Compliance penetration testing
Auditors and customers want testing evidence that is current, independent, and scoped correctly. We map the test to your framework's requirements, document the methodology the way assessors expect, and provide an attestation letter you can share without handing over the full report.
Frameworks we support
- SOC 2 Type I and Type II
- HIPAA Security Rule technical evaluations for systems holding ePHI
- ISO/IEC 27001:2022 Annex A 8.8 (technical vulnerabilities) and 8.29 (security testing)
- Cyber insurance security requirements
- Customer security questionnaires and vendor due diligence
How we approach it
We start from your system boundary and the controls your auditor will test, so the scope is neither too narrow to count nor wider than it needs to be. Reports include the methodology, scope, and tester qualifications assessors look for.
What you get
- Report formatted for auditor review
- Attestation letter for customers and prospects
- Scope and methodology documentation
- Retest report showing remediated findings
Typical use cases
- Your first SOC 2 or ISO 27001 audit
- Annual testing for an existing SOC 2 or ISO 27001 program
- Selling to enterprise customers
- Cyber insurance applications and renewals
Often paired with
Tell us what you need tested.
Send a few details and we'll set up a short scoping call, then follow up with a fixed-fee proposal.