ISO 27001 penetration testing
Pen testing that supports Annex A controls 8.8 and 8.29, with the scope, dates, and fix evidence your certification auditor reviews.
Last reviewed October 2026
Does ISO 27001 require penetration testing?
ISO/IEC 27001:2022 doesn’t name penetration testing. Annex A control 8.8 (management of technical vulnerabilities) asks you to evaluate your exposure to technical vulnerabilities and act on it, and 8.29 (security testing in development and acceptance) asks you to build security testing into development. If those controls are in your Statement of Applicability, a pen test with clear scope, dates, and fix evidence can support both. Your certification body decides what evidence it accepts.
What your certification auditor will want to see
- Scope tied to your ISMS scope
- Testing dates and methodology
- Findings with risk ratings
- How each finding was handled: fixed and retested, or a recorded decision to accept the risk
Reports document the scope, methodology, and dates that assessors typically look for.
Tests to consider
- Web applications The applications inside your ISMS scope, including their own APIs.
- APIs Public and partner APIs inside your ISMS scope.
- Networks and Active Directory Internet-facing systems and internal networks inside your ISMS scope.
- Cloud (AWS, Azure, Google Cloud) The cloud accounts inside your ISMS scope.
- Vulnerability assessments Recurring scans that feed your technical vulnerability management under 8.8.
- Security training Hands-on secure development training for your developers.
Planning around your certification audit
- Check your audit dates. Plan the test so your fixes and the retest are done before your stage 2 or surveillance audit. Start dates are agreed during scoping, so tell us your deadline when you ask for a quote.
- A free scoping call, then a fixed-fee proposal and rules of engagement to sign. Testing can usually start within 5 business days of signing.
- Testing, typically 1 to 3 weeks. Critical findings are reported within 24 hours of confirmation, not held for the report.
- Final report delivered within 5 business days after testing ends. We walk your team through the findings on a call.
- Fix, then retest. One retest of reported findings within 90 days of the final report, included in the price, with an updated report and attestation letter. Record how you handled each finding in your risk treatment plan.
What it costs
- Web application, including its own APIFrom $5,000 per application
- Separate public or partner APIFrom $8,000 per API
- External networkFrom $5,000
- Internal network and Active DirectoryFrom $15,000 per network
- Cloud environmentFrom $10,000 per environment
Starting prices in US dollars for the smallest scope of each service, reviewed October 2026. Your price is a fixed fee, set in a written proposal after a free scoping call.
All testing is performed by HackNow’s own US-based testers. We never pass your test to another firm.
What you get for your certification audit
- A full report: executive summary, scope, dates, methodology, and findings with risk ratings, evidence, and fixes
- An attestation letter with the test dates, scope, method, and results, to share with customers who ask about your certification
- A retest report and an updated letter once you’ve fixed the findings
- A walkthrough call with your team after the report
What a pen test adds to a scan
Control 8.8 asks you to evaluate how exposed you are to technical vulnerabilities. NIST SP 800-115 notes most penetration tests seek combinations of vulnerabilities granting more access than any single flaw, and manual analysis can identify new or obscure vulnerabilities scanners may miss.[1]
Questions about ISO 27001 pen testing
Which Annex A controls does a pen test support?
Mainly 8.8 and 8.29. Depending on scope, results can also inform controls such as 8.9 (configuration management) and 8.20 (networks security).
What will the certification auditor ask for?
Expect to show the report, its scope and dates, and how you handled each finding: fixed and retested, or a recorded decision to accept the risk. Your certification body decides what’s enough.
How often should we test?
Your ISMS sets the schedule, based on your risk assessment and what your customers ask for. Beyond that, test after significant changes to the systems in scope, such as a new product, a major release, or a new cloud environment.
Can one test cover ISO 27001 and SOC 2?
Yes, when the same systems are in scope. If SOC 2 and ISO 27001 cover the same app and cloud, one test can support both. We confirm the scope with you before testing starts.
Tell us what you need tested.
We reply to every request within one business day. Every engagement is a fixed fee after a free scoping call.