Does ISO 27001 require penetration testing?
ISO 27001 doesn't name "penetration testing" as a mandatory control, but in practice it's how most organisations satisfy the technical vulnerability management requirements (Annex A 8.8 in ISO 27001:2022) and demonstrate that security controls actually work. Auditors routinely ask for recent penetration test reports as evidence — at initial certification and again at annual surveillance audits. If you can't produce one, expect a finding.
Right-sized scope, not a blank cheque
Compliance-driven testing has a bad habit of being either theatre (a rebadged vulnerability scan) or overkill (a quote for three times the testing you need). We scope to what your auditor actually needs to see, based on your statement of applicability and the systems that handle sensitive data — usually a focused web application test, an external network test, or both.
The testing itself is the same manual, senior-led work we bring to every engagement. A compliance driver doesn't mean a compliance-grade test.
Auditor-ready deliverables
- A report formatted for evidence. Methodology, scope, dates, tester credentials, findings with risk ratings and remediation status — everything a certification body looks for.
- An attestation letter. A shareable summary confirming testing was performed, for auditors, enterprise customers and due diligence, without exposing technical detail.
- A free 90-day retest. Fix the findings, get them verified, and close the loop with documented evidence of remediation — the part auditors care about most.
Also covers SOC 2, PCI and customer security reviews
The same engagement structure satisfies SOC 2 Type II penetration testing expectations, PCI DSS requirement 11.4, Essential Eight maturity evidence and the security questionnaires your enterprise customers keep sending. Tell us what you're being asked for and we'll scope to it.
FAQ
Frequently asked questions
Is penetration testing mandatory for ISO 27001?
Not by name, but effectively yes. ISO 27001:2022 Annex A 8.8 requires management of technical vulnerabilities, and certification auditors routinely expect a recent penetration test report as evidence that your controls work. Most organisations test annually to stay audit-ready.
How often does ISO 27001 require a penetration test?
Annual testing is the accepted standard, aligning with the surveillance audit cycle. You should also test after major changes to in-scope systems — a new product, a significant architecture change or a migration.
What scope of penetration test do auditors expect?
It depends on your ISMS scope. For most SaaS companies it's the production web application and the external network perimeter. We review your statement of applicability on the scoping call and recommend the minimum scope that will genuinely satisfy your auditor — and tell you honestly if something isn't needed.
How much does an ISO 27001 penetration test cost?
A typical compliance-scoped engagement (web application plus external perimeter) runs 5–10 testing days, usually between AU$8,000 and AU$16,000. You get a fixed quote within one business day of a scoping call — and the report, attestation letter and 90-day retest are included.
We're mid-audit and need a pentest urgently. How fast can you start?
Tell us your audit date on the scoping call. We're a boutique consultancy with a short chain of command, and we can often schedule compliance-driven engagements faster than larger firms — and we'll be straight with you about what's achievable before you commit.
Will the same test cover SOC 2 and customer security questionnaires?
Yes. One properly-scoped annual penetration test typically satisfies ISO 27001 surveillance audits, SOC 2 Type II expectations and enterprise customer due diligence simultaneously. The attestation letter we provide is written to be shared for exactly these purposes.
Contact
Talk to us
Tell us what you're trying to protect, secure or build. We'll come back with a plan.
Need a pentest your auditor will accept?
Drop your email and we'll come back with a plan within one business day.