# Penetration Testing Scope and Rules of Engagement Template

## Engagement Overview
- Client / owner:
- Testing provider:
- Engagement ID:
- Start date / end date:
- Primary timezone:
- Business objective:

## Authorization
- Authorized signer:
- Emergency contact:
- Approved tester(s):
- Written approval location:

## In-Scope Assets
| Asset | Environment | Test Types | Notes |
|---|---|---|---|
|  | Production / staging / lab | Recon / web / API / cloud / mobile |  |

## Out-of-Scope Assets
| Asset | Reason | Contact for exceptions |
|---|---|---|

## Allowed Activities
- Passive reconnaissance against in-scope domains.
- Authenticated testing with supplied test accounts.
- Non-destructive vulnerability validation.
- Rate-limited scanning within approved windows.
- Social engineering only if separately approved in writing.

## Prohibited Activities
- Denial-of-service, stress testing, or destructive data modification unless explicitly approved.
- Accessing real customer data beyond minimal proof and immediate reporting.
- Persistence, stealth, malware, credential harvesting, or lateral movement outside scope.
- Testing third-party SaaS or cloud assets without direct approval.

## Test Windows and Rate Limits
- Approved windows:
- Maximum request rate:
- Maintenance blackout periods:
- Stop-testing triggers:

## Data Handling
- Evidence storage location:
- Encryption requirements:
- Retention period:
- Redaction requirements:

## Communications
- Daily status channel:
- Critical finding notification SLA:
- Emergency pause phrase:
- Final report due date:

## Sign-Off
| Name | Role | Signature | Date |
|---|---|---|---|
