom quote, not a formula.
Mobile apps, internal networks and more than two roles have no published price, so the builder shows none. The figure is indicative and not a quote. The fee is fixed in writing once scope is agreed.
The written boundary of the test. The PTES pre-engagement section calls scope one of the most overlooked parts of a test.
What both sides take as given. A common one is a staging copy that matches production.
Test accounts for each role. Without two accounts per role a tester cannot check that one user is kept out of another user's data.
The testing window and source IPs. Also the stop-test contacts and how urgent findings are raised. NIST SP 800-115 treats these as part of test planning.
The report and who it is written for. Also whether a retest of fixed findings is included.
For web and API targets the method usually follows the OWASP Web Security Testing Guide. If PCI DSS is the driver, requirement 11.4 of PCI DSS v4.0.1 sets the testing requirements and your assessor decides what is accepted. The ASD Essential Eight is a maturity model rather than a testing standard. A test can support that evidence, and Sorami is not an IRAP assessor.
Your answers stay in this page. Nothing is sent until you submit the enquiry form below.
The draft above is attached when you submit. We reply within one business day.
List the systems in scope and what is excluded. Name the roles, environments and testing window, and record the access the tester needs. Then agree the rules of engagement and the deliverables in writing. PTES calls this pre-engagement, and NIST SP 800-115 treats it as test planning.
Six parts. In scope and out of scope assets come first. Then the assumptions and the access or test accounts needed. Then the rules of engagement, such as the testing window and the stop-test contact. Last come the deliverables and any retest. The builder above drafts each part from your answers.
Sorami publishes a starting price of A$7,500 ex GST for one web application with its API and two user roles, or one cloud account. That covers five testing days, the report and a retest of critical and high findings. Other scopes are quoted after a scoping call.
No. A scope says what will be tested. Authorisation is a signed statement from someone with authority over every system in scope that permits the test. Testing should not start without both.
The long version of this checklist is how to scope a penetration test. What you should get back is set out in what a penetration test report should contain. If you are unsure whether you need a test or a configuration review, read cloud security review against penetration test. For APIs, the OWASP API Security Top 10 self-check shows which categories to prioritise. The engagement itself is on penetration testing, and every free tool is on resources.
Last reviewed: