This document is a formal agreement for you as a penetration tester to start your work. The purpose of this document is to define:
- The expectations from the client
- The scope of work
- The schedule of the work
- The pricing
- The deliverables at the end of all the penetration tests
- The payment terms
- The legal agreements
- Finally, the signatures
Of course, you can add your custom contents if you feel that this information is not enough. Tweak it to your liking and experience. In the following, you will see a sample of a statement of the work contract.
Statement of work – Web Application Penetration Test:
For [Client Company Name][Date]
Contents:
- Description
- Expectations
- Scope
- Schedule
- Pricing estimation
- Deliverables
- Payment Terms ...