ISO 27001 · Annex A · Penetration Testing

ISO 27001 pentest:
What your auditor wants to see: we deliver it

Anyone seeking ISO 27001 certification or renewing their certificate will need a penetration test sooner or later, because your auditor expects it. Since the move to ISO/IEC 27001:2022, with a restructured Annex A and an expired transition period for the old 2013 edition, a cleanly documented, current pentest report matters more than ever. We deliver exactly that: a report that addresses the correct Annex A controls of the current edition and holds up in any audit.

Annex A-compliant reporting Audit-proof report format Free initial consultation
What you get
Audit-proof test report
Our report is explicitly designed for ISO 27001 audits, with mapping to the relevant Annex A controls your auditor will examine.
Clear Annex A mapping
Every finding is mapped to the relevant ISO 27001 controls, such as A.8.8, A.8.11, and A.5.15. No interpretation work for your auditor.
Flexible scope
Whether initial certification, recertification, or an event-driven test after changes, we adapt the scope to your certification status.
Fast delivery
We know certification deadlines do not wait. On request we prioritise your project and deliver the report on time.
Our ISO 27001 pentest report is structured so that it provides your auditor with all necessary evidence, without follow-up questions.
Annex A mapping

What is ISO 27001?

Annex A of ISO 27001:2022 contains 93 controls across four categories. A penetration test is the most direct evidence instrument for these six:

Which ISO 27001 controls does our pentest cover?

Control Name How our pentest helps Module
A.8.8Vulnerability managementWe systematically identify exploitable vulnerabilities. This is the most direct evidence for A.8.8.All modules
A.8.11Data masking & system hardeningWe test whether sensitive systems are adequately hardened and whether data access is correctly restricted.Infra, AD
A.5.15Access controlWe test whether access controls actually work in practice, instead of just existing on paper.AD, Physical
A.8.20Network securitySegmentation, firewall rules, exposed services: we test the network against real attack patterns.Infrastructure
A.7.2Physical access controlsFor organisations with physical ISMS assets, we test whether access to critical areas is genuinely controlled.Physical
A.5.37Documented operating proceduresOur final report documents methodology, scope, and findings in a structured way, as evidence for A.5.37.All modules

2013 → 2022: what changed in Annex A

The current edition of the standard restructured Annex A fundamentally. This matters for your pentest scope and its control mapping: the old 2013 control numbers no longer exist.

ISO 27001:2013

114 controls across 14 domains (A.5 to A.18)

The 2013 edition organised Annex A into 14 classic domains such as cryptography, physical security, or supplier relationships. Many controls overlapped in substance, which made mapping and audit preparation unnecessarily complex.

ISO 27001:2022 (currently in force)

93 controls across 4 themes

Organizational (37 controls), People (8), Physical (14), and Technological (34), achieved by merging overlapping controls, not by dropping requirements. On top of that, 11 new controls were added, including threat intelligence (A.5.7) and cloud security (A.5.23), which earlier editions did not cover.

Important if you were still certified under 2013: The transition period set by the IAF expired on 31 October 2025. Certificates issued under ISO 27001:2013 are no longer valid: every current certification and recertification now runs exclusively under the 2022 edition. If your last pentest was still mapped to the old control structure, that mapping should be updated at your next test.

What does your ISO 27001 auditor actually expect?

ISO 27001 does not explicitly require a penetration test, but every experienced auditor will expect one as evidence for several Annex A controls, whether it's an initial certification, a recertification after three years, or an annual surveillance audit. Going into an audit without a current pentest report is a problem.

Show me how you systematically identify and remediate vulnerabilities in your environment. A penetration test is the appropriate instrument for this.
Typical statement from an ISO 27001 auditor in a Stage 2 audit

Annex A of ISO 27001:2022 contains 93 controls across four themes (Organizational, People, Physical, Technological), down from 114 controls across 14 domains in the 2013 predecessor. Several of these controls are difficult to evidence without a penetration test, particularly around vulnerability management, access controls, and network security. A missing or outdated pentest report is one of the most common reasons for findings and non-conformities in the audit, both at certification and during annual surveillance audits.

No explicit mandatory document
ISO 27001 does not require a pentest, but controls A.8.8 and A.8.11 are nearly impossible to evidence without one.
Currency is decisive
A three-year-old pentest report will not convince any auditor. Most accept a maximum of 12 months.
Scope must match the ISMS
The pentest must cover the ISMS scope, instead of testing any system and hoping it is sufficient.

Who is ISO 27001 relevant for?

