When a customer requests a recent VAPT report, use a tiered assurance pack. Start with a current attestation or executive summary stating provider, dates, scope boundary, methodology, finding counts by status and retest position. Share a sanitized report under appropriate confidentiality when needed, and reserve detailed evidence or exploit steps for tightly controlled review. Always respect tester ownership, contracts and data-subject obligations.
Start with the assurance requirement
Ask what decision the customer is making and which contractual or regulatory requirement drives the request. A security questionnaire may need an attestation; a regulated assessor may need a controlled full report.
Record the requesting party, framework or contract clause, assessment boundary, evidence period, due date and decision the evidence must support. Confirm the interpretation with the auditor, assessor or customer where possible. A penetration test can contribute strong assurance, but a report cannot guarantee an audit outcome or replace the organization’s wider control evidence.
Create a traceable evidence index
- Requirement or control identifier and the assertion being supported.
- In-scope systems, interfaces, environments, identities and important exclusions.
- Assessment dates, methodology, tester identity or competence evidence and authorization.
- Finding identifiers, severity rationale, remediation owner, status and exception reference.
- Retest evidence, closure date, residual risk and the location of protected technical detail.
Maintain the original report and sharing rights, NDA and recipient authorization, data classification, executive summary, scope and date statement, methodology, findings by severity and status, retest letter, open-risk treatment, redaction log, approved sanitized version, distribution register and expiry or refresh date.
Use a tiered disclosure model
Different recipients need different evidence depth.
- Public assurance statement.
- NDA executive summary.
- Sanitized report.
- Controlled detailed review.
- Exceptional full-report transfer.
Define approval, channel, watermarking and retention for each tier.
Preserve scope and recency
Customers need to understand what product version and boundary the evidence covers.
- State test dates.
- Name service and environment.
- Summarize included interfaces.
- List material exclusions.
- Explain material changes since test.
Do not describe a narrow application test as organization-wide assurance or conceal a superseding release.
Summarize findings honestly
A useful summary distinguishes original results from current treatment.
- Show counts by original severity.
- Show closed and open status.
- Reference retest.
- Describe accepted risk carefully.
- Avoid zero-risk claims.
Do not delete open findings from totals; show current status alongside the historical result.
Redact sensitive detail systematically
Remove information that increases exploitability or violates privacy while keeping conclusions intelligible.
- Remove credentials and tokens.
- Mask internal addresses.
- Limit exploit steps.
- Protect personal data.
- Remove unrelated customer information.
Maintain a redaction log and verify that document metadata, attachments and images do not leak removed content.
Control approval and delivery
Report sharing is a security and contractual action, not an informal sales attachment.
- Verify sharing rights.
- Obtain accountable approval.
- Authenticate recipient.
- Use encrypted channel.
- Record version and expiry.
Offer a supervised review when contractual or data restrictions prohibit file transfer.
Operate the evidence workflow
- Confirm the requirement, evidence owner, reviewer and deadline.
- Freeze a versioned scope and record every approved change or exclusion.
- Collect assessment artifacts through a controlled, access-limited repository.
- Map findings and closure evidence without changing the tester’s original conclusion.
- Perform a completeness and consistency review before external sharing.
Create the assurance pack once through a cross-functional review by security, GRC, legal or privacy and sales. Reuse only while scope and status remain current, and refresh after material change or new testing.
Preserve evidence integrity and confidentiality
Keep the original signed or versioned report, evidence manifest and retest artifacts. Redact copies rather than overwriting the source. Restrict exploit steps, credentials, personal data and internal architecture to approved recipients. Record who received which version, under what authorization and for what purpose.
Quality checks before reliance
- Scope, dates and environment agree across the report, statement of work and evidence index.
- Every closure claim points to a finding identifier and retest result.
- Exceptions name an owner, rationale, review date and compensating controls.
- Control mappings distinguish direct evidence from supporting context.
- Sanitized summaries do not imply broader coverage or stronger closure than the source report.
Use framework language carefully
Use the applicable official control text and assessor guidance as the authority. The NIST Technical Guide to Information Security Testing and Assessment supports disciplined assessment planning and reporting, while the OWASP Web Security Testing Guide provides application testing context. Neither substitutes for framework-specific interpretation by the responsible auditor or assessor.
Report the assurance conclusion
Provide a concise scope-and-status summary, current retest evidence and contact for controlled follow-up. Mark limitations, confidentiality and validity period clearly on every derivative document.
State observed facts, limitations and management decisions separately. Do not use “compliant,” “certified,” “secure” or “all vulnerabilities fixed” unless the authorized assessor and evidence genuinely support that precise claim.
The GRC decision
Share evidence in proportion to the customer’s legitimate need. A carefully sanitized, traceable assurance pack can support the deal without disclosing credentials, exploit paths or unnecessary internal architecture.
Ask WIMD to discuss a customer assurance pack with accurate scope, closure status and controlled technical disclosure.
