Testing
What a retest letter has to contain to be worth having
A retest is the second half of the evidence, and the letter is what carries it. Most of the ones that get queried are queried for the same few omissions, all of which are easier to ask for upfront than to reconstruct months later.
Facts checked — 2026-09-11
What gets a retest letter queried?
Each finding, identified the way the original report identified it. If the retest letter numbers findings differently from the report it refers to, whoever is reconciling the two documents has to guess, and a reviewer who has to guess asks a question instead.
The outcome per finding, stated individually — closed, partially remediated, or still open. A letter concluding that "the issues have been addressed" without going finding by finding is an assertion rather than a result, and it invites exactly the scrutiny it was meant to close.
The date the retesting happened, and by whom. This is what makes the letter evidence rather than correspondence: a reader needs to know the retest followed the remediation, and that the same firm or a named tester performed it.
And what was not retested, with the reason. Findings accepted as risks, deferred with an owner and a date, or out of scope for the retest — say so. An omission that goes unexplained reads as an oversight; the same omission stated plainly reads as a decision.
The bottom line
Ask for the letter to be finding-by-finding and dated when you commission the retest, not when someone queries it. Reconstructing which finding a general reassurance referred to is considerably harder six months on.
Related services
Vulnerability Assessment and Penetration Testing (VAPT)
Find what an attacker would find, ranked by what it would actually cost you — and get a report your auditor and your engineers can both use.
ISO/IEC 27001 — Information Security Management
Build an information security management system that survives Stage 2 — and the three years of surveillance that follow.
Related insights
Technical testing
The OWASP Testing Guide, and how to tell a real penetration test from a scan
Two tests can cost the same and cover entirely different ground. The methodology is how you tell, and it is checkable before you pay.
Technical testing
NIST SP 800-115: the four phases, and the one that is not a phase
The four-phase shape behind most credible test methodologies — and the phase that is not fourth at all.
Testing
What a CVSS score does and does not tell you about your risk
A shared scale for technical severity — deliberately context-free, which is exactly why it is not your priority order.