ST4S Penetration Test Preparation Checklist
Prepare the product scope, authorized access, reporting requirements and remediation evidence before an independent security test begins.
Reviewed against ST4S Supplier Guide 2026.1 on 12 September 2026.
1. Confirm the assessment and product scope
2. Prepare safe testing access
3. Define the evidence deliverables
4. Close remediation and re-testing
How this checklist relates to ST4S
The current supplier guide includes penetration testing after a major change or at least annually within T1 and lists a recent redacted penetration-testing report for the assessed service as EV10 evidence.
This checklist is CyberSecurityArm’s practical preparation aid. It is not an ST4S publication and does not replace the official guide, the assessment questionnaire or instructions from the assessment team.
Read the official ST4S Supplier Guide 2026.1Need an evidence-focused security test?
Review the service scope, deliverables and assessment boundaries before requesting a proposal.
View ST4S testing support