Popular frameworks include OSSTMM, PTES (Penetration Testing Execution Standard), OWASP Testing Guide, and NIST 800-115. What should be included in a penetration testing report? A pentest report should include an executive summary, methodology, findings, risk ratings, technical details, proof of concept, and remediation recommendations.