✓ OSCP · OSWE · OSEP certified | Joost performs every test himself — no juniors | Response within 1 business day | Based in Haarlem

What Does a Good Pentest Report Look Like? And What’s Actually in It?

What Does a Good Pentest Report Look Like? And What’s Actually in It?

You’ve had a penetration test carried out. Now you receive the report. But how do you know if it’s a good report? And what should you expect from a professional pentester? This article explains what’s in a quality pentest report and what to look out for.

The structure of a good pentest report

1. Executive summary

The executive summary is for leadership and non-technical decision-makers. A good summary includes:

  • What was tested (scope) and how (approach)
  • An overall risk class: critical / high / medium / low
  • The two or three most critical findings in plain language
  • A general recommendation (e.g. “patch immediately” or “address in a planned manner”)

An executive summary should never be more than one page. If it’s two, it’s not a summary.

2. Test scope and methodology

What was in scope? Which approach was used (black/grey/white box)? Which tools were deployed? Which standard was followed (OWASP, PTES, NIST)? When was the test carried out? This is crucial for traceability and audits.

3. Findings — the core of the report

Each finding should include, at minimum:

  • Title — a short, clear name for the vulnerability
  • Severity/risk classification — preferably a CVSS score (0–10) plus a textual explanation
  • Description — what is the vulnerability, technically speaking?
  • Impact — what could an attacker do with this? What’s the potential damage?
  • Reproduction steps — how can the finding be reproduced (for verification)?
  • Evidence — screenshots, HTTP requests/responses, code fragments
  • Remediation advice — concrete and specific, not “implement better security”

4. Overview of all findings

A summary table with all findings, sorted by severity. This gives the development or security team an immediate priority list.

5. Positive findings (optional but valuable)

Good reports also mention what’s already working well. This gives context to the findings and acknowledges work already done.

What is a CVSS score?

CVSS (Common Vulnerability Scoring System) is a standardised way to score the severity of a vulnerability on a scale of 0 to 10:

  • 9.0–10.0 — Critical: immediate action required
  • 7.0–8.9 — High: address as soon as possible
  • 4.0–6.9 — Medium: resolve in a planned manner
  • 0.1–3.9 — Low: monitor and fix when convenient

A good pentester explains why the score is what it is — not just the number, but also the context (e.g. “high in the lab, medium in your specific setup because…”).

What makes a bad report?

Watch for these red flags:

  • Only automated scan results with no manual verification
  • No reproduction steps — you can’t recreate the finding
  • No screenshots or evidence
  • Remediation advice like “update your software” without specifying which version
  • No executive summary, or a four-page “summary”
  • The report is finished within a day after a “5-day pentest”

FAQ

Can I share the report with my customers or auditors?

Yes, but be careful. A full technical report contains detailed attack information. Share the executive summary with external parties, and the full report only with your internal security team or auditors under NDA.

How long is a report valid?

A pentest report has no formal expiry date, but findings are contextual: after significant system changes, or after 12 months, a retest is recommended. Some auditors won’t accept reports older than 12 months.

Can I see a sample report?

MonkeysICT can show an anonymised sample report during an introductory call. Get in touch via the quote request page.

Request a pentest  ·  How to read a pentest report

Scroll to Top