Skip to content
Thornbury Labs
Authorised testing only. We test with your written authorisation, so scope and rules are agreed before testing begins. Testing is delivered by vetted third-party practitioners, and we do not describe our work as certified.

Guide

What a penetration test attestation letter proves, and what it does not

A penetration test attestation letter is a one-page signed letter confirming a test happened and what it covered. So you can prove testing to customers and partners without handing over the findings.

  • Fixed fee before we start
  • Named tester in writing
  • Retest and attestation letter
Penetration test attestation letter: test completes, letter is signed and share with buyers

What a penetration test attestation letter states

The letter is short by design. Therefore it states facts, not findings.

  • Who performed the test and when
  • What was in scope
  • The method followed
  • That a report was delivered to you

Who asks for a penetration test attestation letter

Enterprise customers, partners and some insurers ask for it during vendor reviews. Also, some third-party risk teams, such as those at lenders, ask for a letter and confirmation that high findings were fixed, so the retest letter often travels with it.

Will a penetration test attestation letter satisfy the request?

Tick what the requester asked for. It shows which document to send.

Your result appears here as you tick, so you can see what is still open.

Attestation letter, report or retest letter?

Each document serves a different reader. So send the lightest one that answers the question.

DocumentContainsShare with
Attestation letterTest date, scope and method.Customers and partners.
Retest letterWhich findings were closed.Auditors and risk teams.
Full reportEvery finding with proof.Your engineers and auditor.

What a penetration test attestation letter does not claim

It does not say your systems are secure, because no test can prove that. It also does not certify anything, since a test is never certified. It simply records that independent testing took place inside a stated scope. So treat it as evidence of process, while the retest letter is evidence of outcome.

Getting one from us

Every package includes an attestation letter and a retest letter. So you receive both without extra cost once testing and the retest are done. Method references include NIST SP 800-115.

Penetration test attestation letter questions

Is a penetration test attestation letter enough for SOC 2?

Some auditors accept it, but many want the full report, so check first.

Who signs the letter?

The firm you contracted with, confirming the work and its scope.

Does the penetration test attestation letter list findings?

No. It confirms the test happened, while the retest letter covers closed findings.

Is there an extra charge?

No. Every package includes it.

Related guides

Get a test that includes the attestation letter

Send your scope and the buyer's request. We quote a fixed fee, and the letters are included.

Get my fixed-fee quote