Terms and conditions for a penetration testing business

Business-to-business terms for penetration testers and offensive security firms, drafted for a fixed fee of £995 in five working days.

Share

Terms and conditions for a penetration testing business

Business-to-business supplier terms for penetration testers and red teams, covering authorisation, scope and rules of engagement, third-party hosts, disruption and the risk of testing, and evidence, reports, fees and liability. £995, delivered in five working days.

Buy now, £995

A penetration tester is paid to attack a client's systems, which is lawful only with the right authority and safe only within agreed rules. The terms have to make authorisation and scope conditions of starting, set the rules of engagement, allocate the risk of disruption, deal with third-party hosts, and handle the evidence and the report with care. I draft those terms for a fixed fee of £995, delivered in five working days.

Who this is for

Penetration testing, red team and offensive security businesses in England and Wales testing web applications, networks, cloud environments and people for business clients, as a sole tester or a firm. These are business-to-business terms.

What matters in penetration testing terms

Authorisation is a condition, not a formality

Under section 1 of the Computer Misuse Act 1990 accessing a system without the owner's authority is an offence, whatever the intent, and section 3 makes it an offence to impair a system's operation without authority, which is why denial of service testing needs express authorisation. The terms should make written authorisation from the client, identifying every system, address range and application in scope and confirming the client's right to have them tested, a condition of any work starting, and should place on the client the consequences of authorising a test of something it did not own or control.

Scope, rules of engagement and testing windows

The terms should provide that each test is defined by a scope and rules of engagement: what is in and out, the testing window, whether social engineering, denial of service or physical testing are included, what the tester must stop for, and emergency contacts on both sides. Testing outside the scope or window is prohibited on both sides, and the terms should say that findings outside the scope encountered incidentally are reported but not exploited.

Third-party hosts and cloud providers

Systems hosted by cloud and hosting providers are tested under those providers' rules, and the terms should require the client to confirm the provider's policy allows the test and to obtain any consent the provider requires. A test that breaches a provider's terms is the client's breach with the provider, and the terms should say so.

Disruption, damage and the risk of testing

Testing carries an inherent risk of disruption, data corruption or outage, however careful the tester. The terms should say that the client accepts that risk within the agreed rules, that the client is responsible for backups and for scheduling the test to limit impact, and that the tester is liable only where disruption results from a failure to follow the rules of engagement or to exercise reasonable care. The tester must stop and notify the client if damage is suspected.

Evidence, reports, fees and liability

Data and evidence gathered during a test are handled and destroyed as the terms describe, with any personal data processed under the UK GDPR and the Data Protection Act 2018, and reports are confidential to the client for internal, regulatory and audit use, with the tester not named publicly without agreement. Fees are fixed per test, invoiced in advance, with retesting priced separately, and interest and fixed compensation apply to late payment under the Late Payment of Commercial Debts (Interest) Act 1998. Liability should be capped at a figure matching your insurance, with consequential loss excluded, tested for reasonableness under the Unfair Contract Terms Act 1977, and the terms should give no assurance of security beyond the findings reported.

What it costs

Customer or supplier terms and conditions, £995. One set of terms, customer-facing or supplier-facing, drafted for your business. Five working days.

Review of your existing terms, £495. You already have terms and want them checked and brought up to date. Returned marked up with my amendments and an explanation of the changes. Three working days.

Buying online forms the engagement on payment. The scope is what the terms and conditions drafting page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • A full set of bespoke terms drafted for your business, reflecting the legal requirements that apply to your business and sector
  • A note in plain English explaining the terms I have drafted for you
  • Liability, payment, termination and IP provisions that protect your position and are drafted to withstand scrutiny from the other side
  • Guidance on how to incorporate the terms properly
  • Your questions and comments answered by email or phone
  • One round of amendments to finalise the terms ready for use

What is not included

  • Negotiating your terms with individual customers (I am happy to quote for this as an additional service if required)
  • Sector-specific regulatory compliance beyond the contract terms themselves
  • Website privacy notice and cookie compliance, which I quote separately
  • Terms governed by the law of another country
  • Tax advice

Questions I am often asked

Our test took down the client's production server. Are we liable?

If the terms say the client accepts the inherent risk of testing within the agreed rules, is responsible for backups and scheduling, and the tester followed the rules of engagement with reasonable care, the outage is the accepted risk. If the tester went outside the rules, the exposure is the tester's, subject to the cap.

The client authorised a test of an IP range that turned out to belong to someone else. Who is responsible?

The client, if the terms make its authorisation a warranty of its right to have the systems tested and place the consequences of a wrong authorisation on it. Stop the moment ownership is in doubt.

Can the client publish our report to show they are secure?

The terms should limit the report to internal, regulatory and audit use and prohibit public use or naming the tester without agreement. A report is a snapshot of findings, not a certificate.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: September 2026. Email geoffrey@caesar.co.uk.