COMPLIANCE

Compliance Backed by Real Evidence, Not Guesswork

NIS2, GDPR, ISO 27001, DORA and every other framework your business needs to satisfy all ask the same underlying question: can you prove it? Pentesterra fills in every technical control it can answer itself - straight from your vulnerability scans, pentests, OSINT, External Exposure Assessments and DevGuard results - and gives you a clean, quick way to handle the rest: fill it out in the app, or export the questionnaire, get it completed offline, and import it back.

13 frameworks
NIS2, GDPR, ISO 27001/27701, DORA, SOC 2, NIST CSF, PCI DSS, CMMC, TISAX, CRA, HIPAA, NYDFS 500
5 evidence sources
Vulnerability scanning, pentests, OSINT, External Exposure, DevGuard
Auditor bundle
One click, ready for submission

Standards We Cover

Not sure which ones apply to you? Tell us your industry and country and Pentesterra's applicability wizard shows you exactly which standards you're likely on the hook for - mandatory or voluntary - before you commit to filling out a single control.

NIS2
CIR 2024/2690 baseline security measures
GDPR
Security & breach-readiness articles
ISO/IEC 27001:2022
Full Annex A control catalogue
DORA
ICT risk management for financial entities
SOC 2
Trust Services Criteria
NIST CSF
Identify / Protect / Detect / Respond / Recover
PCI DSS
Cardholder data environment controls
CMMC
DoD supply-chain security levels
TISAX (VDA ISA)
Automotive supplier information security
EU Cyber Resilience Act
Security requirements for products with digital elements
HIPAA Security Rule
Safeguards for electronic protected health information
NYDFS 23 NYCRR 500
Cybersecurity for NY-regulated financial institutions
ISO/IEC 27701:2019
Privacy extension to ISO 27001 (PIMS)

Pentesterra vs. the Traditional Way

DimensionSpreadsheet / GRC Tool / ConsultantPentesterra Compliance
Technical controlsSelf-attested "yes" in a spreadsheet, taken on faithAuto-filled from real scans, pentests, OSINT, DevGuard - with the evidence attached
Which frameworks applyGuess, or pay a consultant to tell youBuilt-in applicability wizard based on industry, country and company profile
FreshnessCollected once before the audit, stale by the time it's reviewedRe-checked automatically as your scans, pentests and exposure monitoring update
Filling it outOne rigid spreadsheet, hard to split across peopleFill in-app or export/import - mix both, assign controls to teammates
Multiple frameworksA separate spreadsheet or GRC module per standard, re-mapped by hand13 frameworks in one workspace, technical evidence shared across them
Auditor deliverableManually assembled from a dozen tools and screenshots the week beforeOne-click bundle: questionnaire, evidence, and gap report, ready to submit
What to prepare firstEvery control gets equal attention, or noneControls assessors dig into are flagged "auditor-focus" ahead of time
SetupA separate GRC platform, integrations to build and maintainThe platform you already scan and pentest with - nothing extra to stand up

See It in the Product

GDPR assessment showing each article as a row with quick Yes / Partly / No / N/A buttons, an auto-evidence indicator, and Export questionnaire / Import filled actions in the toolbar
Answer a control in one click - Yes / Partly / No / N/A - or export the whole questionnaire and import it back once it's filled in offline.
Pentesterra Compliance module listing multiple assessments and standards - ISO 27001, GDPR, DORA, NIS2 - each with its own answered/in-progress status
Every standard you're tracking, in one place - pick a scope, add as many standards as apply, and work through them side by side.
New assessment wizard asking industry sector, country and company profile, then recommending applicable standards such as GDPR and ISO 27001
Not sure where to start? Answer a few questions about your business and get a straight answer on which standards apply to you, and why.
A technical control for network segmentation automatically marked as met, with automated evidence from External Exposure Assessments attached
A technical control answered and evidenced automatically - no one had to log in and manually confirm it.
Assessment overview showing an indicative readiness score out of 100, with counts of controls met, partial, gap and not yet assessed, and a completion progress bar
Watch readiness climb as answers and evidence come in - met, partial, and gap counts, always visible, never buried in a spreadsheet.
A configuration management control flagged as an auditor-focus item, with a note that assessors consistently examine this control in depth, MITRE ATT&CK technique chips, and two separate automated evidence lines - a web pentest gap alongside a covered external exposure check
An auditor-focus control: the plain-language note on what assessors dig into, MITRE ATT&CK technique chips, and two different modules' evidence shown side by side, one a gap, one covered, not averaged away.

