ISO 27001
ISO 27001 & SOC 2 Penetration Testing: What Auditors Want
QUICK ANSWER · BOTH FRAMEWORKS AUDIT EVIDENCE · 2026 Does ISO 27001 require a penetration test? Not by name. ISO/IEC 27001:2022 is risk based, but Annex A 8.8 (management of technical vulnerabilities) and Annex A 8.29 (security testing in development and acceptance) are the applicable controls, and ISO/