Practical resource / 15 September 2026

Continuous Testing Program Planner

Connect testing priorities, remediation ownership and agreed revalidation. Includes a tracker for the evidence behind each security improvement.

Fillable PDF · Type straight into it · No email required

Use this planner to tie each test to a decision, an owner and evidence that a fix worked. Fill it in with the people who commission testing and the people who fix what it finds.

Use internal reference IDs here. Keep findings and evidence in your approved records.

Set the objective

By the next review, we need evidence to decide __________.

Planning fieldYour notes
Program owner and decision-makers
Next review date
Changes or decisions that need evidence
Systems proposed for coverage, and exclusions
Remediation owners and their capacity

Sequence the work

Add one row per proposed test, and only when it has an owner and a reason. Windows are indicative, not agreed dates.

Decision or questionTest and boundaryWindowOwnerRetest agreed

Before confirming the order, check whether a release makes an earlier result less relevant, and whether open findings should be fixed before similar work is repeated.

Track each improvement

Evidence fieldYour notes
Reference and tested boundary
What testing found, and when
Change made, and who owns it
Retest scope and date, or not agreed
Status: open, fixed but not retested, or retested

A closed ticket does not show that the attack path has changed. A retest confirms only what it exercised.

A program does not need every service. Targeted penetration testing answers questions about a defined system. Adversary simulation examines attacker reach and response across a scenario. CAOS (Continuous Adversary Operations Service) runs recurring, human-led red team operations, and an annual program rotates testing across twelve months.