Short answer: Most reviewers want a test of the product they're buying from the last 12 months, the interval PCI DSS uses, not a test of your whole company. Send a one-page attestation letter or an executive summary first, and the full report only under NDA. It should show scope, dates, methodology, findings by severity and retest status.
The email usually comes from procurement, a week before the contract is due: "Please provide your most recent penetration test report." Sometimes it's question 47 of a 200-row spreadsheet. Either way, the deal waits until you answer.
Here's what reviewers look for, which document to send to whom, and how to get one quickly if you don't have a recent test.
What do enterprise buyers actually ask for?
They want to know that someone tested the product they're about to buy, recently, and that you did something about what was found. The questions differ between customers, but they come back to the same handful of things.
| Request | Why they ask | What answers it |
|---|---|---|
| Date of testing | A report from before your last big release says little about the product today | Test end date, ideally within the last 12 months, plus the date of the next test |
| Scope | They're buying one product, so they want that product tested | The app or API by name, the environment, and which user roles were tested while logged in |
| Methodology | To judge how deep the test went | A named standard, such as OWASP WSTG, and a coverage summary |
| Who tested | They want someone other than the team that wrote the code | The provider's name and how the test was run |
| Findings | To see what was exposed | Findings grouped by severity, with evidence for each |
| Remediation and retest | To see whether you act on findings | Fix status per finding and the date of the retest |
| Open critical or high findings | This is often the question that decides the review | A statement that none are open, or a fix plan with dates |
| Something they can file | Most reviewers can't store your full report | An attestation letter or an executive summary |
Letter, summary or full report: what should you send to whom?
Send the least that answers the question, and keep the full report for readers who need it and have signed an NDA.
| Document | What it contains | Who it's for | When to send it |
|---|---|---|---|
| Attestation letter (one page) | Provider, system tested, test dates, method, a result summary and retest status | Procurement and questionnaire answers | First, usually without an NDA |
| Executive summary (two to five pages) | Scope, method, number of findings by severity, remediation status | The customer's security reviewer | When the letter isn't enough and they want more detail |
| Full report | Every finding with evidence, reproduction steps and fix guidance | An auditor, or a deep review on a large deal | Only when asked, under NDA, redacted where needed |
Before you send a full report, take out test credentials, session tokens and anything that tells a reader how to reproduce a finding you haven't fixed yet. Reviewers are after the fix status. They don't need a working exploit.
How do security questionnaires ask about pentests?
Most enterprise questionnaires are built on a standard template or on the customer's own list. The pentest question looks different in each, but the answer is the same set of facts.
- SIG and SIG Lite. The Standardized Information Gathering questionnaire from Shared Assessments is licensed, and SIG Lite is its shorter version. Its threat and vulnerability management questions cover whether you run penetration tests, how often, and how you track findings to a fix.
- CAIQ. The Cloud Security Alliance's Consensus Assessments Initiative Questionnaire follows the Cloud Controls Matrix. Control TVM-06, Penetration Testing, asks for a defined process for periodic penetration tests by independent third parties.
- Customer-specific forms. Often a yes or no, a date and an upload field for the report.
- NIS2 supplier clauses. EU customers covered by NIS2 have to handle security in their supply chain (Article 21(2)(d)), and some pass that down to you as contract terms. NIS2 and penetration testing covers what the law asks for. In Sweden, from 2026-10-01, covered organizations must make sure their suppliers meet the security rules in the security rules in MCFFS 2026:11 (4 kap. 1 §), which include security testing (4 kap. 27 §).
An answer that works for most of them:
Yes. Our web application and API were last penetration tested on <date> by <provider>, using a methodology mapped to OWASP WSTG. The attestation letter is attached. As of the retest on <date>, no critical or high findings are open. The next test is scheduled for <date>.
Fill in real dates. If a finding is still open, say so and give the fix date. Reviewers spot a vague answer quickly.
What does a good attestation letter contain?
