For the complete documentation index, see llms.txt. This page is also available as Markdown.

Pentest checklist

Understanding the purpose of the pentest checklist and how to find and fill it out.

The pentest checklist is a short questionnaire to help ensure that your team and Software Secured's testing team are both prepared to start the pentest on time. Submitting the pentest checklist on time helps our team maximize their time and provides as much coverage as possible.

The information that Software Secured obtains from the pentest checklist gives our team everything that we need to get started quickly on the first day of testing. The contents of the checklist vary depending on the type of testing performed.

For a detailed description of what information we need in each section of the checklist, see Infrastructure summary.


Information requested in the checklist

Two weeks before the pentest's scheduled start date, you will receive reminders to fill out the checklist by email and Slack. Each project has a separate pentest checklist. Because the information is saved automatically, multiple team members can participate in filling out the checklist.

The following information is requested in the checklist:

  • New features and use cases that are in scope for your pentest, if there is anything new since the last test.

  • Availability for a demo meeting.

  • Confirmation that the scope is accurate.

  • URLs and scoping confirmation for environments.

  • x2 sets of access credentials to your system (sent through a secure link).

  • VPN configuration information, if applicable.

PTaaS Clients

You don't need to recomplete this checklist for every test. Once the pentest checklist is completed the first time, you only need to make edits as needed.

If you have changes to any element of the questionnaire—such as new features in scope for the test or a new URL to the test environment—update the checklist with this information before your next pentest.


Finding and filling out the checklist in Portal

  1. Log in to Portal and select the project where you want to review the checklist.

  2. On the Overview tab, check the status of the checklist in the Project Details card.

  3. To view the detailed checklist, go to the Checklist tab.

  4. Add the required information for each component of your test. For more information, see Infrastructure summary.


Checklist FAQ

How do I add more than 20 IP addresses to the checklist?

When you have a large number of IP addresses or hostnames in the testing scope, collect them all in a spreadsheet or CSV file and upload it to the File Dropzone for the respective section.

Last updated

Was this helpful?