15% OFF ON ANY PLANUse code 15off4everClaim now →15% OFF ON ANY PLANUse code 15off4everClaim now →15% OFF ON ANY PLANUse code 15off4everClaim now →15% OFF ON ANY PLANUse code 15off4everClaim now →15% OFF ON ANY PLANUse code 15off4everClaim now →15% OFF ON ANY PLANUse code 15off4everClaim now →
Templates / Proposal

Free Penetration Testing Proposal Template

A penetration testing proposal covers the test scope and rules, the approach and fees, and the payment, data handling, and sign-off terms.

Penetration Testing Proposal template preview

Language:

en

Category:

Last updated:

October 2026

Share template

A penetration test can’t feel like a black box, because the buyer still has to answer for the result in an audit room or a board meeting. This penetration testing proposal puts the scope, the rules of engagement, and the proof standard up front, so the client can agree to the test without guessing what “testing” means or what might put production at risk. The document uses brass-olive and deep blue accents with Zilla Slab headings over Roboto body text, which keeps the tone official without tipping into alarm.

The proposal reads like a controlled plan, not a pile of scanner output. The opening pages explain what the client gets at the end, then ground the work in a named tester and recent engagement examples, before the method gets specific about scoping, test windows, access requirements, and evidence that can be replayed. Payment terms, production safety, and credential handling stay explicit, so “out of scope” and “pause and re-test” don’t get argued about after the fact... and the client sees the constraints before they see the price.

  • Summary Frames the buyer’s need for audit-ready evidence, sets expectations on tight scope and production safety, and points to a scoping call as the next step.
  • My approach Explains how scoping, test windows, asset lists, and evidence-led validation work, and keeps the client informed about access, noise, and constraints.
  • Fees Holds the Standard priced item, which you replace with your own figure before the proposal goes out.
  • Next steps Carries the signature and fee summary, and spells out sign-off, scheduling a testing window, and the booking payment sequence.
  • Credentials and data handling States how credentials get stored, what evidence gets collected, what the report includes, and when changes trigger a pause and re-test conversation.

Once the prices are swapped in for the Standard fee, the proposal goes out for acceptance and online signature, with a fee summary sitting next to the sign-off. The client signs, picks a testing window, and the payment schedule is already written into the terms so booking and delivery follow the same agreement.

We went from spending hours on every proposal to creating fully customized ones in under 5 minutes. That's not an exaggeration - we timed it.

Yazan & Mawaheb
Yazan & MawahebAgency Owners

What to include in a penetration testing proposal

PartWhat it covers

Summary

Explains what the client gets from the engagement and how scope and testing windows stay controlled to avoid downtime. Replace any scope-specific wording so the opening matches the test you’re proposing.

Who you are working with

Introduces the tester and the working style, focusing on explicit scope, clear evidence, and reporting that holds up under review. Swap in your own name, background, and how you document findings.

Recent projects

Sets context for the examples that follow so a client can see how engagements get scoped and evidenced. Update the framing if the proposal needs to match a specific test type.

Portfolio

Gives concrete past engagement snapshots, including what was tested and what the deliverables looked like. Replace the examples with work that matches the buyer’s environment and risk profile.

My approach

Walks through how scoping, asset lists, test windows, and validation work so the client knows what happens before, during, and after active testing. Adjust any steps that change based on the engagement.

Fees

Carries the Standard priced item and a short note on choosing the right tier for evidence depth and coverage. Replace the shipped price with your own before sending.

Next steps

Carries the online signature and a fee summary, then explains how dates get held and what happens after acceptance. Check the sequence matches how you book work and collect the first payment.

Payment

Defines the 50/50 invoicing schedule, 14-day terms, scope change control, access timing, and production safety expectations. Edit the access requirements and safety limits to fit the client’s systems.

Credentials and data handling

Covers credential storage, evidence limits, reporting expectations, change pauses, and permitted use of results. Align the wording with any customer-specific audit or insurance format requirements.

Who it is for

Penetration testers and security consultancies quoting penetration testing engagements for organisations that need an audit-ready report without production disruption.

The proposal in full

Summary

You’ll have a report you can hand to an auditor or a board, plus a fix list your technical team can work through without guessing what I actually proved.

You reached out because you need a test on file for audit, insurance, or a customer, or you want an independent check before a portal goes live. I keep scope and rules tight so testing produces evidence without creating downtime. If you’d like to move ahead, the next step is a short scoping call.

I start by agreeing scope in writing, then I test only what you sign off. During active testing I focus on paths that lead to real impact, and I validate findings with proof that can be replayed. I plan around production hours and account lockout thresholds so operations keep running.

Who you are working with

I’m Matthias Hofer, a penetration tester. I do focused security testing for organisations that need an answer they can stand behind later. Most of my work starts with a simple request: prove what an attacker can do, using the same access and constraints I would have in the real world, and write it down so it holds up.

People hire me when they want a pen test that stays readable under pressure. I keep scope, credentials, and test windows explicit so nobody is surprised. I avoid vague “high risk” language and I attach evidence to each finding so your team can reproduce it, patch it, and show the before and after.

Recent projects

Here are three recent penetration testing engagements that show how I scope, test, and document evidence for sign-off.

