Establishing secure connection…Loading editor…Preparing document…

Penetration Testing Agreement

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

PENETRATION TESTING AGREEMENT

This Penetration Testing Agreement (the Agreement) is entered into as of by and between Client Name: , with address: (Client), and Service Provider Name: , with address: (Service Provider).

WHEREAS

WHEREAS, Client desires to engage Service Provider to perform authorized penetration testing and related services against Client systems and assets as set forth in this Agreement; and

WHEREAS, Service Provider represents that it possesses the technical skill, experience and necessary personnel to perform such services in a professional manner and in accordance with industry-standard methodologies; and

WHEREAS, the parties wish to set forth the scope, limitations, compensation, reporting, confidentiality, and legal terms governing such engagement.

SCOPE OF WORK

Testing types authorized (check all that apply):






Authorized test window: From through . Tests performed outside this window are unauthorized and constitute a breach of this Agreement.

RULES OF ENGAGEMENT

Service Provider will conduct all testing using methods described in the scope of work, will make reasonable efforts to avoid disruption of Client operations, and will immediately cease any action that is reasonably likely to cause material disruption upon notification by Client. Service Provider will not intentionally access, modify, exfiltrate or destroy data except as necessary to demonstrate vulnerabilities as set forth in the scope of work.

PAYMENT TERMS

Client shall pay Service Provider the total fee of $ for the services described herein, subject to the schedule below.

Overdue payments will accrue interest at a rate of per month or the maximum rate permitted by law, whichever is lower. Client is responsible for reasonable collection costs.

DELIVERABLES AND REPORTING

Service Provider will deliver a written report summarizing findings, risk ratings, exploit details, and remediation recommendations within calendar days after completion of testing. The report will be classified as Confidential and will include an executive summary suitable for non-technical stakeholders.

TERM AND TERMINATION

This Agreement commences on Start Date: and, unless earlier terminated pursuant to this Section, will terminate on End Date: .

Either party may terminate this Agreement for convenience upon written notice at least days prior to the desired termination date. Either party may terminate immediately for material breach that remains uncured for a period of days after written notice.

CONFIDENTIALITY

Each party acknowledges that Confidential Information disclosed by the other constitutes proprietary information and agrees to maintain such information in strict confidence and not to use or disclose it except as required to perform under this Agreement. Confidential Information includes vulnerability reports, exploit details, remediation steps, and any non-public system data. Standard exclusions apply to information that is publicly known, rightfully received from a third party, or independently developed.

Confidentiality obligations will survive termination for a period of years, except that Confidential Information constituting trade secrets will be protected for as long as such information remains a trade secret under applicable law.

DATA HANDLING AND DESTRUCTION

Upon request or upon expiration of the retention period, Service Provider will return or securely destroy Client data and confirm destruction in writing.

REPRESENTATIONS, WARRANTIES AND AUTHORIZATION

Client represents and warrants that it is the owner or authorized custodian of the systems to be tested and has full authority to request testing and to grant the access and permissions described in this Agreement. Client will provide any required written authorization to third-party owners where necessary to permit testing.

Service Provider represents and warrants that it will perform services with reasonable care and skill in accordance with prevailing industry standards, and that personnel performing testing have been authorized to perform such tasks.

LIMITATION OF LIABILITY AND INDEMNIFICATION

Except for willful misconduct or gross negligence, neither party will be liable to the other for incidental, consequential, punitive, or special damages. Service Provider's aggregate liability for any claim arising from or relating to this Agreement will not exceed the total fees paid by Client under this Agreement for the applicable engagement.

Client agrees to indemnify and hold harmless Service Provider from claims, liabilities, and costs arising from Client's breach of representations or from unauthorized modifications to systems by Client or third parties.

INSURANCE

Service Provider will maintain commercially reasonable liability and errors & omissions insurance and will provide evidence of such coverage upon Client request. Minimum coverage amounts and additional insured status may be specified here:

GOVERNING LAW; DISPUTE RESOLUTION

This Agreement will be governed by and construed in accordance with the laws of the State of without regard to its conflict of law principles. The parties will attempt in good faith to resolve disputes promptly by negotiation between senior executives.

ENTIRE AGREEMENT

This Agreement, together with any attachments and the Scope of Work, constitutes the entire agreement between the parties relating to the subject matter hereof and supersedes all prior agreements and understandings. Any amendment or modification must be in writing and signed by authorized representatives of both parties.

MISCELLANEOUS

If any provision of this Agreement is held invalid, the remainder of this Agreement will continue in full force and effect. Neither party may assign this Agreement without the prior written consent of the other, except to an affiliate or in connection with a merger or sale of substantially all assets.

Client

Party Label:

By:

Date:

Service Provider

Party Label:

By:

Date:

Enter text✕

What a Penetration Testing Agreement Is

A Penetration Testing Agreement is a contract that defines the scope, rules of engagement, responsibilities, and legal protections for security testing performed against an organization’s systems. It establishes who will test, what systems are in scope or excluded, permitted testing windows, reporting obligations, liability limits, confidentiality, data handling requirements, and approval processes. The document mitigates legal and operational risk by documenting consent, authorization, and remediation expectations between the customer and the tester.

Why a Formal Agreement Matters

A written agreement provides clear authorization to test, reduces legal exposure, and aligns expectations on scope, timing, and handling of sensitive data.

