Penetration testing for ISO 27001, SOC 2 and NIS2
Technical evidence for your assurance work, delivered in 10 working days.
Manual testing across roles and business workflows, backed by 19+ years in IT and security, published CVEs and CRTO certification.
A scoped penetration test can provide technical evidence for assurance work. Manual testing covers authorisation, business logic and chained attacks that an automated scan alone does not assess.
What the engagement includes
Executive and technical report
A concise executive section for management and detailed findings for engineers, including business risk, reproduction steps, evidence and remediation guidance.
Walkthrough with your team
I walk your developers through each finding, answer implementation questions and agree the evidence needed for the retest.
One retest included
Once fixes are ready, I retest them within 3 working days and issue an appendix recording what is fixed, partially fixed or still open.
Defined scope, fixed quote
| Service | What it covers | Turnaround |
|---|---|---|
| Web application pentest (single app) | Authenticated and unauthenticated, every role, and the API behind it | 10 working days |
| External infrastructure pentest | The full external perimeter and every public-facing asset | 7 working days |
| Verification retest | Included in every engagement | 3 days |
Typically booking 4–8 weeks out.
The quote is based on applications, roles, endpoints, integrations and environment. It includes reporting, the walkthrough and one retest. A later reassessment is quoted separately because scope and deployment can change.
See the deliverable before you buy
A full anonymised sample report: executive summary, findings mapped to ISO 27001 and SOC 2 controls, proof-of-concept and concrete remediation. No email required.
"We were preparing for our ISO 27001 certification and needed a proper pentest. Martín found issues that our previous vendor and automated scans had completely missed. Clear report, zero fluff, and he took the time to walk our devs through every fix."
Fintech client, ISO 27001 certification
The engagement behind this quote, with scope, findings and outcome: read the case study →
Public work you can verify
Published CVEs, open-source tools and a professional history you can review before sharing a scope.
Supporting a compliance program that needs technical testing?
I work as a technical partner. You keep the client relationship. I execute, and can deliver under your brand (white label) if you prefer.
How the partnership works →The questions auditors and buyers ask
Can the report support my audit?
It is designed for that purpose: it documents scope and methodology, maps relevant findings to ISO 27001 controls and SOC 2 criteria, and includes retest evidence. Your auditor decides whether the scope and evidence meet your specific requirements, so you can share the sample report with them before the engagement.
What if you don't find anything?
The report still records the tested scope, methodology and results. That can support assurance work even when no critical findings are identified; your auditor determines whether it satisfies the evidence required for your audit.
Do you sign an NDA?
Always, before any scoping call that touches sensitive information. I have a standard mutual NDA I can send, or I sign yours.
Do you test in production?
I normally begin in a representative staging environment with demo or synthetic data to reduce operational risk. Because production can differ in edge controls, integrations and configuration, we agree any production-safe validation explicitly in the rules of engagement.
What do you need from us to start?
The scope (which app or systems), access to the staging environment, and a couple of test accounts. We agree the rules of engagement in writing before anything begins.
Do you carry professional indemnity insurance?
Yes, professional indemnity cover specific to penetration testing work. I can send the certificate before we sign anything, and I am used to it being a procurement requirement, particularly when a consultancy is subcontracting the technical work.
Bring the system list and target date
In 30 minutes we can define the roles, environments, evidence requirements and next available testing window.
Book the scoping call →