Define Your Scope Before Engaging a Vendor

The most important preparation step is defining scope — what systems, networks, and applications are included in the test. For compliance purposes, your scope must align with your regulatory framework. NYDFS requires testing based on your risk assessment. PCI DSS requires testing that covers your cardholder data environment. SOC 2 requires coverage of systems in the audit scope. Coming to a vendor with a clearly defined scope produces a more accurate quote and a more focused engagement.

  • List all external IP addresses and domains in scope
  • Identify the number and type of internal hosts (servers, workstations, network devices)
  • List all web applications and APIs in scope with their URLs
  • Identify segmentation boundaries to be tested
  • Note any systems that must be excluded (production payment systems, life-safety systems, etc.)

Gather Documentation Your Tester Will Need

A manual penetration test is more efficient and produces better results when the testing team has context. Prepare to share:

  • Network diagrams and topology documentation
  • Prior penetration test reports and remediation documentation
  • Active Directory domain names and structure
  • Any known issues or areas of concern you want specifically tested
  • Testing windows and blackout periods (times when testing should not occur)

Notify the Right People Internally

Your IT team, network operations center, and security team should be informed that testing is occurring — even if the wider organization is not. Testing without notifying your own security tools can trigger incident response workflows, waste your team's time, and potentially interrupt the test. Your Grid32 engineer will coordinate with your team before testing begins to establish communication protocols.

Execute an NDA Before Sharing Sensitive Information

Before sharing network documentation, IP ranges, or architecture diagrams, execute a mutual non-disclosure agreement with your testing firm. Grid32 is happy to sign an NDA before any sensitive information is exchanged. We treat all client information as strictly confidential and do not retain data beyond what is necessary to complete the engagement.

Have Remediation Resources Ready

The best outcome of a compliance penetration test is not a clean report — it's finding real issues and fixing them before an attacker does. Ensure your IT team has the bandwidth to address findings promptly after the report is delivered. For compliance purposes, documented remediation of high and critical findings within a defined timeframe is important evidence for auditors.

Ready to schedule your compliance pentest?

Grid32 walks you through scope definition as part of the engagement kickoff. Use our quote builder to get started or contact us to discuss your specific framework requirements.

Get a Quote →