Skip to content

A customer is holding our contract until we have a pentest report

Short answer

What is stuck is not security — it is revenue. Large buyers require a third-party penetration test report before signing. Testing one web application and its interfaces takes 2–3 weeks, produces a report you hand straight to their procurement team, and includes one retest after the findings are fixed.

Typical duration: 2–3 weeks for one application

USD 4,500 · report and one retest included

What this looks like

  • Their procurement team sends a security questionnaire you cannot answer
  • The contract value is agreed but stalls at due diligence
  • They ask for a report from an independent third party, not your own scan
  • A competitor already has one and is described as more prepared
  • The deadline is this quarter and nothing has started

Why this happens

Large buyers push risk onto their suppliers. Since the software supply chain became a common attack path, procurement teams work from a checklist nobody is allowed to skip — including small suppliers with good products.

The trouble is that the requirement surfaces at the end of the sales process, when everyone assumed the deal was as good as signed. At that point there is no time to build a security programme; what is needed is evidence you can hand over.

How we solve it

  1. 01

    Scoping

    We agree what gets tested — which applications, interfaces, and environments. One day.

  2. 02

    Testing

    Manual testing following OWASP and PTES, not just an automated scan. 1–2 weeks depending on scope.

  3. 03

    Reporting

    Findings ranked by real danger, each with a reproducible attack path and a remediation step.

  4. 04

    Remediation

    Your team fixes; we answer questions throughout at no extra charge.

  5. 05

    Retest

    We verify the closed findings and issue the final report, ready to hand to your buyer.

Numbers from our own work

  • Of the 54 engagements we have on record, 49 are security work

  • Our reports have been used by clients to satisfy ISO 27001, SOC 2, and PCI-DSS requirements

  • The retest after remediation is included — not billed separately

Mistakes we keep seeing

  • Submitting an automated scan in place of a pentest report — it is almost always rejected
  • Buying the cheapest test with no retest, then still being unable to prove findings are closed
  • Waiting until the buyer sets a deadline, when testing takes a fixed amount of time
  • Testing only the main application while the questionnaire covers the whole system

Questions we are asked most

How soon can I hand the report to my customer?

Two to three weeks for one application, report included. If your deadline is shorter, say so early — scope can be narrowed while staying meaningful.

Is the report accepted for ISO 27001 or SOC 2?

Yes. The report covers scope, method, findings with severity, and remediation evidence — the parts auditors actually ask for.

How is this different from the automated scan we already run?

Automated scans find known patterns. Manual testing looks for chains of weaknesses that are only dangerous in combination, which is what real attackers use.

If there are critical findings, do we pay again for the retest?

No. One retest is included in the scope.

Can the testing disrupt our live service?

We agree the window and the limits before starting. Anything with disruption risk runs in a test environment or outside peak hours.

Updated 29 July 2026 · Neuraltan

If this is happening to you

Tell us the situation. We will say plainly whether this is worth doing now, and how long it takes.