Program & Compliance

Compliance-Driven Testing

Penetration testing scoped and reported specifically to satisfy what your auditor, customer, or regulator asks for — mapped to the standard, not a generic report you have to translate yourself.

Compliance-ready penetration test report being prepared
Standards

What Each Standard Requires

SOC 2

No fixed methodology, but auditors expect evidence of regular penetration testing under the Security Trust Services Criteria. We map findings to the relevant criteria and provide an attestation-ready letter on request.

ISO 27001

Annex A control A.8.8 (technical vulnerabilities) and A.8.29 (security testing) call for regular testing. Findings are mapped to affected controls in your Statement of Applicability.

PCI DSS

Requirement 11.4 mandates penetration testing at least annually and after significant changes, covering both the network and application layer of the cardholder data environment, plus segmentation testing.

HIPAA

The Security Rule's risk analysis requirement is commonly supported with penetration testing of systems handling electronic protected health information (ePHI). Findings are mapped to the relevant safeguards.

GDPR

Article 32 requires "regular testing, assessing, and evaluating" of technical security measures for systems processing personal data of EU residents.

Not Listed Here?

We've scoped tests against other frameworks too (e.g. FedRAMP, NIST CSF alignment). Tell us your requirement and we'll confirm we can map to it.

Deliverables

Auditor-Ready Reporting

Control Mapping

Every finding tied to the specific control or requirement it affects.

Attestation Letter

A summary letter confirming testing occurred, on the letterhead your auditor expects.

Retest Evidence

Documented proof that findings were remediated, for closure evidence.

FAQ

Compliance Testing Questions

Not sure which standard applies to us?

That's normal — tell us what your customers, investors, or regulator are asking for and we'll help you figure out the right scope on the call.

How often is testing required?

Most standards call for at least annual testing, plus after any significant infrastructure or application change. We'll confirm the exact cadence for your framework.

Can you provide an attestation letter for our auditor?

Yes, a summary attestation letter is available alongside the full technical report on request.

Get an Audit-Ready Penetration Test

Tell us your compliance requirement and we'll scope accordingly.