Skip to main content
Resources

Five open resources, and who each one is for

Nothing here sits behind a form. Each one exists because a different person asks a different question before an engagement starts: what will you do, what will you cover, what can we file, what are we signing, and what does that word mean.

The five

Each one, and the question it settles

Written for different readers, so the shortest route through this section is to open the one that matches the question you turned up with rather than to work down the list.

ResourceWho opens itWhat it settles
Penetration testing methodology A security lead deciding whether to shortlist The six phases in the order they run — discovery, planning, scanning, exploitation, reporting, then QA on the finished report before it reaches you — and the three actions that stop and wait for written approval.
Penetration testing checklist A practitioner scoping a target What is actually worked inside each of the eleven coverage classes, and the one exclusion that holds across all of them: physical, hardware and wireless testing.
Standards mapping A compliance officer preparing evidence Which standard each finding is mapped against, named at its edition — OWASP Top 10 2025, OWASP WSTG v4.2, OWASP ASVS 5.0.0, NIST SP 800-115, CVSS v4.0 — and which control the mapping lands on.
Scope and authorisation template Whoever signs before a run starts The document that fixes the targets, the testing window and the movement boundary, and records the written authorisation the three approval gates are checked against.
Glossary Anyone reading a report with a term in it they did not choose The vocabulary this site uses, defined once: the finding states open, fixed, retested and closed, the three delivery models, and what a reproducible exploit artefact contains.

Penetration testing methodology

Who opens it
A security lead deciding whether to shortlist
What it settles
The six phases in the order they run — discovery, planning, scanning, exploitation, reporting, then QA on the finished report before it reaches you — and the three actions that stop and wait for written approval.

Penetration testing checklist

Who opens it
A practitioner scoping a target
What it settles
What is actually worked inside each of the eleven coverage classes, and the one exclusion that holds across all of them: physical, hardware and wireless testing.

Standards mapping

Who opens it
A compliance officer preparing evidence
What it settles
Which standard each finding is mapped against, named at its edition — OWASP Top 10 2025, OWASP WSTG v4.2, OWASP ASVS 5.0.0, NIST SP 800-115, CVSS v4.0 — and which control the mapping lands on.

Scope and authorisation template

Who opens it
Whoever signs before a run starts
What it settles
The document that fixes the targets, the testing window and the movement boundary, and records the written authorisation the three approval gates are checked against.

Glossary

Who opens it
Anyone reading a report with a term in it they did not choose
What it settles
The vocabulary this site uses, defined once: the finding states open, fixed, retested and closed, the three delivery models, and what a reproducible exploit artefact contains.

By reader

Three people ask for this section, and they want different pages

The same five documents, put in a different order for each reader: the one to open first, then the one that settles the question that brought them here.

Before a shortlist

The procurement lead

The question they arrive with
Whether a platform that tests without a person driving it can be bounded tightly enough to put in front of a security committee.
Open first
The methodology, for the six phases in order and for the three actions that stop and wait for a written approval rather than proceeding on their own judgement.
Then
The scope and authorisation template, because it is the document that would actually be signed: the targets, the window, and the boundary movement is not allowed past.
Scoping a target

The practitioner

The question they arrive with
What is worked inside a class once the run starts, and what lands back at the end of it.
Open first
The checklist, which takes the eleven coverage classes one at a time and states the single exclusion that holds across every one of them.
Then
The methodology, for what each finding carries: the request and the response that produced it, the steps to reproduce it, a severity with a CVSS v4.0 vector, and the CWE.
Assembling evidence

The compliance officer

The question they arrive with
Whether the report stands up in front of an auditor, and which control each finding sits against.
Open first
The standards mapping, which names every standard at the edition the finding was mapped against rather than naming the standard alone.
Then
The glossary, so that open, fixed, retested and closed mean the same thing inside your evidence pack as they do inside the report they came from.

Where one named regime is the question rather than the mapping in general, the compliance framework pages take the regimes one at a time, and approvals and audit trail holds the record of what was authorised and by whom.

Versions

Every standard is named with its edition

OWASP Top 10 2025 rather than OWASP Top 10; ASVS 5.0.0 rather than ASVS. An edition is what a reader checking the mapping against their own control set needs, and what an evidence pack has to record, so it is on the page rather than in a footnote.

How the standards on these pages are cited As of September 2026
  • Each standard carries its edition: OWASP Top 10 2025, OWASP WSTG v4.2, OWASP ASVS 5.0.0, OWASP MASVS v2.1.0 with MASTG v2.0.0, OWASP API Security Top 10 2023, OWASP Top 10 for LLM Applications 2025, NIST SP 800-115, CVSS v4.0 and MITRE ATT&CK v19.2.
  • Every edition above was confirmed against its own source in September 2026, and the standards mapping records the read date beside each one.
  • The OWASP API Security Top 10 is cited at its 2023 edition because 2023 is the current one. A year picked to match the web Top 10 would cite a document that does not exist.
  • NIST SP 800-115 is cited at its September 2008 final edition, which remains the current edition of that publication.
  • Where a body publishes on a rolling cadence, the report names the release a finding was worked against instead of the page pinning a number: MITRE ATLAS, and the CIS Benchmarks, where CIS publishes a Foundations Benchmark per cloud provider on separate schedules.
  • Severity is a CVSS v4.0 vector, and v4.0 is the version FIRST publishes and maintains, so the score can be recomputed from the vector rather than taken on trust.

Deliberately excluded

  • Editions still in development: OWASP WSTG v5.0 is in progress and is cited nowhere on this site. The mapping uses v4.2, the current stable release.
  • Retired constructs: MASVS verification levels became MAS Testing Profiles at v2.0.0, so “MASVS Level 2” appears on no page here.

In preparation

Two more, and what each will contain

Both are artefacts rather than explanations — a reader who wants to see the output rather than read about it is asking for one of these two. They are named here so you know what is coming, and they will join the list above when they are ready.

A redacted sample report

A finished report with the customer and the targets removed, so the structure can be read end to end: a finding with the request and the response that produced it, the steps to reproduce it, a severity with its CVSS v4.0 vector, the CWE, and the state that finding sits in.

A worked sample attack chain

One chain followed from the first foothold to the impact it reaches, step by step, including the point at which an approval gate stops it, what the written approval had to cover before it went further, and what the next step proved once it did.

Where a question cannot wait for them, a scoping call is the direct route, and validation and proof sets out what every finding has to carry before it is reported.

The documents are open. So is the pricing

One scan is one application or target, from $500, and the paid trial is $299. Where the estate is larger than one target, or the report has to carry a signature, a scoping call settles it faster than reading another page.