Skip to content
AttackVector

Testing that satisfies the auditor and actually finds things

Pick the requirement you need to meet. We will tell you what it asks for, which test answers it, and exactly what evidence you will walk away with.

Requirements

Requirement by requirement

Where a framework does not literally mandate a penetration test, we say so. Testing is still the evidence auditors accept.

PCI DSS

Annually and after significant change

Payment Card Industry Data Security Standard v4.0.1

Annual external and internal penetration testing of the cardholder data environment, plus segmentation testing.

Recommended services

What it requires

Requirement 11.4 calls for external and internal penetration testing at least once every 12 months and after significant changes, following a documented methodology, with exploitable findings corrected and retested. Where segmentation isolates the cardholder data environment, segmentation controls must be tested at least every 12 months, or every six months for service providers.

PCI DSS v4.0.1, Requirements 11.4.1 to 11.4.7

Evidence we provide

  • Report following a documented, industry-accepted methodology
  • Segmentation testing results with proof of isolation
  • Retest confirmation of corrected findings
  • Attestation letter for your QSA or SAQ

HIPAA

Periodic, in practice annually

HIPAA Security Rule

Risk analysis and periodic technical evaluation of safeguards protecting electronic protected health information.

Recommended services

What it requires

The Security Rule requires an accurate and thorough risk analysis and a periodic technical and non-technical evaluation of safeguards. It does not name penetration testing explicitly, but HHS guidance and OCR audits treat independent testing as strong evidence that the evaluation was performed and that vulnerabilities were identified and addressed.

45 CFR 164.308(a)(1)(ii)(A) and 164.308(a)(8)

Evidence we provide

  • Findings mapped to the safeguards they affect
  • Risk-ranked remediation roadmap suitable for the risk analysis record
  • Executive summary for compliance and privacy officers
  • Attestation letter

SOC 2

Annually, within the examination period

SOC 2 Trust Services Criteria

Evidence that vulnerabilities are identified, evaluated, and remediated as part of monitoring and risk mitigation.

Recommended services

What it requires

The criteria require the entity to identify, evaluate, and respond to vulnerabilities and to monitor system components for anomalies. A penetration test is not literally mandated, but auditors almost universally request a recent independent test and evidence that findings were remediated as part of a Type II examination.

Trust Services Criteria CC4.1, CC7.1, and CC7.2

Evidence we provide

  • Independent test report dated within the audit period
  • Remediation and retest evidence for open findings
  • Coverage statement for in-scope systems
  • Attestation letter your auditor can reference

ISO 27001

Annually and on significant change

ISO/IEC 27001:2022

Technical vulnerability management and security testing controls in Annex A.

Recommended services

What it requires

Annex A requires information about technical vulnerabilities to be obtained and evaluated with appropriate measures taken, and security testing processes to be defined and implemented in the development lifecycle. Independent penetration testing is the common way organizations demonstrate both controls to certification auditors.

ISO/IEC 27001:2022 Annex A 8.8 and A 8.29

Evidence we provide

  • Findings mapped to Annex A controls
  • Evidence of evaluation and treatment for the risk register
  • Retest results closing the loop
  • Attestation letter

Cyber insurance

Annually, ahead of renewal

Cyber insurance underwriting and renewal

Underwriters increasingly ask for recent independent testing alongside MFA, EDR, and backup controls.

Recommended services

What it requires

There is no single standard. Renewal questionnaires commonly ask whether an external penetration test was performed in the last 12 months, whether critical findings were remediated, and whether phishing resilience is measured. Answering yes with evidence affects both eligibility and premium.

Carrier-specific application and renewal questionnaires

Evidence we provide

  • Dated external test report and attestation letter
  • Remediation confirmation for critical and high findings
  • Phishing campaign results by team
  • Summary suitable for attaching to the application

CMMC

Periodic, in practice annually

CMMC Level 2 and NIST SP 800-171

Vulnerability scanning and periodic assessment of security controls for defense contractors handling CUI.

Recommended services

What it requires

Level 2 aligns to NIST SP 800-171, which requires scanning for vulnerabilities in systems and applications periodically and when new vulnerabilities are identified, and periodic assessment of security controls to determine they are effective. Independent penetration testing provides the effectiveness evidence assessors look for.

NIST SP 800-171 Rev. 2, 3.11.2 and 3.12.1

Evidence we provide

  • Findings mapped to NIST SP 800-171 practices
  • Evidence of control effectiveness testing
  • Plan of action inputs for open items
  • Attestation letter

NYDFS

Annually

NYDFS Cybersecurity Regulation, 23 NYCRR Part 500

Annual penetration testing and regular vulnerability assessments for covered financial services entities.

Recommended services

What it requires

Covered entities must conduct penetration testing of their information systems from inside and outside the boundaries by a qualified party at least annually, along with automated scans and manual reviews at a frequency set by the risk assessment. Results feed the annual certification of compliance.

23 NYCRR 500.5(a)

Evidence we provide

  • Internal and external test reports from a qualified independent party
  • Documented methodology and scope
  • Remediation and retest evidence
  • Attestation letter for the annual certification file

Mapping

Which service answers which requirement

RequirementExternal penetration testInternal penetration testWeb application testAI and LLM application testCloud penetration testSocial engineering testRed team operationContinuous Threat Exposure Management
PCI DSSNot typically requiredNot typically requiredNot typically requiredNot typically required
HIPAANot typically requiredNot typically requiredNot typically requiredNot typically required
SOC 2Not typically requiredNot typically requiredNot typically requiredNot typically required
ISO 27001Not typically requiredNot typically requiredNot typically requiredNot typically required
Cyber insuranceNot typically requiredNot typically requiredNot typically requiredNot typically requiredNot typically required
CMMCNot typically requiredNot typically requiredNot typically requiredNot typically requiredNot typically required
NYDFSNot typically requiredNot typically requiredNot typically requiredNot typically requiredNot typically required

How it works

Compliance testing in three steps

  1. Scope to the requirement

    We map your in-scope systems to the clause you need to satisfy and agree on dates that leave room for remediation before the audit.

  2. Test and remediate

    The engagement runs like any of our tests: manual, evidence-based, and ranked by impact. Your team fixes, we retest.

  3. Deliver the evidence pack

    Report, attestation letter, retest confirmation, and a coverage statement, packaged for your auditor, insurer, or customer.

FAQ

Common questions

Ask about your audit
Do you provide an attestation letter?

Yes. Every penetration test includes an attestation letter that states the scope, dates, methodology, and remediation status. It is written for auditors, customers, and insurers who need confirmation without the full technical report.

Can you test segmentation for PCI DSS?

Yes. Segmentation testing is included in internal penetration tests for cardholder data environments and reported with proof that the controls isolate the environment as intended.

How fast can we start before an audit?

Scoping usually takes a few days and testing typically starts within two weeks. Tell us the audit date and we will plan testing, remediation time, and retest around it.

Will the report satisfy our cyber insurer?

Insurers ask for a recent external test and evidence that critical findings were fixed. Our attestation letter and retest confirmation answer both questions directly.

Do you retest after we fix things?

Yes. One retest of remediated findings is included with every test, and the report and attestation are updated to reflect the closed items.

Have an audit date on the calendar?

Tell us the framework and the deadline. We will scope the test to the requirement and plan remediation and retest so the evidence is ready in time.