Release 9 Oktober 2026
The October release introduces two major additions to PentestPortal: the new Letter of Attestation, allowing customers to generate a concise and shareable pentest statement, and support for BIO 2 alongside existing BIO classifications.
We’ve also expanded the API for assessment and finding management, improved retest reporting, added source-code requests to kick-off emails, and introduced several smaller workflow improvements. As usual, the release also includes fixes across search, Cyber Scans, planning, email invitations, and reseller workflows.
Features & Improvements
PP-762: Letter of Attestation / Pentest Statement - Major Feature
PentestPortal can now generate a Letter of Attestation (LoA) for completed pentests.
Customers are increasingly asked to provide external parties - such as suppliers, investors, auditors, or procurement teams - with confirmation that a penetration test has been performed. Until now, these statements often had to be created manually. The new Letter of Attestation provides a concise, shareable PDF without exposing the full technical pentest report.
The statement can include information such as:
The number of findings per risk classification
The status of findings, such as resolved, accepted, or planned
Assessment information relevant to the attestation
The date on which the Letter of Attestation was first generated
Sensitive technical information such as vulnerability details, endpoints, hostnames, IP ranges, screenshots, evidence, etc. are intentionally excluded. For retests, the Letter of Attestation reflects the retest findings instead of the original findings.
The Letter of Attestation follows the reseller's existing reporting style and can also be customized through report styling.
PentestPortal customers who want to use the LoA as part of their own customer-facing proposition can further tailor the styling to their brand. If assistance is needed, PentestPortal Support can be contacted directly through the chatbox.
PP-776: BIO2 Support - Major Feature
PentestPortal now supports BIO2, allowing findings to be linked to the latest Baseline Information Security Government framework.
BIO versioning is now handled at pentest level, similar to the way other security standards are managed in PentestPortal.
The portal distinguishes between:
BIO 1, v1.04
BIO 2, v1.3
New pentests can only use the latest BIO version, while existing pentests continue to use the version with which they were originally created. The BIO version used is also displayed alongside the related finding information and configuration. BIO measures are available throughout the relevant workflows, including finding classification, risk templates, the portal, and pentest reports.
When an existing pentest needs to be migrated from BIO 1 to BIO 2, this can be done by disabling and re-enabling BIO for the assessment. Existing BIO 1 mappings are removed so that the appropriate BIO 2 measures can subsequently be assigned.
PP-777: Findings and assessments API expansion
The PentestPortal API has been expanded with additional endpoints for managing findings and assessments. The API documentation now includes CRUD operations for:
Risks / findings
Assessments
Targets
This makes it possible to create and manage findings through external integrations and opens up additional options for automating pentest workflows.
PP-774: Retest reports now retain additional report information
Retest reports now automatically carry over relevant information from the original pentest report. This includes now also:
Version numbers
Reviewers
IP information
PP-772: Optional source code request in kick-off emails
Kick-off emails for web application pentests can now optionally request access to the application's source code. When selected, PentestPortal adds an additional item under the Requirements section of the kick-off email explaining that read-only source-code access can provide additional value during the assessment.
Source-code access remains optional, but can help pentesters trace findings to specific code, rule out false positives, and provide more targeted remediation advice.
PP-781: File timestamps
The Files tab within a pentest now displays the time alongside the existing file date. This makes it easier to distinguish files that were uploaded or modified multiple times on the same day.
PP-556: “Open My Pentest” button on the dashboard
A new Open My Pentest action has been added to the planning dashboard. Alongside the existing Scroll to Today functionality, pentesters can now navigate directly to their pentest for the current day and automatically open the corresponding assessment.
Bug Fixes
PP-778: Customer contact invitation displayed “[TEXT NOT FOUND]” - Fixed an issue where customer-contact invitation emails could contain missing translation text instead of the expected invitation content.
PP-775: Typo in Dutch invoice model - Corrected a spelling error in the Dutch invoice template.
PP-779: Special and template-like characters caused errors - Improved handling of special characters and template-like input in the public contact form. Input such as HTML-like characters and template syntax no longer causes unexpected processing errors.
PP-780: Search could return a 500 error when entering an opening parenthesis - Entering characters such as "
(" in the portal search field no longer results in a server error.PP-769: Prevent cyber scans of top-level/public-suffix domains - Cyber Scans can no longer be started against domains such as
co.uk. This prevents users from unintentionally initiating scans against an excessively broad domain scope.PP-768: Interface remained stuck after removing a leave day - Fixed an issue where the frontend could remain in a loading state after deleting an absence or leave day.
PP-767: Incorrect kick-off status for pentests from other resellers - Fixed an issue where the kick-off column could incorrectly appear red for assessments belonging to resellers, even when the corresponding quality requirement had been approved. The status now uses the appropriate kick-off validator rather than relying solely on editable text. Please note that this issue is only relevant for multi-reseller instances. Regular PentestPortal users did not have this issue.
We believe that PentestPortal will greatly enhance the experience of individual penetration testers, penetration testing firms and enterprises conducting their own pentests and that PentestPortal contributes to more efficient and effective penetration testing. Your feedback is invaluable in helping us improve and tailor the software to meet your needs.
Thank you for choosing our software, and we look forward to hearing your thoughts on this exciting new release!