Does your attestation letter actually say anything?
A summary letter is the document you hand customers instead of the report. Tick what yours contains and this tells you what it supports, what it does not, and what a reviewer will ask for next.
The report itself contains reproduction steps for unfixed weaknesses in your own product, so you cannot send it to every customer who asks. The attestation or summary letter exists for that: one or two pages saying a test happened, what it covered, and where the findings stand. Some letters do that job. Others confirm only that money changed hands.
Tick what your letter contains and this tells you what it will support in a customer security review and what it will not. The verdict appears on this page. Nothing is emailed anywhere unless you ask for it at the end.
On its way
Check your inbox shortly.
Why the letter carries the weight
A penetration test report describes how to attack your product, in enough detail that somebody could repeat it. Circulating it widely is a poor idea while any finding is open, and most testing agreements restrict sharing it anyway. So the letter becomes the artefact that travels: attached to security questionnaires, filed in vendor management systems, and read by people who will never see the report.
That makes the letter worth negotiating before the engagement rather than after. Ask for it as a named deliverable in the statement of work, and say what it has to contain. Firms that produce a useful one have a template already. The difference between the two documents is set out on penetration test report against attestation letter.
The severity counts question
Teams often resist publishing counts, on the reasoning that four highs looks worse than silence. In a security review the opposite is true. A letter with counts and a closure status reads as a team that tests and fixes. A letter without them reads as a team with something to leave out, and the reviewer asks the question anyway, which now costs an email exchange and some credibility. Counts with closure status are the strongest single thing a short letter can carry.
Common questions
Is an attestation letter the same as an audit opinion?
No, and the word attestation causes real confusion here. A SOC 2 report is an attestation engagement performed by a licensed CPA firm under professional standards. A penetration test letter is a testing firm confirming what it did and what it found. Both are useful and they are not interchangeable, so do not let a vendor form collapse them into one box.
Can we write it ourselves?
You can write a summary of your own testing program, and it is worth having. It is not the same document, because the value of the letter is that an independent party signed it. If the testing firm will not produce one, that is worth knowing before the next engagement rather than during a customer review.
Should the letter name the tester?
A named signer with a role and firm is the useful minimum. Certifications add weight for reviewers who check them. What no letter should do is name an individual who did not do the work, and a reviewer who asks a follow-up question will occasionally find that out.
How long is a letter good for?
Twelve months is the convention and almost no customer states it explicitly. What they do is ask for the most recent test and then notice the date. Anything past a year invites the question of what has changed since, which is a reasonable question and one you should be able to answer.
What if the letter is thin and the engagement is over?
Ask for a revised one. It costs the firm an hour and most will do it, particularly if a retest is still in the window. Ask for the scope named, the dates, the severity counts and the closure status, since those four close most of the gap. Then put the requirement in the next statement of work so it is not a favour the second time.