A letter is useful only if a reviewer can check what it covers. Ask your provider for a letter or attestation, and make sure it has these items.
| Item | What to look for |
|---|---|
| Provider | Company name and a contact for questions |
| Signer | A named person at the provider who stands behind the statement |
| Client and system | Your company and the exact app or API tested |
| Test window | Start and end dates |
| Scope | Environment, main URLs or API base, and which roles were tested |
| Methodology | The standard followed, such as OWASP WSTG |
| Results | Number of findings by severity |
| Remediation | What was fixed and when it was retested |
| Limits | What the test didn't cover, such as internal networks or mobile apps |
| Validity | Whether it's a point-in-time statement or states a date it's current until |
| Verification | A way for the reader to confirm the letter is genuine |
A letter isn't a certification, and a good one says what it doesn't prove. If a provider's letter says your product "is secure", ask them to reword it.
How fast can you get a report to send?
Hours for the test, not weeks. What takes longest is usually setting up test accounts and fixing what the test finds.
| Step | Time |
|---|---|
| Approve the scope and add test accounts | Your side. Often under an hour if the accounts exist |
| Pentest run | Hours |
| Report release | On completion for Light. Within one working day from Standard up, after a security engineer has reviewed the findings |
| Fix the findings | Your team |
| Retest | Free. It reuses the scope and test accounts from the original run |
| Send the letter or summary | Once the retest shows where each finding stands |
If a deal is waiting, you can start a single pentest yourself today. Essential starts at €199/month, and per-run prices are on pricing. What a pentest costs elsewhere is on penetration testing cost. If you're not sure how close your app is to passing, run the free pre-pentest check first. It's a passive scan, not a pentest.
How Barrion does it
Barrion's AI agents test your web app and API the way an attacker would, mapped to the OWASP WSTG test cases, the OWASP Top 10 and the OWASP API Security Top 10. Tests are rate-limited and non-destructive, and you approve the scope before any traffic goes out.
- Reports come as PDF, XLSX and JSON, with an OWASP WSTG coverage matrix. The sample report shows the layout.
- Findings are checked against the live app before they're reported. Confirmed ones come with the request and response behind them. Anything that can't be confirmed is kept as a lower-confidence lead, so a reviewer can tell which is which.
- Every finding carries its fix status, and retests of found issues are free.
- From Standard up a security engineer reviews the findings, and deeper tests come with a report signed off by that engineer.
Where your test data lives
Some questionnaires also ask where your pentest provider keeps test data and reports, since a list of findings is sensitive. For Barrion: stored and hosted in Sweden, with AI processing in the EU. The full subprocessor list is on the trust page.
What it doesn't cover
We don't test internal networks, Active Directory, mobile apps, physical security or social engineering. A Barrion report isn't a SOC 2 report and isn't a certification. If a reviewer asks whether an AI pentest counts, the AI vs manual pentesting guide covers what each finds. For framework context, see SOC 2 and PCI DSS, and audit-ready security for how reports fit an audit.
How do you keep the next review easy?
Don't let the report go stale. A report from last year answers this year's questionnaire badly, and the next customer will ask again.
A saved pentest can rerun on a schedule, so there's always a recent run to point to. Each run labels findings new, still open, resolved or regressed, so you can show a reviewer that a fix held. For how often that should be, see how often to pentest. If you run several apps and APIs, pentesting for growing SaaS companies covers how to set up a program.
Sources
All sources checked 2026-09-26.
Cloud Controls Matrix v4 and CAIQ v4, Cloud Security Alliance, control TVM-06 Penetration Testing
Standardized Information Gathering (SIG) questionnaire, Shared Assessments (licensed, so described and not quoted)
PCI DSS v4.0.1, PCI Security Standards Council, Requirement 11.4
Directive (EU) 2022/2555 (NIS2), Article 21(2)(d)
MCFFS 2026:11 (föreskrifter om säkerhetsåtgärder), 4 kap. 1 §, in force 2026-10-01, decided by MCF, now published by FRA (NCSC)
Barrion product facts, facts page