Direct answer: We published two full specimen deliverables as PDFs, ungated: a penetration test report and a Phase 1 gap assessment. Both come out of the same generators that produce a real client's documents, so the format is the one you would receive. The client and the findings are invented and every page says so. This post walks through what is in each, and what separates a report worth paying for from a tool export with a logo on it.
Why nobody shows you the deliverable
Security and compliance are sold on a description of an artifact you will not see until the engagement is over. The proposal says "a prioritised findings report". The website says "actionable remediation guidance". Both are true of a genuinely good report and equally true of a scanner export somebody pasted into a template.
The reason firms rarely publish one is understandable. Reports are confidential, so a real one cannot go on a website, and building a fake one is work that produces no billable hour. The result is a market where the thing you are buying is the one thing you cannot inspect.
These two are our answer to that. They are specimens rather than redactions, because a redacted real report is worse on both counts: it still leaks something about a client, and the redactions remove exactly the parts you wanted to read.
What is in the penetration test report
Eight pages, nine findings, running from a critical authorization flaw down to one informational note.
Scope stated as a boundary. The first table names the targets, the testing type and the dates, and the sentence under it says plainly that anything not named was not tested. That sentence matters more than it looks. Without it, a report invites the reading that everything unmentioned was examined and found clean, which is the single most common way a test report gets misused six months later.
A summary you can scan. Counts by severity, then a one-line-per-finding table with the reference, the severity, the CVSS score and the retest status. An executive reads that table and nothing else, which is fine, because it is built to survive being the only thing read.
Severity separated from CVSS. Both numbers appear, side by side, and they do not always agree. CVSS scores a vulnerability class in the abstract. Severity is a judgement about impact in your architecture. A missing security header is a 3.1 everywhere; an authorization flaw on a sequential identifier is a 9.1 in a system holding customer shipping data and something far less alarming in an internal tool with four users. A report that publishes only one of the two numbers is hiding the argument.
Remediation written as a first move. Each finding says what to do, and deliberately says the first thing rather than the whole plan. "Add an ownership check server-side, applied as middleware across the resource family rather than endpoint by endpoint" is a sentence an engineer can act on this afternoon. "Implement proper access controls" is not advice, it is a restatement of the finding.
Retest status per finding. Seven of the nine show as retested and passed, with a note saying what was verified. Two do not. A report where every finding is closed is either a very short engagement or a document that stopped being updated.
What is in the Phase 1 gap assessment
Four pages, covering a SOC 2 readiness position at the end of the assessment phase.
A readiness score that counts unanswered against you. The sample scores 67 percent, with two controls unanswered. Those two count as failures rather than being excluded from the denominator, because "we do not know" is not a neutral state. Scoring it as neutral is how a readiness number arrives at 90 percent while the evidence register is empty.
The scope decisions, first. Which Trust Services Categories are in, whether there are physical sites, Type I or Type II. Everything downstream is measured against those answers, and changing one changes the findings. Putting scope in an appendix is how two people end up arguing about a gap that only exists under a boundary one of them did not agree to.
Gaps worst first, with effort. Each row carries the control, its status, whether closing it is a quick win or a moderate lift, why it matters and the first move. The effort column is what turns a list into a plan, because the order you actually work in is severity weighted by cost, not severity alone.
Claims with nothing behind them. This is the section most gap reports do not have, and the one an experienced buyer looks for. These are controls answered as in place where no artifact has been collected. They are not findings yet. They are the places where the only thing on file is somebody's word, and an auditor samples exactly there first.
What the next phase does about it. The report ends by saying the remediation phase starts from this exact list, ordered by what blocks evidence collection rather than by severity. A gap report that ends at the gap list has handed you a problem and called it a deliverable.
How to tell a real report from an export
If you are comparing quotes, ask every firm for a specimen. Most will not have one, which is itself information. When you get one, four things separate the products.
- Is the scope a boundary or a list? A real report tells you what it does not cover. An export tells you what it scanned.
- Is severity argued or inherited? If every severity exactly matches the CVSS base score, nobody made a judgement about your environment. That is a scan.
- Could an engineer act on the remediation without a follow-up call? Read three remediation paragraphs. If they restate the finding in the imperative mood, you are buying a list you already could have generated.
- Does it say what it does not say? Every honest test report has a limitations section that gives away its own weaknesses: point in time, these targets, no claim that nothing else exists. A document with no limitations section is marketing.
The same test works on a gap assessment. Does it distinguish a control that is genuinely in place from one that is merely asserted? Does it rank by effort as well as severity? Does it say what happens next, in enough detail that you could hold someone to it?
Why they are not gated
An email form in front of a sample deliverable converts the document into a lead magnet, and changes what it is for. The point of publishing these is to answer the question before the call, including for people who read them, decide we are not the right fit, and go elsewhere better informed. That is a fair trade for us and a better one for them.
Both are on the sample reports page. If you want one of these about your own systems, the penetration testing and compliance readiness pages say what each engagement covers, and the first call is free.
Comparing quotes right now? Send us the two you are weighing. We will tell you what each one is actually selling, including when the cheaper one is the right buy.
Read the samplesOr send us the quotes