ISO 27001 is a management-system standard, so what your certification body cares about is evidence that controls are implemented and effective. Annex A 8.8 requires you to obtain information about technical vulnerabilities and take action; 8.29 expects security testing during development. A penetration test is the artefact that demonstrates both, provided its findings actually flow back into your ISMS rather than sitting in a PDF.
We scope the test against your ISMS scope statement and risk assessment, and write findings so they drop straight into your risk treatment plan with owners and treatment decisions. The result is not just a report for the auditor; it closes the loop the standard is actually asking for, information gathered, risk assessed, action taken.
Because we also deliver ISO 27001 implementation and internal audits, the test is built to satisfy a certification auditor, not just to find bugs.
The frequent gap is a disconnect between the test and the ISMS. A penetration test that never makes it into the risk treatment plan, or findings with no owner and no treatment decision, tells an auditor the control is not really operating. Equally, a test scoped without reference to the ISMS scope can miss the assets the certification actually covers.
We close that gap by scoping against your documented ISMS and delivering findings in the language of risk treatment, so the evidence is coherent end to end.
An auditor is assessing whether your control operates, not whether you own a report. We deliver testing that evidences the former.
Tell us your ISMS scope and audit timeline and we’ll scope testing that evidences Annex A 8.8, with a fixed quote within one working day.