Before onboarding a penetration-testing company, collect documents that prove who will perform the work, whether they are competent and independent where required, how they protect sensitive evidence, and how contractual accountability works. Apply due diligence proportionate to the access and data involved; do not mistake a certificate bundle for proof of engagement quality.

Start with the assurance requirement

Start from the access model, data classification, regulatory obligations, geography, customer commitments and procurement policy. Mark mandatory evidence and permitted alternatives before vendors submit documents.

Record the requesting party, framework or contract clause, assessment boundary, evidence period, due date and decision the evidence must support. Confirm the interpretation with the auditor, assessor or customer where possible. A penetration test can contribute strong assurance, but a report cannot guarantee an audit outcome or replace the organization’s wider control evidence.

Create a traceable evidence index

  • Requirement or control identifier and the assertion being supported.
  • In-scope systems, interfaces, environments, identities and important exclusions.
  • Assessment dates, methodology, tester identity or competence evidence and authorization.
  • Finding identifiers, severity rationale, remediation owner, status and exception reference.
  • Retest evidence, closure date, residual risk and the location of protected technical detail.

Request corporate registration and tax details, ownership and sanctions declarations where required, insurance, security and privacy policies, certifications with scope, data locations, subprocessors, tester profiles, conflicts and independence, methodology, QA, sample redacted report, incident process, evidence retention and deletion, business continuity and references.

Know the contracting entity and its ability to accept accountability.

  • Verify registration.
  • Confirm tax and banking identity.
  • Review insurance.
  • Identify ownership and conflicts.
  • Check authorized signatory.

Validate high-risk documents through authoritative sources rather than email attachments alone.

Assess team competence

The actual testers must match the application, API, cloud or mobile scope.

  • Review relevant experience.
  • Inspect certifications as supporting evidence.
  • Confirm senior review.
  • Identify subcontractors.
  • Check language and time-zone support.

Ask who is assigned after award and how substitutions are approved.

Review security and privacy controls

Pentesters may hold credentials, architecture and exploit evidence.

  • Review access control.
  • Confirm encryption.
  • Identify data locations.
  • Set retention and deletion.
  • Assess incident notification.

Match controls to the real engagement workflow, including collaboration and report-delivery tools.

Evaluate methodology and QA

Operational documents should demonstrate controlled, reproducible and reviewed work.

  • Inspect scoping process.
  • Review validation standard.
  • Check safety controls.
  • Confirm peer review.
  • Examine redacted deliverable.

Generic marketing slides do not replace a usable methodology and quality process.

Record exceptions and approvals

Missing evidence needs an accountable decision and compensating safeguard.

  • Log evidence gap.
  • Assess associated risk.
  • Request alternative proof.
  • Name approver.
  • Set review trigger.

Do not mark questionnaires complete when material answers remain unsupported.

Operate the evidence workflow

  1. Confirm the requirement, evidence owner, reviewer and deadline.
  2. Freeze a versioned scope and record every approved change or exclusion.
  3. Collect assessment artifacts through a controlled, access-limited repository.
  4. Map findings and closure evidence without changing the tester’s original conclusion.
  5. Perform a completeness and consistency review before external sharing.

Use one evidence register with source, date, reviewer, result, expiry and exception. Keep sensitive vendor documents access-controlled and refresh time-bound evidence.

Preserve evidence integrity and confidentiality

Keep the original signed or versioned report, evidence manifest and retest artifacts. Redact copies rather than overwriting the source. Restrict exploit steps, credentials, personal data and internal architecture to approved recipients. Record who received which version, under what authorization and for what purpose.

Quality checks before reliance

  • Scope, dates and environment agree across the report, statement of work and evidence index.
  • Every closure claim points to a finding identifier and retest result.
  • Exceptions name an owner, rationale, review date and compensating controls.
  • Control mappings distinguish direct evidence from supporting context.
  • Sanitized summaries do not imply broader coverage or stronger closure than the source report.

Use framework language carefully

Use the applicable official control text and assessor guidance as the authority. The NIST Technical Guide to Information Security Testing and Assessment supports disciplined assessment planning and reporting, while the OWASP Web Security Testing Guide provides application testing context. Neither substitutes for framework-specific interpretation by the responsible auditor or assessor.

Report the assurance conclusion

Produce a due-diligence decision summary covering mandatory gates, residual concerns, contract conditions and the approved engagement access model.

State observed facts, limitations and management decisions separately. Do not use “compliant,” “certified,” “secure” or “all vulnerabilities fixed” unless the authorized assessor and evidence genuinely support that precise claim.

The GRC decision

Onboard the vendor when evidence supports legal accountability, suitable competence and safe handling for the proposed scope. Collect only what informs a real decision and verify the highest-risk claims.

Ask WIMD for vendor documentation covering company, team, methodology, quality, privacy and secure evidence handling.