Penetration Testing for Client Contracts

A customer has made testing a condition of the contract. The question is not whether to do it, but what specifically satisfies them — and that is usually narrower than you fear.

Usual trigger
Security questionnaire or MSA
Typical obligation
Annual, with evidence
Scoping call
Free
Deliverable
Shareable summary available

Read the clause, not the panic

Contractual security clauses are usually copied from a template, and the wording is often broader than the customer's actual concern. "Supplier shall conduct regular penetration testing of all systems" sounds enormous. In practice the reviewer wants assurance about the systems that touch their data.

Send us the clause or the questionnaire. Establishing what is genuinely being asked for is free, takes about half an hour, and frequently reduces the scope and the cost.

What the reviewer is actually checking

Whoever reads your response is usually working through a checklist. They want:

  • Independence. Testing by a third party, not your own developers.
  • Accreditation. Increasingly specified, and increasingly verified. CREST is the usual named standard.
  • Recency. Almost always within the last twelve months.
  • Relevant scope. Covering the systems that process their data, not an unrelated corporate network.
  • Evidence of remediation. Findings identified is half an answer. Findings closed is the whole one.

The recurring obligation people miss

Most contractual testing clauses are annual, not one-off. Signing means committing to a recurring cost for the life of the agreement, and to producing evidence each year without being chased for it.

Worth budgeting for at signature rather than discovering at the first renewal. Worth also checking whether the clause allows you to share a summary rather than the full technical report — most customers accept one, and it protects detail you would rather not circulate.

What we provide

A full technical report for your team, and where useful a customer-facing summary or letter of attestation you can share without exposing exploitation detail. Retest is included as standard, so you can evidence closure rather than just identification.

If the contract sets a recurring obligation, we will diary it and contact you ahead of the anniversary rather than leaving you to remember.

Be careful buying on price here

This is the situation where cheap testing most often backfires, because the report has to satisfy someone else. A scan presented as a penetration test is usually obvious to a competent security reviewer, and being caught submitting one damages the commercial relationship considerably more than the cost saved.

If the client's reviewer rejects your evidence, you commission a second test under time pressure and pay twice. The cheapest credible option is a properly scoped test from an accredited provider, not the lowest number you can find.

Common questions

The contract says 'all systems'. Do we really need to test everything?

Rarely. Template wording is usually broader than the customer's actual concern, which is the systems handling their data. Send us the clause and we will help you scope to what is genuinely being asked for, which is normally considerably less.

Can we share the report with our client?

Yes, it is yours. Many organisations share a summary or a letter of attestation instead of the full technical detail. We can provide a customer-facing version alongside the full report.

What if the client's reviewer rejects our report?

It happens, usually over scope, age or provider accreditation. If you can, send us the requirement before commissioning anything so this does not arise. If it has already happened, send us the rejection and we will tell you what would satisfy it.

Is this an annual commitment?

Most contractual clauses are annual. Check the wording before you sign, and budget for it. We will remind you ahead of the anniversary rather than waiting for you to be chased by the client.

The client also sent a 200-question security questionnaire. Can you help?

Send it over. A good portion of these are answered by Cyber Essentials certification plus a current test report, and knowing which questions actually need work saves considerable time.

Related

Ready to talk?

Scoping conversations are free and there is no sales team to get past. Tell us what you're dealing with and we'll tell you honestly what you need.