Compliance Backed by Real Evidence, Not Guesswork
NIS2, GDPR, ISO 27001, DORA and every other framework your business needs to satisfy all ask the same underlying question: can you prove it? Pentesterra fills in every technical control it can answer itself - straight from your vulnerability scans, pentests, OSINT, External Exposure Assessments and DevGuard results - and gives you a clean, quick way to handle the rest: fill it out in the app, or export the questionnaire, get it completed offline, and import it back.
Standards We Cover
Not sure which ones apply to you? Tell us your industry and country and Pentesterra's applicability wizard shows you exactly which standards you're likely on the hook for - mandatory or voluntary - before you commit to filling out a single control.
Pentesterra vs. the Traditional Way
| Dimension | Spreadsheet / GRC Tool / Consultant | Pentesterra Compliance |
|---|---|---|
| Technical controls | Self-attested "yes" in a spreadsheet, taken on faith | Auto-filled from real scans, pentests, OSINT, DevGuard - with the evidence attached |
| Which frameworks apply | Guess, or pay a consultant to tell you | Built-in applicability wizard based on industry, country and company profile |
| Freshness | Collected once before the audit, stale by the time it's reviewed | Re-checked automatically as your scans, pentests and exposure monitoring update |
| Filling it out | One rigid spreadsheet, hard to split across people | Fill in-app or export/import - mix both, assign controls to teammates |
| Multiple frameworks | A separate spreadsheet or GRC module per standard, re-mapped by hand | 13 frameworks in one workspace, technical evidence shared across them |
| Auditor deliverable | Manually assembled from a dozen tools and screenshots the week before | One-click bundle: questionnaire, evidence, and gap report, ready to submit |
| What to prepare first | Every control gets equal attention, or none | Controls assessors dig into are flagged "auditor-focus" ahead of time |
| Setup | A separate GRC platform, integrations to build and maintain | The platform you already scan and pentest with - nothing extra to stand up |
See It in the Product
How It Works
Pick the standards that apply to you
Tell Pentesterra your industry, country, and a few basics about your business, and it shows you which frameworks you're actually likely to need - NIS2, DORA, GDPR, ISO 27001, and more - so you're not guessing which ones matter.
Let the platform fill in what it already knows
The moment an assessment is scoped to your domains and infrastructure, every technical control that can be answered from scanning, pentesting, OSINT, external exposure monitoring, and DevGuard is filled in automatically, with the evidence attached.
Fill in the rest, your way
Answer the remaining organizational and policy questions directly in the app - quick Yes / Partly / No / N/A on simple items, full detail where an auditor needs it - or export the questionnaire, hand it to whoever owns the answer offline, and import it back when it's done.
Track readiness and hand auditors what they ask for
Watch your readiness score and gap count move as answers and evidence come in, then generate a gap report, an evidence matrix, or a complete auditor bundle - built for the actual question an auditor asks: "show me the evidence."
Two Ways to Get a Questionnaire Answered
Not every question can be answered by a scan - organizational and policy controls need a person to answer them. Pentesterra gives you two ways to do that, and you can mix both within the same assessment.
Fill It Out Directly in the App
- -Every control is a row with quick Yes / Partly / No / N/A buttons - answer a simple item in one click
- -Open any row for full detail: what the control requires, what an auditor expects to see, and space for a fuller answer
- -Assign a control to a specific teammate and see who answered it, and when
- -Every standard you're tracking lives in the same interface, side by side - not a separate static form per framework
Export, Fill Offline, Import Back
- -One click exports the full questionnaire - one standard, or every standard you're tracking - to a spreadsheet
- -Hand it to whoever owns the answer - legal, a business unit, an outside consultant, a supplier - no login needed on their side
- -Import the completed file back in; answers merge straight into the same assessment, next to the automated evidence
- -Useful when the respondent works offline, or when different sections need different people answering in parallel
Where the Automatic Evidence Comes From
You're likely already doing the security work a compliance framework asks about. Pentesterra connects that work directly to the control that needs it, instead of asking you to describe it a second time in a questionnaire.
Vulnerability Scanning
Open ports, missing patches, weak TLS, exposed services and misconfigurations feed straight into the controls they speak to - no re-typing a scan result into a spreadsheet.
Pentest Modules
Verified findings from Web Pentest and Network Pentest cycles - the kind of proof an auditor actually wants to see, not a self-reported "yes".
OSINT
What's publicly discoverable about your organization - leaked credentials, exposed infrastructure, employee footprint - feeding the controls around external attack surface and information exposure.
External Exposure Assessments
Continuous outside-in monitoring of your domains and IP ranges - TLS posture, open relays, exposed admin panels, DNS/email hygiene - kept current automatically, not just at audit time.
DevGuard
Secrets, vulnerable dependencies, insecure configuration and supply-chain risk caught in your codebase and CI pipeline before release, mapped to the development-lifecycle controls that ask for exactly that.
