15% OFF ON ANY PLANUse code 15off4everClaim now →15% OFF ON ANY PLANUse code 15off4everClaim now →15% OFF ON ANY PLANUse code 15off4everClaim now →15% OFF ON ANY PLANUse code 15off4everClaim now →15% OFF ON ANY PLANUse code 15off4everClaim now →15% OFF ON ANY PLANUse code 15off4everClaim now →
Templates / Contract

Free Penetration Testing Contract Template

A penetration testing contract covers the test scope boundaries, payment milestones, confidentiality, responsibilities, early termination, and signing terms.

Penetration Testing Contract template preview

Language:

en

Category:

Last updated:

October 2026

Share template

A production release is getting close, and a penetration test has to prove the obvious routes in got checked without becoming the reason systems fall over. This penetration testing contract puts the control points in writing, so the engagement stays predictable once work starts, with headings in Raleway over Roboto body text and a green and orange palette.

The opening ties the contract to an accepted proposal and spells out what gets tested and what gets delivered at the end. What I will test limits work to the targets and hours authorised in writing, then confirms reporting, evidence capture, and a retest window, with a clear rule for scope changes and extra fees. Payment sets a 40% invoice at sign, 60% at completion, 14 day terms, and when work or sign off pauses if an invoice goes past due... and the middle sections cover confidentiality, access and approvals, and how stability risks get handled before any high impact step.

  • It sits alongside the proposal you Connects the contract to the accepted proposal and frames the engagement as controlled, auditable, and predictable.
  • What I will test Defines authorised targets, environments, and test hours, plus deliverables, retest, and how scope changes get confirmed in writing.
  • Payment States the 40% and 60% invoicing split, 14 day payment terms, and when non-urgent work pauses for overdue invoices.
  • Keeping things private Covers confidentiality of system details and findings, and when sharing the final report is allowed.
  • Stopping early Explains how either side can end the project, what gets paid, and what gets handed over if work stops mid-engagement.

Once the wording fits the engagement, the contract gets sent alongside the accepted proposal and the client signs online. The signed copy gives both sides something auditable to point to when access is requested, testing starts, findings get shared, or the schedule has to move.

We went from spending hours on every proposal to creating fully customized ones in under 5 minutes. That's not an exaggeration - we timed it.

Yazan & Mawaheb
Yazan & MawahebAgency Owners

What to include in a penetration testing contract

PartWhat it covers

It sits alongside the proposal you

Links the contract to the accepted proposal and explains how both documents define what gets tested, when it happens, and what gets delivered.

What I will test

Keeps testing inside written scope and authorised hours, then covers deliverables, evidence capture, the retest period, and how changes and extra fees get confirmed before work continues.

Payment

Spells out the 40% invoice at signing and the remaining 60% on completion, with 14 day terms and a pause on non-urgent work if payment goes overdue.

Keeping things private

Defines what stays confidential, when the final report can be shared with an auditor or customer, and what gets retained after the project ends.

How I am engaged

Clarifies independent contractor status and divides responsibilities for tools and approach versus internal approvals, change management, and providing access before Day 1.

What I am responsible for

Explains how stability risk gets handled, when written approval is needed for higher-risk steps, and what sits outside responsibility during the test.

Stopping early

Covers ending the project by notice, what gets paid if the work stops early, what gets handed over, and includes the Signature section for signing.

Who it is for

Independent penetration testers and security consultancies sending terms to a client ahead of a scoped engagement tied to an audit or go-live.

The contract in full

It sits alongside the proposal you have accepted, and together they describe what I will test, when I will test, and what you will receive at the end.

My job is to find realistic ways an attacker could get in, without creating avoidable disruption for your production systems. The terms below are how I keep the engagement controlled, auditable, and predictable once work starts.

What I will test

Penetration testing under this agreement covers only the targets, environments, dates and test hours you authorise in writing. Before Day 1, you confirm what is in scope and what is off limits, and I test only within those boundaries.

What you get is the deliverables listed in the proposal, including reporting, evidence capture, and one retest of agreed fixes during the Days 9 to 12 retest period. If you add targets, swap environments, or shift the timeline after I have started, I will confirm the change and any extra fee in writing before I continue, so you are not surprised later.

