Sample Reports

SOC 2 & ISO 27001-Ready Sample Penetration Testing Reports

See exactly what you get before you engage.

Every report we deliver includes an executive summary for leadership, CVSS-scored technical findings with reproduction steps, developer-ready remediation guidance, and compliance mapping for SOC 2, PCI DSS, HIPAA, ISO 27001, and GDPR — not a scanner dump, not a generic template.

153+ Engagements delivered
6,000+ Vulnerabilities validated
250+ Clients in 30+ countries

Browse sample reports by engagement type below.

finding-excerpt.md SAMPLE
## Finding Summary — Web & API Pentest
## Scope: app.target.com · api.target.com

CRITICAL SQL Injection — /api/v1/search?q=
CVSS 9.8 OWASP A03:2021 SOC 2 CC6.1 PCI 11.3
CRITICAL IDOR — /api/v1/invoices/{id}
CVSS 8.6 OWASP API1:2023 SOC 2 CC6.3
HIGH JWT None-Algorithm Accepted
CVSS 7.5 OWASP API2:2023 SOC 2 CC6.6
HIGH Broken Function-Level Authorization
CVSS 7.2 OWASP API5:2023 SOC 2 CC6.1
MEDIUM Missing Rate Limiting on Auth Endpoints
CVSS 5.3 OWASP API4:2023
LOW Security Headers Misconfiguration
CVSS 3.1 OWASP A05:2021

[+] 15 findings total · All manually exploited · Retest closure included

Download a sample report for your stack

Real engagements. All credentials, PII, and client-identifying details sanitised before publication.

Available now

Web Application & API / SaaS Penetration Test

A combined web application and SaaS/API assessment covering SQL Injection, XSS, CSRF, session fixation, BOLA, broken function-level authorization, token non-invalidation, mass assignment, and more.

1 Critical 7 High 3 Medium 3 Low 1 Info
SOC 2 OWASP Top 10 OWASP API Security Top 10

Coming soon

Web Application Penetration Test

Standalone web application assessment — auth flows, broken access control, injection vulnerabilities, and business logic flaws with validated proof-of-exploit.

Sample report coming soon Contact us to request a preview →

Coming soon

API Penetration Test

REST and GraphQL tested for BOLA, BFLA, JWT/OAuth weaknesses, rate-limit bypass, and mass assignment — mapped to the OWASP API Security Top 10 (2023).

Sample report coming soon Request a preview →

Coming soon

Mobile App Penetration Test

iOS and Android: insecure data storage, weak transport security, and certificate pinning gaps via static and dynamic analysis.

Sample report coming soon

Coming soon

Cloud Penetration Test

AWS, Azure, or GCP: misconfigured storage, IAM privilege escalation paths, and exposed services.

Sample report coming soon

Coming soon

Network Penetration Test

External attack surface mapping plus internal lateral-movement simulation from a compromised endpoint.

Sample report coming soon

Not sure which report matches your stack? Book a free 30-minute scoping call and we’ll walk you through it.

Why our reports hold up under audit scrutiny

Report quality that scales from your dev team to your board to your auditor — in a single document.

FeatureAutomated ScannerTypical PentestPentest Testing Corp
Manual exploitation of every findingSometimes✅ Always
False positives filtered outSometimes✅ Always
CVSS v3.1 score per findingPartialSometimes✅ Always
Reproduction steps (sanitised)Sometimes✅ Always
Developer-ready remediation guidanceSometimes✅ Always
Compliance mapping (SOC 2 / PCI / HIPAA)Rarely✅ Always
Executive summary for board / CISOSometimes✅ Always
Retest closure evidenceRarely✅ Always
Encrypted evidence packageRarely✅ Always

Report formats your auditor will accept

Our reports are structured to serve as direct audit evidence. We’ve been through this process hundreds of times — the format is designed to pass vendor security reviews without a second request.

SOC 2 Type II
Findings mapped to Trust Service Criteria
CC6.1 · CC6.3 · CC6.6 · CC7.1 · CC7.2 · CC8.1
PCI DSS v4.0
Requirement 11.3 documentation in PCI-compatible format
Internal & external scope · QSA-ready evidence
HIPAA Security Rule
Technical safeguard findings for your SRA
45 CFR § 164.308 · § 164.312
ISO/IEC 27001:2022
Annex A risk treatment evidence
A.8.8 · A.8.29
GDPR Article 32
Technical failure findings for DPIA documentation
Art. 32 · Art. 35 DPIA support
OWASP LLM Top 10 / AI
AI system findings with NIST AI RMF alignment
LLM01–LLM10 (2025) · NIST AI RMF

Frequently asked questions about our reports

What information is included in your reports?

Every report includes an executive summary, scope and methodology documentation, a consolidated findings table, detailed per-finding write-ups (description, evidence, reproduction steps, remediation guidance), a CVSS and OWASP mapping table, a prioritised remediation roadmap, a retest status tracker, and relevant appendices — OWASP reference tables, SOC 2 TSC mappings, and a tested endpoint inventory.

Are the sample reports from real engagements?

Yes. Our samples are based on real penetration test engagements. All live credentials, personally identifiable information, client-identifying details, and customer data are sanitised before publication. The findings, severity ratings, reproduction steps, and remediation guidance reflect what was actually discovered and documented.

How are findings prioritised in the report?

Each finding is assigned a CVSS v3.1 score and a corresponding severity label (Critical, High, Medium, Low, or Informational). The remediation roadmap groups findings into time-based action tracks: Immediate (0–7 days) for actively exploitable vulnerabilities, Short Term (1–4 weeks) for high-impact issues requiring architecture changes, and Medium Term (1–3 months) for process and configuration improvements.

Can your reports be submitted directly to auditors?

Yes. Our reports are structured with SOC 2, PCI DSS, HIPAA, ISO 27001, and GDPR mapping built in. We have delivered reports that passed SOC 2 Type II audits, PCI DSS QSA reviews, and enterprise vendor security assessments without requiring supplementary documentation. A Letter of Attestation can also be issued separately if your auditor requires it.

What format are reports delivered in?

Reports are delivered as password-protected PDFs. A separate encrypted archive contains raw evidence: Burp Suite request/response captures, screenshots, and tool output. All test data is destroyed or returned to the client upon engagement completion.

Can I request a sample for a specific technology stack?

Yes. If none of the published samples match your environment — say, a GraphQL API sample, a mobile app sample, or a cloud infrastructure sample — contact us and we’ll share the most relevant example under NDA.

Do you offer a retest after findings are remediated?

Yes. Every engagement includes the option of a formal retest once critical and high findings are remediated. The retest confirms fixes are correctly implemented and produces a retest closure letter suitable for auditor submission. Retest scope and pricing are confirmed at the time of the original engagement.

Ready to commission your own report?

Share your scope – URLs, API endpoints, IP ranges, or app bundle identifiers, and we’ll respond within one business day with a fixed-price quote and a proposed timeline.

NDA available on request · Fixed-price engagements · Compliance-ready reporting · Production-safe testing

Scroll to Top
Pentest_Testing_Corp_Logo
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.