EdTech supplier resource

    ST4S Penetration Test Preparation Checklist

    Prepare the product scope, authorized access, reporting requirements and remediation evidence before an independent security test begins.

    Reviewed against ST4S Supplier Guide 2026.1 on 12 September 2026.

    1. Confirm the assessment and product scope

    Record the exact product or service name and version being assessed.
    Identify student, teacher, administrator, support and integration roles.
    List web applications, APIs, mobile apps, cloud services and external infrastructure that form the assessed solution.
    Confirm whether testing is required after a major change, for an annual cycle or for another stated assessment need.

    2. Prepare safe testing access

    Provide written authorization and identify an accountable engagement owner.
    Create representative test accounts for each relevant role and tenant.
    Prefer controlled test data and agree how production data must be protected.
    Document testing windows, prohibited actions, escalation contacts and stop conditions.
    Confirm cloud-provider or third-party testing restrictions before active testing.

    3. Define the evidence deliverables

    Require a clear scope, dates, methodology, limitations and tester identity.
    Include an executive summary and reproducible technical findings with risk ratings.
    Request practical remediation guidance and a finding-status register.
    Agree whether a separately redacted report is needed for assessment submission.
    Confirm the organization name and product/service identification expected on final evidence.

    4. Close remediation and re-testing

    Assign an owner and target date for each accepted finding.
    Record risk acceptance separately from technical remediation.
    Re-test agreed fixes against the same finding and relevant scope.
    Preserve the original finding while adding verified remediation status.
    Submit only the evidence requested by the assessment team through the approved channel.

    How this checklist relates to ST4S

    The current supplier guide includes penetration testing after a major change or at least annually within T1 and lists a recent redacted penetration-testing report for the assessed service as EV10 evidence.

    This checklist is CyberSecurityArm’s practical preparation aid. It is not an ST4S publication and does not replace the official guide, the assessment questionnaire or instructions from the assessment team.

    Read the official ST4S Supplier Guide 2026.1

    Need an evidence-focused security test?

    Review the service scope, deliverables and assessment boundaries before requesting a proposal.

    View ST4S testing support