ISO 27001 · Annex A · Penetration Testing

ISO 27001 pentest: What your auditor wants to see: we deliver it

Anyone seeking ISO 27001 certification or renewing their certificate will need a penetration test sooner or later, because your auditor expects it. Since the move to ISO/IEC 27001:2022, with a restructured Annex A and an expired transition period for the old 2013 edition, a cleanly documented, current pentest report matters more than ever. We deliver exactly that: a report that addresses the correct Annex A controls of the current edition and holds up in any audit.

  • Annex A-compliant reporting
  • Mapping to Annex A controls
  • Free initial consultation
3 years valid
01 Certification audit Stage 1 + Stage 2
02 Surveillance audit Year 1
03 Surveillance audit Year 2
04 Recertification Year 3
The certification cycle: after three years it starts over. Before each of these dates the auditor asks for current evidence.

What you get

  1. 01

    Audit-proof test report

    Our report is explicitly designed for ISO 27001 audits, with mapping to the relevant Annex A controls your auditor will examine.

  2. 02

    Clear Annex A mapping

    Every finding is mapped to the relevant ISO 27001 controls, such as A.8.8, A.8.9, and A.5.15. No interpretation work for your auditor.

  3. 03

    Flexible scope

    Whether initial certification, recertification, or an event-driven test after changes, we adapt the scope to your certification status.

  4. 04

    Fast delivery

    We know certification deadlines do not wait. On request we prioritise your project and deliver the report on time.

Our ISO 27001 pentest report is structured so that it provides your auditor with all necessary evidence, without follow-up questions.

Annex A mapping

What is ISO 27001?

Annex A of ISO 27001:2022 contains 93 controls across four categories. A penetration test is the most direct evidence instrument for these six:

93controls in Annex A 6of them a pentest answers directly

Which ISO 27001 controls does our pentest cover?

Control Name How our pentest helps Module
A.8.8 Vulnerability management We systematically identify exploitable vulnerabilities. This is the most direct evidence for A.8.8. All modules
A.8.9 Configuration management We test whether systems, services and network components are configured in a hardened state and whether default configurations were left behind. Infra, AD
A.5.15 Access control We test whether access controls actually work in practice, instead of just existing on paper. AD, Physical
A.8.20 Network security Segmentation, firewall rules, exposed services: we test the network against real attack patterns. Infrastructure
A.7.2 Physical access controls For organisations with physical ISMS assets, we test whether access to critical areas is genuinely controlled. Physical
A.8.29 Security testing in development and acceptance This is the control your auditor most directly ticks off with a penetration test report. All modules
ISO 27001:2022

2013 → 2022: what changed in Annex A

The current edition of the standard restructured Annex A fundamentally. This matters for your pentest scope and its control mapping: the old 2013 control numbers no longer exist.

ISO 27001:2013

114 controls across 14 domains (A.5 to A.18)

The 2013 edition organised Annex A into 14 classic domains such as cryptography, physical security, or supplier relationships. Many controls overlapped in substance, which made mapping and audit preparation unnecessarily complex.

114 controls · 14 domains

ISO 27001:2022 (currently in force)

93 controls across 4 themes

Organizational (37 controls), People (8), Physical (14), and Technological (34), achieved by merging overlapping controls, not by dropping requirements. On top of that, 11 new controls were added, including threat intelligence (A.5.7) and cloud security (A.5.23), which earlier editions did not cover.

  • 37 Organizational
  • 8 People
  • 14 Physical
  • 34 Technological

93 controls · 4 themes · drawn to the same scale as the row above

The auditor perspective

What does your ISO 27001 auditor actually expect?

ISO 27001 does not explicitly require a penetration test, but every experienced auditor will expect one as evidence for several Annex A controls, whether it's an initial certification, a recertification after three years, or an annual surveillance audit. Going into an audit without a current pentest report is a problem.

Show me how you systematically identify and remediate vulnerabilities in your environment. A penetration test is the appropriate instrument for this.

Typical statement from an ISO 27001 auditor in a Stage 2 audit

Annex A of ISO 27001:2022 contains 93 controls across four themes (Organizational, People, Physical, Technological), down from 114 controls across 14 domains in the 2013 predecessor. Several of these controls are difficult to evidence without a penetration test, particularly around vulnerability management, access controls, and network security. A missing or outdated pentest report is one of the most common reasons for findings and non-conformities in the audit, both at certification and during annual surveillance audits.

  • No explicit mandatory document

    ISO 27001 does not require a pentest, but controls A.8.8 and A.8.29 are nearly impossible to evidence without one.

  • Currency is decisive

    A three-year-old pentest report will not convince any auditor. Most accept a maximum of 12 months.

  • Scope must match the ISMS

    The pentest must cover the ISMS scope, instead of testing any system and hoping it is sufficient.

Who is this relevant for?

Who is ISO 27001 relevant for?

