Without an outside-in picture and written approval boundaries, scope creep, production risk, and findings nobody can map to the goal appear. Then the pentest feels “expensive and unclear” — because prep was missing.
Before a penetration test — sharpen scope and exposure first.
The most expensive pentest is the one with unclear scope. Before active testing, outside-in clarity pays: which domains and services are visible? What is no-go? What should the test prove? CASP and clean RoE prep reduce blind flight and renegotiation.
- Purpose before tooling
- RoE are mandatory
- CASP optional
Example preparation (anonymised)
A release in 6 weeks needs evidence. We clarify: goal “regression safety login+API”, no-gos (prod payment), windows, contacts, stop criteria. Optional CASP on staging because shadow endpoints were unclear. RoE signed, then active testing. Without this prep, day one would have been scope fighting only. Figures and names are anonymised; the flow matches typical engagements. Decision criteria stay explicit. No ranking or lead guarantees apply.
Good pentests rarely fail on tooling — they fail on prep. We require approval and RoE — customer protection, not bureaucracy. That is intentional and part of the positioning.
This page’s job: Owns preparation and RoE before active testing. CASP is optional, not forced; not a substitute for the vs-pentest page.
RoE outline (minimum content)
What should be written before the first active step:
- 01
Goals & success
What the test proves — and what it does not.
- 02
In-scope assets
Hosts, apps, APIs, accounts — IDs and environments.
- 03
Out-of-scope / no-go
Payments, prod data, partner systems …
- 04
Windows & rate limits
When testing is allowed, how aggressive.
- 05
Contacts & escalation
24/7 or business hours, stop path.
- 06
Data & reporting
PoC format, confidentiality, retest option.
Unclear scope burns budget
Security, IT, and procurement planning an authorised pentest who still need to sharpen scope, goals, and proof purpose.
Not for you if…
- You want to attack something immediately without approval
- You refuse RoE and test windows
- You expect CASP to replace the pentest
Before a pentest: how we differ — and what to watch.
The most expensive pentest is the one with unclear scope. We help sharpen purpose, no-gos, and optional outside-in — and we do not start blind testing in production without approval and RoE.
How we differ in pentest preparation
Purpose before tooling
What should the test prove? Compliance evidence, release gate, or targeted validation?
RoE is not optional
Windows, contacts, stop criteria, and allowed actions before the first active step.
CASP optional, not forced
Outside-in when exposure is unclear — not as a forced upsell.
No production blind flight
We refuse “just go live-fire” without approval.
What to watch before a penetration test
- Offer without rules of engagement and without test windows
- No written approval of target systems
- “Total black box” without emergency contact and stop criteria
- Price that only covers scanner runtime but promises manual depth
- No definition of success and out-of-scope
- Forced bundle with irrelevant services
Included vs. deliberately not (pentest prep)
Typical boundaries before active testing:
- We do / include
Scope/RoE clarification and optional CASP prep
- We do / include
Declining unclear or unauthorised active tests
- We do / include
Clean handoff into the authorised pentest
- We do not / exclude
Immediate active testing without approval “due to time pressure”
- We do not / exclude
Guarantees of criticals or zero downtime
- We do not / exclude
Selling CASP as a silent substitute for the pentest
If you want to prepare and approve a pentest cleanly: scope meeting. If you want unlimited immediate attack without rules, we decline.
What you decide, what is authorised, what is out of scope.
Method boundaries first — no mixed CASP/pentest theatre.
What you can decide
A pentest with clear goals and mappable results.
What is authorised
Optional outside-in + RoE + approval.
How fast you get clarity
Prep saves rework during active testing.
What comes from you
Provide goals, contacts, no-gos — we structure.
Practical outcomes for you.
Better targets
Exposure and business risk steer scope.
Fewer surprises
No-gos and windows upfront.
Clean separation
CASP prep and pentest deliverables stay separate.
Core offer and clear options.
CASP before the pentest
Sharpen outside-in.
Scope & RoE workshop
Goals, limits, windows.
Authorised pentest
Active testing after approval.
Retest path
Where included in the offer.
Settled before start
- Goal and success criteria
- Scope and no-go list
- Optional: CASP report as input
- Path into the authorised pentest
Preparation path
- 01
Purpose
What should the pentest prove?
- 02
Outside-in (optional)
CASP for exposure clarity.
- 03
RoE & approval
Written, clear, accountable.
- 04
Active test
Only in approved scope.
Objections, answered honestly.
Must CASP run before every pentest?
No, but often useful when exposure is unclear.
Who must approve?
Authorised domain/system owners in writing — details in scope.
What is RoE?
Rules of engagement: allowed actions, windows, contacts, stop criteria.
How do I start?
Contact with test purpose; optional CASP link and pentest page.
Do we need staging?
Not always, but often wise. Prod-only needs stricter windows and no-gos.
What if scope grows during the test?
Change and approval — no silent expansion. Otherwise results and liability are unclear.
Start pentest preparation
Share goal and timing — we propose prep and scope.