# Security Assessment Scope Template

## Business objective
What do we need to learn or validate?

## In scope
- Domains / subdomains:
- IP ranges:
- Applications / APIs:
- Cloud accounts / subscriptions:
- Identity systems:

## Out of scope

## Testing constraints

## Access provided

## Critical assets

## Primary and emergency contacts

## Desired timeline

## Reporting requirements
