Inside a CREST Pen-Test: Methodology, Deliverables & What a Board-Ready Report Looks Like

We get asked this a lot — here’s how we explain it to a new CISO over coffee.

Hook: Most “pen-test reports” fail the board test: 60 pages of CVEs, zero business narrative. Here’s what a CREST board-ready report actually looks like — with a redacted sample.

The 6 Phases (CREST-Aligned)

1. Scoping & ROE (90 min workshop) — Objectives, out-of-scope, business criticality, threat model (MITRE ATT&CK), NDA. Outcome: no surprise outages. 2. Reconnaissance — OSINT, asset discovery, attack surface mapping. 3. Vulnerability Discovery — Automated (Burp, Nessus) + manual — triangulated, not dumped. 4. Exploitation — Objective-Based — Can we reach PII, bypass authz, or achieve RCE? Full chain documented. 5. Post-Exploitation & Stealth — Lateral movement, persistence, and can your SOC detect us? 6. Reporting, Briefing & Retest — Executive summary (2 pages) + Technical findings (PoC, CVSS, OWASP Risk) + Compliance mapping (ISO 27001/SOC 2/PCI DSS/GDPR) + Live debrief + Free retest within 30 days.

Deliverables — What You Actually Get

  • Executive Risk Summary: Heat map, business impact in USD/reputation, investment recommendation — the slide your CEO forwards.
  • Technical Findings: Each with PoC, evidence (redacted screenshots/burp logs), CVSS 3.1 + OWASP Risk Rating, and fix guidance ranked by exploitability, not just severity.
  • Compliance Map: One finding → many controls (e.g., IDOR → ISO 27001 A8.26, SOC 2 CC6.1, PCI DSS 6.5.8).
  • Appendix: Methodology, scope, ROE, tester CREST IDs (anonymized), tooling, and retest results.

Hook: [See Redacted Sample: 2-Page Exec Summary + 1 Finding with PoC →] See the quality before you buy.

CTA: Request Sample Report + Live Walkthrough — 30 Min → · See Proposal VAPT with Retest →

Benchmark your risk while you wait: OWASP Risk Calculator →