ISO 27001 Penetration Testing for Certification and Surveillance Audits
ISO 27001 does not name penetration testing as a single mandatory control, but certification auditors expect to see evidence that technical vulnerabilities are identified and handled. An independent penetration test is the clearest evidence. Scantra Security delivers ISO 27001 penetration testing with findings mapped to Annex A controls and retest evidence included.
Last reviewed 2026-09-28 by the Scantra Security testing team
Relevant ISO 27001:2022 controls
- 8.8 Management of technical vulnerabilities
- 8.29 Security testing in development and acceptance
- 8.20 Network security
- 8.9 Configuration management
- 5.36 Compliance with policies, rules and standards
How a pentest supports your ISMS
Your risk assessment identifies what could go wrong. A penetration test shows whether it can. Findings feed your risk register and treatment plan, and the retest demonstrates that treatment worked. That closed loop is exactly what auditors look for during Stage 2 and surveillance audits.
What to test for ISO 27001
Scope should follow your ISMS scope: the applications, networks and cloud environments that hold in-scope information. We help you define a proportionate scope so the test is meaningful without testing systems outside your certification.
Process
1. Align with ISMS scope
Map assets to your Statement of Applicability.
2. Testing
Manual penetration testing of in-scope assets.
3. Control mapping
Each finding is linked to the relevant Annex A control.
4. Free retest and certificate
We verify fixes at no extra cost and issue an updated report and certificate.
Frequently asked questions
Is penetration testing mandatory for ISO 27001?
Not by name, but it is the most common evidence for vulnerability management controls, and most auditors expect it.
How often should we test?
At least once per certification year, and after significant changes.
Can the same test cover SOC 2?
Yes, we can map one test to both frameworks.
