Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
  1. Home
  2. Blog
  3. How Does a Penetration Testing Firm Get Complete Scoping Information From Clients Without Chasing for Weeks?
Problems We Solve

How Does a Penetration Testing Firm Get Complete Scoping Information From Clients Without Chasing for Weeks?

Pen test scoping drags on over calls and emails, and tests start with gaps. We build scoping workflows for pen testing firms that collect what testers need.

Updated 3 min readBy SpiderHunts Technologies

Free estimateNo obligation

Get a free estimate

Tell us what you need. A senior engineer reads every enquiry.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →

Quick answer — TL;DR

Scoping drags because clients do not know what a tester needs, the questions differ for web applications, infrastructure, cloud and mobile, and answers come back scattered across emails and calls. We build a scoping workflow that asks each client the right questions for the test types they want, checks answers for gaps, turns them into a day estimate for your consultants to review, and keeps everything in one record that follows the engagement.

Scoping by email thread

A prospective client wants 'a pen test'. Your sales lead books a scoping call with a senior tester. On the call it turns out they mean an external infrastructure test, a test of their customer portal, and maybe something on their Microsoft 365 set-up. The tester asks how many IP addresses, how many user roles in the portal, whether there is an API, where it is hosted. The client does not know and promises to find out.

Over the next fortnight answers trickle in. A spreadsheet of IP ranges arrives, some of which belong to a hosting provider. A developer sends a partial list of roles. Nobody mentions the staging environment until the tester asks. Your senior tester, who is also booked on client work, has to re-read the thread each time to remember where things are.

The quote finally goes out. The client signs. And on day one of the test, the tester finds a whole API the scope did not include.

At the other end, when the client asks next year for the same test again, most of what was learned during scoping is buried in that thread, and the process starts almost from scratch.

Why scoping takes so long

  • Clients buy 'a pen test' and do not know what information a tester needs.
  • Each test type (web application, API, external or internal infrastructure, cloud configuration, mobile) needs different questions.
  • Answers come from several people at the client: IT, developers, a hosting provider.
  • Senior testers are the only people who can judge scope, and they are billable elsewhere.
  • Scope details live in emails and call notes, not in a structured record.

Scoping is where the size of the job, the price and the client's expectations are all set. Doing it loosely makes everything after it harder.

What loose scoping costs a testing firm

Scoping gapConsequence
Asset count underestimatedTest overruns, or coverage is thinner than sold
Environment unclearTester waits on day one for access or clarity
Third-party hosting not identifiedAuthorisation missing, test delayed
Senior testers on scoping callsBillable time lost
Slow quoteClient goes with a firm that answered faster

The scoping workflow we build

  1. After the first conversation, the client receives a scoping form tailored to the test types they are interested in, with plain explanations of why each question matters.
  2. The form can be shared inside the client's business, so their developer answers the application questions and their IT lead answers the infrastructure ones.
  3. Answers are checked as they come in: IP ranges validated, URLs checked for format, hosting providers noted for authorisation, and missing items listed back to the client.
  4. Your scoping rules (for example, days per application size band or per number of roles and API endpoints) turn the answers into a draft day estimate for each test type.
  5. A senior tester reviews the draft scope and estimate in one screen instead of a thread, adjusts it, and adds any caveats.
  6. The agreed scope becomes the basis of the quote and statement of work, and later the tester's briefing pack for the engagement.

We can build this into your existing CRM or practice system, or as a small portal on your own domain. The estimating rules stay yours and are easy to change.

What scoping looks like afterwards

Clients get a clear list of what you need, in language they understand, and can pass sections to the right colleague. Most scopes arrive complete, or with gaps named and chased automatically. Senior testers spend a short review on each scope rather than several calls. Quotes go out faster and match what the tester finds on day one.

And when the same client comes back next year, last year's scope is the starting point, with a simple 'what has changed?' form.

Signs your scoping needs work

  • Scoping takes several calls and a long email thread.
  • Senior testers spend significant time on unpaid scoping.
  • Tests start with scope surprises on day one.
  • Estimates vary depending on who scoped the job.
  • Returning clients are re-scoped from scratch.

FAQ

Frequently asked questions

The questions readers ask us after this guide.

Still have a question?

Ask us directly — a senior engineer will get back to you.

Ask about your project

Does this replace the scoping call?

Not entirely. Many firms still have a short call, but it becomes a conversation about the client's concerns rather than collecting facts.

Can the estimating rules reflect our own method?

Yes. You set them, by test type and size bands, and a senior tester always reviews the result.

Where is client scoping data stored?

In your own environment, with access limited to your team. We design storage and access with you, given how sensitive scope details can be.

Does it work with our reporting platform?

Where your reporting platform has an API, the agreed scope can be passed into the engagement record. We check yours first.

Keep reading

More on Problems We Solve

Start here

Tell us where the admin slows your security practice down

Describe how engagements run today, from scoping call to final report and retest: the reporting tool, the calendars, the trackers and the email threads. We will tell you what we would build and what we would leave alone, and if your existing tools can already do it, we will say so.

  1. You tell us what you needTwo minutes on the form, or a message on WhatsApp.
  2. A senior engineer reviews itAnd comes back with questions, a realistic range and an honest view on fit.
  3. Free 30-minute scoping callWe talk through scope, options and a realistic estimate — with no obligation.
Free estimateNo obligation

Talk to someone who builds this

Send a short brief and we will come back with an honest view and a realistic range.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →