Skip to main content

Overview

The Penetration Tests module lets you plan, execute, and track penetration testing engagements directly in Matproof. Connect your testing provider, import findings, track remediation, and automatically link results as evidence against the relevant compliance controls. Penetration testing is required or recommended by most compliance frameworks:
Navigate to Penetration Tests in the sidebar to access the module.

Creating a test engagement

Finding management

Each finding contains:

Remediation workflow

  1. Review imported findings and assign owners
  2. Set remediation due dates based on severity:
    • Critical: 7 days (recommended)
    • High: 30 days
    • Medium: 90 days
    • Low: next scheduled maintenance window
  3. Owners update the finding status as they work through fixes
  4. Upload remediation evidence (configuration changes, patches applied, retest results)
  5. When all findings are addressed, mark the engagement as Completed
Do not mark critical or high severity findings as Accepted without documenting a risk acceptance rationale. Auditors will scrutinize accepted findings, especially for frameworks that require active vulnerability remediation.

Provider integration

Matproof integrates with penetration testing providers to streamline finding import:
  • Manual upload - upload the provider’s report in PDF, CSV, or JSON
  • API integration - for providers with API access, configure automatic finding sync
To configure a provider:
  1. Go to Settings - Integrations - Penetration Testing
  2. Select your provider or add a custom one
  3. Follow the setup instructions for API-based sync

Linking to compliance controls

Penetration test results serve as evidence for multiple framework controls. To link findings:
  1. Open a completed engagement
  2. Click Link to controls
  3. Matproof suggests relevant controls based on the engagement type and findings
  4. Confirm the mapping - the engagement summary and finding status become evidence on those controls
Set up recurring test engagements (quarterly or annually) and link them to the same controls. This creates a continuous evidence trail that demonstrates ongoing testing over time.

Scheduling and reminders

Stay on top of your testing program:
  1. Go to Penetration Tests - Schedule
  2. Set up recurring reminders (e.g., “External pentest due every 12 months”)
  3. Matproof sends notifications 30 days before the next test is due
  4. Track compliance with testing schedules from the dashboard

Reporting

Generate penetration test summary reports:
  1. Open a completed engagement
  2. Click Generate report
  3. The report includes: scope, findings by severity, remediation status, and timeline
  4. Export as PDF for management review or audit evidence