We provide the technical evidence
A penetration test provides the technical evidence behind an audit, assessment or customer review. We agree the scope, run the test and document the results in a reviewed report. Exactly what your auditor wants to see.
The report brings together the evidence, technical detail, severity ratings and attack paths your auditor wants to see.
What your auditor actually wants to see
An automated scan is not a penetration test. Your auditor knows the difference.
The frameworks that send people our way
Pick who's asking: the deliverable is the same.
Evidence for an ISO 27001 assessment.
A scoped penetration test can support evidence that technical risks are assessed and treated. Confirm the expected scope and timing with your auditor.
Evidence you actively test.
Our report documents the scope, methodology, findings and retest results, giving your SOC 2 auditor clear evidence of how your security controls perform in practice.
Show you test and assess.
For an organisation in scope, a penetration test may form part of the evidence used to assess technical security measures. It is one input to a wider NIS2 programme.
Regular testing, demonstrated.
A penetration test can form part of the testing described in Article 32, depending on the risks and systems in scope.
PCI DSS includes specific penetration-testing requirements. Confirm the applicable scope and tester requirements with your assessor.
Financial entities must test ICT resilience; the largest also face threat-led testing (TLPT).
For US healthcare, a pentest supports the Security Rule's evaluation requirement.
Scoped to what the audit needs
We scope to the assets inside the audit's boundary: your app, your API, your network, your cloud account, limited to what the review requires. Pricing follows the agreed scope, so you get a fixed quote before anything starts.
Follow the test. Talk to the tester
Checklist progress and confirmed findings appear in Outer Core as our testers validate and document them. You can talk to the tester, move findings through remediation and give your auditor a current report.
See how delivery worksStraight answers
Does a pentest make us ISO 27001 or SOC 2 compliant?
No. A penetration test can support an audit or assessment, but it does not establish compliance on its own. Your auditor, assessor or customer decides what evidence is required.
Which frameworks do you support?
A penetration test may support work related to ISO 27001, SOC 2, NIS2, GDPR, PCI DSS, DORA and HIPAA. The relevance and required scope depend on your organisation and the receiving assessor.
How fast can we start?
If you need to move fast, we are here to help. Once the scope is agreed, we can start within three days.
Will our auditor accept the report?
The report is built for audit review. It includes the approved scope, methodology, severity-rated findings, evidence and remediation guidance, giving your auditor a clear record of what was tested, what was found and how each issue was addressed.