Before a penetration test — sharpen scope and exposure first.

The most expensive pentest is the one with unclear scope. Before active testing, outside-in clarity pays: which domains and services are visible? What is no-go? What should the test prove? CASP and clean RoE prep reduce blind flight and renegotiation.

  • Purpose before tooling
  • RoE are mandatory
  • CASP optional
Concrete example

Example preparation (anonymised)

A release in 6 weeks needs evidence. We clarify: goal “regression safety login+API”, no-gos (prod payment), windows, contacts, stop criteria. Optional CASP on staging because shadow endpoints were unclear. RoE signed, then active testing. Without this prep, day one would have been scope fighting only. Figures and names are anonymised; the flow matches typical engagements. Decision criteria stay explicit. No ranking or lead guarantees apply.

Good pentests rarely fail on tooling — they fail on prep. We require approval and RoE — customer protection, not bureaucracy. That is intentional and part of the positioning.

This page’s job: Owns preparation and RoE before active testing. CASP is optional, not forced; not a substitute for the vs-pentest page.

Checklist

RoE outline (minimum content)

What should be written before the first active step:

  1. 01

    Goals & success

    What the test proves — and what it does not.

  2. 02

    In-scope assets

    Hosts, apps, APIs, accounts — IDs and environments.

  3. 03

    Out-of-scope / no-go

    Payments, prod data, partner systems …

  4. 04

    Windows & rate limits

    When testing is allowed, how aggressive.

  5. 05

    Contacts & escalation

    24/7 or business hours, stop path.

  6. 06

    Data & reporting

    PoC format, confidentiality, retest option.

Problem & fit

Unclear scope burns budget

Cost of the status quo

Without an outside-in picture and written approval boundaries, scope creep, production risk, and findings nobody can map to the goal appear. Then the pentest feels “expensive and unclear” — because prep was missing.

What “done” looks likeA sharpened test space and clear rules before active testing — optionally with CASP as outside-in prep.
For teams about to test actively

Security, IT, and procurement planning an authorised pentest who still need to sharpen scope, goals, and proof purpose.

Not for you if…

  • You want to attack something immediately without approval
  • You refuse RoE and test windows
  • You expect CASP to replace the pentest
Differentiation & buying guide

Before a pentest: how we differ — and what to watch.

The most expensive pentest is the one with unclear scope. We help sharpen purpose, no-gos, and optional outside-in — and we do not start blind testing in production without approval and RoE.

How we differ in pentest preparation

Purpose before tooling

What should the test prove? Compliance evidence, release gate, or targeted validation?

RoE is not optional

Windows, contacts, stop criteria, and allowed actions before the first active step.

CASP optional, not forced

Outside-in when exposure is unclear — not as a forced upsell.

No production blind flight

We refuse “just go live-fire” without approval.

What to watch before a penetration test

  • Offer without rules of engagement and without test windows
  • No written approval of target systems
  • “Total black box” without emergency contact and stop criteria
  • Price that only covers scanner runtime but promises manual depth
  • No definition of success and out-of-scope
  • Forced bundle with irrelevant services

Included vs. deliberately not (pentest prep)

Typical boundaries before active testing:

  • We do / include

    Scope/RoE clarification and optional CASP prep

  • We do / include

    Declining unclear or unauthorised active tests

  • We do / include

    Clean handoff into the authorised pentest

  • We do not / exclude

    Immediate active testing without approval “due to time pressure”

  • We do not / exclude

    Guarantees of criticals or zero downtime

  • We do not / exclude

    Selling CASP as a silent substitute for the pentest

If you want to prepare and approve a pentest cleanly: scope meeting. If you want unlimited immediate attack without rules, we decline.

How delivery works

What you decide, what is authorised, what is out of scope.

Method boundaries first — no mixed CASP/pentest theatre.

/ 01

What you can decide

A pentest with clear goals and mappable results.

/ 02

What is authorised

Optional outside-in + RoE + approval.

/ 03

How fast you get clarity

Prep saves rework during active testing.

/ 04

What comes from you

Provide goals, contacts, no-gos — we structure.

What changes

Practical outcomes for you.

01

Better targets

Exposure and business risk steer scope.

02

Fewer surprises

No-gos and windows upfront.

03

Clean separation

CASP prep and pentest deliverables stay separate.

In the package

Core offer and clear options.

01
Optional

CASP before the pentest

Sharpen outside-in.

02
Core

Scope & RoE workshop

Goals, limits, windows.

03
Core

Authorised pentest

Active testing after approval.

04
Bonus

Retest path

Where included in the offer.

Settled before start

  • Goal and success criteria
  • Scope and no-go list
  • Optional: CASP report as input
  • Path into the authorised pentest
Steps

Preparation path

  1. 01

    Purpose

    What should the pentest prove?

  2. 02

    Outside-in (optional)

    CASP for exposure clarity.

  3. 03

    RoE & approval

    Written, clear, accountable.

  4. 04

    Active test

    Only in approved scope.

FAQ

Objections, answered honestly.

Must CASP run before every pentest?

No, but often useful when exposure is unclear.

Who must approve?

Authorised domain/system owners in writing — details in scope.

What is RoE?

Rules of engagement: allowed actions, windows, contacts, stop criteria.

How do I start?

Contact with test purpose; optional CASP link and pentest page.

Do we need staging?

Not always, but often wise. Prod-only needs stricter windows and no-gos.

What if scope grows during the test?

Change and approval — no silent expansion. Otherwise results and liability are unclear.

Next step

Start pentest preparation

Share goal and timing — we propose prep and scope.

Scope before active workNext step
Request a scope meeting