Executive Summary
A concise overview of objectives, business impact, and high-level approach so non-technical stakeholders can approve the engagement.
Signers should be documented with authority and role to ensure the authorization is valid and enforceable.
Typically the CISO or Head of IT who approves the scope, budget, and risk acceptance. Their signature confirms organizational authorization and internal notification procedures have been followed.
Often the General Counsel or procurement officer who accepts legal terms, liability limits, and confidentiality obligations. Their signature binds the organization to contractual protections.
A concise overview of objectives, business impact, and high-level approach so non-technical stakeholders can approve the engagement.
Detailed list of target systems, in-scope IP ranges, applications, APIs, and explicit exclusions to prevent unauthorized access.
Description of testing types (external, internal, web app, social engineering), tools to be used, and whether exploitation is attempted.
Specify report formats, executive summary, technical findings, remediation guidance, and timelines for preliminary and final reports.
Testing window, pre-test checklist, daily coordination, and expected delivery dates for draft and final reports.
Breakdown of fees, change-order process, liability caps, insurance, confidentiality, and data-handling obligations.
| Field | Configuration |
|---|---|
| Upload Document | Accept PDF or DOCX; ensure final draft is locked. |
| Signature Fields | Place signature, name, title, and date fields for each party. |
| Authentication | Choose email, SMS code, or higher-assurance methods. |
| Audit Trail | Enable detailed logs: IP, timestamp, and action metadata. |
Choose an e-signature provider and storage stack that support your required authentication and retention controls.
Number of days the quoted price and scope remain valid
Date by which client must sign to proceed
Approved start and end dates for active testing
Date for preliminary findings to be shared with client
Date for the completed report with remediation guidance
Vendor sends proposal and supporting documents to client for review
Authorized signer approves scope and signs the proposal
Coordination call, emergency contacts, and safety checks completed
Conduct tests, produce draft findings, and deliver final report
The interface is simple and easy-to-use for our team; more importantly it is just as easy for our customers.
We felt most comfortable with airSlate SignNow given their SOC 2 certification and strict focus on ESIGN and UETA act compliance.
| Criteria | Pen Test Proposal | Vulnerability Assessment |
|---|---|---|
| Purpose | active exploitation | passive discovery |
| Depth | high | moderate |
| Tools | exploitation tools | scanners and configs |
| Deliverables | exploit proof-of-concept | findings inventory |
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies by vendor | Varies by vendor | Varies by vendor | Varies by vendor |
| Bulk Send | Yes (Premium tier) | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes (BAA) | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Envelope Cap | No cap | 100 envelopes/user/year | Varies by plan | Varies by plan | Varies by plan |