Pentesting for the framework your auditor is asking about.
One evergreen guide per major framework: what auditors expect, what "in scope" actually means, and what evidence to have on hand before the audit window opens.
Which report do I need?
Pick your framework and we'll show the scope and cadence auditors expect.
Written by the people running the engagements.
No filler. Each guide is designed to answer the questions we actually get asked on scoping calls.
Pentesting for SOC 2 Type II
What auditors expect in the scope of your trust services criteria, why the retest matters, and the six artifacts a Type II auditor is going to ask for.
Pentesting for ISO 27001
How to map pentest findings to Annex A controls, what the "significant change" clause actually requires, and how to plan cadence around your surveillance audit.
Pentesting for PCI DSS 4.0
Requirement 11.4 unpacked: segmentation testing, internal vs external scope, cardholder data environment boundaries, and QSA-ready evidence.
Pentesting for HIPAA Security Rule
How pentest findings feed into the risk analysis, framing against the administrative/physical/technical safeguards, and Business Associate Agreement basics.
Cloud services testing for ISO 27017 / 27018
Cloud-specific control coverage: shared responsibility framing, tenant isolation testing, and PII protection controls for cloud service providers.
Threat-led penetration testing for DORA
What the EU Digital Operational Resilience Act requires of financial entities: TLPT scope, tester independence, and reporting obligations.
Not sure which framework applies?
Start the scoping form. It asks which frameworks you're prepping for and quotes accordingly.
