Skip to content
MD-5

// Compliance Pentest

Penetration Testing for SOC 2, ISO 27001 & PCI DSS

A penetration test scoped and reported the way auditors expect, so it counts as evidence for SOC 2, ISO 27001, PCI DSS and customer security reviews.

Overview

Most compliance frameworks either require or strongly expect independent penetration testing: SOC 2 auditors look for it as evidence of control effectiveness, ISO 27001 expects technical vulnerability management, and PCI DSS explicitly requires it.

A compliance-ready test is the same rigorous testing, scoped against the systems your auditor cares about and documented so the evidence is accepted first time.

Who this is for

  • Startups going through their first SOC 2 Type I or Type II audit
  • Companies certifying to ISO 27001
  • Merchants and service providers with PCI DSS obligations

What gets tested

Aligned to your framework

  • Scope mapped to your in-scope systems and trust boundaries
  • Methodology statement and tester independence documented in the report
  • Remediation retest to show findings were closed

What you receive

  • Full technical report plus an executive summary for auditors
  • Live readout call to walk your team through the results
  • Retest report showing each finding was fixed
  • Letter of attestation you can share with customers and auditors

Standards followed

  • SOC 2
  • ISO/IEC 27001:2022
  • PCI DSS v4.0 (Req. 11.4)
  • OWASP WSTG
  • PTES

Read the full testing methodology.

// Process

How the engagement runs

  1. 01 Day 0

    Scope

    A short call to agree targets, test type, dates and rules of engagement. You get a quote for that scope, then written authorization is signed before any testing starts.

  2. 02 Days 1 to 10

    Test

    Hands-on, tool-assisted testing aligned to OWASP and PTES, with every finding verified. Anything critical is reported to you immediately, not saved for the report.

  3. 03 +3 days

    Report

    A clear report: executive summary, then every finding with severity, evidence, reproduction steps and a specific fix. Followed by a readout call.

  4. 04 When you’re ready

    Retest

    Once fixes are in, we verify each one and issue an updated report and an attestation letter you can share with customers and auditors.

// FAQ

Compliance Pentest questions

Is a small, independent provider acceptable to auditors?

Yes. Auditors look for a qualified tester who is organizationally independent from the systems being tested, a documented methodology, and evidence of remediation. All three are in the report.

Are you a PCI Approved Scanning Vendor (ASV)?

No. Quarterly external ASV scans (PCI DSS Req. 11.3.2) must come from an ASV. Penetration testing (Req. 11.4) does not require an ASV and is what this service covers.

// Further reading

// Also available

Other services

Web App Pentest

An authenticated test of your web application against the OWASP Top 10 and the business-logic flaws scanners never find.

API Pentest

Testing of REST and GraphQL APIs for broken object-level authorization, auth flaws, mass assignment and data over-exposure.

Network Pentest

External testing of everything you expose to the internet, and internal testing of what an attacker could reach once inside.