Skip to main content
    ISO 27001 Compliance

    ISO 27001 Requires Evidence of Security Testing. Make Sure Yours Holds Up.

    StealthNet delivers AI pentests and hybrid (AI + human) penetration testing reports mapped to ISO 27001 Annex A controls, delivered in as little as 48 hours. AI pentests start at $1,500 and hybrid pentests start at $5,000.

    48-Hour Reports Annex A Mapped US-Based Senior Testers AI + Human Hybrid

    Get Scoped in 24 Hours

    Sample report

    Share a few details and pick a time to chat right after.

    Fixed-fee quote in 24 hours. No credit card. No sales pitch.

    Your details stay private. NDA available on request.

    No commitment. We'll follow up within 1 business day.

    Trusted by Companies Where Security Isn't Optional

    TopLeft logo
    Derma Monitor logo
    Avara Software logo
    Phish Firewall logo
    TopLeft logo
    Derma Monitor logo
    Avara Software logo
    Phish Firewall logo

    What customers say

    Highly recommend StealthNet AI

    "StealthNet AI performed a thorough and comprehensive pen test, fast turnaround on conducting the test, they were very responsive, and it was great value."
    RB

    Richard B.

    Founder · Avara Software · Health, Wellness & Fitness

    The best choice for penetration testing

    "The testing was thorough and the reports were structured precisely for the regulatory requirements. Explanation of issues along with steps to reproduce and remediation advice were detailed and clear, making corrections a breeze."
    JM

    Jeremy M.

    Director · IKO Corp · Medical Devices

    The Problem

    Auditors Expect Real Pentest Evidence.

    Your auditor flags missing evidence

    Certification bodies expect penetration testing mapped to Annex A controls. Vulnerability scans alone won't satisfy A.12.6.1 requirements.

    Surveillance audits catch gaps

    Annual surveillance audits require fresh evidence. Stale or one-time testing leaves you exposed to non-conformities.

    Legacy firms overcharge for compliance

    Traditional consultancies charge $20K to $60K for ISO 27001 pentests. StealthNet delivers AI pentests starting at $1,500 and hybrid pentests from $5,000.

    The Solution

    Pentest Reports Built for ISO 27001, Not Retrofitted for It.

    StealthStrike

    $1,500

    • 48-hour delivery
    • Exploit-validated findings
    • Mapped to Annex A controls

    Best for: Surveillance audits, control validation, continuous improvement

    Most Popular

    Hybrid (AI + Human) Pentest

    Starting at $5,000

    Typical engagements range from $5,000 to $10,000 depending on scope

    • AI attack simulation + senior US-based pentester validation
    • 48-hour first report
    • Dedicated project manager + private Slack channel
    • Compliance-ready report + free retest included

    Best for: Initial certification, recertification, auditor-facing evidence

    Deliverables

    Mapped to ISO 27001 Annex A Controls.

    Access Control (A.9)

    Testing of authentication, authorization, and user access management policies

    Cryptography (A.10)

    Validation of encryption implementations protecting data at rest and in transit

    Operations Security (A.12)

    Assessment of technical vulnerability management and system hardening

    Communications (A.13)

    Testing network security controls, segmentation, and data transfer protections

    Annex A Mapping

    Every Finding Ties Back to an Annex A Control.

    ISO 27001:2022 restructured Annex A into 93 controls. These are the ones an ISO 27001 penetration test produces evidence for, what we test against each, and what your certification body sees.

    A.5.15 Access control
    What we test
    Role separation, privilege escalation, and cross-tenant access across in-scope applications
    Evidence in your report
    Proven access-control failures with reproduction steps and affected data
    A.5.17 Authentication information
    What we test
    MFA coverage, session handling, password reset abuse, and machine identities
    Evidence in your report
    Authentication bypass and account takeover findings with impact
    A.8.8 Management of technical vulnerabilities
    What we test
    Exploitability of known and unknown weaknesses across the ISMS boundary
    Evidence in your report
    CVSS-rated findings with exploitation evidence, the core A.8.8 artifact
    A.8.9 Configuration management
    What we test
    Hardening drift, default credentials, and exposed management interfaces
    Evidence in your report
    Configuration findings with the secure baseline they deviate from
    A.8.20 to A.8.22 Network security and segregation
    What we test
    Perimeter exposure, network service abuse, and segmentation between zones
    Evidence in your report
    Segmentation test results showing which boundaries actually hold
    A.8.24 Use of cryptography
    What we test
    TLS configuration, key handling, and encryption in transit and at rest
    Evidence in your report
    Cryptographic findings with configuration remediation
    A.8.25 to A.8.28 Secure development and coding
    What we test
    Injection, business logic abuse, and insecure deserialization in your code
    Evidence in your report
    Application findings mapped to the affected component and owner
    A.8.29 Security testing in development and acceptance
    What we test
    The test itself, run against a release candidate or production environment
    Evidence in your report
    Dated report and retest evidence satisfying the control outright
    Clause 9.1 and Clause 10
    What we test
    Whether prior findings were actually remediated
    Evidence in your report
    Free retest section evidencing continual improvement

    Certifying against more than one framework this year? The same engagement can produce SOC 2 penetration testing evidence and NIST penetration testing mappings alongside ISO 27001. See how the overlap works on our compliance penetration testing page.

