Penetration Test Rules of Engagement — What It Covers and Why It Matters
Reviewed: 2 August 2026 — reviewed quarterly
Quick Answer
A Rules of Engagement (RoE) document is the signed agreement that authorises a penetration test before it starts. It names the exact scope, testing window, permitted techniques, emergency contacts, and data-handling rules, and is signed by someone with authority over the systems being tested — without it, testing activity has no documented permission behind it.
What Is a Rules of Engagement Document?
A Rules of Engagement is the document both parties sign before a penetration test begins, defining exactly what's authorised: which systems can be tested, when, by what methods, and under what constraints. It exists because the techniques used in a legitimate penetration test — scanning, exploitation attempts, privilege escalation — are functionally identical to a real attack. The RoE is what separates authorised testing from something that would otherwise be treated as an intrusion.
It's typically prepared during the scoping stage of an engagement, after the target systems and objectives are agreed but before any active testing starts, and it's referenced throughout the engagement if questions come up about what's in or out of bounds.
What Fields Does a Rules of Engagement Typically Define?
| Field | What it defines |
|---|---|
| Scope (in / out) | Names the exact systems, IP ranges, domains and applications that may be tested, and explicitly lists anything excluded |
| Testing window | The start and end date/time the engagement is authorised to run, including timezone |
| Authorised testing hours | Whether testing may run 24/7 or only during agreed maintenance windows, to control business impact |
| Test type and depth | Whether the engagement is a Vulnerability Assessment, black/grey/white-box penetration test, and which techniques are in or out of bounds (e.g. social engineering, physical access, DoS) |
| Emergency contacts | Named individuals on both sides who can be reached immediately if testing causes an unexpected issue |
| Data handling rules | How any data accessed during testing (e.g. via a demonstrated vulnerability) is handled, stored and destroyed afterward |
| Authorisation signatures | The signed authorisation from someone with the authority to approve testing against the named systems — this is what makes the testing legally authorised |
| Reporting and disclosure terms | How findings will be communicated during testing (e.g. immediate escalation for Critical issues) and confidentiality terms for the final report |
| Rules for stopping testing | Conditions under which either party can pause or halt the engagement, and how that decision is communicated |
Why Does This Matter Beyond Legal Cover?
Beyond authorisation, a clear RoE reduces operational risk on both sides. It sets expectations about business impact (e.g. no testing during a peak sales window), gives both teams a named contact if something unexpected happens mid-test, and prevents scope disputes after the fact — if a finding falls outside the agreed scope, the RoE is the reference point for what happens next, rather than a judgment call made in the moment.
Before Testing Starts, Check the RoE Covers This
Every engagement we run starts with a signed Rules of Engagement before testing begins. See our penetration testing services or how a report is structured once testing is complete. See also our security testing glossary.
Talk to Us About Testing