Free provider planning tool
Turn your asset list into a clear testing brief.
Prepare a penetration testing request with assets, roles, exclusions, operating limits, reports, and retesting. Compare three provider proposals.
For engineering, security, compliance, procurement, and leadership. No signup required.
This is a planning brief, not authorization to test. The asset owners and provider must agree written authorization and rules of engagement before testing begins. Do not include passwords, tokens, or live customer data.
Your entries stay in this page unless you save them on this device or download a file. Sharing a tool link opens a blank brief. Files and copied briefs include your entries; review them before sending.
Name your brief
Compare proposals
Send the same scope to each provider
Capture verified answers and differences. Blank answers appear as “not specified.” These worksheets do not rank providers or estimate prices.
Review and share
Your request-for-proposal draft
Copy request brief includes your scope and open items, without provider comparison notes. Download and print include the full comparison.
Find providers and prepare your questions
Browse penetration testing providers · Read the buying guide · Download the Word template
Source context: NIST SP 800-115. Reviewed October 1, 2026. The worksheet prompts are original editorial questions.
Work with teammates
Open shared worksheets to store reviewed JSON for a named team. Saving there is explicit; local entries are not uploaded automatically. Team members can edit saved revisions, with conflict checks and history.