By EJN Labs · 21 Jul 2026 · 8 min read
To scope a penetration test, you define exactly what will be tested, how, and when, before any quote is built. Work through twelve questions covering targets, environment, test type, access, timing and reporting. Clear answers give you an accurate fixed price, a focused engagement, and findings that map to the systems you actually care about rather than a generic, padded test.
Knowing how to scope a penetration test is the difference between a tight, well-priced engagement and a vague one that misses the systems that matter. Scoping is the structured conversation that turns “we need a pen test” into a defined list of targets, an agreed method, and a clear set of deliverables. Get it right and your quote is accurate and your report covers the assets you care about; get it wrong and you risk paying for the wrong work or leaving real exposure untested. This checklist walks through the twelve questions our CREST-certified testers ask on every scoping call, and our CREST pen testing quote form captures most answers in a few minutes.
Why scoping decides the price and the value of a pen test
Every credible penetration testing quote is built from the same maths: the number of tester days the work needs, multiplied by a day rate. Scoping fixes the day count, which is where almost all of the cost is decided. A tightly scoped engagement spends its days on the systems that carry real risk, while a loose scope either pads the count with low-value targets or, worse, leaves a critical asset out entirely.
Good scoping also protects you from scope creep mid-engagement. When the targets, environment and rules of engagement are written down up front, there is no awkward conversation halfway through about a forgotten staging host or an extra user role. The agreed scope becomes the contract, which is why we translate the answers into a single fixed figure rather than billing open-ended days. Our UK penetration testing cost guide breaks the day-count maths down by test type.
Questions 1 to 4: define your targets and goals
The first block establishes what you are protecting and why. Without clear answers, everything downstream is guesswork.
- What are you trying to achieve? A compliance test for ISO 27001 or Cyber Essentials Plus has different priorities to an assurance test before a product launch or a board-mandated risk review. State the driver, because it shapes depth and reporting.
- What assets are in scope? List the specific applications, websites, APIs, networks, IP ranges or cloud accounts to be tested. Be precise: “the customer portal at app.example.co.uk and its supporting API” is scopeable; “our systems” is not.
- What is explicitly out of scope? Naming the systems you do not want touched matters as much as naming those you do. Shared hosting, third-party SaaS you do not own, and production payment processors often sit out of scope for good reason.
- How big is each target? Count the web application user roles, the API endpoints, the live IP addresses, or the cloud subscriptions. Size is the single biggest driver of the tester-day count, so an honest count up front gives you an honest price.
If you are unsure whether something belongs in scope, flag it rather than omitting it. Our testers would rather discuss a borderline asset on the call than discover it untested after the report lands.
Questions 5 to 8: choose the test type and approach
With the targets defined, the next block decides how they will be tested. The same asset can be tested several ways, and the choice changes both the day count and the findings.
- Which test type do you need? External network, internal network, web application, API, mobile, cloud configuration, wireless and red team engagements all carry different methods and day counts. One scope can combine several, but each is priced on its own merits. Browse the full range on our penetration testing services page.
- Black box, grey box or white box? Black box means the tester starts with no inside knowledge, grey box gives them credentials and limited documentation, and white box hands over full source or architecture detail. Grey box is the usual sweet spot for application testing because it mirrors a real authenticated attacker without wasting days on blind discovery.
- Authenticated or unauthenticated? For any application with logins, testing each user role from inside the authentication boundary finds the privilege-escalation and access-control flaws that matter most. Decide which roles need testing and have credentials ready.
- Production or staging environment? Testing production is the most realistic but demands care around data and availability. A representative staging environment removes that risk, provided it matches production. State which you intend to use, as it affects the rules of engagement.
If you are weighing a standard pen test against a broader adversary simulation, the test-type answer is where that decision is made. A scoping call is the right moment to ask which approach fits your maturity and your goal, rather than buying the most expensive option by default.
