Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
  1. Home
  2. Blog
  3. How Does a Penetration Testing Firm Make Sure Every Authorisation Form Is Signed Before Testing Starts?
Problems We Solve

How Does a Penetration Testing Firm Make Sure Every Authorisation Form Is Signed Before Testing Starts?

Pen tests start late when authorisation and third-party permissions are chased on day one. We build pre-test paperwork tracking for penetration testing firms.

Updated 3 min readBy SpiderHunts Technologies

Free estimateNo obligation

Get a free estimate

Tell us what you need. A senior engineer reads every enquiry.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →

Quick answer — TL;DR

Testing cannot start until the paperwork is right: signed authorisation from someone entitled to give it, confirmed scope and test window, emergency contacts, and permission where the systems sit with a hosting or cloud provider. We build a pre-test pack that collects each item from the client in advance, checks it against the agreed scope, and stops a booking going ahead until every item is in place.

Monday morning, no signature

The tester is ready at nine on Monday. The scope is agreed, the tools are set up, the client's VPN credentials arrived on Friday. Then the tester checks the engagement folder for the signed authorisation form. It is not there. The client's IT manager says their director signed it, but it is sitting in the director's inbox and the director is at a conference.

When the form does arrive, at lunchtime, the IP ranges on it do not match the scope in the statement of work: the client added a new range last week and emailed it separately. And one of the web applications turns out to be hosted with a provider whose terms need notice before testing. Nobody asked.

The tester spends the day on internal work. Day one of a five-day test is gone, and the client still expects five days of testing.

Your operations manager has been here before. Every firm has its own checklist of what must be in place before testing, but the checklist is a document, and whether each item is actually done is tracked in email.

Why paperwork is still missing on day one

  • The authorisation form is sent with the proposal and forgotten until the week of the test.
  • The person who signs is often not the person you deal with day to day.
  • Scope changes after signing (new ranges, new URLs) are sent by email and not added to the signed documents.
  • Third-party hosting and cloud providers each have their own rules on notice and permission, and clients do not know them.
  • Emergency contacts and test windows are assumed rather than confirmed.

What your firm requires before testing, and what the law and your insurers expect, are for you and your advisers to decide. The problem we deal with is making sure your own requirements are met, every time, before the tester starts.

What a late signature costs

Missing itemConsequence
Signed authorisationTesting cannot start, tester day lost
Scope on form differs from agreed scopeRework, or testing held until corrected
Hosting provider not notifiedPart of the test postponed
No emergency contactNobody to call if something unexpected happens
Test window unclearTesting at a time the client did not expect

There is a further cost that does not show on a timesheet. A firm that is seen to start testing without proper authorisation, even once, has a reputational problem far bigger than a lost day.

The pre-test pack we build

  1. When an engagement is booked, a pre-test pack is created from your own checklist: authorisation, scope confirmation, test windows, emergency contacts, credentials and access, and third-party permissions.
  2. The client gets a single link with each item explained. Authorisation is signed electronically by the named signatory, through a tool such as DocuSign or Adobe Sign, and the signatory's role is recorded.
  3. The scope on the authorisation is generated from the agreed scope in the statement of work, so the two cannot drift apart. Any later scope change creates a new version for signature.
  4. Hosting and cloud providers are listed from the scoping answers, and the client is asked to confirm each provider's permission or notice has been dealt with under that provider's terms.
  5. Each item has a due date set back from the test start. Items still missing at that point alert the account manager, and at a final cut-off the booking is flagged not ready.
  6. On the morning of the test, the tester sees a single status: ready, with every document attached, or not ready, with what is missing.

Your checklist and cut-off points are settings, not code, so they can change when your procedures or your insurers' requirements change.

How the start of a test feels afterwards

The chasing happens in the fortnight before the test, automatically, not on the morning. The account manager sees at a glance which upcoming tests are at risk and why. When something is missing at the cut-off, the conversation with the client is about moving the date, with notice, rather than wasting a tester's day.

And the engagement record holds every signed version, every scope change and every permission confirmation, which is exactly what you want to have in one place if a question is ever raised about a test.

Is this happening to your testers?

  • Tests start late because authorisation is not signed.
  • The scope on the signed form differs from the statement of work.
  • Hosting provider permissions are dealt with at the last minute.
  • Emergency contacts are missing or out of date.
  • Your pre-test checklist is a document, not a tracked process.

FAQ

Frequently asked questions

The questions readers ask us after this guide.

Still have a question?

Ask us directly — a senior engineer will get back to you.

Ask about your project

Does this tell us what authorisation we need?

No. Your firm and its advisers decide your requirements. We build the process that makes sure they are met before each test.

Can the client's signatory sign electronically?

Yes, through an e-signature service, with their name and role recorded.

What if the client changes scope after signing?

A new version of the authorisation is generated from the updated scope and sent for signature, and the tester sees which version is current.

Can we override a not-ready status?

Your checklist can mark some items as essential and others as advisory. Essential items cannot be overridden without a named senior person recording why.

Keep reading

More on Problems We Solve

Start here

Tell us where the admin slows your security practice down

Describe how engagements run today, from scoping call to final report and retest: the reporting tool, the calendars, the trackers and the email threads. We will tell you what we would build and what we would leave alone, and if your existing tools can already do it, we will say so.

  1. You tell us what you needTwo minutes on the form, or a message on WhatsApp.
  2. A senior engineer reviews itAnd comes back with questions, a realistic range and an honest view on fit.
  3. Free 30-minute scoping callWe talk through scope, options and a realistic estimate — with no obligation.
Free estimateNo obligation

Talk to someone who builds this

Send a short brief and we will come back with an honest view and a realistic range.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →