Free provider planning tool

Turn your asset list into a clear testing brief.

Prepare a penetration testing request with assets, roles, exclusions, operating limits, reports, and retesting. Compare three provider proposals.

For engineering, security, compliance, procurement, and leadership. No signup required.

This is a planning brief, not authorization to test. The asset owners and provider must agree written authorization and rules of engagement before testing begins. Do not include passwords, tokens, or live customer data.

Your entries stay in this page unless you save them on this device or download a file. Sharing a tool link opens a blank brief. Files and copied briefs include your entries; review them before sending.

Name your brief

Compare proposals

Send the same scope to each provider

Capture verified answers and differences. Blank answers appear as “not specified.” These worksheets do not rank providers or estimate prices.

Review and share

Your request-for-proposal draft

Copy request brief includes your scope and open items, without provider comparison notes. Download and print include the full comparison.

Find providers and prepare your questions

Browse penetration testing providers · Read the buying guide · Download the Word template

Source context: NIST SP 800-115. Reviewed October 1, 2026. The worksheet prompts are original editorial questions.

Work with teammates

Open shared worksheets to store reviewed JSON for a named team. Saving there is explicit; local entries are not uploaded automatically. Team members can edit saved revisions, with conflict checks and history.