SecureBlockLog inStart a pentest
ISO 27001

ISO 27001 compliance testing. Evidence your auditor can act on.

We scope the penetration test to your ISMS boundary, map every finding to Annex A controls, and deliver an audit-ready evidence pack — so you go into certification with confirmed fixes, not open issues.

See a sample report
Annex A control mapping on every findingAudit-ready evidence pack includedFree retest within 90 days
What we do

Built for your certification cycle.

Every part of the engagement is designed to produce evidence your auditor expects — not a generic pentest report that you then have to translate.

ISMS-scoped technical testing

We start from your Statement of Applicability and asset inventory. Every test is constrained to your declared ISMS boundary — no findings outside the scope your auditor will review, no wasted effort on out-of-scope systems.

Annex A control mapping

Every finding in the report is cross-referenced to the relevant ISO 27001:2022 Annex A control. Your auditor gets a direct mapping between technical issues and the controls they are evaluating — without you having to build it.

Audit-ready evidence pack

Alongside the technical report you receive an ISO 27001 evidence pack — scoped to your certification body's requirements. Scope statement, methodology, CVSS-scored findings, Annex A references, and a signed retest certificate.

Free retest before your audit window

Once you've remediated findings, we retest and issue a closure certificate within your 90-day retest window — so you go into the audit with confirmed fixes, not open findings.

How it works

From scoping call to signed evidence pack.

Four steps. Fixed price agreed before we start. Report and evidence pack delivered within five business days of testing completion.

1
Scoping call

We review your Statement of Applicability, ISMS boundary, and asset inventory together. The scoping form outputs an exact quote — no surprises at invoice time.

2
Technical testing

Manual penetration testing of all assets within your ISMS scope: web apps, APIs, network perimeter, cloud environments, or internal infrastructure — led by OSCP or CREST certified testers.

3
Report and control mapping

Every finding written up with CVSS score, proof of concept, remediation guidance, and the Annex A control it relates to. Delivered within five business days of testing completion.

4
Evidence pack delivery

ISO 27001 evidence pack assembled and named for your certification body — ready to attach to your audit submission without reformatting or additional work from your team.

What's included

No add-ons. No premium evidence tier.

ISMS-scoped penetration test
Annex A control cross-references on every finding
Executive summary for management review
Technical report with CVSS scores
ISO 27001 evidence pack
Remediation guidance per finding
Free retest within 90 days
Retest closure certificate
Named lead tester across your audit cycle
Mutual NDA before scoping
Sample findings

The kind of issues we surface — and how they map.

Every finding includes the Annex A control reference alongside the technical detail. Titles and targets anonymised from real engagements.

criticalCVSS 9.1SB-ISO-001
Privilege escalation from user to administrator via API endpoint
app.acme.com/api/v2/admin/usersDay 2
Remediation — Enforce server-side role checks on all administrative endpoints. Annex A reference: A.5.15 Access Control, A.8.2 Privileged Access Rights.
highCVSS 7.8SB-ISO-002
Outdated TLS 1.0 accepted on customer-facing endpoints
api.acme.com:443Day 1
Remediation — Disable TLS 1.0 and 1.1, enforce TLS 1.2 minimum. Annex A reference: A.8.8 Management of Technical Vulnerabilities.
mediumCVSS 5.4SB-ISO-003
Internal admin panel reachable without MFA requirement
admin.internal.acme.comDay 3
Remediation — Enforce MFA for all administrative access. Annex A reference: A.8.2 Privileged Access Rights, A.5.17 Authentication Information.
FAQ

ISO 27001 compliance testing.

Questions we get on every scoping call for certification and surveillance engagements.

Not in so many words, but Annex A.8.8 (Management of Technical Vulnerabilities) requires a systematic process for identifying and evaluating technical vulnerabilities — and certification bodies treat penetration testing as the primary evidence. In practice, your auditor will ask for it.

Know where you stand before your auditor does.