INTERACTIVE TOOL · PENETRATION TEST SCOPE

BUILD A BETTER PENTEST SCOPE.

Choose target types, approximate target count, access model, environment and test depth to generate an indicative engagement shape. Free, with no login required.

What needs testing?
Access model
Environment
Test depth
ABOUT THIS TOOL

A DRAFT SCOPE, NOT A QUOTATION.

The scope builder helps buyers identify assets, objectives, exclusions, timing and constraints before requesting a test. It produces an indicative engagement shape based on your answers; it is not a quotation or a statement of work.

C3SA then reviews the draft scope and designs safe rules of engagement and an appropriate testing depth for your environment.

COMMON QUESTIONS
What is the difference between black-box and authenticated testing?

Black-box testing starts with no credentials, like an outside attacker. Authenticated testing uses valid accounts to find what a logged-in user, or an attacker who has stolen credentials, could do. Most applications benefit from both.

Should we test production?

Production testing gives the most realistic results but needs careful timing, safety limits and stop conditions. Non-production environments are safer but may differ from what is live.

Is my information shared?

Your answers are processed in your browser. The site may record an anonymous completion event (tool name and score) in its analytics. Your contact details and full result are only sent to C3SA if you choose to request detailed results through the form. Do not enter sensitive, classified or controlled information into public web forms.

THE C3SA DIFFERENCE

FROM DRAFT SCOPE TO TEST PLAN.

WHAT YOU GET NOW

A draft scope across targets, access model, environment and depth.

WHAT C3SA ADDS

C3SA reviews the scope and designs safe rules of engagement and testing depth.

THE NEXT STEP

A testing proposal with defined scope, schedule and deliverables.

UNDER ATTACK? CYBERFIRE →