Built for the Way Audits Actually Go
Not every control gets the same amount of scrutiny in a real audit, and not every piece of evidence agrees with every other piece. Pentesterra is built around both of those facts instead of pretending they away.
Auditor-Focus Flags
Controls that assessors consistently dig into, and follow up on, are starred and filterable to "auditor-focus only," each with a plain-language note on what to have ready - so preparation time goes to the questions that actually get asked, not spread evenly across every row.
Multiple Evidence Sources, Never Averaged Away
A single control can be evidenced by more than one module at once - a web pentest finding and an External Exposure check, say. If one source shows a gap, that's what's shown, even when another source for the same control looks fine. Nothing gets quietly rounded up to "met."
MITRE ATT&CK Mapping
Every control with automated technical evidence shows the ATT&CK technique IDs it relates to, linked straight through to attack.mitre.org - so a control reads as a real attack surface, not just a compliance line item.
Structure It However Your Organization Needs
Not every company tracking multiple standards wants them tracked the same way. Pentesterra supports both, and you can mix them across your organization.
One Standard, One Record
Create a standalone assessment for a single standard when it stands on its own - a different subsidiary, a different jurisdiction, a different scope of domains, or simply the only standard that applies right now. It behaves exactly like a normal assessment: its own score, its own export, its own auditor bundle.
Multiple Standards, One Engagement
When several standards apply to the same scope, bundle them into one engagement instead: NIS2, ISO 27001 and DORA as tabs under a single readiness dashboard, sharing target domains and cross-mapped answers, with one combined XLSX workbook and one rollup score across all of them.
Answer Once, Reuse Everywhere
Tracking more than one standard isn't more work per standard - the controls overlap, and Pentesterra carries a confirmed answer across every framework it applies to.
Confirm Once, Prefill Everywhere
Confirm an answer for NIS2 and the matching control in ISO 27001, DORA, GDPR, or TISAX prefills itself, clearly marked "prefilled from your NIS2 answer - confirm," so a second standard never means re-answering the same question from scratch.
One Score Across Every Standard You're Tracking
Add several standards under one engagement and get a single rollup dashboard - overall readiness, plus each standard's own score and gap count, without switching between separate assessments to see the whole picture.
Trigger a Scan Straight From a Gap
Find a control with no evidence yet, and kick off the External Exposure or pentest scan that would answer it directly from that row - no need to leave the assessment to go start one elsewhere.
Frequently Asked Questions
Do we still need to fill out a questionnaire ourselves?
For the organizational and policy questions - the ones only your team can answer, like who owns incident response or whether a supplier contract exists - yes, and that's expected. For the technical controls, Pentesterra fills them in automatically from your scanning, pentest, OSINT, external exposure, and DevGuard results, so you're only answering what genuinely requires a human.
Can we export the questionnaire and have someone else complete it offline?
Yes. Export the questionnaire for any standard, send it to whoever holds the answer - legal, IT, a supplier - and import it back into the platform once it's filled in. Everything lands back in the same assessment, alongside the automated evidence.
Which frameworks does Pentesterra support?
NIS2, GDPR, ISO/IEC 27001, ISO/IEC 27701, DORA, SOC 2, NIST CSF, PCI DSS, CMMC, TISAX (VDA ISA), the EU Cyber Resilience Act, HIPAA Security Rule, and NYDFS 23 NYCRR 500, with a guided wizard that tells you which ones are likely to apply based on your industry, country and company profile.
Does a high readiness score mean we're certified?
No, and we're explicit about that in the product. A readiness score is an indicative evidence base for an assessor or auditor to work from - it accelerates the audit, it doesn't replace it or issue a certification.
What does the auditor actually receive?
A one-click auditor bundle: the completed questionnaire, every piece of automated technical evidence, and a gap report showing what's met, partial, or still open - control by control, in the format an accredited auditor expects to review.
How do you decide which controls are flagged "auditor-focus"?
By what assessors actually spend their time on in a real audit, not an arbitrary weighting. Those controls are starred throughout the assessment, filterable on their own, and carry a plain-language note on what an auditor typically expects to see and follow up on - so preparation time goes where it's actually needed first.
What happens if two modules disagree about the same control?
Both pieces of evidence are shown, side by side, not merged into a single average. If a web pentest finding says a control has a gap while another module's check looks clean for the same control, the gap is what's surfaced - nothing gets quietly rounded up to "met" because most of the evidence looked fine.
If we track five standards, do we answer every overlapping question five times?
No. Confirming an answer on one standard prefills the same answer on every other standard whose control maps to it, clearly marked as prefilled from the source standard so it still gets a quick confirm rather than being accepted silently. The overlap is real work saved, not just a marketing number.
Should we track each standard separately, or combine them?
Either, and you can mix both across your organization. Create a standalone assessment when a standard stands on its own - a different subsidiary, a different scope. Bundle several standards into one engagement when they apply to the same scope - one shared dashboard, one rollup score, with cross-mapped controls answered once and reused across every standard in that engagement.