Questions 9 to 12: access, timing, rules and reporting
The final block covers the logistics that keep an engagement smooth and lawful. These answers rarely change the price much, but missing them is the most common cause of delays once a test is booked.
- What access and prerequisites can you provide? Test accounts, VPN access, allowlisting of tester IP addresses, API documentation and a named technical contact all remove discovery overhead. The better prepared the access, the fewer days are spent on setup and the more on testing.
- When does it need to run, and are there constraints? Agree the testing window, any change freezes, and whether sensitive actions must be confined to out-of-hours periods. If a hard deadline exists, such as a certification audit date, name it so the schedule can be locked.
- What are the rules of engagement? Define what is permitted and what is off-limits: denial-of-service testing, social engineering, physical access and any data the testers must not exfiltrate. For production systems, agree an emergency stop and escalation contact up front.
- What deliverables and follow-up do you need? Confirm the report format, whether you need an executive summary for the board and technical detail for developers, CVSS scoring, and whether a retest is included. We build a free retest into every engagement so remediation is verified without a fresh invoice.
Authorisation deserves a special mention. Penetration testing is only lawful with the explicit, written permission of the system owner, and if a target is hosted by a third party, such as a cloud provider, you may need their sign-off too. A signed scope plus an authorisation letter documents it.
How EJN Labs approaches scoping
Every engagement we run starts with a short scoping call where our CREST-certified testers work through these twelve questions with you, then translate the answers into a number of tester days at our standard UK day rate. All testing is delivered by senior and principal testers, never juniors or associates. You receive one fixed figure tied to a written scope, and that figure does not move unless you change the scope, in which case we document and re-quote the change first. There is no open-ended day billing and no surprise final invoice.
As a CREST-accredited firm that also holds Cyber Essentials, Cyber Essentials Plus, ISO 27001 and ISO 9001, we produce reports that stand up to auditor and customer scrutiny, with CVSS-scored findings, reproduction steps and a prioritised remediation plan. A free retest is included so your developers can fix the issues and have us verify them without a fresh charge. Explore the full range on our penetration testing services page.
Frequently Asked Questions
How do you scope a penetration test?
You scope a penetration test by defining what will be tested, how, and when, before any quote is built. Work through the targets and goals, the test type and approach, then access, timing, rules of engagement and reporting. Clear answers to these twelve areas give the firm an accurate tester-day count, which is what an honest fixed price is built from.
What information do I need to provide to scope a pen test?
You need a precise list of in-scope and out-of-scope assets, counts such as user roles, API endpoints and live IP addresses, the driver for testing, your preferred test type, the environment to be used, the testing window, the rules of engagement, and the deliverables you require. Bringing these to a scoping call turns it into a quick confirmation rather than a fact-finding exercise.
Does scope affect the cost of a penetration test?
Yes, scope is the main driver of cost. A penetration testing price is the number of tester days the work needs multiplied by a day rate, and scope determines that day count. A larger or more complex scope needs more days, while a tight, well-defined scope spends its days on the assets that carry real risk, so accurate scoping up front protects your budget.
Do I need written permission to run a penetration test?
Yes. Penetration testing is only lawful with the explicit, written permission of the system owner. If a target is hosted by a third party, such as a cloud provider, you may also need their authorisation. A reputable firm confirms this before testing begins, and a signed scope document plus an authorisation letter is part of how that permission is recorded and the rules of engagement are agreed.
Should I test production or a staging environment?
Testing production is the most realistic but demands care around live data and availability, with an agreed emergency stop and escalation contact. A representative staging environment removes that risk, provided it genuinely matches production in configuration and code. The right choice depends on your tolerance for disruption and how closely staging mirrors live.
Get a fixed-price quote from a clear scope
Tell us what you need tested and we will work through these scoping questions on a short call, then return a fixed-price quote with the tester days and day rate laid out plainly. No open-ended day billing, no obligation, just a clear figure from a CREST-certified tester with a free retest included. Start with our CREST pen testing quote form.




Leave a Reply