A pentest report without a retest documents a state, not an improvement. Value only arrives in the loop: finding, prioritization, remediation, retest, evidence. That is why at SPNORTH Security all retests within the explicitly agreed scope are included. Systems or functions outside that scope are a separate engagement.
Three rules for a pentest that moves something
- Owner and SLA before the report: every finding gets an owner and a remediation deadline before the report is issued, not after.
- Schedule the retest immediately: as soon as remediation is reported the retest is planned, not in the next annual cycle.
- Evidence instead of recommendation: management assessments cite the retest evidence, not the original recommendation.
What a retest record contains
- Reference to the original finding and its severity.
- Date, method and result of the retest (fixed, partially fixed, open).
- Remaining residual risk and the owner's decision.
From test to programme
That turns a single pentest into a programme: a recurring rhythm, register-driven remediation and a traceable posture. The report is structured for audit use and can serve as evidence. Whether an auditor or certification body accepts it is that body's own decision; this is not promised.