ISO and IEC · ISO/IEC 27001:2022
Does ISO 27001 require a penetration test?
ISO/IEC 27001 is a certifiable standard for an information security management system. Unlike SOC 2 it produces a certificate rather than a report, and it is the assurance European and Asian buyers usually ask for first.
The short answer
ISO 27001 does not use the words penetration test in the requirements of the standard. Annex A 8.8 requires management of technical vulnerabilities and A 8.29 requires security testing in development and acceptance. ISO/IEC 27002:2022, the implementation guidance for those controls, names penetration testing directly, which is why certification bodies expect to see it.
Who it applies to
Companies selling internationally, particularly into Europe, and organizations that want a certificate a buyer can verify rather than a report they have to read.
In detail
ISO 27001 is structured differently from SOC 2. Clauses 4 through 10 define the management system itself, and Annex A lists 93 controls in the 2022 revision, reorganized into four themes from the 114 controls of the 2013 version. An organization selects controls via a Statement of Applicability and justifies any it excludes.
Two Annex A controls create the testing expectation. A 8.8, management of technical vulnerabilities, requires information about technical vulnerabilities to be obtained and the organization's exposure evaluated. A 8.29, security testing in development and acceptance, requires security testing processes to be defined and implemented. The guidance in ISO/IEC 27002:2022 for these controls references penetration testing as a means of meeting them.
Certification runs in two stages. Stage 1 reviews documentation and readiness, Stage 2 audits the management system in operation, and surveillance audits follow annually with recertification every three years. A penetration test report is a standard Stage 2 artifact, and its absence is a common nonconformity for first-time certifications.
What to have in scope
- The systems inside the ISMS scope defined in the Statement of Applicability
- Evidence that findings feed the vulnerability management process, not just a PDF filed away
- Testing timed before Stage 2 rather than after the certificate is chased
- Retesting that demonstrates the corrective action process under Clause 10
Questions people ask
Does ISO 27001 require a penetration test?
The standard itself does not use the phrase. Annex A 8.8 requires management of technical vulnerabilities and A 8.29 requires security testing, and ISO/IEC 27002:2022, which provides implementation guidance for those controls, names penetration testing explicitly. Certification bodies therefore expect testing evidence at Stage 2.
What changed in ISO 27001:2022?
Annex A was restructured from 114 controls in 14 domains to 93 controls in four themes, and 11 controls were new, including threat intelligence, secure coding and information deletion. Organizations certified against the 2013 version had a transition period to move across.
Is ISO 27001 better than SOC 2?
They answer different questions for different buyers. ISO 27001 certifies that a management system meets a standard and produces a certificate anyone can check. SOC 2 is an attestation report a buyer reads in full. European and Asian buyers tend to ask for ISO 27001; North American enterprise buyers tend to ask for SOC 2.
Can one penetration test cover both ISO 27001 and SOC 2?
Usually yes, if the scope covers the systems in both the ISMS scope and the SOC 2 system description, and the report documents method and severity clearly enough for both audiences. The scopes are rarely identical, so confirm the overlap before testing rather than after.
Related frameworks
This page describes published standards and regulations and is not legal advice. Where a rule is proposed rather than in force, it is labelled as such. Confirm obligations with your auditor or counsel.
Get a scoped price without a discovery call
Tell us what is in scope and what your audit needs. You get a fixed price and a date, not a quote after two meetings.