COMPLIANCE

Penetration Testing That Satisfies Auditors

SOC 2, PCI-DSS, ISO 27001, and NIST CSF all require evidence of regular penetration testing. Pentesterra automates those cycles - generating per-finding PoCs, cycle reports, and auditor-ready evidence packages without manual coordination.

Supported Frameworks

SOC 2 Type II

CC6 - Logical accessCC7 - System operationsA1 - Availability

Automated pentests run on each audit cycle. Per-test evidence packages include scope, findings, validation proofs, and remediation status.

PCI-DSS v4

Req 11.3 - Pen testingReq 6.4 - Web app securityReq 11.4 - Intrusion detection

Quarterly automated scans + annual internal and external pentests. DevGuard maps code-level findings to PCI-DSS scope automatically.

ISO 27001 / 27002

A.8.8 - Vulnerability managementA.8.29 - Security testingA.8.16 - Monitoring

Continuous VM module feeds the ISMS risk register. Attack chain output documents residual risk with evidence per finding.

NIST CSF 2.0

ID.RA - Risk assessmentPR.PS - Platform securityDE.CM - Continuous monitoring

BAS cycles map to Identify/Protect/Detect functions. Findings include MITRE ATT&CK phase to satisfy DE.CM evidence requirements.

Evidence Artefacts per Audit Cycle

Per-finding PoC

Every verified vulnerability includes a proof-of-concept attached to the finding record.

Cycle-level report

PDF and JSON export per pentest cycle - scope, methodology, results, remediation status.

Delta reporting

Side-by-side comparison between cycles: new, resolved, and changed findings.

Remediation workflow

Jira / ServiceNow tickets auto-created from verified findings. Track closure in the platform.

Auditor export

One-click package containing all evidence artefacts for a given period - ready for auditor submission.

Continuous retesting

Re-run verification for any finding after a patch without triggering a full new scan cycle.

Take Control of Your Attack Surface.

Start with the free tier or talk to us about your environment - network, web, cloud, or on-prem.