We scope the penetration test to your ISMS boundary, map every finding to Annex A controls, and deliver an audit-ready evidence pack — so you go into certification with confirmed fixes, not open issues.
Every part of the engagement is designed to produce evidence your auditor expects — not a generic pentest report that you then have to translate.
We start from your Statement of Applicability and asset inventory. Every test is constrained to your declared ISMS boundary — no findings outside the scope your auditor will review, no wasted effort on out-of-scope systems.
Every finding in the report is cross-referenced to the relevant ISO 27001:2022 Annex A control. Your auditor gets a direct mapping between technical issues and the controls they are evaluating — without you having to build it.
Alongside the technical report you receive an ISO 27001 evidence pack — scoped to your certification body's requirements. Scope statement, methodology, CVSS-scored findings, Annex A references, and a signed retest certificate.
Once you've remediated findings, we retest and issue a closure certificate within your 90-day retest window — so you go into the audit with confirmed fixes, not open findings.
Four steps. Fixed price agreed before we start. Report and evidence pack delivered within five business days of testing completion.
We review your Statement of Applicability, ISMS boundary, and asset inventory together. The scoping form outputs an exact quote — no surprises at invoice time.
Manual penetration testing of all assets within your ISMS scope: web apps, APIs, network perimeter, cloud environments, or internal infrastructure — led by OSCP or CREST certified testers.
Every finding written up with CVSS score, proof of concept, remediation guidance, and the Annex A control it relates to. Delivered within five business days of testing completion.
ISO 27001 evidence pack assembled and named for your certification body — ready to attach to your audit submission without reformatting or additional work from your team.
Every finding includes the Annex A control reference alongside the technical detail. Titles and targets anonymised from real engagements.
Questions we get on every scoping call for certification and surveillance engagements.