PTaaS engagement lifecycle
How an expert-led engagement runs end to end — scope, staffing, testing, retest, certification and billing.
Crowd-sourced testing gives breadth; an expert-led PTaaS engagement gives scheduled depth with evidence that stands up to review. This document follows an engagement from planning to closure.
1. Planning
- Asset lifecycle setup — the assets in scope are defined, and each is classified and tiered. The same scope definition used by crowd-sourced programs is reused here, so nothing is tested twice by accident and nothing is missed by omission.
- Engagement model — fixed-scope, tiered or subscription. Fixed suits a point-in-time assessment; subscription suits continuous coverage with a named team.
- Rules of engagement — boundaries, prohibited techniques, testing windows and data-handling rules agreed before anyone logs in.
- Success criteria — what the engagement is expected to produce: findings, coverage evidence, a compliance artefact, or all three.
2. Staffing
- Named testers — the engagement staffs to specific people rather than a pool.
- Scheduler and staffing coordination — availability is planned against the engagement window.
- Dedicated tester pools — continuity for organisations that want the same testers each cycle, so environment knowledge accumulates. This is Enterprise-tier.
- Expert gates — each tester must hold the expert role, be covered by the organisation's entitlement, and accept the engagement invitation before receiving any access. See Identity and access.
3. Access and confidentiality
- NDA acceptance is recorded per tester with a timestamp.
- Credential locker distributes testing credentials under control, scoped to the engagement.
- VPN access is provisioned where internal systems must be reached, and revoked when the window closes.
- Access expiry is a property of the engagement, not a manual step someone has to remember.
4. Testing
Testing combines black-box and white-box work depending on what the engagement needs:
- External and internal network testing within the agreed scope.
- Application and API testing against documented business flows.
- Source code review where a repository is in scope, so white-box depth complements black-box findings.
- CI integration so offensive security activity can be triggered and evidenced from the delivery pipeline.
- Risk scoring and attack paths to prioritise by realistic exploitability rather than raw severity alone.
Progress and collaboration happen in-platform: testers, program owners and engineering share the same record, with realtime chat and notifications rather than email threads.
5. Reporting
Output is structured rather than a slide deck:
- Findings with severity, affected assets, reproduction, evidence and remediation guidance.
- Compliance report exports formatted for the obligation in question.
- Delta and regression reporting between cycles — new, resolved, recurring and carried-over findings. See Remediation and verification.
6. Retest and certification
- Retest confirms that a fix closes the finding, within the engagement scope.
- Certification produces an attestation artefact for stakeholders and auditors, tied to the engagement record rather than assembled by hand afterwards.
- Recertification on a subscription keeps the attestation current instead of expiring annually.
7. Billing and metering
- Usage metering tracks consumed effort transparently during the engagement, visible to both sides.
- Billing models — fixed, tiered or subscription, with invoicing generated from the metering and engagement records.
- Overage follows pre-agreed thresholds and rates, so exceeding a tier does not become a billing dispute.
8. Closure
An engagement closes with a defined set of outputs recorded on the same platform record: findings and their remediation state, the retest result, the certification artefact where applicable, the metered effort, and the invoice. Nothing about the engagement exists only in a document that someone has to find later.
Availability and limits
- Engagement creation, scoped assets, rules of engagement, invitations, NDA tracking, retest and reporting are available wherever PTaaS is licensed.
- Dedicated tester pools, SLA response guarantees and custom severity scoring are Enterprise-tier.
- VPN access, source code review, retesting, compliance exports and CI integration are Professional-tier.
- The platform provides structure and evidence for an engagement. The assurance it produces is bounded by the scope that was agreed.
Related docs
- Scope and rules of engagement — how scope and boundaries are modelled
- Remediation and verification — retest, proof of fix and deltas
- Financial operations — metering, budgets and invoicing
- Integrations — where findings land for engineering