An Enterprise Customer Asked for Your Penetration-Test Report. What Should a Small SaaS Vendor Share?
Published August 2026 by Solarc Labs
The buyer is asking for confidence, not necessarily every page of your security history
NCSC supplier-assurance guidance says buyers should understand how suppliers gain confidence that security controls work in practice, including independent testing such as penetration testing. It also says the level of evidence should depend on supplier criticality and risk. For a small SaaS vendor, that means the first job is to understand the request precisely. Is the buyer asking whether independent testing exists, for the date and scope, for remediation status, for a customer-safe summary, or for the full report? Do not assume those are interchangeable, and do not claim a lighter artifact satisfies a buyer requirement when the buyer has explicitly required something stronger.
Verify the evidence before deciding how to share it
Before responding, identify the exact product or environment that was tested, the test date, the testing provider, the scope, whether important exclusions existed, the status of material findings and whether a re-test or remediation evidence exists. A penetration test against one old environment should not silently become evidence for every product, deployment or customer configuration. If the report is stale, out of scope or has unresolved findings, preserve that state. A sales deadline does not turn partial evidence into current assurance.
Use proportionate disclosure, but do not hide a hard procurement requirement
NCSC guidance is risk-based: buyers may need different evidence depending on the supplier and service. That supports a proportionate disclosure process rather than automatically treating every security artifact as public collateral. Classify the available evidence with a security owner: customer-safe summary or letter, restricted evidence available under an agreed control, internal-only material, and unavailable or needs-review material. If a buyer genuinely requires the full report, route that requirement to the responsible security and commercial owners. Decide whether the deal justifies the disclosure controls and risk. Do not send sensitive exploit detail casually, but do not tell the buyer a summary is equivalent to the full report if it is not.
Keep a security questionnaire separate from independent testing evidence
A questionnaire records the supplier’s answers about controls. A penetration test is a separate form of testing evidence. Completing one does not manufacture the other. Store the approved customer-facing answer beside the source artifact, evidence owner, last-reviewed date, exposure classification and caveats so the next questionnaire starts from controlled evidence rather than an old spreadsheet answer. This is also where a trust pack becomes useful: one controlled inventory of what exists, who owns it, what can be shared, under what conditions and when it needs review.
Do not turn “we had a pen test” into “we are secure”
Independent testing can be useful evidence, but it is not a universal security certificate and it does not prove that every vulnerability is absent. Scope, timing, methodology, findings and subsequent product changes all matter. Avoid claims such as “penetration tested therefore secure” or “no vulnerabilities” unless the evidence genuinely supports the exact statement being made. A defensible customer response is narrower: what was tested, when, by whom, what evidence exists, what remediation state can be supported and what disclosure path is available.
Make the next enterprise review cheaper without weakening the evidence boundary
After the first request, preserve the approved answer and evidence-routing decision in a reusable answer library. Add an owner, review date, exposure classification and refresh trigger. That reduces repeat work while keeping stale evidence from being reused automatically. VendorOS Security Questionnaire Rescue can help organize customer questions, reviewed answers and evidence references. It does not perform a penetration test, assess whether a test was technically sufficient, certify your security posture or authorize disclosure of a sensitive report. Those decisions remain with the responsible human owners.
Primary sources
Sources used for this article
Continue the job