ClearPenTest

Articles

Testing, audits, and the evidence in between

Written for the person who has to produce the artifact, not the person selling it. Every claim about what a framework requires carries the clause it comes from.

SOC 2 · 1 minProduction liveness probeA temporary row that exists only in the production Convex deployment and not in the checked-in corpus, used to prove which of the two the deployed site is reading. Removed immediately after.Penetration testing · 7 minHow to scope a penetration test without wasting half of itScope decides what a penetration test can find and what its report can be used to claim. The four decisions that matter are which systems, which environment, how much access the tester gets, and what is explicitly out of bounds.ISO 27001 · 6 minDoes ISO 27001 require a penetration test?ISO/IEC 27001 does not use the phrase penetration test. Annex A 8.8 requires management of technical vulnerabilities and A 8.29 requires security testing. ISO/IEC 27002:2022, the implementation guidance for those controls, names penetration testing directly, which is why certification bodies expect it at Stage 2.SOC 2 · 6 minHow long a first SOC 2 actually takesA first SOC 2 Type II usually takes four to eight months from decision to report. The audit itself is a small part of that. Most of the time goes to implementing controls that produce evidence, and to the observation window, which cannot be compressed.SOC 2 · 6 minWhat an auditor actually wants from a penetration test reportAuditors do not read penetration test reports for the findings. They read them for scope, dates, method and closure, because those are the four things that let a report support a control. Reports that bury those details create audit work rather than removing it.SOC 2 · 7 minDoes SOC 2 require a penetration test?SOC 2 does not require a penetration test. The AICPA Trust Services Criteria never use the phrase. In practice most auditors accept a penetration test as the evidence for CC4.1 and CC7.1, and a company with no security testing evidence at all should expect questions.Penetration testing · 7 minAI-assisted penetration testing should make evidence easier, not more opaqueAutomation is useful in security testing when it removes repetitive work while preserving accountable human judgment. It stops being useful when it turns the assessment into an unexplained score or a report with no defensible method behind it.Audit operations · 5 minWhy pen test buying stalls the audit before testing even beginsThe slowest part of an assessment is usually not the testing. It is the handoff between the security buyer, the test provider and the audit workstream, and most of that delay is created during purchasing rather than during the work.Penetration testing · 6 minThe pen test quote problem: why security buyers still cannot see the pricePenetration testing effort changes for knowable reasons: how much is in scope, how much context the tester gets, how fast evidence is needed, and whether testing continues after the report. A quote-only process does not make those inputs more accurate, it moves price discovery into a sales cycle.

Get a scoped price without a discovery call

Tell us what is in scope and what your audit needs. You get a fixed price and a date, not a quote after two meetings.