🛡️ Pentest from €539 · Compliance from €89. See All Services →
Optimum Web
Resource · Penetration Testing

Penetration Test Rules of Engagement — What It Covers and Why It Matters

Reviewed: 2 August 2026 — reviewed quarterly

Quick Answer

A Rules of Engagement (RoE) document is the signed agreement that authorises a penetration test before it starts. It names the exact scope, testing window, permitted techniques, emergency contacts, and data-handling rules, and is signed by someone with authority over the systems being tested — without it, testing activity has no documented permission behind it.

What Is a Rules of Engagement Document?

A Rules of Engagement is the document both parties sign before a penetration test begins, defining exactly what's authorised: which systems can be tested, when, by what methods, and under what constraints. It exists because the techniques used in a legitimate penetration test — scanning, exploitation attempts, privilege escalation — are functionally identical to a real attack. The RoE is what separates authorised testing from something that would otherwise be treated as an intrusion.

It's typically prepared during the scoping stage of an engagement, after the target systems and objectives are agreed but before any active testing starts, and it's referenced throughout the engagement if questions come up about what's in or out of bounds.

What Fields Does a Rules of Engagement Typically Define?

FieldWhat it defines
Scope (in / out)Names the exact systems, IP ranges, domains and applications that may be tested, and explicitly lists anything excluded
Testing windowThe start and end date/time the engagement is authorised to run, including timezone
Authorised testing hoursWhether testing may run 24/7 or only during agreed maintenance windows, to control business impact
Test type and depthWhether the engagement is a Vulnerability Assessment, black/grey/white-box penetration test, and which techniques are in or out of bounds (e.g. social engineering, physical access, DoS)
Emergency contactsNamed individuals on both sides who can be reached immediately if testing causes an unexpected issue
Data handling rulesHow any data accessed during testing (e.g. via a demonstrated vulnerability) is handled, stored and destroyed afterward
Authorisation signaturesThe signed authorisation from someone with the authority to approve testing against the named systems — this is what makes the testing legally authorised
Reporting and disclosure termsHow findings will be communicated during testing (e.g. immediate escalation for Critical issues) and confidentiality terms for the final report
Rules for stopping testingConditions under which either party can pause or halt the engagement, and how that decision is communicated

Why Does This Matter Beyond Legal Cover?

Beyond authorisation, a clear RoE reduces operational risk on both sides. It sets expectations about business impact (e.g. no testing during a peak sales window), gives both teams a named contact if something unexpected happens mid-test, and prevents scope disputes after the fact — if a finding falls outside the agreed scope, the RoE is the reference point for what happens next, rather than a judgment call made in the moment.

Before Testing Starts, Check the RoE Covers This

Scope is named explicitly enough that there's no ambiguity about what's in vs out
Testing window and permitted hours match your actual business constraints
An emergency contact is named on both sides, reachable during the testing window
Data-handling terms are stated for anything the tester might access during testing
The signature is from someone with actual authority over the named systems

Every engagement we run starts with a signed Rules of Engagement before testing begins. See our penetration testing services or how a report is structured once testing is complete. See also our security testing glossary.

Talk to Us About Testing

Frequently Asked Questions

Is a Rules of Engagement document legally required for a penetration test?+
It isn't a legal requirement in the way a contract is, but it functions as the authorisation record that makes the testing lawful rather than unauthorised access. Without a signed RoE naming the specific systems and dates, testing activity that would otherwise look identical to an attack has no documented permission behind it.
Who needs to sign the Rules of Engagement?+
Someone with the actual authority to authorise testing against the named systems — typically a system owner, IT/security lead, or an executive with delegated authority, not just the person who requested the test. For infrastructure hosted by a third party (cloud provider, SaaS vendor), that provider's own testing-notification or authorisation process may also need to be followed separately.
What happens if testing needs to go outside the agreed scope?+
It shouldn't happen without a documented change to the RoE first. If a tester finds something that suggests a related system outside scope is also affected, the correct process is to report it and get written authorisation to extend scope, rather than testing it under the original agreement.
Does the RoE cover what happens to data found during testing?+
It should. A well-formed RoE states how any data the tester encounters — for example, through a vulnerability that exposes records — is handled, whether it's copied for evidence, and how it's destroyed once the report is finalised. This is a common area to check that expectations line up before testing starts.
Can testing be stopped once it's started?+
Yes — the RoE should define the conditions and process for pausing or halting testing, for example if a test causes an unexpected service disruption. Having this agreed in advance avoids ambiguity in the middle of an active engagement about who has the authority to call a stop.
Is the Rules of Engagement the same document as the test report?+
No — they serve different purposes at different times. The RoE is agreed before testing starts and defines what's authorised; the report is delivered after testing ends and describes what was found. Some engagements also produce a short pre-test scoping document that feeds into the RoE, but the RoE itself is the authorisation record.