BUILD A BETTER PENTEST SCOPE.
Choose target types, approximate target count, access model, environment and test depth to generate an indicative engagement shape. Free, with no login required.
Get your detailed C3SA results
Receive a copy of your result and recommended next steps without leaving this page.
Your assessment result is submitted with the form so C3SA can provide the requested report and relevant follow-up. Do not enter sensitive, classified or controlled information into public web forms.
A DRAFT SCOPE, NOT A QUOTATION.
The scope builder helps buyers identify assets, objectives, exclusions, timing and constraints before requesting a test. It produces an indicative engagement shape based on your answers; it is not a quotation or a statement of work.
C3SA then reviews the draft scope and designs safe rules of engagement and an appropriate testing depth for your environment.
What is the difference between black-box and authenticated testing?
Black-box testing starts with no credentials, like an outside attacker. Authenticated testing uses valid accounts to find what a logged-in user, or an attacker who has stolen credentials, could do. Most applications benefit from both.
Should we test production?
Production testing gives the most realistic results but needs careful timing, safety limits and stop conditions. Non-production environments are safer but may differ from what is live.
Is my information shared?
Your answers are processed in your browser. The site may record an anonymous completion event (tool name and score) in its analytics. Your contact details and full result are only sent to C3SA if you choose to request detailed results through the form. Do not enter sensitive, classified or controlled information into public web forms.
FROM DRAFT SCOPE TO TEST PLAN.
A draft scope across targets, access model, environment and depth.
C3SA reviews the scope and designs safe rules of engagement and testing depth.
A testing proposal with defined scope, schedule and deliverables.
