Annex A of ISO 27001:2022 contains 93 controls across four categories. A penetration test is the most direct evidence instrument for these six:
| Control | Name | How our pentest helps | Module |
|---|---|---|---|
| A.8.8 | Vulnerability management | We systematically identify exploitable vulnerabilities. This is the most direct evidence for A.8.8. | All modules |
| A.8.11 | Data masking & system hardening | We test whether sensitive systems are adequately hardened and whether data access is correctly restricted. | Infra, AD |
| A.5.15 | Access control | We test whether access controls actually work in practice, instead of just existing on paper. | AD, Physical |
| A.8.20 | Network security | Segmentation, firewall rules, exposed services: we test the network against real attack patterns. | Infrastructure |
| A.7.2 | Physical access controls | For organisations with physical ISMS assets, we test whether access to critical areas is genuinely controlled. | Physical |
| A.5.37 | Documented operating procedures | Our final report documents methodology, scope, and findings in a structured way, as evidence for A.5.37. | All modules |
The current edition of the standard restructured Annex A fundamentally. This matters for your pentest scope and its control mapping: the old 2013 control numbers no longer exist.
The 2013 edition organised Annex A into 14 classic domains such as cryptography, physical security, or supplier relationships. Many controls overlapped in substance, which made mapping and audit preparation unnecessarily complex.
Organizational (37 controls), People (8), Physical (14), and Technological (34), achieved by merging overlapping controls, not by dropping requirements. On top of that, 11 new controls were added, including threat intelligence (A.5.7) and cloud security (A.5.23), which earlier editions did not cover.
Important if you were still certified under 2013: The transition period set by the IAF expired on 31 October 2025. Certificates issued under ISO 27001:2013 are no longer valid: every current certification and recertification now runs exclusively under the 2022 edition. If your last pentest was still mapped to the old control structure, that mapping should be updated at your next test.
ISO 27001 does not explicitly require a penetration test, but every experienced auditor will expect one as evidence for several Annex A controls, whether it's an initial certification, a recertification after three years, or an annual surveillance audit. Going into an audit without a current pentest report is a problem.
Annex A of ISO 27001:2022 contains 93 controls across four themes (Organizational, People, Physical, Technological), down from 114 controls across 14 domains in the 2013 predecessor. Several of these controls are difficult to evidence without a penetration test, particularly around vulnerability management, access controls, and network security. A missing or outdated pentest report is one of the most common reasons for findings and non-conformities in the audit, both at certification and during annual surveillance audits.
Unlike NIS2 or KRITIS, ISO 27001 applies across all industries: the standard carries no statutory applicability threshold. Certification is pursued by those who choose it to build trust with customers and partners, or by those who must, because customers, clients, or tenders require it as a precondition. More than 50,000 organisations worldwide currently hold ISO 27001 certification, and the number keeps growing.
Most common trigger: a major client sets ISO 27001 certification as a supplier requirement. After that, the clock is ticking.
Aligned with your certification status, your audit date, and the relevant Annex A controls.
We analyse your ISMS scope and clarify which systems, processes, and locations fall within the certification boundary, so the pentest covers exactly what your auditor examines.
Based on your ISMS, we define the pentest scope and map it to the relevant Annex A controls. No extra work for you at the audit.
Manual penetration tests on agreed systems and areas. We document every step completely, which auditors value for traceability.
Every finding is assessed by severity and ISMS relevance. Critical findings are communicated immediately, so you can act before the audit.
Complete report with Annex A mapping, management summary, and technical appendix. Structured so your auditor finds all answers without follow-up questions.
The right scope depends on your ISMS. These three modules cover the most common Annex A requirements.