Free Tool

Penetration Testing Retest Request Form Template
trigger remediation verification on the same record the engagement opened on

A free, copy-ready penetration testing retest request form template. Eleven structured sections covering header and engagement references, parties and signing authority, the authorisation basis (inside the retest window, addendum, or fresh statement of work) and retest type (retest only, retest plus regression, delta retest), the findings in scope with original IDs and remediation summaries, the verification method per finding (reproduce, re-scan, code review, configuration review, hybrid), the access and credential plan, the deliverable expected and the disposition matrix for verified-fixed, partially fixed, not fixed, and regressed outcomes, the commercial basis and schedule, evidence handling and confidentiality, framework and regulatory references (PCI DSS 11.4, ISO 27001 8.8, SOC 2 CC4.1 and CC7.2, DORA Article 26, HIPAA, GDPR), and signature blocks. Pairs with the executed engagement letter, statement of work, rules of engagement, original report, and closure letter so the retest sits inside the existing authorisation chain rather than reopening it. Aligned with PTES, NIST SP 800-115, OWASP WSTG, and the CREST Defensible Penetration Test specification.

No credit card required. Free plan available forever.

Loading tool...

Run retests on the same record the engagement opened on

SecPortal pairs every retest to the original finding so the lineage from initial capture through fix to verified-fixed runs on one record. The retest request form lives alongside the engagement letter, SOW, ROE, original findings, evidence pack, final report, debrief deck, attestation letter, closure letter, credential handover form, rotation log, and (at the end of the retest) the retest report and any updated attestation. Free plan available.

No credit card required. Free plan available forever.