    Scope

    What Belongs Inside the ISMS Test Boundary

    Your statement of applicability sets the boundary. These are the six areas that make up almost every ISO 27001 penetration testing scope we run.

    External attack surface

    Internet-facing applications, marketing and login subdomains, VPN and remote access, and forgotten hosts still resolving to your ranges.

    Applications and APIs

    The products holding in-scope information, their authentication flows, tenant isolation, and the REST or GraphQL APIs behind them.

    Cloud tenancies

    AWS, Azure, and GCP accounts inside the ISMS: identity and role trust, storage exposure, secrets handling, and backup access.

    Identity provider

    Entra ID, Okta, or Google Workspace. Conditional access gaps, legacy authentication, token handling, and privileged role assignment.

    Internal network

    Segregation between corporate and production zones (A.8.22), lateral movement, and domain privilege escalation paths.

    Third-party integrations

    Suppliers and connected apps that process in-scope information, tested as the supplier-relationship controls in A.5.19 to A.5.22 expect.

    Most scopes combine web application penetration testing, API penetration testing, and external network penetration testing in one engagement.

    Cost and Timeline

    What an ISO 27001 Pentest Costs and How Long It Takes

    Fixed fees quoted before kickoff. No hourly billing, no change orders when a finding turns out to be interesting.

    Single application or API
    Typical fee
    $1,500 to $3,000
    First report
    48 hours
    Best fit
    Surveillance audit evidence, control validation between cycles
    Application plus external network
    Typical fee
    $5,000 to $7,500
    First report
    48 hours, hybrid in 5 to 7 business days
    Best fit
    Stage 2 certification evidence for a typical SaaS ISMS
    Multi-app ISMS with cloud and internal
    Typical fee
    $7,500 to $15,000
    First report
    48 hours, hybrid in 7 to 10 business days
    Best fit
    Initial certification for a larger or multi-product ISMS
    Continuous annual program
    Typical fee
    Custom
    First report
    Rolling
    Best fit
    Clause 10 continual improvement and recertification readiness

    Every tier includes one free retest after remediation. Full breakdown on our penetration testing pricing page.

    When to test

    Test eight to twelve weeks before Stage 2

    Stage 1 reviews your documentation. Stage 2 examines whether the controls actually operate, and that is where a current penetration test report does the heavy lifting. Testing early enough to remediate and retest turns a potential non-conformity into evidence of a working corrective-action process.

    • Initial certification: test before Stage 2, retest after remediation.
    • Surveillance audits: fresh evidence each year, not last year's report.
    • Recertification in year three: full-scope test across the ISMS boundary.
    • After any material change to in-scope systems, per A.8.29.

    ISO 27001:2013 to 2022 re-mapping

    The 2022 revision consolidated 114 controls into 93 across organizational, people, physical, and technological themes, and added 11 new controls including configuration management and monitoring activities. Reports written against the old numbering confuse auditors working from the new Annex A.

    Every report we deliver uses the 2022 numbering. If you hold a report against the 2013 control set, we will map it forward as part of scoping at no extra cost.

    ISO 42001 crossover for AI products

    Teams shipping AI features are increasingly asked for ISO 42001 alongside ISO 27001. The AI management system adds requirements around model integrity, training data handling, and adversarial robustness that a standard Annex A test does not touch.

    We cover both in one engagement. See AI penetration testing for how model and pipeline testing gets added to an ISMS scope.

    Compare

    ISO 27001 Pentest vs. Vulnerability Scan vs. Internal Audit

    Three evidence artifacts your certification body treats very differently.

    What it produces
    ISO 27001 Penetration Test
    Exploited findings proving which Annex A controls fail in practice
    Vulnerability Scan
    A list of known CVEs and misconfigurations, unexploited
    Internal Audit
    A conformity assessment of the ISMS against the standard
    Combined (Recommended)
    Documented conformity backed by proof the controls hold
    Primary control satisfied
    ISO 27001 Penetration Test
    A.8.8 and A.8.29
    Vulnerability Scan
    Partial A.8.8 only
    Internal Audit
    Clause 9.2
    Combined (Recommended)
    A.8.8, A.8.29, Clause 9.2, and Clause 10
    Auditor weight at Stage 2
    ISO 27001 Penetration Test
    High, this is the operating-effectiveness evidence
    Vulnerability Scan
    Low on its own
    Internal Audit
    Required, but does not test technical controls
    Combined (Recommended)
    What certification bodies expect to see
    Typical cadence
    ISO 27001 Penetration Test
    Annually and after material change
    Vulnerability Scan
    Monthly or continuous
    Internal Audit
    At planned intervals, usually annually
    Combined (Recommended)
    Annual pentest, continuous scanning, annual internal audit
    Why StealthNet

    AI Handles Speed. Humans Validate Everything.

