ClearPenTest

Audits and frameworks

What each framework actually says about penetration testing

Three of these require testing by name. Most do not, and expect it anyway. Each page gives the specific clause, the careful answer, and a link to the primary source rather than a vendor summary.

FrameworkPen test required?Where it comes from
SOC 2Common evidenceTrust Services Criteria CC4.1 and CC7.1
SOC 2 Type ICommon evidenceTrust Services Criteria CC4.1
SOC 2 Type IICommon evidenceTrust Services Criteria CC4.1 and CC7.1
ISO 27001Testing expectedAnnex A 8.8 and Annex A 8.29
PCI DSSRequired by nameRequirement 11.4
HIPAATesting expected45 CFR 164.308(a)(1)(ii)(A) and 164.308(a)(8)
FedRAMPRequired by nameNIST SP 800-53 Rev. 5 control CA-8 and the FedRAMP Penetration Test Guidance
GDPRTesting expectedArticle 32(1)(d)
CMMCCommon evidenceNIST SP 800-171 Rev. 2 for Level 2; NIST SP 800-172 for Level 3
HITRUSTTesting expectedHITRUST CSF control 09.ab and the r2 assessment requirements
SOC 3Common evidenceTrust Services Criteria, same as SOC 2
NIST CSFCommon evidenceID.RA and DE.CM categories
ISO 42001Common evidenceAnnex A controls on AI system impact assessment and verification
NIS2Testing expectedArticle 21(2)
DORARequired by nameArticles 24 to 27, with threat-led penetration testing at Articles 26 and 27

Required by name means the published text names penetration testing. Testing expected means the text mandates testing that a penetration test is the normal evidence for. Common evidence means the standard does not compel it and auditors generally ask anyway.

These pages describe published standards and regulations and are not legal advice.

Get a scoped price without a discovery call

Tell us what is in scope and what your audit needs. You get a fixed price and a date, not a quote after two meetings.