🛡️ Pentest from €539 · Compliance from €89. See All Services →
Optimum Web
Penetration Testing

Penetration Testing for SOC 2, ISO 27001 & PCI DSS Compliance Platforms

Quick Answer

If your compliance automation platform flagged a control that needs penetration test evidence, you need an independent tester — the platform itself doesn't perform testing. A pentest report typically satisfies SOC 2 CC4.1/CC7.1, ISO 27001 Annex A.8.29, and PCI DSS Requirement 11.4 (the one framework with an explicit annual testing mandate). We don't integrate with any specific platform's API — you'll upload our report and findings export manually as evidence.

Why Your Compliance Platform Flags This

Compliance automation platforms map your organisation's evidence against the controls required by the framework you're pursuing — typically SOC 2, ISO 27001, or PCI DSS. Penetration testing is one of the few controls these platforms can't automate or verify themselves: it requires an independent human tester actively attempting to exploit your systems, not a continuous automated check. That's why the control stays open with a "manual evidence needed" flag until you upload a report from a real testing engagement.

Which Controls Does a Pentest Satisfy?

FrameworkControlRequirementHow a pentest helps
SOC 2CC4.1The entity selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioningAn independent pentest is a common form of "separate evaluation" evidence for the technical controls in scope
SOC 2CC7.1The entity uses detection and monitoring procedures to identify... vulnerabilities... and evaluates the effectiveness of controlsFindings and remediation evidence demonstrate that vulnerability identification and response processes actually work
ISO/IEC 27001Annex A.8.29Security testing should be carried out during development and after deploymentA pentest report against production or pre-production systems is direct evidence for this control
PCI DSSRequirement 11.4External and internal penetration testing is performed at least once every 12 months and after significant changesDirectly named — PCI DSS is the one framework here with an explicit, unambiguous testing mandate

Control references reflect the frameworks' published structure at the time of writing; verify exact clause numbering against your current audit period's framework edition.

Fixed Pricing & Timelines

TierScopeTimelinePrice
Vulnerability AssessmentExternal-facing IPs/domains, automated + manual verification5 business daysFrom €539
Focused Web App PentestSingle web application, core OWASP Top 10 coverage5–7 business daysFrom €1,490
Standard Web App PentestWeb app + API, full OWASP WSTG methodology7–10 business daysFrom €3,200
Enterprise SaaS PentestMulti-tenant SaaS, API, auth/authorization deep-dive, business logic10–15 business daysFrom €6,500–€12,000

Most compliance platform controls only need external evidence — start with our fastest tier.

Start with Vulnerability Assessment — €539

Working Alongside Your Compliance Platform

We deliver a standard PDF report plus a machine-readable findings export (CSV/JSON) your team can upload as evidence to your compliance platform manually
We do not have a live API integration with Vanta, Drata, Secureframe, or any other compliance automation platform
We do not have a commercial partnership with any specific compliance platform vendor
Your compliance platform will still show the control as requiring manual evidence upload — we don't change that

What We Are — and Aren't

We are

An independent penetration testing provider using recognised methodologies (OWASP WSTG, PTES, ASVS)
Able to produce evidence formatted for SOC 2, ISO 27001, and PCI DSS control mapping
Transparent about our certification status

We aren't

A CREST-accredited firm — Moldova currently has no local CREST accreditation path
ISO/IEC 27001 certified yet — certification is in progress, targeted for Q4 2026
Integrated with any compliance automation platform's API
A compliance auditor — we don't issue SOC 2 reports or ISO certificates ourselves

Frequently Asked Questions

Does Vanta require a penetration test?+
Vanta itself doesn't set audit requirements — it maps your evidence to the framework you're pursuing (typically SOC 2 or ISO 27001) and flags controls where a pentest is commonly used as evidence, such as SOC 2 CC7.1 or ISO 27001 Annex A.8.29. Whether a pentest is strictly required depends on your auditor and the specific framework, not on Vanta as a platform.
Does Drata require a penetration test?+
Same principle as Vanta — Drata tracks evidence against your chosen framework's controls and will flag a testing-related control as needing evidence, but the actual requirement comes from the framework and your auditor's expectations, not from Drata itself.
Do you integrate with Vanta, Drata, or Secureframe?+
No. We don't have an API integration or commercial partnership with any compliance automation platform. We provide a standard report and a findings export your team can upload manually as evidence.
Which controls does a pentest satisfy?+
Most commonly SOC 2 CC4.1 (separate evaluations of control effectiveness) and CC7.1 (vulnerability detection and monitoring), ISO/IEC 27001 Annex A.8.29 (security testing in development and operations), and PCI DSS Requirement 11.4 (the one framework here with an explicit, named annual testing mandate).
How long does a pentest take?+
Our fixed-price tiers range from a 5-business-day Vulnerability Assessment (from €539) to a 10–15 business day Enterprise SaaS Pentest (from €6,500–€12,000), depending on scope and application complexity.
Can we get the report before our audit deadline?+
Our fastest tier (Vulnerability Assessment) delivers in 5 business days from kickoff. If your audit window is tight, tell us the deadline during scoping and we'll confirm whether it's achievable before you commit.
Are you CREST accredited?+
No. We are not a CREST-member firm. CREST currently has no local accreditation path in Moldova, where we're based. Our testers follow CREST-aligned methodologies (OWASP WSTG, PTES) and we're transparent about this status rather than implying an accreditation we don't hold.
Are you ISO 27001 certified?+
Not yet — certification is in progress, targeted for Q4 2026. We follow ISO/IEC 27001-aligned internal controls in the meantime and will update this page once certification is complete.

Clear Your Compliance Platform's Testing Control

From €539 · 5 business days · Report formatted for SOC 2 / ISO 27001 / PCI DSS evidence