The auditor perspective
What does your ISO 27001 auditor actually expect?
ISO 27001 does not explicitly require a penetration test, but every experienced auditor will expect one as evidence for several Annex A controls, whether it's an initial certification, a recertification after three years, or an annual surveillance audit. Going into an audit without a current pentest report is a problem.
Annex A of ISO 27001:2022 contains 93 controls across four themes (Organizational, People, Physical, Technological), down from 114 controls across 14 domains in the 2013 predecessor. Several of these controls are difficult to evidence without a penetration test, particularly around vulnerability management, access controls, and network security. A missing or outdated pentest report is one of the most common reasons for findings and non-conformities in the audit, both at certification and during annual surveillance audits.