Why Attestation Documentation Matters

A penetration test report serves two audiences with different needs: your technical team needs granular findings and remediation guidance, while your auditors, clients, and regulators need confirmation that testing occurred, what it covered, and what the outcome was. Attestation documentation bridges that gap — providing compliance-ready evidence without exposing sensitive technical findings to audiences who don't need them.

What Grid32 Provides After Every Engagement

Every Grid32 engagement delivers a tiered documentation package:

  • Executive Summary — A two to three page non-technical overview of scope, methodology, overall findings, and risk posture. Suitable for board presentations, CISO reporting, and auditor review without disclosing exploitable details.
  • Detailed Technical Report — The complete findings document: every vulnerability, evidence of exploitation, severity rating, affected systems, and step-by-step remediation guidance. For your CISO, IT team, and security engineers.
  • Attestation Letter — A signed letter on Grid32 letterhead confirming the scope, dates, methodology, and overall outcome. Formatted specifically for auditors, regulators, clients, and cyber insurers who need to confirm testing occurred without receiving the full technical report.
  • Client-Facing Summary — A condensed, business-language summary suitable for sharing with customers who ask for evidence of your security testing program.

Using Attestation Documentation for Specific Frameworks

  • NYDFS — The attestation letter and executive summary support the annual compliance certification. The detailed report supports examiner requests for penetration test documentation.
  • SOC 2 — The attestation letter and executive summary integrate directly into the audit evidence package. The detailed report is available to auditors under NDA.
  • PCI DSS — The complete report including segmentation test results satisfies Requirement 11.4 documentation requirements. Your QSA receives the full technical report.
  • Cyber Insurance — The attestation letter confirms annual testing for carriers who require evidence of it at renewal.

Need compliance-ready documentation?

Grid32 structures every engagement to produce the documentation your auditors and regulators require. Our reports are designed for compliance, not just security teams.

Talk to an Expert →