All articlesFundamentals

Penetration Testing Methodology: PTES, OWASP and NIST

2026-09-28 7 min read

How professional penetration testers structure an engagement using PTES, the OWASP Testing Guide and NIST SP 800-115, from scoping to retest.

Why methodology matters

A documented methodology makes a penetration test repeatable, comparable and defensible. Auditors, QSAs and regulators often ask vendors to describe their methodology, and PCI DSS requirement 11.4.1 explicitly requires one based on industry-accepted approaches.

The main standards

PTES, the Penetration Testing Execution Standard, describes the phases of an engagement from pre-engagement to reporting. The OWASP Web Security Testing Guide gives detailed test cases for web applications, and OWASP MASTG covers mobile. NIST SP 800-115 is a technical guide to information security testing and assessment from the US National Institute of Standards and Technology. Most professional testers combine these.

The phases of an engagement

Pre-engagement: scope, rules of engagement, authorisation and contacts. Intelligence gathering: mapping the attack surface. Threat modelling: identifying what an attacker would target. Vulnerability analysis: finding weaknesses with tools and manual review. Exploitation: safely proving impact. Post-exploitation: understanding what access means for the business. Reporting: CVSS-rated findings, evidence and fixes. Retesting: verifying remediation.

Evaluating a vendor's methodology

Ask which standards they follow, how much of the process is manual, how they test business logic and access control, and how they rate severity. A vendor who can explain each phase clearly is usually one who follows it.

Get started

Ready to find what attackers will?

Talk to a senior pentester. Get a tailored scope, sample report and timeline within 24 hours.