Why a Formal Agreement Matters

Common Parties and Use Cases

Organizations use penetration testing agreements to authorize third-party or internal security assessments while protecting customer data and maintaining regulatory compliance.

  • Enterprise security teams authorizing external testers for scheduled or ongoing assessments
  • Managed security providers contracting scope-based red team or vulnerability assessments
  • Legal and procurement groups approving liability, indemnity, and confidentiality provisions

Agreements also help vendors, managed security service providers, and legal teams standardize engagement terms and speed approval cycles.

Who Signs and Why

CISO

The chief information security officer or equivalent typically approves scope, risk exceptions, and scheduling. They confirm business risk tolerance, required notifications, and any regulatory constraints that the test must respect.

Security Vendor

The third-party security provider signs to accept scope, confidentiality, and non-disclosure obligations, and to acknowledge constraints on testing techniques, data handling, and reporting timelines.

Core Elements to Include in the Agreement

A professional Penetration Testing Agreement organizes legal, operational, and technical requirements into clear sections to reduce ambiguity and speed approvals.

Scope of Work

Define systems, IP ranges, environments (production, staging), and explicit exclusions to prevent unintended impact.

Authorization

A clear statement authorizing testers to access and test named assets, signed by an authorized representative.

Testing Rules

Allowed techniques, prohibited actions (e.g., data destruction), escalation processes for critical findings, and blackout windows.

Data Handling

Requirements for collection, storage, access controls, retention, reporting of sensitive or regulated data.

Liability & Indemnity

Limits on damages, indemnification obligations, and insurance minimums if applicable.

Reporting & Remediation

Deliverable schedule, vulnerability severity definitions, timelines for remediation and retesting.

Security and Compliance Details to Specify

Encryption in transit: TLS 1.2/1.3 required
Encryption at rest: AES-256 recommended
Access controls: Role-based unique credentials
Audit logging: Retain signed action logs
HIPAA handling: BAA required where PHI present
Evidence preservation: Tamper-evident records required

Key Legal Risks to Address

Unauthorized access: Criminal exposure
Data breach: Regulatory fines
Service outage: Contractual damages
IP disputes: Ownership conflicts
Insurance gaps: Uninsured liabilities
Scope creep: Expanded testing liability

Common Preparation Mistakes to Avoid

  • Failing to document explicit authorization which can expose both parties to criminal or civil claims
  • Omitting system exclusions such as critical third-party services, backups, or safety systems that must not be tested
  • Neglecting data handling rules which can lead to noncompliance with HIPAA, GLBA, or other regulations
  • Using vague timelines or vague severity definitions that delay remediation and increase operational risk

How to Complete a Penetration Testing Agreement

Follow a stepwise process to define scope, obtain approvals, and confirm technical and legal protections before testing begins.

  • 01
    Define scope: List assets, IPs, and exclusions
  • 02
    Authorize: Obtain signature from authorized party
  • 03
    Set rules: Document allowed techniques and windows
  • 04
    Confirm logistics: Agree reporting, contact and rollback plans

Typical Digital Workflow Settings

Configure the electronic signing and document routing to capture authorization, timestamps, and an audit trail.

Field Configuration
Signature field Require signer name, title, and date
Authentication Use email link or SMS code
Access control Restrict by domain or IP when needed
Audit trail Capture IP, timestamp, and actions

Digital Signing and Evidence Collection

Use an eSignature platform that preserves an audit trail, secures documents, and supports required authentication.

  • Authentication: Email, SMS, or stronger multi-factor
  • Audit details: IP, timestamps, and action logs
  • File formats: PDF/A or standard PDF with embedded audit

Signing and Approval Flow

A clear operational flow reduces delays and preserves legal evidence for authorization and completion.

  • Upload contract: Prepare final agreement PDF
  • Place fields: Add signature, initial, and date fields
  • Send to signer: Use secure email or signing link
  • Capture audit: Store signed PDF and audit record

Key Deadlines and Timing Expectations

Penetration testing agreements should specify timing for authorization, test windows, reporting, and retesting to avoid operational conflict.

Authorization lead time:

Allow at least 5 business days for approvals

Testing window:

Specify start and end dates and blackout periods

Pre-test notice:

Provide 48–72 hours notice unless otherwise agreed

Preliminary report:

Deliver within 3–7 business days of test completion

Remediation retest:

Schedule within 30–90 days as defined in agreement

Milestones from Approval to Closure

A milestone timeline helps coordinate technical teams, legal signoffs, and executive reviews during a test engagement.

01

Approval Received

Authorized signature and scope confirmed by legal and security

02

Pre-Test Setup

Credentials and monitoring rules put in place

03

Active Testing

Tester performs agreed activities within scheduled window

04

Reporting & Remediation

Findings reported and remediation plan initiated

Real-World Examples of Use

Examples show how organizations structure agreements to control risk while enabling effective security testing.

Optica Ventures

A small portfolio firm needed consistent authorization for vendors

  • They required a standard clause limiting blast radius
  • The result was faster approvals, consistent reporting, and clearer remediation responsibilities across their assets.

Xerox Operations

An enterprise integrated testing with procurement approvals

  • They used a single master agreement tied to statements of work
  • This reduced legal review time and standardized security and data-handling controls for each engagement.

Frequently Asked Questions

Answers to common legal and operational questions about Penetration Testing Agreements and electronic execution.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users