Can both teams verify the promised coverage?
For Penetration Testing as a Service, the proposed coverage includes external, internal, web and api, mobile, cloud, wireless, iot and ot, people. The agreement should identify the systems and owners behind each area, the access or telemetry needed, the validation performed during onboarding, and the process for detecting and resolving a silent coverage failure.