🛡️ Pentest from €539 · Compliance from €89. See All Services →
Optimum Web
Resource · Attestation Letter

What Is a Penetration Test Attestation Letter?

Reviewed: 24 August 2026 — reviewed quarterly

Quick Answer

A penetration test attestation letter is a short signed document confirming that an independent party tested a defined scope, when the testing took place, which methodology was used, and the current remediation status. It is written to be shared with auditors, insurers and enterprise customers who need proof that testing happened but must not receive the full technical report.

What Goes Into an Attestation Letter?

FieldWhy it matters to the reader
Exact scope tested (domains, applications)Auditors check it against the ISMS scope; insurers check it against the insured assets
Testing start and end datesThe common "within the last 12 months" requirement is verified from these dates
Type of work — vulnerability assessment or penetration testDifferent controls require different depth; substituting one term for the other is grounds to reject the document
Named methodologyShows the testing followed a recognised standard rather than an ad-hoc process
Severity scoring scheme (CVSS v3.1)Lets the reader compare findings against other reports on a common scale
Remediation status as of the letter's dateThe insurer's key question isn't what was found — it's what was done about it
Name, title and signature of the accountable engineerPersonal accountability in place of an anonymous company logo
Statement of tester independenceConfirms whoever tested the system was not the same party who built it

Why Not Just Send the Full Report?

A full penetration test or vulnerability assessment report contains exactly what you don't want circulating outside your organisation: reproducible exploitation steps, specific technical weaknesses, and enough detail for a reader with the right skills to attempt the same attack. Sending it to an auditor is one thing; sending it to an insurer, an enterprise customer, or a vendor-review team multiplies the number of people and systems holding a live map of your weaknesses, whether or not those weaknesses are still unpatched.

The attestation letter exists to solve exactly this problem. It answers the actual question the reader has — did independent testing happen, when, and what's the current status — without handing over the technical detail a full report contains. Everyone who needs proof of testing gets it; no one accumulates a copy of your vulnerability inventory who doesn't strictly need one.

Who Accepts an Attestation Letter?

ISO 27001 / SOC 2 auditors

As dated evidence of independent testing, cross-referenced against the audit period and the relevant Annex A control (A.8.8 or A.8.29).

Cyber insurance underwriters

AIG, Hiscox, Beazley, Chubb, Travelers and Lloyd's syndicates commonly request one as part of the application or renewal evidence pack, rather than the full technical report.

Enterprise procurement / vendor security review

As the standard proof point in vendor security questionnaires — confirming testing happened without handing a prospective customer your full vulnerability inventory.

Attestation Letter, Executive Summary, Full Report — What's the Difference?

DocumentAudienceContentCan be shared
Attestation letterAuditors, insurers, procurement teams outside your organisationScope, dates, methodology, remediation status, signature — one to two pagesFreely — designed for external sharing
Executive summaryYour own leadership, boardRisk overview in business language, headline severity counts, no exploitation detailInternally, sometimes with a trusted partner under NDA
Full technical reportYour engineering / security teamEvery finding with reproduction steps, CVSS vectors, CWE classification, remediation guidanceNever outside your organisation without redaction

What an Attestation Letter Does Not Prove

That no vulnerabilities exist beyond what was found — absence of evidence isn't evidence of absence
That the system remains secure indefinitely — a letter reflects a point in time, not an ongoing guarantee
Coverage of anything outside the stated scope — a letter for one application says nothing about a different one

What to Check Before You Accept One From a Provider

Is the exact scope stated, not just a company name?
Are start and end dates present, and recent enough for your requirement?
Is the type of work named correctly — vulnerability assessment vs penetration test?
Is a methodology named (OWASP WSTG, PTES, NIST SP 800-115)?
Is it signed by a named individual, not just a company stamp?

Every tier of our vulnerability assessment and penetration testing services includes a signed attestation letter as standard — even if the requirement is a cyber insurance application or a vendor security questionnaire, not just an ISO 27001 audit. See what Annex A.8.8 requires if that's your specific driver.

Start with Vulnerability Assessment

Frequently Asked Questions

Is an attestation letter the same as a certificate?+
No. A certificate typically implies a formal, often accredited certification scheme with its own audit process (like an ISO 27001 certificate issued by a certification body). An attestation letter is a signed statement from the testing provider confirming what was tested, when, and what the outcome was — it documents a single engagement, not an ongoing certified management system.
Can we share the attestation letter with our own customers?+
Yes — that's exactly what it's designed for. Unlike the full technical report, the letter is written to be safely shared outside your organisation, with enterprise customers, auditors, or insurers, without disclosing exploitable technical detail.
How long is an attestation letter valid?+
There's no universal expiry built into the document itself, but most auditors and insurers treat testing older than 12 months as stale and will ask for a refreshed letter. Treat it as valid for roughly the same period your next scheduled test is due.
Will an insurer accept a letter for a vulnerability assessment, or does it have to be a penetration test?+
It depends on the underwriter's specific questionnaire wording and your policy's requirements — some accept vulnerability assessment evidence, others specifically ask for penetration testing. Check the exact wording of the question being asked before assuming either one is sufficient, and make sure the letter states the work type accurately either way.
What if our scope changes after the letter is issued?+
The letter only covers what was actually tested at the time — if you add a new application, integration, or environment afterward, that addition falls outside the letter's scope until it's tested separately. Material scope changes are generally a trigger to schedule a fresh assessment rather than rely on the existing letter.
Do you issue an attestation letter even if no critical findings are identified?+
Yes. The letter documents that testing was performed and states the outcome, whatever it is — a clean result is a valid, useful outcome for an auditor or insurer, not a reason to withhold the letter.