Unlike NIS2 or KRITIS, ISO 27001 applies across all industries: the standard carries no statutory applicability threshold. Certification is pursued by those who choose it to build trust with customers and partners, or by those who must, because customers, clients, or tenders require it as a precondition. More than 50,000 organisations worldwide currently hold ISO 27001 certification, and the number keeps growing.

  • SaaS & cloud providers
  • Managed service providers
  • Government & public entities
  • Financial services & fintechs
  • Healthcare & medical technology
  • Defence & aerospace
  • Mid-market companies with enterprise clients
  • Research institutions & universities

Most common trigger: a major client sets ISO 27001 certification as a supplier requirement. After that, the clock is ticking.

Our approach

How does an ISO 27001 pentest work?

Aligned with your certification status, your audit date, and the relevant Annex A controls.

  1. 01

    ISMS scope analysis

    We analyse your ISMS scope and clarify which systems, processes, and locations fall within the certification boundary, so the pentest covers exactly what your auditor examines.

  2. 02

    Annex A mapping & scoping

    Based on your ISMS, we define the pentest scope and map it to the relevant Annex A controls. No extra work for you at the audit.

  3. 03

    Test execution

    Manual penetration tests on agreed systems and areas. We document every step completely, which auditors value for traceability.

  4. 04

    Risk assessment & prioritisation

    Every finding is assessed by severity and ISMS relevance. Critical findings are communicated immediately, so you can act before the audit.

  5. 05

    ISO 27001-compliant final report

    Complete report with Annex A mapping, management summary, and technical appendix. Structured so your auditor finds all answers without follow-up questions.

50,000+
ISO 27001-certified organisations worldwide
93
Annex A controls in ISO 27001:2022
6
Controls directly evidenced by pentest
12 mo.
Maximum report age accepted by most auditors

What our ISO 27001 report contains

  1. Explicit mapping to relevant Annex A controls
  2. Management summary for ISMS managers and board
  3. Technical appendix with complete methodology documentation
  4. Prioritised remediation plan by severity and ISMS relevance
  5. Re-test offer after remediation of findings before the audit
Relevant pentest modules

Which tests do you need for ISO 27001?

The right scope depends on your ISMS. These three modules cover the most common Annex A requirements.

Frequently asked questions

ISO 27001 & penetration testing: your questions

ISO 27001 does not explicitly require a penetration test. But the standard requires evidence that vulnerabilities are systematically identified and remediated (A.8.8) and that access controls are effective (A.5.15). A penetration test is the most direct and convincing instrument for this evidence. In practice, nearly all experienced auditors will request a current pentest report, at the latest in the Stage 2 audit.
This depends on the auditor and the certification body. There is no universal rule. In practice, most auditors accept reports that are no older than 12 months. If there have been significant changes to the IT infrastructure since the last test, a new report is expected regardless of age. We recommend conducting the pentest at least six weeks before the planned audit date to leave sufficient time for remediation.
The pentest scope must match the ISMS scope. There is no benefit in testing an arbitrary system if your auditor has your core ISMS infrastructure in focus. We jointly analyse your ISMS scope and define a pentest scope that covers exactly what is needed, leaving no open questions for your auditor.
Technically yes, but we advise against it. Ideally, conduct the pentest at least six weeks before the audit. This gives you time to remediate critical findings and document this in the report. A report with open critical findings is a burden in the audit. A report with remediated findings and a re-test confirmation is a strong argument.
That is exactly the point of the pentest, not a reason to panic. Knowing findings before the audit is better than not knowing them. We communicate critical findings immediately after discovery so you can act. After remediation, we conduct a re-test on request and document the successful fix in the report. This shows your auditor a working improvement cycle, exactly what ISO 27001 requires.
The methods are technically identical. The difference lies in reporting and preparation. Our ISO 27001 pentest begins with an analysis of your ISMS scope, maps the pentest scope to the relevant Annex A controls, and delivers a report explicitly aligned with the evidence requirements of the standard. A standard pentest report without this mapping creates unnecessary extra work at the audit.
Yes, this affects every organisation with ISO 27001 certification. Annex A was restructured from 114 controls across 14 domains (2013) to 93 controls across four themes (Organizational, People, Physical, Technological) in the 2022 edition, including 11 new controls such as threat intelligence (A.5.7) and cloud security (A.5.23). The transition period set by the IAF expired on 31 October 2025: certificates under the old 2013 edition are no longer valid. For your pentest, this means one thing above all: the Annex A mapping in the report must reference the current 2022 control numbers, not the old ones.
An ISO 27001 certificate is valid for three years. During that period, two annual surveillance audits take place (lighter than the certification audit, usually sampling controls from the catalogue), before a full recertification audit after three years, which in substance matches a new Stage 2 audit. Because most auditors accept a pentest report for no more than 12 months, we recommend an annual rhythm in practice, at minimum a current report before each surveillance audit, and one is mandatory before recertification.