We cover all technical code and cloud security requirements for GDPRSOC 2ISO 27001PCI DSSHIPAANIST 800-53and more

Sample report

European frameworks

EU rules for cyber risk, operational resilience, personal data, and digital products.

SECURITYFRAMEWORKNIS2

NIS2

Network and Information Systems Directive

Article 21 requires risk controls to be tested for effectiveness, although it does not prescribe a pentest.

SECURITYFRAMEWORKDORA

DORA

Digital Operational Resilience Act

Articles 24–25 require a testing programme; the separate TLPT duty applies only to selected financial entities.

SECURITYFRAMEWORKGDPR

GDPR

General Data Protection Regulation

Article 32 requires regular evaluation of security measures, but it leaves the testing method risk-based.

SECURITYFRAMEWORKEU CRA

EU CRA

EU Cyber Resilience Act

Manufacturers must test products with digital elements and manage vulnerabilities throughout the support period.

Global frameworks

Assurance, payment, healthcare, government, application, and cloud security standards.

SECURITYFRAMEWORKSOC 2

SOC 2

System and Organization Controls 2

The criteria do not name pentesting, but auditors and customers commonly expect current independent evidence.

SECURITYFRAMEWORKISO 27001

ISO 27001

Information Security Management Systems

Auditors use testing evidence to assess technical vulnerability management and security testing controls.

SECURITYFRAMEWORKPCI DSS

PCI DSS

Payment Card Industry Data Security Standard

Requirement 11.4 explicitly requires internal and external penetration testing at least every 12 months.

SECURITYFRAMEWORKHIPAA

HIPAA

Health Insurance Portability and Accountability Act

The Security Rule requires risk analysis and periodic technical evaluation, not a named pentest.

SECURITYFRAMEWORKNIST 800-53

NIST 800-53

Security and Privacy Controls for Information Systems

CA-8 explicitly covers penetration testing when that control is selected for the system.

SECURITYFRAMEWORKOWASP ASVS

OWASP ASVS

Application Security Verification Standard

A verification standard whose higher assurance levels depend on hands-on security testing.

SECURITYFRAMEWORKISO 27017/27018

ISO 27017/27018

Cloud Security and PII Protection

Cloud and PII guidance extends ISO 27001 controls; testing evidence follows the shared-responsibility boundary.

Get your Audit Evidence right now

Run a security assessment of your system, or contact us if your compliance programme requires additional support.