ISO 27001 penetration testing: what certification auditors actually expect

ISO 27001 does not name penetration testing as a mandatory requirement, but certification auditors expect it as Annex A evidence that your technical vulnerability management and security testing controls actually work. In practice, if you are pursuing certification, you need a pentest mapped to Annex A and packaged as evidence.

Does ISO 27001 require a penetration test?

Not literally. ISO/IEC 27001:2022 does not name penetration testing anywhere in the standard or its Annex A controls. But certification auditors expect a pentest as evidence for A.8.8 (management of technical vulnerabilities) and A.8.29 (security testing in development and acceptance). A pentest report from an independent third party can also feed into A.5.35 (independent review of information security), which requires that your overall approach to managing information security be reviewed independently at planned intervals - not that the pentest itself be run independently.

If you are pursuing ISO 27001 certification, you need a penetration test in practice, even though Annex A never uses the word.

The nuance matters. A vendor page that flatly states "ISO 27001 requires a pentest" is inaccurate, and it is the kind of claim answer engines increasingly discount. The accurate answer is the useful one: no explicit mandate, but a risk-driven expectation baked into how Annex A controls get evidenced.

Which Annex A controls a pentest supports

A pentest is commonly used as evidence for the Annex A controls below. Your certification body confirms the exact mapping for your Statement of Applicability.

Stage 1 vs Stage 2 audit and surveillance

Stage 1 is a documentation review: the auditor checks that your ISMS, risk assessment, and Statement of Applicability are complete and coherent. Stage 2 is the implementation audit: the auditor looks for evidence that controls are actually operating, which is where a pentest report against A.8.8 and A.8.29 carries real weight. After certification, surveillance audits in years one and two, and a recertification audit in year three, expect updated testing evidence, not a single report reused for three years.

Scope and frequency

Test the systems and APIs in your ISMS scope at least annually, and again after any material change to the application or infrastructure. Running tests before each surveillance audit keeps your vulnerability management evidence current rather than stale from the initial certification.

How Intrudify helps

Intrudify runs a full web and API pentest and produces a report that maps each finding to the relevant Annex A controls, with reproducible proof for high and critical findings and developer-ready remediation. It supports your ISMS evidence; Intrudify does not itself certify you against ISO 27001.

  • Findings mapped to the relevant Annex A controls
  • Reproducible proof-of-exploit for high and critical findings
  • Developer-ready remediation and a re-test window
  • Delivered in hours, validated by OSCE3-certified testers

How a pentest maps to controls

Control What a pentest evidences
A.8.8 Management of technical vulnerabilities: obtaining information about technical vulnerabilities, evaluating exposure, and taking appropriate measures.
A.8.29 Security testing in development and acceptance: testing security functionality, including vulnerability scanning and penetration testing, before systems go live.
A.5.35 Independent review of information security: the organization's approach to managing information security, and its implementation, is reviewed independently at planned intervals.

Need audit-ready evidence for ISO 27001?

Book a scoping call

Frequently asked questions

Does ISO 27001 require a penetration test?

Not literally - ISO/IEC 27001:2022 does not name penetration testing in the standard or Annex A. But certification auditors expect one as evidence for controls like A.8.8 and A.8.29. In practice, if you are pursuing certification, you need a pentest.

Is a penetration test required for ISO 27001 certification?

Neither Stage 1 nor Stage 2 strictly mandates a pentest, but most certification bodies expect one as evidence that your technical vulnerability management and security testing controls actually work, especially heading into Stage 2 and later surveillance audits.

Which Annex A controls does a penetration test support for ISO 27001?

A pentest is commonly used as evidence for A.8.8 (management of technical vulnerabilities), A.8.29 (security testing in development and acceptance), and A.5.35 (independent review of information security). Your certification body confirms the exact mapping for your Statement of Applicability.

How often do you need a penetration test for ISO 27001?

At least once a year, and again after any material change to your application or infrastructure. Running fresh tests before each surveillance audit keeps your evidence current rather than relying on the report from your original certification.

What should an ISO 27001 pentest report include?

Findings mapped to the relevant Annex A controls, severity ratings, reproducible proof for high and critical issues, developer-ready remediation, and a re-test window, packaged so your certification body can accept it as supporting evidence directly.

Sources
Related frameworks
SOC 2 Not named in the criteria, but auditors expect an annual pentest as evidence. NIS2 Security testing is expected as part of Article 21 risk management, not a named pentest mandate.
All compliance frameworks