Sample penetration test report: what is inside
What is in a Pentrox penetration test report?
A penetration test report is the real deliverable of a penetration test. You use it for remediation, for the retest and as evidence for an auditor or a customer. Every Pentrox report has the same structure, so your team and your auditor find their way quickly.
- Executive summary; the risk in plain language, the severity distribution and the remediation priorities.
- Scope and approach; which systems were tested, in which period, with which access level (black box, grey box or white box) and what was left out.
- Findings overview; all vulnerabilities in order of severity, each with its rating and status.
- Detailed findings; per vulnerability the location, the evidence, the reproduction steps, the impact and a concrete remediation advice.
- Technical conclusion; what the findings say together about resilience, including attack paths in which several findings were chained.
- Appendices; the method used and the standards (OWASP, PTES, NIST SP 800-115).
How to read a finding
Every finding has a fixed layout. The title says what is wrong. The severity, from informational to critical, follows the OWASP risk rating and the context of your environment. Compliance assessments (ISO 27001, NIS2, DigiD, PCI DSS, NEN 7510) also carry a CVSS score per finding. The location names the system, the URL or the parameter. The evidence consists of masked screenshots and requests. The reproduction steps are written so that your developer can see the problem without help. The remediation advice fits your environment; it is not boilerplate. After the retest every finding gets an updated status: resolved, partly resolved or open.
What to look for when comparing reports
Ask every provider for a sample report before you sign. Look for three things. Are there reproduction steps for every finding? Is the severity explained, or only a number? Does it say what was not tested? A report that consists mostly of raw scanner output says little about your real risks. More on this in Why the report is the real deliverable and in the glossary under What is a penetration test report?.
Request the sample report
Want to see what a Pentrox report looks like? Request the sample report with the button below. You receive an anonymised sample report with the same structure as the report you receive after your own test. Findings appear in the Pentrox Portal during the test; the full report follows within 5 business days after testing and a retest within 90 days is included.
Reporting & Deliverables
Insight that enables confident decisions.
Every security assessment results in a clear, board-ready report. Not raw vulnerability lists, but structured insight that supports prioritisation, decision-making and improvement.
All reports are delivered in English and designed for both executive leadership and technical teams.
What this report delivers
- Clear visibility of risk and priorities
- Insight into business impact
- Actionable remediation guidance
- A solid foundation for governance and audits
Executive Summary
Decision-making at a glance.
Summarises the objective, scope and approach of the assessment. Findings are grouped by severity and business impact, with clear remediation priorities. Written for both executives and management.
Vulnerability Overview
Where risk concentrates.
An overview of identified findings, categorised by type and severity. Supports prioritisation and remediation planning. Status indicators (open, fixed, retested) may be included.
Technical Conclusion
From findings to structural improvement.
Evaluates overall security posture based on severity, patterns and underlying control gaps. Recommendations focus on increasing security maturity beyond individual fixes.
Assessment Strategy & Scope
Context for correct interpretation.
Defines goals, assessed environments, test approach (e.g. white-box) and scope boundaries. Ensures findings are interpreted within the correct context.
Detailed Findings
Technical depth, practically applicable.
Each vulnerability is documented with evidence, reproducible steps and clear risk explanation (likelihood and impact), including practical remediation guidance and retesting support.
- Description and affected component
- Evidence and reproduction steps
- Severity rating (OWASP risk rating; CVSS in compliance assessments) and impact context
- Mitigation and remediation guidance
What a Pentrox report looks like
Structured for both technical teams and executive leadership.
Vulnerability Summary
Detailed Findings
Ready to Secure Your Environment?
Schedule a free intake call to scope your assessment. Pentrox identifies vulnerabilities in your applications, infrastructure, and cloud environments before attackers do.
Schedule an intake call