Compliance / ISO 27001

ISO/IEC 27001 and the penetration test

Auditor-expectedthe evidence your assessor expects to see

ISO 27001 certification turns on two Annex A controls, 8.8 and 8.29, and a penetration test is how a Stage 2 auditor sees them operating: technical vulnerabilities found and treated, security testing performed across the lifecycle. Your risk assessment sets the cadence; the pentest supplies the evidence.

ISO 27001, in one panel

Standard
ISO/IEC 27001:2022 (with ISO/IEC 27002:2022 controls)
Pentest status
Auditor-expected · the evidence your assessor expects to see
Where it lives
Annex A 8.8 and A 8.29
Frequency
Set by your risk assessment; typically annual and after change
Scope
Driven by your Statement of Applicability and ISMS scope, typically internet-facing applications and infrastructure, and software you develop.
What the assessor wants
Evidence that A 8.8 and A 8.29 are actually operating: a scoped independent report, findings feeding your risk-treatment process, and closure tracking. The auditor cares about the loop, find then treat then verify, as much as the report.

What ISO 27001 is

ISO/IEC 27001:2022 is the international standard for an information security management system, an ISMS. Unlike SOC 2, it is a certification: an accredited body audits your ISMS and certifies it against the requirements.

The 2022 revision reorganized the Annex A controls, aligned to ISO/IEC 27002:2022. Two of those controls are what a technical assessment turns on.

Where the pentest fits

Two Annex A controls carry it. A 8.8, management of technical vulnerabilities, requires you to identify, evaluate and address technical weaknesses. A 8.29, security testing in development and acceptance, requires security testing across the lifecycle. A penetration test is how a certifiable ISMS satisfies both.

The cadence and depth are set by your own risk assessment, which is why two certified companies can test at different intervals and both hold the certificate.

How an AI-native pentest meets it

Uvy delivers the recurring technical-vulnerability and pre-release security-testing evidence A 8.8 and A 8.29 expect.

Its findings drop straight into the ISMS risk-treatment loop, and retests demonstrate that corrective actions actually closed.

What a seasoned assessor knows

ISO 27001 ties the pentest to a loop, not a date: find the vulnerability, treat it, verify it closed. A Stage 2 auditor reads that closure trail as closely as the findings, and continuous testing is what keeps the loop evidenced.

Find every way in, before an attacker does

Uvy runs continuous offense and defense across your applications, agents, and embodied AI, at machine speed, and hands your team proof and the exact fix. Start with an application pentest, or talk to sales to cover the rest.

Free to test. No card to start.

Or write to [email protected]