How to Scope a Penetration Test Safely and Usefully

Define authorized targets, environments, test windows, exclusions, contacts, data handling, methods, and deliverables before penetration testing begins.

On this page

Scope and fit

A useful penetration test starts with written permission and a boundary both sides can explain. Clear scope protects production, testers, customers, and evidence quality.

Name the authorized assets

List domains, applications, APIs, IP ranges, accounts, cloud projects, and approved test environments. Identify third-party systems and customer data that are explicitly out of scope.

Agree on limits and escalation

Set test windows, prohibited actions, rate limits, social-engineering permissions, safety stop conditions, emergency contacts, and notification rules. Define how a suspected critical exposure is reported immediately.

Specify reporting and retest

Agree on evidence handling, severity discussion, affected versions, remediation guidance, and retest boundaries. NIST SP 800-115 describes planning and testing considerations; written authorization remains essential.

Decisions and tradeoffs

Use this table as a working review record. Replace assumptions with evidence from the target environment.

Decision areaWorking guidance
Name the authorized assetsList domains, applications, APIs, IP ranges, accounts, cloud projects, and approved test environments. Identify third-party systems and customer data that are explicitly out of scope.
Agree on limits and escalationSet test windows, prohibited actions, rate limits, social-engineering permissions, safety stop conditions, emergency contacts, and notification rules. Define how a suspected critical exposure is reported immediately.
Specify reporting and retestAgree on evidence handling, severity discussion, affected versions, remediation guidance, and retest boundaries. NIST SP 800-115 describes planning and testing considerations; written authorization remains essential.

Implementation questions

What should the team decide about name the authorized assets?

List domains, applications, APIs, IP ranges, accounts, cloud projects, and approved test environments. Identify third-party systems and customer data that are explicitly out of scope. Use a named owner and a written acceptance check so this decision can be reviewed after deployment.

What should the team decide about agree on limits and escalation?

Set test windows, prohibited actions, rate limits, social-engineering permissions, safety stop conditions, emergency contacts, and notification rules. Define how a suspected critical exposure is reported immediately. Use a named owner and a written acceptance check so this decision can be reviewed after deployment.

What should the team decide about specify reporting and retest?

Agree on evidence handling, severity discussion, affected versions, remediation guidance, and retest boundaries. NIST SP 800-115 describes planning and testing considerations; written authorization remains essential. Use a named owner and a written acceptance check so this decision can be reviewed after deployment.

Plan, build, verify, operate

Name the authorized assets: List domains, applications, APIs, IP ranges, accounts, cloud projects, and approved test environments. Identify third-party systems and customer data that are explicitly out of scope. Record the result and the next owner before changing the next boundary.

Deployment checks

Turn the page into a reviewable handover by assigning each check to a person and retaining its result.

How to Scope a Penetration Test Safely and Usefully: decision 1

Write down the boundary, owner, dependency, and proof required for how to scope a penetration test safely and usefully before implementation begins.

How to Scope a Penetration Test Safely and Usefully: decision 2

Write down the boundary, owner, dependency, and proof required for how to scope a penetration test safely and usefully before implementation begins.

How to Scope a Penetration Test Safely and Usefully: decision 3

Write down the boundary, owner, dependency, and proof required for how to scope a penetration test safely and usefully before implementation begins.

Handover and ownership

Before handover, name the system owner, support path, access boundary, backup or recovery responsibility, and the condition that pauses a change.

Keep a short record of what was tested, what remains outside scope, and when the review should happen again.

Sources and further reading

Talk to our team.

Tell us what you're working on, whether it's a deployment, an audit, a security test or a cyber range. You'll speak with an engineer who can help you scope it.

  • 30-minute call: free, with no obligation.
  • NDA on request: we can sign before you share details.
  • Clear next steps: a scope and plan after the call.