← Trust package
CyberGrid · Procurement Template 04

Statement of Work — Penetration Test

SoW for a single web-application penetration test under the Master Services Agreement.
SoW number
SoW-[####]
Effective date
[Effective Date]
Underlying MSA
Master Services Agreement dated [MSA Date]
Engagement type
Penetration Test · Web application
Fixed fee
USD $4,999 (initial engagement) · USD $1,999 (retest)

This Statement of Work ("SoW") is governed by the Master Services Agreement (the "MSA") between CyberGrid ("Provider") and [Customer Legal Name] ("Customer") dated [MSA Date]. In the event of conflict between this SoW and the MSA, this SoW controls solely with respect to this engagement.

1. Engagement summary

EngagementWeb application penetration test
Target(s)[https://app.example.com] (production / staging — see Section 3)
Lead testerCyberGrid Senior Engineer
MethodologyOWASP WSTG v4.2 · OWASP ASVS v4.0.3 · PTES · MITRE ATT&CK · CVSS v3.1
Scheduled start[YYYY-MM-DD]
Scheduled end[YYYY-MM-DD]
Duration5–10 business days (testing) + 2–3 business days (reporting)
Total fixed feeUSD $4,999 (engagement) · USD $1,999 (retest, optional, scheduled separately within 12 months)

2. In scope

3. Out of scope (unless explicitly added below)

Items added to scope: [none / list]. Items explicitly excluded that would otherwise be in scope: [none / list].

4. Testing approach

Approach. Grey-box. Customer provides test-tier credentials (at minimum: one standard user, one administrative user) and any internal documentation needed to understand the application's intended behavior. Provider may also test from an unauthenticated perspective for parts of the surface area.

Testing window. Testing performed during the scheduled period, Monday–Friday, 09:00–18:00 [Customer time zone]. Outside-hours testing only by mutual agreement.

Profile. Non-destructive. No test will intentionally cause data loss, account deletion, or service disruption. If a test technique carries any risk of disruption, Provider will pause and confirm with Customer before executing.

Rate limits. Default ceiling of 50 requests per second per host. Lower limits may be agreed in writing.

Source IP(s). Provider will share a list of source IP ranges before kickoff so Customer may allow them through any WAF, IDS, or rate limiter.

5. Rules of engagement

6. Deliverables

7. Customer responsibilities

8. Fees, billing, and payment

Initial engagement. USD $4,999, fixed fee, invoiced upon execution of this SoW; due net thirty (30) days.

Retest (optional). USD $1,999, fixed fee, scheduled separately within twelve (12) months of final report delivery. Retest covers re-testing every finding from this engagement, marking each as fixed / partial / not fixed, issuing a remediation addendum to the original report, and updating the public attestation.

Out-of-scope changes. Any expansion of scope requires a written amendment to this SoW and may incur additional fees, quoted in advance.

9. Retest policy

Customer may schedule a retest at any time within twelve (12) months of final report delivery for the flat fee of USD $1,999. The retest covers re-testing of each finding identified in this engagement. New findings discovered during the retest will be reported but are not within the scope of remediation; if Customer wishes a full new engagement, a new SoW is required.

10. Confidentiality & data handling

All Customer data observed during this engagement is Confidential Information under the MSA / NDA between the Parties. Test data is deleted from Provider's systems within thirty (30) days of final report delivery, except for the report itself and the attestation, which Customer retains.

11. Term

This SoW is effective upon execution by both Parties and terminates upon delivery of the final report (or earlier if the engagement is cancelled per the MSA). Section 9 (Retest policy) survives termination for 12 months.

IN WITNESS WHEREOF, the Parties have executed this Statement of Work as of the Effective Date.

CyberGrid (Provider)
CyberGrid
Name:[Authorized Signatory]
Title:[Title]
Date:[Date]
Customer
[Customer Legal Name]
Name:[Name]
Title:[Title]
Date:[Date]
CyberGrid · Statement of Work · Template v1.0thecybergrid.com/trust-package