Do you provide a written security report?
Always. Every audit ends with a prioritised written report: each finding rated by severity and exploitability, with reproduction notes, the affected component, and a clear, costed remediation step. Hardening engagements also include a before/after report from the verification re-scan, so you have documented proof every finding was closed, useful for stakeholders, insurers and PCI assessors.