What the request usually means
Carriers and enterprise clients rarely specify what they want, which is why the request causes so much confusion. Read the question closely. If it asks whether you perform regular penetration testing, it means a scoped test with a report. If it asks about vulnerability scanning, that is a different and cheaper control, and answering one with the other is how questionnaires come back.
The second thing to read is the frequency. Annual is the common ask. Some carriers want a retest after remediation, which changes the engagement you should buy.
The three scopes, and which one they mean
If the questionnaire does not say, external is nearly always the answer. It is also the scope where findings translate most directly into work you can finish before the renewal date.
A scan report is not a test report
Automated scanners are useful, and they belong in an ongoing program. What they produce is a list of things that look wrong, sorted by a severity score, with a meaningful share of it inapplicable to how your systems are actually configured.
A test report says what a person tried, what worked, what that access made possible, and how it was fixed. That difference is the reason a carrier asked in the first place. It is also why anything advertised as costing nothing is almost always a scan with a report template on top.
What should be in the report
- The agreed scope and the dates, written plainly enough that your carrier or client can read it.
- The method, including whether the testers were given credentials or worked blind.
- Findings ranked by what they would actually let an attacker do in your environment, not only by a generic score.
- Evidence for each finding, so remediation is not guesswork.
- Remediation guidance specific to your systems.
- A retest option, so you can show the finding was closed rather than only acknowledged.
How the engagement runs here
A test is scoped against a defined target, run against agreed rules of engagement and a window that does not take production down, then written up with an optional retest. It sits under Cybersecurity & MSSP rather than being sold as a product on its own, because a finding you cannot fix is not worth much.
If the honest situation is that nobody has looked at the environment yet, a test is the wrong first step. An IT assessment costs less and tells you where you stand. Then test the perimeter once the obvious gaps are closed, so you are paying for depth rather than for a list you already knew.