Statement of work

This document is a formal agreement for you as a penetration tester to start your work. The purpose of this document is to define:

  • The expectations from the client
  • The scope of work
  • The schedule of the work
  • The pricing
  • The deliverables at the end of all the penetration tests
  • The payment terms
  • The legal agreements
  • Finally, the signatures

Of course, you can add your custom contents if you feel that this information is not enough. Tweak it to your liking and experience. In the following, you will see a sample of a statement of the work contract.

Statement of work – Web Application Penetration Test:

For [Client Company Name][Date]

Contents:

  1. Description
  2. Expectations
  3. Scope
  4. Schedule
  5. Pricing estimation
  6. Deliverables
  7. Payment Terms ...

Get Practical Web Penetration Testing now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.