What goes in a rules-of-engagement document

Scope says what gets tested. The rules of engagement say how, and they are the document that keeps an authorized penetration test on the right side of both your operations and the law. Skipping or rushing it is how engagements turn into outages, disputes, or worse. The Penetration Testing Execution Standard treats it as core pre-engagement work, and so should you.
Authorization: the part that makes it legal
The single most important element is explicit, written authorization from someone with the authority to grant it. A penetration test without documented permission is, legally, unauthorized access. The rules of engagement record who authorized the test, for which systems, over what dates. This is also why systems you do not control (a cloud provider's infrastructure, third-party services) belong in writing as out of scope: you cannot authorize what you do not own.
What goes in the document
- Authorization: who approved the test, and their authority to do so.
- Targets and exclusions: exact in-scope systems, IPs, domains, and the explicit out-of-scope list.
- Permitted techniques: what is allowed (and what is not, for example denial-of-service or social engineering).
- Testing windows: when testing may run, including any required off-peak hours.
- Escalation path: what happens when a critical finding surfaces mid-test, and who to call.
- Emergency contacts and a stop procedure: how to halt the test instantly if something breaks.
- Data handling: how any sensitive data the testers encounter is treated and disposed of.
Scope is what we test. Rules of engagement are how we test it, who said we could, and what we do when something goes sideways. The unwritten parts are the ones that cause incidents.
Why exclusions carry equal weight
It is tempting to treat the out-of-scope list as an afterthought, but exclusions carry the same legal weight as inclusions. Testing a system you did not authorize, even by accident, is the problem the document exists to prevent. The access and consent boundary we discuss in how much access should you give a pentester is precisely what the rules of engagement put in writing.
A serious test treats the rules of engagement as a hard contract, scope guardrails, an escalation path, and an instant stop, not a formality. That discipline is built into how Uvy runs. See how it works.