The summary.
STATE WHAT IS OUT OF SCOPE, AND WHY
It is the part of a strategy that protects you afterwards. And agree what severity blocks release before testing, because under pressure the answer shifts.
LEAD REPORTS WITH CAN WE RELEASE, WHAT IS THE RISK, WHAT DO WE NOT KNOW
Test counts and pass rates do not answer the question stakeholders face. Never imply completeness, and never overstate or understate — both destroy credibility.
Record what you reported and when; it is what protects you when a decision is questioned.
TESTING A DEFECTIVE BUILD TAKES FAR LONGER
Because of reporting and retesting cycles. Estimate retesting explicitly, and state the assumptions any estimate rests on.
WITH VENDOR SOFTWARE, FINDINGS BECOME NEGOTIATION RATHER THAN DEFECT REPORTS
Agree acceptance criteria in advance, test data migration above all, and automate checks of your critical paths against their system.
DISABLED TESTS MEAN SOMETHING BROKE AND WAS HIDDEN
Introduce defects deliberately to discover how much of an inherited suite verifies anything at all.
TO INTRODUCE TESTING, WRITE A TEST FOR A DEFECT EVERYONE REMEMBERS
Then require a test with every fix. One flaky test early destroys the argument entirely.