Unlike NIS2 or KRITIS, ISO 27001 applies across all industries: the standard carries no statutory applicability threshold. Certification is pursued by those who choose it to build trust with customers and partners, or by those who must, because customers, clients, or tenders require it as a precondition. More than 50,000 organisations worldwide currently hold ISO 27001 certification, and the number keeps growing.

SaaS & cloud providers
Managed service providers
Government & public entities
Financial services & fintechs
Healthcare & medical technology
Defence & aerospace
Mid-market companies with enterprise clients
Research institutions & universities

Most common trigger: a major client sets ISO 27001 certification as a supplier requirement. After that, the clock is ticking.

How does an ISO 27001 pentest work?

Aligned with your certification status, your audit date, and the relevant Annex A controls.

SCHRITT 01

ISMS scope analysis

We analyse your ISMS scope and clarify which systems, processes, and locations fall within the certification boundary, so the pentest covers exactly what your auditor examines.

SCHRITT 02

Annex A mapping & scoping

Based on your ISMS, we define the pentest scope and map it to the relevant Annex A controls. No extra work for you at the audit.

SCHRITT 03

Test execution

Manual penetration tests on agreed systems and areas. We document every step completely, which auditors value for traceability.

SCHRITT 04

Risk assessment & prioritisation

Every finding is assessed by severity and ISMS relevance. Critical findings are communicated immediately, so you can act before the audit.

SCHRITT 05

ISO 27001-compliant final report

Complete report with Annex A mapping, management summary, and technical appendix. Structured so your auditor finds all answers without follow-up questions.

50,000+
ISO 27001-certified organisations worldwide
93
Annex A controls in ISO 27001:2022
6
Controls directly evidenced by pentest
12 mo.
Maximum report age accepted by most auditors
What our ISO 27001 report contains
Explicit mapping to relevant Annex A controls
Management summary for ISMS managers and board
Technical appendix with complete methodology documentation
Prioritised remediation plan by severity and ISMS relevance
Re-test offer after remediation of findings before the audit

Which tests do you need for ISO 27001?

The right scope depends on your ISMS. These three modules cover the most common Annex A requirements.

ISO 27001 & penetration testing: your questions

ISO 27001 does not explicitly require a penetration test. But the standard requires evidence that vulnerabilities are systematically identified and remediated (A.8.8) and that access controls are effective (A.5.15). A penetration test is the most direct and convincing instrument for this evidence. In practice, nearly all experienced auditors will request a current pentest report, at the latest in the Stage 2 audit.
This depends on the auditor and the certification body. There is no universal rule. In practice, most auditors accept reports that are no older than 12 months. If there have been significant changes to the IT infrastructure since the last test, a new report is expected regardless of age. We recommend conducting the pentest at least six weeks before the planned audit date to leave sufficient time for remediation.
The pentest scope must match the ISMS scope. There is no benefit in testing an arbitrary system if your auditor has your core ISMS infrastructure in focus. We jointly analyse your ISMS scope and define a pentest scope that covers exactly what is needed, leaving no open questions for your auditor.
Technically yes, but we advise against it. Ideally, conduct the pentest at least six weeks before the audit. This gives you time to remediate critical findings and document this in the report. A report with open critical findings is a burden in the audit. A report with remediated findings and a re-test confirmation is a strong argument.
That is exactly the point of the pentest, not a reason to panic. Knowing findings before the audit is better than not knowing them. We communicate critical findings immediately after discovery so you can act. After remediation, we conduct a re-test on request and document the successful fix in the report. This shows your auditor a working improvement cycle, exactly what ISO 27001 requires.
The methods are technically identical. The difference lies in reporting and preparation. Our ISO 27001 pentest begins with an analysis of your ISMS scope, maps the pentest scope to the relevant Annex A controls, and delivers a report explicitly aligned with the evidence requirements of the standard. A standard pentest report without this mapping creates unnecessary extra work at the audit.
Yes, this affects every organisation with ISO 27001 certification. Annex A was restructured from 114 controls across 14 domains (2013) to 93 controls across four themes (Organizational, People, Physical, Technological) in the 2022 edition, including 11 new controls such as threat intelligence (A.5.7) and cloud security (A.5.23). The transition period set by the IAF expired on 31 October 2025: certificates under the old 2013 edition are no longer valid. For your pentest, this means one thing above all: the Annex A mapping in the report must reference the current 2022 control numbers, not the old ones.
An ISO 27001 certificate is valid for three years. During that period, two annual surveillance audits take place (lighter than the certification audit, usually sampling controls from the catalogue), before a full recertification audit after three years, which in substance matches a new Stage 2 audit. Because most auditors accept a pentest report for no more than 12 months, we recommend an annual rhythm in practice, at minimum a current report before each surveillance audit, and one is mandatory before recertification.