ISO 27001

ISO 27001 Penetration Testing for Certification and Surveillance Audits

ISO 27001 does not name penetration testing as a single mandatory control, but certification auditors expect to see evidence that technical vulnerabilities are identified and handled. An independent penetration test is the clearest evidence. Scantra Security delivers ISO 27001 penetration testing with findings mapped to Annex A controls and retest evidence included.

Last reviewed 2026-09-28 by the Scantra Security testing team

Relevant ISO 27001:2022 controls

  • 8.8 Management of technical vulnerabilities
  • 8.29 Security testing in development and acceptance
  • 8.20 Network security
  • 8.9 Configuration management
  • 5.36 Compliance with policies, rules and standards

How a pentest supports your ISMS

Your risk assessment identifies what could go wrong. A penetration test shows whether it can. Findings feed your risk register and treatment plan, and the retest demonstrates that treatment worked. That closed loop is exactly what auditors look for during Stage 2 and surveillance audits.

What to test for ISO 27001

Scope should follow your ISMS scope: the applications, networks and cloud environments that hold in-scope information. We help you define a proportionate scope so the test is meaningful without testing systems outside your certification.

Process

  1. 1. Align with ISMS scope

    Map assets to your Statement of Applicability.

  2. 2. Testing

    Manual penetration testing of in-scope assets.

  3. 3. Control mapping

    Each finding is linked to the relevant Annex A control.

  4. 4. Free retest and certificate

    We verify fixes at no extra cost and issue an updated report and certificate.

Frequently asked questions

Is penetration testing mandatory for ISO 27001?

Not by name, but it is the most common evidence for vulnerability management controls, and most auditors expect it.

How often should we test?

At least once per certification year, and after significant changes.

Can the same test cover SOC 2?

Yes, we can map one test to both frameworks.

Related services

Get started

Ready to find what attackers will?

Talk to a senior pentester. Get a tailored scope, sample report and timeline within 24 hours.