Portfolio

External network test. Tested internet-facing assets against the agreed IP ranges and domains, then validated the few paths that mattered. Delivered findings with reproduction steps and screenshots so the client could prove fixes to an auditor without a follow-up call.

Customer portal web test. Tested authentication, session handling, and data access controls in a pre-release portal. Confirmed which issues were exploitable with a standard user account, then re-tested after patches to confirm the exploit chain no longer worked.

Internal network test. Worked from a controlled internal foothold and mapped lateral movement paths that could reach sensitive systems. Focused on credential exposure and privilege escalation, then documented the exact pivot steps so remediation could be verified in a change window.

“Clear scope, no surprises, and the report answered every audit question.”

IT manager, a mid-sized manufacturer

My approach

I run penetration testing like a controlled exercise: agreed scope first, then a planned window, then evidence that stands up to review. You’ll always know what I’m testing, what access I’m using, and what might create noise in your environment.

1. Scope and rules Days 1-2 I confirm what is in scope and out of scope, what success looks like, and what safety limits apply. We agree the testing window, monitoring contacts, and lockout thresholds. If you need VPN access or test accounts, I specify exactly what I need and how I will store it. 2. Inventory and plan Days 2-4 You provide the final asset list for the agreed test type, and I turn it into a test plan you can sign off. This is where you catch surprises like third-party hosted services, legacy IP ranges, or production systems that must not be stressed. 3. Active testing Days 5-10 I perform hands-on testing against the signed-off scope and I prioritise exploit paths that lead to real access or data exposure. I keep attempts controlled to reduce account lockouts and unnecessary load. If I find a path that could cause disruption, I stop and confirm before pushing further. 4. Validation and handover Days 11-14 I validate findings with proof, capture evidence, and write up exactly how each issue was confirmed. Then we do a remediation call to walk through priority and sequencing. If you fix quickly, I can re-check the specific items during the engagement so you have confirmation in the final report.

Fees

Pick the tier based on how many environments and paths you need tested, and how much evidence you need the report to carry for audit and insurance.

Priced items

Next steps

If you want this booked in, I can lock dates once the scope and access approach are agreed.

1. Sign this proposal and choose your preferred testing window. 2. Pay the 50% booking invoice to reserve the dates. 3. Join a 30-minute scoping call so I can write the rules of engagement.

Signature

Fee summary

Payment

To book the engagement, the invoice for 50% is due when you sign. The remaining 50% is invoiced when the engagement is complete. Each invoice is payable within 14 days of its date.

Scope. Penetration testing only covers what we both list in the scope and rules of engagement. Anything not listed is out of scope. If you want to add or change targets, I will confirm the change in writing before I test.

Access and timing. You will provide working VPN or allowlisted access, and test credentials where needed, by the start of Day 5. If access is not ready, the active testing window moves, because I cannot safely validate findings without it.

Production safety. I will plan noisy or high-risk checks into an agreed testing window and avoid denial-of-service style testing unless you explicitly approve it. If I see a risk of lockout or outage, I will stop and contact you before continuing.

Credentials and data handling

I only store the credentials and keys I need to run the test, and I keep them in an encrypted vault. I will not copy business data unless it is required as evidence, and any evidence stays limited to what proves access.

Evidence and reporting. The report documents what was tested, what was proven, and how it was proven, with timestamps and clear reproduction notes where that is safe. If you need a specific format for audit or insurance, tell me at scoping.

Change pauses. If a major system change lands during Days 5 to 10, the results can stop matching what is live. In that case I will pause, confirm what changed, and agree with you whether to re-test the affected area.

Ownership and use. Once the engagement is paid in full, you own the report and can share it with auditors, insurers, and customers. I will not reuse your names, IPs, screenshots, or findings in marketing or talks without your written approval.

Questions about this proposal template

What should a penetration testing proposal include?

A penetration testing proposal typically covers the scope and rules of engagement, the testing approach, the fees, and the terms around access, timing, and reporting. This proposal also spells out credential and data handling so evidence and reproduction notes are agreed in advance.

How do we define what’s in scope and out of scope for a pen test?

Scope needs a written target list and clear exclusions, plus rules that say what access gets used and what “success” looks like. This proposal keeps anything not listed as out of scope and treats additions as a confirmed change before testing starts.

Will penetration testing disrupt production systems or lock accounts?

Risk goes down when the engagement defines test windows, monitoring contacts, and lockout thresholds before any active testing. This proposal also calls out “noisy or high-risk” checks and treats them as planned work rather than surprises.

What information does a penetration tester need to start?

Many engagements need allowlisted or VPN access and test credentials by an agreed start point for active testing. This proposal makes access and timing part of the written agreement so the testing window can move if access isn’t ready.

How should credentials and sensitive data be handled during a security test?

Credentials should be limited to what’s required and stored securely, and evidence should stay limited to what proves access. This proposal states encrypted credential storage and avoids copying business data unless it’s required as evidence.

What do we get at the end of a penetration test, and will it satisfy audit or insurance?

A typical deliverable is a report that documents what was tested, what was proven, and how it was proven, with evidence and reproduction notes where that’s safe. This proposal also flags audit or insurance format requirements at scoping so the final report matches what needs to be filed.

Start free today

Your entire business, one login away

No credit card required. No contracts. Just the tools you need to run, grow, and automate your business with Super Work AI.

No credit card required

Plutio - Your entire business, one login away