Penetration testing for compliance
Pen tests scoped and reported for SOC 2, HIPAA, ISO 27001, customer security reviews, and cyber insurance.
We map the test to your program, document it the way reviewers expect, and give you an attestation letter you can share without handing over the full report. Your auditor decides what evidence it accepts.
Last reviewed October 2026
SOC 2
SOC 2 doesn’t name a required test, and your auditor decides what evidence it accepts. A current pen test scoped to your system boundary can support your auditor’s evaluation, for a Type I or Type II report.
Tests to consider
Get a SOC 2 pen test quote Read more about SOC 2 pen testing
HIPAA
The HIPAA Security Rule requires a periodic technical and nontechnical evaluation of your safeguards (45 CFR 164.308(a)(8)). It doesn’t name penetration testing, but a pen test of the systems that hold ePHI can support that evaluation and your risk analysis. As on every test, we access ePHI only as far as needed to prove impact.
Tests to consider
Get a HIPAA pen test quote Read more about HIPAA pen testing
ISO 27001
ISO/IEC 27001:2022 doesn’t name penetration testing. Annex A control 8.8 (management of technical vulnerabilities) asks you to evaluate your exposure to technical vulnerabilities and act on it, and 8.29 (security testing in development and acceptance) asks you to build security testing into development. A pen test with clear scope, dates, and fix evidence can support both.
Get an ISO 27001 pen test quote Read more about ISO 27001 pen testing
Customer security reviews
When a customer’s security review asks for a recent third-party pen test, we scope the test to the systems they care about. Your team gets the full report, and you get an attestation letter to share with the customer instead.
Why customers ask
Verizon 2026 DBIR: “breaches with third-party involvement have increased by 60% from last year’s dataset, reaching 48% of total breaches.”Source: Verizon Business, 2026 Data Breach Investigations Report: Executive Summary (2026) (PDF)
Get a quote for a customer review Read more about customer security reviews
Cyber insurance
If your cyber insurance application or renewal asks for an external penetration test or phishing testing, we run either one or both. You get an attestation letter you can give your broker or insurer.
Tests to consider
External network tests start at $5,000.
Phishing campaigns: quoted for your scope. Minimum project $5,000.
Starting prices in US dollars for the smallest scope of each service, reviewed October 2026. Your price is a fixed fee, set in a written proposal after a free scoping call.
Get a quote for your renewal Read more about testing for cyber insurance
What reviewers look for in a pen test report
Every HackNow report includes the basics reviewers check:
- The scope and system boundary we tested
- Testing dates
- Methodology and standards: PTES, NIST SP 800-115, and the OWASP testing guides
- Findings with severity, evidence, and recommended fixes
- Retest status, in an updated report and attestation letter
Reports document the scope, methodology, and dates that assessors typically look for. Your auditor decides what evidence it accepts.
Working back from your deadline
- A free scoping call, then a fixed-fee proposal.
- Signed proposal and rules of engagement. Testing can usually start within 5 business days of signing.
- Testing, typically 1 to 3 weeks. Critical findings are reported within 24 hours of confirmation, not held for the report.
- Final report delivered within 5 business days after testing ends.
- Your fixes, then the retest: one retest of reported findings within 90 days of the final report, included in the price. We update the report and attestation letter.
Tell us your deadline in the quote form.
The attestation letter
Every pen test comes with an attestation letter. It states the test dates, the scope, the method, and a summary of the results, and after your retest it shows the retest status. It confirms a test took place. It isn’t a SOC 2 report, a certification, or an audit opinion.
Questions about compliance testing
Are you an audit firm?
No. We’re a penetration testing firm. We provide the testing evidence, and your auditor performs the audit and issues the report.
Can one test cover more than one program?
Yes, when the same systems are in scope. If SOC 2 and ISO 27001 cover the same app and cloud, one test can support both. We confirm the scope with you before testing starts.
Can we share the report with customers?
You decide. Share the attestation letter with your customers, auditors, or insurer, and keep the full technical report for your team or share it under NDA.
How often should we test?
Check what your auditor, customer contracts, or insurer ask for, since they set the schedule. Beyond that, test after significant changes to the systems in scope, such as a new product, a major release, or a new cloud environment.
Can a penetration test find every vulnerability?
No test can promise that. A penetration test is a time-boxed assessment of the agreed scope at a point in time. We focus testing time where the risk is highest and report everything we confirm.
Audit or deal deadline coming up?
We reply to every request within one business day. Every engagement is a fixed fee after a free scoping call.