Audits and frameworks
What each framework actually says about penetration testing
Three of these require testing by name. Most do not, and expect it anyway. Each page gives the specific clause, the careful answer, and a link to the primary source rather than a vendor summary.
| Framework | Pen test required? | Where it comes from |
|---|---|---|
| SOC 2 | Common evidence | Trust Services Criteria CC4.1 and CC7.1 |
| SOC 2 Type I | Common evidence | Trust Services Criteria CC4.1 |
| SOC 2 Type II | Common evidence | Trust Services Criteria CC4.1 and CC7.1 |
| ISO 27001 | Testing expected | Annex A 8.8 and Annex A 8.29 |
| PCI DSS | Required by name | Requirement 11.4 |
| HIPAA | Testing expected | 45 CFR 164.308(a)(1)(ii)(A) and 164.308(a)(8) |
| FedRAMP | Required by name | NIST SP 800-53 Rev. 5 control CA-8 and the FedRAMP Penetration Test Guidance |
| GDPR | Testing expected | Article 32(1)(d) |
| CMMC | Common evidence | NIST SP 800-171 Rev. 2 for Level 2; NIST SP 800-172 for Level 3 |
| HITRUST | Testing expected | HITRUST CSF control 09.ab and the r2 assessment requirements |
| SOC 3 | Common evidence | Trust Services Criteria, same as SOC 2 |
| NIST CSF | Common evidence | ID.RA and DE.CM categories |
| ISO 42001 | Common evidence | Annex A controls on AI system impact assessment and verification |
| NIS2 | Testing expected | Article 21(2) |
| DORA | Required by name | Articles 24 to 27, with threat-led penetration testing at Articles 26 and 27 |
Required by name means the published text names penetration testing. Testing expected means the text mandates testing that a penetration test is the normal evidence for. Common evidence means the standard does not compel it and auditors generally ask anyway.
What enterprise buyers ask for
The reports and certificates that unblock a sale.
Regulated industries
Where the obligation comes from a regulator or a card brand rather than a customer.
Public sector
Selling to government, where the assessor is accredited into the program.
Regional and emerging
Obligations that arrive with a market rather than a customer.
These pages describe published standards and regulations and are not legal advice.
Get a scoped price without a discovery call
Tell us what is in scope and what your audit needs. You get a fixed price and a date, not a quote after two meetings.