Always-on AI pentesting for your web apps and APIsAlways-on AI pentestingStart an AI pentest
Penetration testing

Your customer asked for a pentest report. Here's what to send.

Short answer: Most reviewers want a test of the product they're buying from the last 12 months, the interval PCI DSS uses, not a test of your whole company. Send a one-page attestation letter or an executive summary first, and the full report only under NDA. It should show scope, dates, methodology, findings by severity and retest status.

The email usually comes from procurement, a week before the contract is due: "Please provide your most recent penetration test report." Sometimes it's question 47 of a 200-row spreadsheet. Either way, the deal waits until you answer.

Here's what reviewers look for, which document to send to whom, and how to get one quickly if you don't have a recent test.

What do enterprise buyers actually ask for?

They want to know that someone tested the product they're about to buy, recently, and that you did something about what was found. The questions differ between customers, but they come back to the same handful of things.

RequestWhy they askWhat answers it
Date of testingA report from before your last big release says little about the product todayTest end date, ideally within the last 12 months, plus the date of the next test
ScopeThey're buying one product, so they want that product testedThe app or API by name, the environment, and which user roles were tested while logged in
MethodologyTo judge how deep the test wentA named standard, such as OWASP WSTG, and a coverage summary
Who testedThey want someone other than the team that wrote the codeThe provider's name and how the test was run
FindingsTo see what was exposedFindings grouped by severity, with evidence for each
Remediation and retestTo see whether you act on findingsFix status per finding and the date of the retest
Open critical or high findingsThis is often the question that decides the reviewA statement that none are open, or a fix plan with dates
Something they can fileMost reviewers can't store your full reportAn attestation letter or an executive summary

Letter, summary or full report: what should you send to whom?

Send the least that answers the question, and keep the full report for readers who need it and have signed an NDA.

DocumentWhat it containsWho it's forWhen to send it
Attestation letter (one page)Provider, system tested, test dates, method, a result summary and retest statusProcurement and questionnaire answersFirst, usually without an NDA
Executive summary (two to five pages)Scope, method, number of findings by severity, remediation statusThe customer's security reviewerWhen the letter isn't enough and they want more detail
Full reportEvery finding with evidence, reproduction steps and fix guidanceAn auditor, or a deep review on a large dealOnly when asked, under NDA, redacted where needed

Before you send a full report, take out test credentials, session tokens and anything that tells a reader how to reproduce a finding you haven't fixed yet. Reviewers are after the fix status. They don't need a working exploit.

How do security questionnaires ask about pentests?

Most enterprise questionnaires are built on a standard template or on the customer's own list. The pentest question looks different in each, but the answer is the same set of facts.

  • SIG and SIG Lite. The Standardized Information Gathering questionnaire from Shared Assessments is licensed, and SIG Lite is its shorter version. Its threat and vulnerability management questions cover whether you run penetration tests, how often, and how you track findings to a fix.
  • CAIQ. The Cloud Security Alliance's Consensus Assessments Initiative Questionnaire follows the Cloud Controls Matrix. Control TVM-06, Penetration Testing, asks for a defined process for periodic penetration tests by independent third parties.
  • Customer-specific forms. Often a yes or no, a date and an upload field for the report.
  • NIS2 supplier clauses. EU customers covered by NIS2 have to handle security in their supply chain (Article 21(2)(d)), and some pass that down to you as contract terms. NIS2 and penetration testing covers what the law asks for. In Sweden, from 2026-10-01, covered organizations must make sure their suppliers meet the security rules in the security rules in MCFFS 2026:11 (4 kap. 1 §), which include security testing (4 kap. 27 §).

An answer that works for most of them:

Yes. Our web application and API were last penetration tested on <date> by <provider>, using a methodology mapped to OWASP WSTG. The attestation letter is attached. As of the retest on <date>, no critical or high findings are open. The next test is scheduled for <date>.

Fill in real dates. If a finding is still open, say so and give the fix date. Reviewers spot a vague answer quickly.

What does a good attestation letter contain?

A letter is useful only if a reviewer can check what it covers. Ask your provider for a letter or attestation, and make sure it has these items.

ItemWhat to look for
ProviderCompany name and a contact for questions
SignerA named person at the provider who stands behind the statement
Client and systemYour company and the exact app or API tested
Test windowStart and end dates
ScopeEnvironment, main URLs or API base, and which roles were tested
MethodologyThe standard followed, such as OWASP WSTG
ResultsNumber of findings by severity
RemediationWhat was fixed and when it was retested
LimitsWhat the test didn't cover, such as internal networks or mobile apps
ValidityWhether it's a point-in-time statement or states a date it's current until
VerificationA way for the reader to confirm the letter is genuine

A letter isn't a certification, and a good one says what it doesn't prove. If a provider's letter says your product "is secure", ask them to reword it.

