Home/Free tools/Pentest Readiness Assessment

Pentest Readiness Assessment

Ten questions covering scope, authorisation, environment, credentials and remediation capacity. Answer them all for a readiness score and the gaps worth closing before testing begins.

Runs entirely in your browser. Nothing you type here is transmitted, logged, or stored. There is no server to send it to. Open your developer tools and watch the network tab if you want to confirm it.

1. Have you defined exactly which applications, systems and IP ranges are in scope?

2. Do you have written authorisation from the owner of every in-scope asset? · critical

3. Is there a staging or pre-production environment that mirrors production?

4. Can you provide test accounts at each privilege level, including an administrative one?

5. Are current, tested backups in place before testing starts?

6. Is a named technical contact available during the test window?

7. Do you have an up-to-date inventory of your internet-facing assets?

8. Can you avoid major deployments and changes during the testing window?

9. Do you have engineering capacity to remediate findings after the report?

10. Have critical issues from previous scans or tests already been fixed?

0 of 10 answered — answer them all to see your result.

← All free tools