Payment

To book the project, I invoice 40% of the price when you sign the proposal. I schedule the engagement once that invoice is issued, and I start work once it is paid and access is ready.

I invoice the remaining 60% when the engagement is complete. Each invoice is payable within 14 days of its date. If a payment goes past due, I will pause non-urgent work, including report final sign-off and any retest booking, until your account is back up to date. If timing matters for an audit or go-live, tell me early so I can plan around payment dates.

Keeping things private

During penetration testing I may see system details, configurations, data, and security weaknesses. I treat anything I learn from your environment, and the fact of the findings themselves, as confidential. I do not share it outside your organisation.

You may need to share the final report with an auditor or a customer to prove you have been tested. That is fine once the final invoice is paid, and you can share it for the purpose it was written for. When the project ends, I keep my working notes private and I only retain what I need to support the report and answer reasonable follow-up questions. If you need an NDA or customer-specific wording, send it before Day 1.

How I am engaged

I do this work as an independent penetration tester, not as your employee. That means I control how I run my day-to-day work, the tools I use, and the technical approach, as long as I stay within the agreed rules of engagement.

You are responsible for your own internal approvals, change management, and communications to your users and stakeholders. I am responsible for my own taxes, insurance, equipment, and safe handling of the access you provide. I will ask for the access I need, such as test accounts, VPN details, and IP allowlisting, and you provide it before Day 1 so I can start on time.

What I am responsible for

I take care to keep production stable. I avoid actions that are likely to knock over systems, and if a step carries a meaningful stability risk I will stop and ask you for written approval and a safer time window. You also agree that penetration testing involves probing real systems, so some side effects can happen, especially in fragile environments or where monitoring and rate limits are tight.

I am responsible for the quality of my work and for handling your access and materials with care. I am not responsible for pre-existing weaknesses, outages caused by third-party providers, or issues caused by changes made in your environment while testing is in progress.

Stopping early

Either of us can end the project by giving notice. Because timing often ties to audits and go-live dates, I will agree the notice period with you in writing so it fits your schedule and mine.

If the project ends early, you pay for the work I have completed up to the end date, plus any non-cancellable costs you approved. I will hand over what is ready at that point, such as notes needed to explain confirmed findings and any draft or final report sections that are complete. If I am waiting on access, approvals, or a change window you have not provided, the schedule moves, and you can either keep the project on hold or end it under this clause.

Signature

Legal Notice: Please consult legal advice and carefully review the content of this contract template before implementing this template in your business.

Questions about this contract template

What should a penetration testing contract include?

A penetration testing contract typically includes scope boundaries, authorised targets and hours, deliverables, payment milestones, confidentiality, responsibilities, and what happens if the work stops early. The contract also needs clear rules for approving scope changes in writing before extra work starts.

How do you define scope for a penetration test?

Scope usually names the targets, environments, dates, and test hours the client authorises in writing. Anything out of scope stays off limits until the client approves a change, which also confirms any added fee before testing continues.

Can penetration testing be done without taking production down?

Penetration testing can be run with stability as a priority, but probing real systems can still cause side effects in fragile environments. The contract language should spell out that higher-risk steps pause until the client gives written approval and a safer window.

What access does a penetration tester typically need?

Access often includes test accounts, VPN details, and IP allowlisting so the tester can start on time. The contract should also put internal approvals, change windows, and stakeholder communications on the client side so access delays don’t become disputes.

When can a client share a penetration test report with an auditor?

A client can usually share the final report with an auditor or customer for the purpose the report was written for. The contract here ties that permission to the final invoice being paid and keeps working notes private.

What happens if a penetration test project ends early?

Early termination usually means the client pays for completed work up to the end date plus any approved non-cancellable costs. The tester then hands over what’s ready, such as confirmed findings notes and any draft or finished report sections that are complete.

Start free today

Your entire business, one login away

No credit card required. No contracts. Just the tools you need to run, grow, and automate your business with Super Work AI.

No credit card required

Plutio - Your entire business, one login away