VAPT Scoping Checklist
50+ pre-engagement scoping questions for VAPT buyers, organised by surface — engagement, inventory, exclusions, auth, application, third-party, cloud, AD, mobile, test windows, deliverable, legal. Free, email-only.
Preview of the document.
- →11 sections covering surface inventory, exclusions, auth, app architecture, cloud, AD, mobile, windows, deliverable, legal
- →50+ questions in operator voice — these are the questions we actually ask
- →Quick 'scoping is over' gate-check at the end so you know when to sign the SOW
- →Markdown — copy into your wiki, fork freely, no NDA
Section 0. Engagement-level
Why this pentest, who signs off, when is the immovable deadline, has this scope been pentested before, what regulation drives it, will the report be shared externally, will retest run on critical/high or all findings, are there blackout windows.
Section 1. Surface inventory
Web apps, APIs (REST / GraphQL / gRPC), mobile apps, network ranges, cloud accounts, Active Directory topology, source-code disposition, third-party SaaS integrations, wireless / IoT / OT / physical / social-engineering surfaces, LLM / AI components.
Section 3. Authentication & authorisation
Auth methods (SSO, OIDC, SAML, mTLS, API keys, JWTs), role inventory, credential provisioning, MFA / passkey posture, session lifecycle, multi-tenant boundary enforcement, admin / support impersonation paths.
Section 6. Cloud-specific
Account / subscription / project IDs, regions, IAM / RBAC boundary documentation, IMDSv2 enforcement, S3 / blob policy posture, KMS key rotation, audit-log destinations, managed-service notification requirements.
Section 9. Test windows, environments, monitoring
Production vs. staging, allowed test windows, source IP allowlisting, blind vs. announced vs. purple disposition, mid-test critical-finding escalation, outage escalation.
Who this is written for.
First-time pentest buyers. Repeat buyers who want a tighter scoping conversation. Engineering leads filling in scope async before the call.
Real public references.
We cite the canonical source so you can verify anything in the document yourself. No fabricated stats, no "industry research says" without a link.
- → AWS Pentest Policy · https://www.aws.amazon.com/security/penetration-testing/
- → MeitY (DPDP Act 2023) · https://www.meity.gov.in/
- → AICPA (SOC 2 TSC) · https://www.aicpa-cima.com/
- → RBI · https://www.rbi.org.in
We send the document. That is it.
The VAPT Scoping Checklist lands in your inbox the same business day. The request is read by the operator who owns the artefact — not by a marketing system.
No drip after that. No "day-3 nudge", no auto-enrolment in a newsletter, no calendar invite for a discovery call you did not ask for. If you want a 30-minute scoping call, the contact form routes the same way and the call is free.
Want a 30-minute scoping call instead?
The VAPT Scoping Checklist is useful as a working document. If you would rather walk through your specific situation with an operator, the call is free and you get a written summary either way.