The deliverable

Exam report guides, by vendor

Most of these exams are scored on a written report, not just on getting root — and a large share of failures are report failures, not hacking failures. Every vendor's standard reduces to one test: could a competent stranger reproduce your work from the page alone? Start with the general standard, then your vendor's specifics.

Report-graded vendors
5
The one test
Reproducible?
Top avoidable fail
No IP in the proof shot
The six parts of a penetration-test exam report, from executive summary to appendices.
What a report has to contain — the same standard behind every vendor's rules.
Start hereThe general standard

Structure, evidence standards and grading criteria that sit behind every vendor's rules — and the failure modes that cost people an exam they had already passed on the machines.

Read the guide →

Not listed: CRTO (Zero-Point), BSCP (PortSwigger) and eJPT (INE) are flag-based or auto-graded and have no written report to prepare.