What to Expect From a Penetration Test, From Scoping to Retest
What to expect from a penetration test goes well beyond the final report. At least, that’s how we do it at 7ASecurity. Before testing starts, you'll agree on scope and hand over access. During testing, you're expected to stay reachable. Afterwards, you get a report built around severity and reproduction steps, then a retest once fixes are in place, at no extra cost with us.

Most people think a penetration test ends when the report lands in your inbox. It doesn't. The report sits roughly in the middle of the penetration testing process, not at the finish line.
What happens before and after it shapes the value you get from the whole engagement, including how our quality guarantee plays out once the testing itself is done.
So, we’re answering what you can expect from a penetration test as the client, not just what the tester does behind the scenes.
Before Testing Starts: Access and Scope
A scoping call happens before anything technical begins. This is where we agree on targets, like which apps, environments, or network segments are in play. We also settle access, testing windows, and anything explicitly out of scope, like a third-party payment processor you don't control, for example.
Access usually means test accounts at a few different privilege levels, not your production admin credentials. What we ask for depends entirely on the test.
- A web app engagement might need a standard user account and a higher-privilege one.
- An internal penetration test might need nothing more than a network connection point, since the whole idea is to simulate what someone without prior access could reach.
Testing windows matters more than they might seem. Agreeing to them upfront means the tester knows when to push harder without you mistaking it for a real incident. It also means you're not caught off guard if something looks unusual on a dashboard during the agreed window.
One thing worth knowing upfront: we delete whatever access details and materials you handed over as soon as the project ends. That's not a vague promise. It's a fixed point in how every one of our engagements closes out.
What We Expect From You During Testing
You don't need to be available around the clock, but you do need a named point of contact who can respond to urgent issues. Two situations call for that urgent response.
- A tester finds something that looks like an active, real-world compromise, not a test finding, but a genuine live issue.
- A question about scope needs answering before testing can safely continue.
Outside of that, testing largely runs without needing anything further from you. That's by design. A test that depends on constant client input isn't testing much of anything.
What to Expect From a Penetration Test Report
This is where a lot of the value either shows up or leaves a gaping hole.
The Findings
In our reports every finding gets a unique reference ID and a severity rating right in its title. Findings are listed in the order they were found, not ranked by severity, so nothing gets buried by how the report is organised.
Core vulnerabilities and hardening recommendations sit in separate sections too. The first covers active security issues. The second covers lower-risk, best-practice items that strengthen your posture without representing an exploitable path. You won’t have to hunt through one list to work out which is which.
Each finding carries a technical description and reproduction steps, a working proof of concept, not just a theoretical write-up. Specific remediation guidance is included too, along with the exact files or code involved where applicable.
The strongest reports go further than just listing findings individually. Ours closes with a section that ties related findings together under a handful of named themes, access control or input handling, for example. That way you see the pattern behind a cluster of issues, not just a flat list of line items. That kind of synthesis comes from a person looking at the whole picture and asking what these findings have in common. A scanner can't do that; it reports each issue in isolation, with no way to reason about how they relate.
The Fixes
Once fixes are in and confirmed, each finding is also updated with its outcome:
- Resolved and verified
- Accepted as a residual risk
- Scheduled for a later release
This way, the report remains an accurate record of where things stand, not a snapshot that goes stale the moment you start fixing things.
Our testers work from a structured methodology broadly informed by recognised guides such as NIST's SP 800-115, but every engagement is scoped around your systems rather than run against a fixed checklist.
Pentest Retesting: What "Verified Fixed" Means
Once you've addressed the findings, retesting confirms the fix holds. A retest is narrower than the original test. It only checks the specific issues that were reported, not the whole system again from scratch.
We include free fix verification as part of every engagement, so confirming a fix doesn't come with a second invoice.
As a general rule of thumb, it’s best to do a pentest at least once a year and every time you make a material change to your environment. When you make a change, like rebuilding architecture or a major release, you only need to test the change and where it connects to your other systems.
A pentest retest is triggered by what you've fixed, not by a fixed calendar or system changes.
Our Guarantee Doesn't End at the Report
If a test ever falls short of our standard, we keep working at no extra cost until it meets the mark. That same guarantee backs free fix verification once you've made changes. The report is the middle of the engagement, not the end of it, and that's intentional.
Common Questions About the Penetration Testing Process
What Access or Credentials Will Testers Need From Us?
The specifics get confirmed during scoping rather than guessed at upfront, but two things are worth sorting out early.
- If your systems sit behind MFA, plan for a way to provision the test accounts around it; otherwise, the tester loses time getting locked out rather than testing.
- And credentials should reach the tester through a secure channel agreed in advance, rather than being dropped into an email thread.
Is Retesting Included or a Separate Cost?
With 7ASecurity, free fix verification is part of the engagement, so confirming that a reported issue is genuinely fixed doesn't come with an added invoice. Not every provider works this way, so it's worth confirming directly with whoever you're comparing.
How Is a Retest Different From a Brand New Test?
A penetration retest is narrower on purpose. It checks the specific findings from the original report rather than re-running the whole engagement, which keeps it faster and more focused than starting over.
How Long Does a Penetration Test Take?
There's no fixed answer, because a pentest timeline depends on scope
- How much ground there is to cover
- Whether the test runs black-box or white-box
- How many testers are assigned to it, etc.
As a rough sense of scale, a single, focused test can wrap up in under two weeks, while larger, multi-component engagements we've completed have run past thirty working days. Your scoping call is where that gets pinned down for your specific systems.
Do We Need a Data Processing Agreement in Place?
Often, yes. Since we're EU-based and GDPR-aware, a data processing agreement is standard practice if anything shared during testing counts as personal data. Raise it during scoping so it's signed before access changes hands, not chased down afterwards.
Will Testing Disrupt Our Production Environment?
That's what the testing windows agreed upon during scoping are for. Anything with a real risk of disruption gets flagged and agreed on in advance, and if a representative test environment exists, we'll usually recommend testing there first for anything higher-risk.
Want to See What a Real Report Looks Like?
We publish real pentest reports rather than just describing our process in the abstract, so you can see the depth of reporting and reproduction detail before you ever book a call.
Want to Read More?
- Ensure your basic security posture is solid before testing begins by reviewing the basic cybersecurity mistakes some companies make.
- Learn how testing scopes impact your final invoice in our guide to pentest pricing.
- Don't sign a contract until you know exactly what to ask a pentest company before you hire them.