How It Works

1

Pick the standards that apply to you

Tell Pentesterra your industry, country, and a few basics about your business, and it shows you which frameworks you're actually likely to need - NIS2, DORA, GDPR, ISO 27001, and more - so you're not guessing which ones matter.

2

Let the platform fill in what it already knows

The moment an assessment is scoped to your domains and infrastructure, every technical control that can be answered from scanning, pentesting, OSINT, external exposure monitoring, and DevGuard is filled in automatically, with the evidence attached.

3

Fill in the rest, your way

Answer the remaining organizational and policy questions directly in the app - quick Yes / Partly / No / N/A on simple items, full detail where an auditor needs it - or export the questionnaire, hand it to whoever owns the answer offline, and import it back when it's done.

4

Track readiness and hand auditors what they ask for

Watch your readiness score and gap count move as answers and evidence come in, then generate a gap report, an evidence matrix, or a complete auditor bundle - built for the actual question an auditor asks: "show me the evidence."

Two Ways to Get a Questionnaire Answered

Not every question can be answered by a scan - organizational and policy controls need a person to answer them. Pentesterra gives you two ways to do that, and you can mix both within the same assessment.

Fill It Out Directly in the App

  • -Every control is a row with quick Yes / Partly / No / N/A buttons - answer a simple item in one click
  • -Open any row for full detail: what the control requires, what an auditor expects to see, and space for a fuller answer
  • -Assign a control to a specific teammate and see who answered it, and when
  • -Every standard you're tracking lives in the same interface, side by side - not a separate static form per framework

Export, Fill Offline, Import Back

  • -One click exports the full questionnaire - one standard, or every standard you're tracking - to a spreadsheet
  • -Hand it to whoever owns the answer - legal, a business unit, an outside consultant, a supplier - no login needed on their side
  • -Import the completed file back in; answers merge straight into the same assessment, next to the automated evidence
  • -Useful when the respondent works offline, or when different sections need different people answering in parallel

Where the Automatic Evidence Comes From

You're likely already doing the security work a compliance framework asks about. Pentesterra connects that work directly to the control that needs it, instead of asking you to describe it a second time in a questionnaire.

Vulnerability Scanning

Open ports, missing patches, weak TLS, exposed services and misconfigurations feed straight into the controls they speak to - no re-typing a scan result into a spreadsheet.

Pentest Modules

Verified findings from Web Pentest and Network Pentest cycles - the kind of proof an auditor actually wants to see, not a self-reported "yes".

OSINT

What's publicly discoverable about your organization - leaked credentials, exposed infrastructure, employee footprint - feeding the controls around external attack surface and information exposure.

External Exposure Assessments

Continuous outside-in monitoring of your domains and IP ranges - TLS posture, open relays, exposed admin panels, DNS/email hygiene - kept current automatically, not just at audit time.

DevGuard

Secrets, vulnerable dependencies, insecure configuration and supply-chain risk caught in your codebase and CI pipeline before release, mapped to the development-lifecycle controls that ask for exactly that.

Built for the Way Audits Actually Go

Not every control gets the same amount of scrutiny in a real audit, and not every piece of evidence agrees with every other piece. Pentesterra is built around both of those facts instead of pretending they away.

A configuration management control flagged as an auditor-focus item, with a note that assessors consistently examine this control in depth, MITRE ATT&CK technique chips, and two separate automated evidence lines - a web pentest gap alongside a covered external exposure check
An auditor-focus control: the plain-language note on what assessors dig into, MITRE ATT&CK technique chips, and two different modules' evidence shown side by side, one a gap, one covered, not averaged away.

Auditor-Focus Flags

Controls that assessors consistently dig into, and follow up on, are starred and filterable to "auditor-focus only," each with a plain-language note on what to have ready - so preparation time goes to the questions that actually get asked, not spread evenly across every row.

Multiple Evidence Sources, Never Averaged Away

A single control can be evidenced by more than one module at once - a web pentest finding and an External Exposure check, say. If one source shows a gap, that's what's shown, even when another source for the same control looks fine. Nothing gets quietly rounded up to "met."

