Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
  1. Home
  2. Blog
  3. How Does a Penetration Testing Firm Handle Retest Requests Without Losing Days to Scoping and Unbilled Time?
Problems We Solve

How Does a Penetration Testing Firm Handle Retest Requests Without Losing Days to Scoping and Unbilled Time?

Pen test retests arrive unannounced, unscoped and often unbilled. We build retest handling for pen test firms that ties each retest to findings, dates and fees.

Updated 3 min readBy SpiderHunts Technologies

Free estimateNo obligation

Get a free estimate

Tell us what you need. A senior engineer reads every enquiry.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →

Quick answer — TL;DR

Retests cause trouble because they are small, urgent and badly defined: the client wants a quick check next week, nobody has confirmed which findings are in scope or whether the retest is included in the original fee, and the tester who did the original test may not be free. We build retest handling that starts from the original findings, confirms scope and commercial terms, books the right tester and produces a retest report that links back to the original.

The quick check

A client emails on Thursday: they have fixed the critical and high findings from the test in spring and need a retest before a customer audit at the end of the month. 'It should only take a day.' Your operations manager looks at the original engagement. Was a retest included in the price? The proposal says 'one retest within three months', and it has been five. The tester who did the original work is booked solid.

Someone agrees a day, partly to keep the client happy. Another tester picks it up, reads the original report the night before, and on the day finds that the client also changed their login flow, and wants that looked at 'while you are in there'. The day becomes two. The second day is not invoiced because nobody wants to argue about it.

The retest report is a new document with its own numbering, and the client's auditor asks how it relates to the original.

Why retests are messy

  • Retest terms (included or chargeable, time limits, how many) are written in each proposal differently.
  • Clients rarely say exactly which findings they want retested.
  • The original tester has the context, but may not be available.
  • Scope creep on retests is common, because the client sees the tester as already 'in'.
  • Retest reports are written from scratch rather than as an update to the original findings.

Individually a retest is small. Across a busy testing firm, they add up to a steady leak of unplanned, often unbilled days.

What retests cost when they are not managed

ProblemResult
Included retest terms unclearPaid work given away
Scope not confirmedRetest grows on the day
Different tester, no handoverTime spent re-learning the environment
Standalone retest reportClient confused, auditor asks questions
Urgent bookingOther engagements moved to fit it in

The retest handling we build

  1. Every engagement records its retest terms in structured form: whether a retest is included, how many, within what period, and at what rate otherwise.
  2. A client requests a retest through a short form listing their original findings. They tick the ones they want retested and confirm they are fixed. Anything new they mention is flagged as out of retest scope.
  3. The system checks the request against the engagement's retest terms and shows your operations manager whether it is included, chargeable or needs a new quote, before anyone agrees a date.
  4. An estimate is suggested from the number and type of findings selected, using your own rules, for a person to confirm.
  5. Booking prefers the original tester, and if they are not available, the new tester gets a handover pack: the original findings, notes, access details and the client's remediation notes.
  6. The retest report updates the original findings with their new status (resolved, partially resolved, not resolved) and links to the original report, so the client's auditor can follow the thread.
  7. Chargeable retests create the invoice line automatically when the report is issued.

We connect this to your reporting platform and your practice or accounting system through their APIs where available, so nothing is retyped.

How retests run afterwards

A retest request arrives with the findings selected and the commercial position already clear. If it is chargeable, the client is told up front, with a price. The tester, original or not, starts with everything they need. Anything new is quoted separately rather than absorbed. And the client gets a retest report that reads as a continuation of the original, which is what their auditor wants to see.

You also see, over time, how many retests are included versus chargeable, which is useful when you set retest terms in future proposals.

Recognise this?

  • Retest requests arrive without a list of findings.
  • Nobody is sure whether a retest is included in the original fee.
  • Retests regularly grow beyond what was agreed.
  • Retest reports do not link back to the original findings.
  • Chargeable retests sometimes go unbilled.

FAQ

Frequently asked questions

The questions readers ask us after this guide.

Still have a question?

Ask us directly — a senior engineer will get back to you.

Ask about your project

Can clients request retests themselves?

Yes, through a form tied to their engagement, which lists their original findings for them to select.

Does it work with our reporting platform?

Where the platform has an API, findings and statuses are read and updated directly. Otherwise we work from report exports.

What if a client insists on extra scope during a retest?

The tester can log it as additional scope in the moment, and it goes to the account manager to quote rather than being done unbilled.

Will it decide what counts as included?

It applies the terms you recorded for the engagement and shows the result. Commercial decisions stay with your team.

Keep reading

More on Problems We Solve

Start here

Tell us where the admin slows your security practice down

Describe how engagements run today, from scoping call to final report and retest: the reporting tool, the calendars, the trackers and the email threads. We will tell you what we would build and what we would leave alone, and if your existing tools can already do it, we will say so.

  1. You tell us what you needTwo minutes on the form, or a message on WhatsApp.
  2. A senior engineer reviews itAnd comes back with questions, a realistic range and an honest view on fit.
  3. Free 30-minute scoping callWe talk through scope, options and a realistic estimate — with no obligation.
Free estimateNo obligation

Talk to someone who builds this

Send a short brief and we will come back with an honest view and a realistic range.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →