
Pentesting Frameworks: OWASP & NIST Guide
Learn how OWASP WSTG and NIST SP 800-115 shape professional penetration testing. Compare their scope, use, and how they work together.
The OWASP Testing Guide and NIST SP 800-115 are the two standards that most often shape how a professional penetration test is scoped, executed, and reported. This guide explains what each document is, how they differ, how they work together on one engagement, and how to check that a provider is using them rather than namechecking them.
A pentesting framework is a structured methodology that defines how penetration testing is scoped, executed, and reported. Frameworks exist so testers apply the same categories of work in a consistent, repeatable, and comprehensive way instead of relying on ad-hoc hunting.
This page focuses on the OWASP Testing Guide (WSTG) and NIST SP 800-115. Other documents such as PTES and OSSTMM exist, but they sit outside the primary scope here. A framework is the structure. A methodology is how a provider applies that structure to your assets, constraints, and risk.
Frameworks are necessary but not sufficient. They define what should be considered for testing. They do not automatically produce a high-quality test. A provider can follow a framework poorly, so adherence must be judged alongside scoping discipline, exploitation judgement, and reporting quality.
| Attribute | OWASP Testing Guide (WSTG) | NIST SP 800-115 |
|---|---|---|
| Primary focus | Web application security test cases | Technical assessment process for networks, systems, and applications |
| Designed for | Structured, deep web testing | Phased end-to-end security testing and assessment |
| Who uses it | Teams testing customer portals, SaaS, and other web apps | Teams assessing broader infrastructure or needing a defensible test process |
| Compliance relationship | Supports evidence of web control testing; not a compliance regime | Gives a defensible assessment structure often referenced in due diligence |
| Typical report | Findings mapped to WSTG categories and web risk themes | Phase-based evidence, test plan traceability, and technical findings |
| When to prioritise | The main asset is a web application | The engagement spans infrastructure, systems, and process evidence |
| Overlap | Supplies web test-case depth NIST does not list | Supplies engagement structure WSTG does not define |
| Best combined use | Attack-phase depth on the web surface | Scoping, discovery, infrastructure attack, and reporting discipline |
What Are Pentesting Frameworks?
A pentesting framework is a structured methodology that defines how penetration testing is scoped, executed, and reported. An ad-hoc test can find interesting issues and still miss whole classes of work. A framework-driven test makes the intended coverage visible, so you can see what was in scope, what was deferred, and why.
The framework is still only a map. Delivery quality is the journey. Frameworks define what should be considered. They do not replace scoping discipline, exploitation judgement, or reporting quality.
This guide focuses on OWASP WSTG and NIST SP 800-115. PTES and OSSTMM exist, but they sit outside the primary scope here.
What Is the OWASP Testing Guide (WSTG)?
The OWASP Testing Guide (WSTG) is a comprehensive framework for testing the security of web applications, published by the Open Worldwide Application Security Project. Use it when you need structured, repeatable, deep web application testing rather than a high-level risk list.
Typical WSTG categories
- Identity management
- Authentication
- Authorisation
- Session management
- Input and data validation
- Error handling, cryptography, business logic, and client-side testing
WSTG is not a flat checklist. A professional engagement uses it to decide which test cases apply and which high-risk categories take priority. A customer portal with complex roles should spend more time on authorisation and session handling than a low-risk brochure page.
If a provider says they test to OWASP, ask whether they mean WSTG test cases or only the Top 10 awareness list. The first is a methodology. The second is a ranking of common issues. Mobile and API work can borrow the same thinking, but WSTG itself is written for web application testing depth.
What Is NIST SP 800-115?
NIST SP 800-115 is the National Institute of Standards and Technology’s technical guide for information security testing and assessment. It is a national-level technical standard for assessing networks, systems, and applications, not a web-only catalogue of test cases.
Four assessment phases
- Planning: scope, rules of engagement, authority, and the test plan.
- Discovery: enumeration of hosts, services, and attack surface.
- Attack: authorised exploitation, privilege escalation, and proof of impact.
- Post-assessment: evidence handling, analysis, and reporting.
The standard still does not prescribe every exploit path. It tells testers how to plan, discover, attack, and close the work. Treating it as a box-ticking certificate is a common misconception.
Do not confuse it with the NIST Cybersecurity Framework (CSF). CSF is a strategic governance model. Only SP 800-115 defines how to run a technical security test. For UK organisations, NIST technical guidance often complements NCSC expectations and GDPR security-testing duties. That is a mapping conversation, not a claim that NIST replaces UK regulation.
How OWASP and NIST Work Together
A professional pentest often blends both frameworks: NIST SP 800-115 defines the overall process, and OWASP WSTG supplies web application testing detail inside those phases. Using both is a sign of maturity, not overcomplication.
| Engagement phase | Framework contribution |
|---|---|
| Planning | NIST owns scope, rules of engagement, and the test plan. WSTG informs which web categories belong in that plan. |
| Discovery | NIST owns network discovery, port and service enumeration, and surface mapping before web cases begin. |
| Attack / testing | WSTG drives web cases such as data validation and session management. NIST covers broader infrastructure exploitation and privilege escalation. |
| Post-assessment | NIST owns evidence and report structure. Web findings are mapped to OWASP categories so developers and auditors can trace the work. |
If this, then that. If you are testing a web application such as an e-commerce site or customer portal, start with OWASP. If you are assessing broader infrastructure with a compliance or due-diligence driver, use NIST SP 800-115 as the reference process.
This is the approach used on client engagements at Pentesting Company: TEST. FIND. FIX. PROTECT. Framework adherence belongs in the methodology of a live service, not only in a proposal sentence. See how that methodology is described on the Penetration Testing Services page.
What a Framework-Aligned Report Should Show
Framework alignment is visible in the report structure, not just the proposal. A namecheck in a quote is not evidence that WSTG or SP 800-115 shaped the work.
- Findings mapped to specific OWASP WSTG categories, such as injection, broken access control, or security misconfiguration.
- Evidence traceable to test cases, not only a scanner export.
- Severity ratings that stay consistent with framework thinking rather than arbitrary labels.
- Remediation prioritisation based on attack-path risk.
A report that claims to be OWASP-aligned but does not show WSTG mapping in the findings is a warning sign. Ask for a sample report that shows the mapping. That is the fastest way to see whether the framework is core delivery or brochure language.
How to Choose the Right Framework
The right framework choice follows your asset type, compliance pressure, risk appetite, and the need to demonstrate due diligence — not a one-line claim that OWASP is for web and NIST is for enterprise.
- If the focus is e-commerce, a customer portal, or SaaS, treat OWASP WSTG as the primary depth layer.
- If the environment is broader infrastructure or a regulated setting such as finance, healthcare, or the public sector, treat NIST SP 800-115 as the primary structure and keep OWASP for web components.
- If a compliance driver exists, ask the provider to map the report to the relevant framework controls and evidence requirements.
- If you must demonstrate due diligence to auditors or a board, NIST gives a defensible structure and OWASP gives testing depth for web surfaces.
UK organisations often need frameworks to sit alongside NCSC expectations and GDPR security responsibilities. A provider that can explain that mapping is supporting a wider compliance picture, not only running a test.
Five Questions to Ask About Frameworks
These questions test whether a provider genuinely follows the frameworks they claim. A strong answer is specific, names categories or phases, and offers evidence. A weak answer is a generic “we use OWASP” line with no mapping.
- Which framework is your methodology based on? Strong: names WSTG, SP 800-115, and how each is used. Warning: “industry best practice” with no document.
- How do you map findings back to OWASP WSTG categories? Strong: category mapping in the findings. Warning: only mentions the Top 10 as a slogan.
- Can you show a sample report with framework mapping? Strong: redacted sample with mapped findings. Warning: cannot produce one. This is the single best procurement test.
- How does your process follow NIST SP 800-115 phases? Strong: walks through planning, discovery, attack, and post-assessment artefacts. Warning: jumps straight to tools.
- How do you decide what is in scope versus out of scope? Strong: explains which WSTG cases and NIST activities apply to your assets. Warning: “we test everything” with no trade-offs.
Watch for providers that claim OWASP alignment but deliver reports with no OWASP categories, no mapped findings, and no test-case traceability. Framework language without that evidence is a checkmark, not a quality control.
The Framework Is the Map, Not the Journey
OWASP WSTG is the web application testing methodology. NIST SP 800-115 is the technical security testing process guide. Together they tell you what to test and how the engagement should run.
Frameworks are necessary but not sufficient. They define structure. The differentiator is the quality of the provider’s judgement. Treat a framework as a quality signal, not a shield or a checkmark on its own.
Talk to a provider who can demonstrate how they apply OWASP and NIST in practice. If you want to see how Pentesting Company applies these frameworks on a real engagement, walk through the methodology and a sample report via the Penetration Testing Services page.
Frequently Asked Questions
What is the difference between OWASP and NIST?
OWASP WSTG is a web application test-case framework. NIST SP 800-115 is a phased technical guide for assessing networks, systems, and applications. They answer different questions: what to test on a web app versus how to run the whole assessment.
Which framework is best for web applications — OWASP or NIST?
OWASP WSTG is the better primary depth layer for web applications. NIST SP 800-115 still helps if you need formal scoping, discovery, and reporting structure around that web work.
Do I need both OWASP and NIST for a pentest?
Not always. Combining them is common on mature engagements because NIST structures the process and OWASP supplies web test cases.
What is the difference between NIST SP 800-115 and the NIST Cybersecurity Framework (CSF)?
SP 800-115 is the technical testing and assessment guide. CSF is the strategic governance model. They are related by brand, not interchangeable as pentest manuals.
Is the OWASP Top 10 the same as the OWASP Testing Guide?
No. The Top 10 ranks common web risks. The Testing Guide is the methodology used to test those and many other issues through defined cases.
Will following a pentesting framework guarantee my application is secure?
No. A framework organises the test. It cannot guarantee that every relevant flaw is found or that identified issues will be fixed. Provider judgement, exploitation quality, and remediation still decide the outcome.
Need a framework-aligned pentest, not a namecheck?
Talk to our London-based team about a legally authorised engagement that applies OWASP WSTG and NIST SP 800-115 in the report, not just the proposal.