MITRE ATT&CK Mapping

Every control with automated technical evidence shows the ATT&CK technique IDs it relates to, linked straight through to attack.mitre.org - so a control reads as a real attack surface, not just a compliance line item.

Structure It However Your Organization Needs

Not every company tracking multiple standards wants them tracked the same way. Pentesterra supports both, and you can mix them across your organization.

One Standard, One Record

Create a standalone assessment for a single standard when it stands on its own - a different subsidiary, a different jurisdiction, a different scope of domains, or simply the only standard that applies right now. It behaves exactly like a normal assessment: its own score, its own export, its own auditor bundle.

Multiple Standards, One Engagement

When several standards apply to the same scope, bundle them into one engagement instead: NIS2, ISO 27001 and DORA as tabs under a single readiness dashboard, sharing target domains and cross-mapped answers, with one combined XLSX workbook and one rollup score across all of them.

Answer Once, Reuse Everywhere

Tracking more than one standard isn't more work per standard - the controls overlap, and Pentesterra carries a confirmed answer across every framework it applies to.

Confirm Once, Prefill Everywhere

Confirm an answer for NIS2 and the matching control in ISO 27001, DORA, GDPR, or TISAX prefills itself, clearly marked "prefilled from your NIS2 answer - confirm," so a second standard never means re-answering the same question from scratch.

One Score Across Every Standard You're Tracking

Add several standards under one engagement and get a single rollup dashboard - overall readiness, plus each standard's own score and gap count, without switching between separate assessments to see the whole picture.

Trigger a Scan Straight From a Gap

Find a control with no evidence yet, and kick off the External Exposure or pentest scan that would answer it directly from that row - no need to leave the assessment to go start one elsewhere.

Frequently Asked Questions

Do we still need to fill out a questionnaire ourselves?

For the organizational and policy questions - the ones only your team can answer, like who owns incident response or whether a supplier contract exists - yes, and that's expected. For the technical controls, Pentesterra fills them in automatically from your scanning, pentest, OSINT, external exposure, and DevGuard results, so you're only answering what genuinely requires a human.

Can we export the questionnaire and have someone else complete it offline?

Yes. Export the questionnaire for any standard, send it to whoever holds the answer - legal, IT, a supplier - and import it back into the platform once it's filled in. Everything lands back in the same assessment, alongside the automated evidence.

Which frameworks does Pentesterra support?

NIS2, GDPR, ISO/IEC 27001, ISO/IEC 27701, DORA, SOC 2, NIST CSF, PCI DSS, CMMC, TISAX (VDA ISA), the EU Cyber Resilience Act, HIPAA Security Rule, and NYDFS 23 NYCRR 500, with a guided wizard that tells you which ones are likely to apply based on your industry, country and company profile.

Does a high readiness score mean we're certified?

No, and we're explicit about that in the product. A readiness score is an indicative evidence base for an assessor or auditor to work from - it accelerates the audit, it doesn't replace it or issue a certification.

What does the auditor actually receive?

A one-click auditor bundle: the completed questionnaire, every piece of automated technical evidence, and a gap report showing what's met, partial, or still open - control by control, in the format an accredited auditor expects to review.

How do you decide which controls are flagged "auditor-focus"?

By what assessors actually spend their time on in a real audit, not an arbitrary weighting. Those controls are starred throughout the assessment, filterable on their own, and carry a plain-language note on what an auditor typically expects to see and follow up on - so preparation time goes where it's actually needed first.

What happens if two modules disagree about the same control?

Both pieces of evidence are shown, side by side, not merged into a single average. If a web pentest finding says a control has a gap while another module's check looks clean for the same control, the gap is what's surfaced - nothing gets quietly rounded up to "met" because most of the evidence looked fine.

If we track five standards, do we answer every overlapping question five times?

No. Confirming an answer on one standard prefills the same answer on every other standard whose control maps to it, clearly marked as prefilled from the source standard so it still gets a quick confirm rather than being accepted silently. The overlap is real work saved, not just a marketing number.

Should we track each standard separately, or combine them?

Either, and you can mix both across your organization. Create a standalone assessment when a standard stands on its own - a different subsidiary, a different scope. Bundle several standards into one engagement when they apply to the same scope - one shared dashboard, one rollup score, with cross-mapped controls answered once and reused across every standard in that engagement.

Take Control of Your Attack Surface.

Talk to us about your environment - network, web, cloud, or on-prem.