Built on standards.
Executed with precision.

Every CMTA Cyber engagement follows a structured, repeatable methodology aligned to the industry's most recognized frameworks. Our process is designed to satisfy both technical teams and compliance requirements - producing findings that hold up to scrutiny.

Choose your depth.

Every engagement is scoped to the right testing approach for your environment, threat model, and compliance requirements. We will recommend the most appropriate type during scoping.

Black box, gray box, and white box penetration testing comparison Three testing approaches shown side by side with access level indicators and key characteristics Black Box Zero knowledge Access Level None SIMULATES EXTERNAL ATTACKER No credentials, no docs, no source access Real-world attack simulation SOW · RECON Gray Box Partial knowledge Access Level Partial SIMULATES INSIDER THREAT Limited credentials, some architecture docs Most common for web app engagements SOW · RECON · CODE White Box Full knowledge Access Level Full MAXIMUM COVERAGE Source code, architecture, credentials, full access Deepest coverage, code-level findings SOURCE · ARCH · CREDS Attacker perspective Balanced Maximum depth
// PHASE 01
Scoping &
Planning

Define the engagement

We work with your team to define scope, rules of engagement, testing windows, and success criteria before any testing begins. This phase produces the Statement of Work and test plan that governs the entire engagement.

NIST SP 800-115 NIST SP 800-53 SA-11 PTES Pre-Engagement
Statement of Work · Rules of Engagement · Test Plan
// PHASE 02
Reconnaissance &
Discovery

Map the attack surface

Passive and active reconnaissance to enumerate the target environment. Asset discovery, technology fingerprinting, endpoint mapping, and open source intelligence gathering to build a complete picture before active testing begins.

NIST SP 800-115 §3 PTES Intelligence Gathering OWASP WSTG-INFO
Attack Surface Map · Asset Inventory · Technology Stack
// PHASE 03
Vulnerability
Analysis

Identify weaknesses

Systematic vulnerability identification combining AI-assisted automated scanning with manual expert analysis. Every potential finding is verified before escalation - no unvalidated scanner dumps in our reports.

NIST SP 800-115 §4 OWASP WSTG OWASP Top 10 PTES Vulnerability Analysis
Validated Vulnerability List · Risk Ratings · CVE Mapping
// PHASE 04
Exploitation &
Validation

Prove the impact

Controlled exploitation of confirmed vulnerabilities to demonstrate real-world impact. We go beyond identification - we prove what an attacker could actually achieve, including business logic flaws and chained attack scenarios that automated tools miss entirely.

NIST SP 800-115 §5 OWASP WSTG PTES Exploitation PTES Post-Exploitation
Proof-of-Concept · Impact Demonstration · Evidence Package
// PHASE 05
Reporting &
Remediation

Deliver findings that drive action

Every engagement concludes with a structured report containing an executive summary for leadership and detailed technical findings for your engineering team. Findings are mapped to CVSS scores, OWASP categories, and remediation priority. We include a free retest to verify fixes.

NIST SP 800-53 CA-8 NIST SP 800-53 SI-2 OWASP Top 10 PTES Reporting
Executive Summary · Technical Report · Remediation Roadmap · Free Retest

Industry-recognized standards
at every phase.

// NIST
SP 800-115
Technical Guide to Information Security Testing and Assessment. The federal standard for how penetration tests should be planned, executed, and reported.
Used in: Scoping · Execution · Reporting
// NIST
SP 800-53
SA-11 · CA-8 · SI-2
Security and Privacy Controls for Federal Information Systems. SA-11 governs developer security testing, CA-8 mandates penetration testing, SI-2 drives remediation verification.
Used in: SOW · Test Planning · Final Report
// OWASP
Web Security
Testing Guide
The definitive open source guide for web application security testing. Provides step-by-step test cases for every major vulnerability category across authentication, authorization, injection, and more.
Used in: Vulnerability Analysis · Exploitation
// OWASP
Top 10
The industry-standard awareness document for web application security risks. All findings in our reports are mapped to OWASP Top 10 categories for clear communication with development teams.
Used in: Vulnerability Naming · Report Findings
// PTES
Penetration Testing
Execution Standard
A community-driven standard covering the full engagement lifecycle from pre-engagement through reporting. Provides the operational blueprint that structures how our engagements are run end to end.
Used in: All Phases

Standards mapped
to deliverables.

Deliverable Primary Standards Purpose
Sales Proposal / SOW NIST SP 800-115 PTES Pre-Engagement Demonstrates professional execution framework and scope methodology to prospective clients
Technical Test Plan NIST SP 800-53 SA-11 OWASP WSTG Justifies target scoping decisions and maps test cases to recognized vulnerability categories
Vulnerability Report OWASP Top 10 OWASP WSTG PTES Reporting Consistent vulnerability naming and risk ratings that development teams can act on immediately
Executive Summary NIST SP 800-115 PTES Reporting Business-language findings with risk context aligned to how executives evaluate security posture
Final Deliverable Report NIST SP 800-53 CA-8 NIST SP 800-53 SI-2 OWASP Top 10 Full audit checklist verification and remediation prioritization suitable for compliance review
Retest Verification NIST SP 800-53 SI-2 PTES Post-Exploitation Confirms remediation effectiveness against the original proof-of-concept with documented closure

Ready to start an engagement?

Tell us about your environment and we will scope the right test for your risk profile and compliance requirements.

Engage Us View Services