How fast can you get a report to send?

Hours for the test, not weeks. What takes longest is usually setting up test accounts and fixing what the test finds.

StepTime
Approve the scope and add test accountsYour side. Often under an hour if the accounts exist
Pentest runHours
Report releaseOn completion for Light. Within one working day from Standard up, after a security engineer has reviewed the findings
Fix the findingsYour team
RetestFree. It reuses the scope and test accounts from the original run
Send the letter or summaryOnce the retest shows where each finding stands

If a deal is waiting, you can start a single pentest yourself today. Essential starts at €199/month, and per-run prices are on pricing. What a pentest costs elsewhere is on penetration testing cost. If you're not sure how close your app is to passing, run the free pre-pentest check first. It's a passive scan, not a pentest.

How Barrion does it

Barrion's AI agents test your web app and API the way an attacker would, mapped to the OWASP WSTG test cases, the OWASP Top 10 and the OWASP API Security Top 10. Tests are rate-limited and non-destructive, and you approve the scope before any traffic goes out.

  • Reports come as PDF, XLSX and JSON, with an OWASP WSTG coverage matrix. The sample report shows the layout.
  • Findings are checked against the live app before they're reported. Confirmed ones come with the request and response behind them. Anything that can't be confirmed is kept as a lower-confidence lead, so a reviewer can tell which is which.
  • Every finding carries its fix status, and retests of found issues are free.
  • From Standard up a security engineer reviews the findings, and deeper tests come with a report signed off by that engineer.

Where your test data lives

Some questionnaires also ask where your pentest provider keeps test data and reports, since a list of findings is sensitive. For Barrion: stored and hosted in Sweden, with AI processing in the EU. The full subprocessor list is on the trust page.

What it doesn't cover

We don't test internal networks, Active Directory, mobile apps, physical security or social engineering. A Barrion report isn't a SOC 2 report and isn't a certification. If a reviewer asks whether an AI pentest counts, the AI vs manual pentesting guide covers what each finds. For framework context, see SOC 2 and PCI DSS, and audit-ready security for how reports fit an audit.

How do you keep the next review easy?

Don't let the report go stale. A report from last year answers this year's questionnaire badly, and the next customer will ask again.

A saved pentest can rerun on a schedule, so there's always a recent run to point to. Each run labels findings new, still open, resolved or regressed, so you can show a reviewer that a fix held. For how often that should be, see how often to pentest. If you run several apps and APIs, pentesting for growing SaaS companies covers how to set up a program.

Sources

All sources checked 2026-09-26.

FAQ

Frequently asked questions

What is a pentest letter of attestation?
A one-page letter from the pentest provider that confirms a test took place. It names the provider and the signer, the system tested, the test dates, the method, a summary of results by severity and the retest status. It lets you answer a questionnaire without sharing the full report.
Is an attestation letter enough for a security questionnaire?
Often it's enough for the pentest question, but not always. Some reviewers want the executive summary or the full report under NDA, especially on large deals or when a finding is still open. Send the letter first and offer the summary if they need more.
Should I share the full pentest report with a customer?
Only under NDA and only when they ask for it. Send the letter or executive summary first. Before sharing the full report, remove test credentials, session tokens and reproduction steps for anything that isn't fixed yet.
How recent does a pentest need to be?
Most reviewers expect a test from the last 12 months, which matches the PCI DSS requirement to test at least once every 12 months and after significant changes. If you've shipped a major change since your last test, such as a new login flow or a new API, test again before you answer.
What if the report still has open findings?
Say so. Show each open finding's severity, the fix plan and the retest date. Reviewers mostly look for open critical or high findings and whether you have a plan for them. A report with open lows and a clear plan usually goes down better than a vague answer.
Will a customer accept an AI pentest report?
It depends on the reviewer, and nobody can promise it. What helps is a report that shows scope, a methodology mapped to OWASP WSTG, the request and response behind each confirmed finding, and a security engineer's review. Share a sample report with the reviewer early and ask.
How fast can I get a report to send?
The test itself takes hours. On Barrion a Light report is released on completion, and from Standard up it's released within one working day, after a security engineer has reviewed the findings. Add the time to fix what was found and run the free retest, then send the letter or summary.
Where does Barrion store pentest data and reports?
Customer data is stored and hosted in Sweden, and AI processing runs in the EU. Every subprocessor is listed on our trust page.

Get a report you can send.

Start an AI pentest and have a reviewed report within a working day from Standard up. Deeper tests add a report signed off by a security engineer.