How to Prepare for a Penetration Test: A Checklist
The quality of a penetration test is decided before the tester starts. Scope, access, and rules of engagement determine what gets tested and how deep the testing goes. This checklist covers what to sort out beforehand so you get a useful report instead of an expensive scan.
Define scope and objectives
- List the exact systems in scope: applications, APIs, hosts, and network segments. Ambiguous scope gets tested shallowly or skipped.
- State the objective: compliance evidence, a product launch, a client requirement, or a security review. The objective shapes depth and focus.
- Decide what is explicitly out of scope and write it down.
If you are testing for ISO 27001, map the scope to the systems declared in your statement of applicability from the start.
Provide access and environment
- Grant the accounts the tester needs. Grey-box with low-privileged credentials produces deeper findings than black-box, and the difference matters.
- Decide test versus staging. Production tests find real issues but carry risk; staging misses configuration differences. Many organizations test production with careful rules.
- Sort out data handling: what the tester may access, what must not be touched, and the NDA.
- A short walkthrough of the environment, the credentials, and the expected user roles saves the tester a day and buys you depth.
Set the rules of engagement
- Define the testing window and whether out-of-hours testing is allowed.
- List prohibited techniques: denial of service, phishing, password changes, and anything that could affect availability should be explicit, not assumed.
- Provide an emergency contact who can stop the test immediately.
- Agree on check-in frequency and how critical findings get escalated during the engagement.
Prepare your side
- Make sure logging and monitoring are on, so you have evidence of what the testers did and the security team can confirm they only did that.
- Decide on a change freeze. A change freeze protects the integrity of the test; if you cannot freeze, tell the tester so findings can be validated against the changes.
- Have rollback and incident response plans ready, even if the expectation is that they will not be needed.
During the test
- Expect a kickoff call and a walkthrough of the scope and credentials.
- Ask for early notification of critical findings so you can start remediation planning before the report lands.
- Keep the communication channel open; the best engagements are conversations, not transactions.
After the test
- Triage findings by severity, not by count. A report with three verified criticals is worth more than one with forty scan echoes.
- Record remediation decisions in your risk register, with owners and dates.
- Schedule the retest as part of the engagement. Fixes are only done when they are verified. Our engagement writeup shows what a closed loop looks like.
- Ask the tester for a prioritization session: which three fixes would have stopped the most severe paths, and what the residual risk is after they are done.
Common preparation mistakes
Most preparation failures are the same handful. Scoping too wide and testing everything shallowly instead of a focused surface deeply. Handing over credentials without a walkthrough, so the tester wastes time rediscovering what the team already knows. Skipping the kickoff call, then discovering mid-test that staging does not match production. And treating the report as the end, when the retest is where fixes actually get verified.
How long preparation takes
Plan two weeks of lead time for a typical engagement: one for scope and rules of engagement, one for access, environment, and the kickoff. Compliance-driven tests need longer, because the scope often has to be agreed with auditors or the board. Rushing the preparation compresses the part of the engagement that produces the report.
Takeaways
- Scope, access, and rules of engagement decide the value of the test.
- Grey-box access produces deeper findings than black-box.
- Logging and monitoring should be on before the tester starts.
- Escalate critical findings live, not only in the final report.
- Include the retest and track fixes in the risk register.
Preparing well is half the test. NIMR's web, API, and network VAPT includes a scoping call, clear rules of engagement, and a built-in retest. Request an assessment, or budget first.