Book a scoping callBook a call

Penetration testing for audits

We work with you to define the right scope, conduct the penetration test and deliver a reviewed report with clear, traceable evidence for audits and customer security reviews.

Scope your pentest View a sample report
What we deliver

We provide the technical evidence

A penetration test provides the technical evidence behind an audit, assessment or customer review. We agree the scope, run the test and document the results in a reviewed report. Exactly what your auditor wants to see.

We deliver the test, the evidence, and the report
The report is ready to share with auditors, assessors and customers
Your auditor issues the certificate
the compliance logic
What every framework is really asking for
ISO 27001
SOC 2
NIS2
GDPR
each one requires independent technical testing
The input we deliver
Independent penetration test
produces
What your auditor sees
Reviewed report

The report brings together the evidence, technical detail, severity ratings and attack paths your auditor wants to see.

What "acceptable" looks like

What your auditor actually wants to see

An automated scan is not a penetration test. Your auditor knows the difference.

01
Independent & scoped
An independent test against a clearly defined boundary.
02
Methodology on record
Testing mapped to a recognised methodology, so the work is verifiable.
03
Severity-rated findings with evidence
Each finding reproduced, rated, and explained.
04
Remediation you can act on
What to fix and how, in your developers' language.
05
A retest that closes the loop
Evidence that shows the problems and whether the fixes hold.
The frameworks

The frameworks that send people our way

Pick who's asking: the deliverable is the same.

ISO 27001

Evidence for an ISO 27001 assessment.

A scoped penetration test can support evidence that technical risks are assessed and treated. Confirm the expected scope and timing with your auditor.

The requirementThe relevant testing evidence depends on your risks, controls and audit plan.
What we deliverA reviewed pentest report with the approved scope, methodology and confirmed findings.
SOC 2

Evidence you actively test.

Our report documents the scope, methodology, findings and retest results, giving your SOC 2 auditor clear evidence of how your security controls perform in practice.

The requirementThe evidence depends on the controls and review period in your examination.
What we deliverAn independent technical assessment and a reviewed report.
NIS2

Show you test and assess.

For an organisation in scope, a penetration test may form part of the evidence used to assess technical security measures. It is one input to a wider NIS2 programme.

The requirementNIS2 requires risk-management measures and assessment of their effectiveness.
What we deliverTechnical findings that can support that wider assessment.
GDPR

Regular testing, demonstrated.

A penetration test can form part of the testing described in Article 32, depending on the risks and systems in scope.

The requirementArticle 32 describes a process for regularly testing and evaluating security measures.
What we deliverA scoped technical test that may support that process.
Also covered
PCI DSS

PCI DSS includes specific penetration-testing requirements. Confirm the applicable scope and tester requirements with your assessor.

DORA

Financial entities must test ICT resilience; the largest also face threat-led testing (TLPT).

HIPAA

For US healthcare, a pentest supports the Security Rule's evaluation requirement.

Scope & pricing

Scoped to what the audit needs

We scope to the assets inside the audit's boundary: your app, your API, your network, your cloud account, limited to what the review requires. Pricing follows the agreed scope, so you get a fixed quote before anything starts.

Follow the test. Talk to the tester

Checklist progress and confirmed findings appear in Outer Core as our testers validate and document them. You can talk to the tester, move findings through remediation and give your auditor a current report.

See how delivery works
Methodology checklist
OWASP ASVS 5.0 Checklist
2 Pass1 Fail1 N/A
v5.0.0-1.2.4Injection prevention
Database queries resist injection
Fail
v5.0.0-2.3.1Business logic
Flows enforce the expected step order
Pass
v5.0.0-3.3.4Cookie setup
Session cookies are protected from client-side scripts
Pass
v5.0.0-4.3.1GraphQL
Queries enforce depth or cost limits
N/A
Checklist updates appear as the tester completes each check
FAQ

Straight answers

Does a pentest make us ISO 27001 or SOC 2 compliant?

No. A penetration test can support an audit or assessment, but it does not establish compliance on its own. Your auditor, assessor or customer decides what evidence is required.

Which frameworks do you support?

A penetration test may support work related to ISO 27001, SOC 2, NIS2, GDPR, PCI DSS, DORA and HIPAA. The relevance and required scope depend on your organisation and the receiving assessor.

How fast can we start?

If you need to move fast, we are here to help. Once the scope is agreed, we can start within three days.

Will our auditor accept the report?

The report is built for audit review. It includes the approved scope, methodology, severity-rated findings, evidence and remediation guidance, giving your auditor a clear record of what was tested, what was found and how each issue was addressed.

Compliance & audit

Someone asked you for a pentest?

Tell us what's in scope and who's asking. You'll get a fixed quote and a start date.

Book a scoping call Request a scoped quote