# Penetration Test Readiness Checklist

- [ ] Define the security question and success criteria
- [ ] Confirm in-scope domains, applications, IP ranges, cloud accounts, and exclusions
- [ ] Identify system owners and emergency contacts
- [ ] Obtain third-party authorization where needed
- [ ] Prepare test accounts, MFA, VPN, and allow-listing
- [ ] Define communication and escalation channels
- [ ] Confirm testing window and production constraints
- [ ] Agree on report audience and debrief participants
- [ ] Assign remediation owners
- [ ] Schedule the retest path
