PCI DSS v4.0.1
Requirements 11.4.1 – 11.4.7
- What it requires
- External and internal penetration testing at least once every 12 months and after any significant change. Segmentation testing every 12 months, and every 6 months for service providers.
- Evidence expected
- A report with the method, a scope that matches the cardholder data environment, and proof that exploitable findings were corrected and retested.
DORA, Regulation (EU) 2022/2554
Articles 24 – 27; Delegated Regulation (EU) 2025/1190
- What it requires
- A testing programme for ICT systems. Systems that support critical or important functions are tested at least yearly. Designated entities undergo threat-led penetration testing at least every 3 years.
- Evidence expected
- Test reports and remediation plans. For threat-led testing, the documents that the technical standards prescribe.
NIS2, Directive (EU) 2022/2555
Article 21(2)(e) and (f)
- What it requires
- Security in the acquisition, development and maintenance of systems, including vulnerability handling and disclosure. Policies and procedures to assess the effectiveness of risk management measures.
- Evidence expected
- Results of security testing as proof of effectiveness, and a vulnerability disclosure policy.
ISO/IEC 27001:2022
Annex A, controls 8.8 and 8.29
- What it requires
- Management of technical vulnerabilities, and security testing in development and acceptance.
- Evidence expected
- Test reports as evidence that the controls operate.
SOC 2
Trust Services Criteria CC4.1 and CC7.1
- What it requires
- Evaluations that establish whether controls are present and functioning, and procedures that detect vulnerabilities.
- Evidence expected
- A report of an independent tester dated within the audit period, with a retest.
GDPR, Regulation (EU) 2016/679
Article 32(1)(d)
- What it requires
- A process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures.
- Evidence expected
- Records showing that the measures protecting personal data are tested regularly.
HIPAA Security Rule
45 CFR 164.308(a)(8)
- What it requires
- Periodic technical and non-technical evaluation of the safeguards that protect electronic health information.
- Evidence expected
- Evaluation records, of which a penetration test report is the technical part.
Cyber Resilience Act, Regulation (EU) 2024/2847
Annex I, Part II; Article 14
- What it requires
- Vulnerability handling for products with digital elements: a coordinated disclosure policy and regular security tests. Reporting of actively exploited vulnerabilities applies from 11 September 2026, the full set of obligations from 11 December 2027.
- Evidence expected
- The disclosure policy, test records and the vulnerability handling procedure.
The test your assessor will ask for
Regulations and standards rarely say “penetration test” in so many words, and assessors almost always expect one. This page maps the requirements to the evidence and to the services that produce it.
01Requirements
Frameworks, requirement by requirement
References were verified against the published texts on September 28, 2026. They are a guide for orientation; the text of the regulation or standard prevails.
02Limits
What a test does not do
- A penetration test does not make an organisation compliant. Compliance is determined by your assessor on the basis of all controls.
- We are not an audit or certification body and issue no certificates of compliance.
- Whether a regulation applies to you is a legal question for your lawyers.
- A test designed only to pass an audit protects nothing. The scope follows the requirement; the depth follows the risk.
03Request
Tell us what needs testing
- Website check free of charge
- Reply within 1 business day
- NDA before any technical detail
- Fixed price for paid engagements
- No obligation
Request received
Reference
Keep the reference: we name it in all further communication with you.
What happens next
- A manager reviews the request and replies within 1 business day.
- We agree the scope, the rules of engagement and a secure channel for sensitive material.
- You receive a proposal with method, schedule and a fixed price. For the free website check you receive the authorisation to sign.
We never ask for payment, passwords or remote access in the first reply.