All posts
Compliance·May 19, 2026·6 min

What auditors actually want from a pentest report

What auditors actually want from a pentest report

A penetration test report has more than one audience, and the auditor is the pickiest of them. A report your engineers love can still draw a frown from an assessor, because they are reading for different things. If your test is meant to support SOC 2, PCI, or another framework, it helps to know exactly what the auditor is checking before you commission it.

It has to match your real scope

The first thing an auditor checks is whether the systems tested are the systems in question. A beautiful report on a convenient subset of your environment does not cover the boundary the audit cares about. The scope of the test should map to your audit scope, your system boundary, or your cardholder data environment, and the report should state that scope plainly.

It has to fall in the right window

Timing is non-negotiable, especially for a SOC 2 Type II or a PCI assessment. The test generally needs to fall within the audit period or the required frequency, and a report from too long ago is simply not valid evidence. A current report scoped correctly beats a thorough report that is out of date.

Findings, evidence, and a severity an auditor trusts

  • Each finding with a clear severity, real evidence, and a specific remediation, not a raw tool dump.
  • Proof of exploit where it applies, so the finding is demonstrably real rather than a scanner's guess.
  • Findings mapped to the relevant control or criterion, so the auditor can connect the proof to the requirement.
  • An executive summary the auditor can read first, and detail they can verify second.

Proof you closed the serious ones

This is the part teams underestimate. Finding issues is expected; what the auditor wants is evidence you remediated the important ones and verified the fix, usually through a retest. An open critical on the last day of your audit window is a problem; the same critical, fixed and retested, is a strength. We cover the reader's side of this in how to read a penetration test report, and the SOC 2 specifics in does SOC 2 require a penetration test.

Uvy reports are written for all three readers from one validated run: scoped to your boundary, dated in your window, every exploitable finding proven, every fix specific, and a retest to confirm the serious ones are closed. See how it works.

Find every way in, before an attacker does

Uvy runs continuous offense and defense across your applications, agents, and embodied AI, at machine speed, and hands your team proof and the exact fix. Start with an application pentest, or talk to sales to cover the rest.

Free to test. No card to start.

Or write to [email protected]