    A named, US-based senior tester validates every finding before your report is delivered.

    Reports are mapped to Annex A controls, so there is no manual reformatting for auditors.

    Most clients receive their first report within 48 hours of scoping call completion.

    Cost
    Traditional
    $20K to $60K
    StealthNet
    AI: $1,500 / Hybrid: from $5,000
    Delivery
    Traditional
    3 to 6 weeks
    StealthNet
    48 hours
    Annex A Mapping
    Traditional
    Manual / extra cost
    StealthNet
    Included
    Retest
    Traditional
    Extra charge
    StealthNet
    Free
    ISO 42001 Coverage
    Traditional
    Not available
    StealthNet
    Included
    FAQ

    ISO 27001 Pentesting Questions

    ISO 27001 Annex A control A.12.6.1 requires organizations to manage technical vulnerabilities. Penetration testing is the most effective way to demonstrate compliance with this control, and certification auditors routinely expect it as evidence during initial certification and surveillance audits.

    ISO 27001 penetration testing evaluates the security of systems within your ISMS (Information Security Management System) scope. It validates that your Annex A controls (access management, cryptography, operations security, and communications security) are implemented effectively against real-world attack scenarios.

    Best practice is annual penetration testing aligned with your surveillance audit cycle, plus additional testing after significant changes to systems within your ISMS scope. Many organizations test quarterly as part of continuous improvement (Clause 10).

    ISO 27001 focuses on information security management controls. ISO 42001 extends this to AI management systems, adding requirements for AI-specific risks like model integrity, training data security, and adversarial robustness. StealthNet covers both under a unified pentest engagement.

    Yes. Our reports are structured to map directly to Annex A controls, making it easy for your auditor to verify compliance. We include executive summaries, technical findings with CVSS scores, remediation guidance, and evidence of retesting, exactly what auditors expect.

    Traditional consultancies charge $20,000 to $60,000 for an ISO 27001 pentest. StealthNet AI pentests start at $1,500 and hybrid AI plus human engagements start at $5,000, with most ISMS scopes landing between $5,000 and $10,000 depending on the number of in-scope applications and networks.

    Most scopes deliver a first AI pentest report within 48 hours of kickoff. Hybrid engagements with senior human validation typically complete in 5 to 10 business days, plus one included free retest after remediation, which fits comfortably inside a certification or surveillance audit window.

    Yes. Every hybrid engagement is validated by a named, US-based senior tester holding credentials such as OSCP, OSWE, GPEN, or CREST. Certification bodies accept these as evidence that the testing was performed by competent, independent personnel.

    Each report includes an executive summary for management review, CVSS-rated technical findings with exploitation evidence, a mapping of every finding to the relevant Annex A control, prioritized remediation guidance, and a retest section confirming fixes were validated.

    A penetration test produces direct evidence for A.5.15 access control, A.5.17 authentication information, A.8.7 protection against malware, A.8.8 management of technical vulnerabilities, A.8.9 configuration management, A.8.20 network security, A.8.21 security of network services, A.8.22 segregation of networks, A.8.24 use of cryptography, A.8.25 secure development lifecycle, A.8.28 secure coding, and A.8.29 security testing in development and acceptance. It also feeds Clause 9.1 monitoring and measurement and Clause 10 continual improvement.

    The 2022 revision restructured 114 controls into 93 across four themes and introduced 11 new controls, including A.8.9 configuration management and A.8.16 monitoring activities. Penetration testing is still the practical evidence for A.8.8 technical vulnerability management, and A.8.29 now names security testing explicitly. Reports produced against the 2013 Annex A numbering should be re-mapped to the 2022 numbering before your next audit.

    Scope follows your ISMS statement of applicability. In practice that means the internet-facing applications and APIs holding in-scope information, the corporate and production networks inside the ISMS boundary, cloud tenancies and identity providers, and any third-party integrations that process in-scope data. Anything excluded from the ISMS should be documented as excluded from the test so the auditor sees a deliberate boundary rather than a gap.

    Stage 1 is a documentation review, so a test is not strictly required, but auditors often ask to see a testing plan. Stage 2 is where evidence of operating effectiveness is examined, and that is where a current penetration test report and its remediation evidence carry the most weight. Testing eight to twelve weeks before Stage 2 leaves time to remediate and retest.

    Yes. The technical scope for ISO 27001 Annex A and the SOC 2 Common Criteria overlap heavily, particularly around access control, change management, and network security. We map a single engagement to both frameworks in the same report, so you pay once and hand the same evidence to both your certification body and your SOC 2 auditor.
    Related Services

    Pentest Services Included in Every Compliance Engagement

    Every compliance pentest pulls from these test-type services as needed. Scope is sized to your environment, not padded with hours.

    Get Scoped

    Get Your ISO 27001 Pentest Scoped in 24 Hours

    Share a few details and we'll follow up within one business day.

    Fixed-fee quote in 24 hours. No credit card. No sales pitch.

    Your details stay private. NDA available on request.

    No commitment. We'll follow up within 1 business day.