You can export Defender for Cloud recommendations and secure score data as a CSV (see top of the recommendations page). There is an Azure Advisor page based on the same policies, slightly different presentation with CSV export. This does not involve pen testing.
This will reflect cloud configuration vulnerabilities and can be improved by resolving recommendations or excluding those that are not applicable. You might consider converting this to a slide or presentation for your customer.
We also have some free survey-based assessments. https://learn.microsoft.com/en-us/assessments/