SecureBlockLog inStart a pentest
Compliance guides

Pentesting for the framework your auditor is asking about.

One evergreen guide per major framework: what auditors expect, what "in scope" actually means, and what evidence to have on hand before the audit window opens.

Compliance

Which report do I need?

Pick your framework and we'll show the scope and cadence auditors expect.

Required scope
External web app + API in scope of the trust services criteria
Frequency
Annually
Retest
Expected by auditors
Type II auditors ask for evidence that findings were remediated — the free retest covers it.
Guides

Written by the people running the engagements.

No filler. Each guide is designed to answer the questions we actually get asked on scoping calls.

SOC 2

Pentesting for SOC 2 Type II

What auditors expect in the scope of your trust services criteria, why the retest matters, and the six artifacts a Type II auditor is going to ask for.

#Trust Services#Type II#Evidence packs
ISO 27001

Pentesting for ISO 27001

How to map pentest findings to Annex A controls, what the "significant change" clause actually requires, and how to plan cadence around your surveillance audit.

#Annex A#ISMS#Surveillance audits
PCI DSS

Pentesting for PCI DSS 4.0

Requirement 11.4 unpacked: segmentation testing, internal vs external scope, cardholder data environment boundaries, and QSA-ready evidence.

#Req 11.4#CDE#Segmentation
HIPAA

Pentesting for HIPAA Security Rule

How pentest findings feed into the risk analysis, framing against the administrative/physical/technical safeguards, and Business Associate Agreement basics.

#Security Rule#Risk analysis#BAA
ISO 27017 & 27018

Cloud services testing for ISO 27017 / 27018

Cloud-specific control coverage: shared responsibility framing, tenant isolation testing, and PII protection controls for cloud service providers.

#Cloud#PII#CSP
DORA

Threat-led penetration testing for DORA

What the EU Digital Operational Resilience Act requires of financial entities: TLPT scope, tester independence, and reporting obligations.

#EU#Financial#TLPT

Not sure which framework applies?

Start the scoping form. It asks which frameworks you're prepping for and quotes accordingly.