Compliance
Compliance frameworks and where penetration testing fits
Most frameworks do not 'require a pentest' the way vendors claim - one (PCI DSS) does. Here is what each really expects, and where an AI pentest fits.
European frameworks
NIS2 Security testing is expected as part of Article 21 risk management, not a named pentest mandate. DORA General testing (incl. penetration testing) is required under Art. 24-25; a separate, human-led TLPT is required only for entities identified under Art. 26-27, and no automated test substitutes for it. GDPR GDPR does not name pentesting, but Article 32(1)(d) requires regularly testing the effectiveness of security measures. CRA The CRA requires manufacturers to security-test products with digital elements and handle vulnerabilities; not a named pentest.
Global frameworks
SOC 2 Not named in the criteria, but auditors expect an annual pentest as evidence. ISO 27001 Not named in Annex A, but certification auditors expect a pentest as evidence. PCI DSS Explicitly required: internal and external penetration testing at least every 12 months (Requirement 11.4). HIPAA The Security Rule does not name pentesting, but requires risk analysis and periodic technical evaluation - a pentest is a common way to meet both. NIST 800-53 800-53 is a control catalog, not a mandate, but it contains an explicit penetration-testing control (CA-8) that applies when selected. OWASP ASVS ASVS is not a legal mandate - it is a verification standard whose higher levels are demonstrated through hands-on security testing. ISO 27017/27018 Like ISO 27001, these cloud extensions do not name pentesting, but auditors expect testing evidence for the technical controls they build on.