Penetration testing for SOC 2 & ISO 27001
SOC 2 and ISO 27001 don't certify a report — they certify that you run a defensible security process. Neither names a price or a specific vendor. What they need is evidence you find vulnerabilities and act on them. Here's exactly what the controls ask for, and how an audit-ready automated pentest answers them.
The specific clauses auditors look at
SOC 2 · CC7.1
Detect vulnerabilities and monitor for new ones. A pentest that finds and rates issues is standard evidence.
SOC 2 · CC4.1
Evaluate whether controls are operating. Proof of attacks attempted and held — not just failures — is exactly this.
ISO 27001 · A.8.8
Manage technical vulnerabilities: identify, assess, remediate, verify. A dated, re-tested report demonstrates the full loop.
An audit-ready report, built to answer the clause
| Auditor wants | In the Aegis report |
|---|---|
| Defined scope & methodology | Ownership-verified target, documented test suite |
| Dated findings with severity | Every finding timestamped, CVSS-rated, retained 18 months |
| Evidence & remediation | Reproduction steps and a specific fix per finding |
| Control verification | Verified Controls — attacks attempted and found safe |
| Re-testing | Free re-test after you remediate |
See the full control mapping in our methodology.
Your auditor decides — and sometimes needs a human
No report is "SOC 2 compliant" on its own; SOC 2 certifies organisations, not documents. Most auditors accept audit-ready automated pentest evidence, but the final call is theirs. And specific mandates — PCI DSS 11.4, some government procurement — require a named human tester. We'd rather say that plainly than sell you something that won't clear your audit. Here's exactly when we're the wrong choice.
Get an audit-ready pentest for $999.
Verify a domain, accept the rules, and Aegis does the rest. Free to start; no sales call.