Can I share the report with auditors or customers?

Yes. Reports are your property and you decide who has access. Through the Security Reporter platform, you can easily give other stakeholders such as auditors, customers or investors access to your assessment.

Sharing access through Security Reporter

As a Client Lead account holder, you can independently add other stakeholders to your assessment within the Security Reporter platform. This functionality is designed for situations where external parties need access, such as:

  • External auditors and certifying bodies. For ISO 27001, NIS2, DORA or DigiD audits where evidence of technical security testing is required.
  • Customers and enterprise buyers. As part of Third Party Risk Management (TPRM) processes where your customers require demonstrable security of your services.
  • Supervisory authorities. For reporting obligations to DNB, AFM, Dutch Data Protection Authority, Logius or other sector-specific regulators.
  • Investors and due diligence teams. During mergers, acquisitions, investment rounds or technical due diligence.
  • Insurers. Cyber insurers frequently request recent pentest reports during application or renewal.
  • Supply chain partners. If you supply NIS2-covered organizations, your security may become part of their compliance accountability.

Export formats for external distribution

For parties that do not receive a Security Reporter account, you can export the report:

  • PDF export. Most commonly used format. Static, printable and directly shareable. Contains management summary and compliance mapping.
  • CSV export of findings. For GRC tools, ticketing systems or import into internal compliance systems.

What to share (or not)

Although you may share the full report, some practical considerations apply:

  • Full report. For auditors, supervisory authorities and internal stakeholders needing complete technical depth.
  • Management summary report. For customers, investors or partners needing only high-level assurance. This compact version conveys the overall risk picture without detailed exploitation information.

Sharing with other pentest providers

Some customers request a "second opinion" pentest by another provider. You may share our report in that case as well. We do not view this as competition but as sound security practice. Our reports are transparent enough for a second party to validate them.

Learn more about report formats? See the FAQ on sample report via demo. Contact us for a management summary report or questions about access management.