Skip to content
Pentesys
Knowledge Base

Compliance&Assurance

Very few standards name penetration testing as a mandatory control, but auditors, customers and insurers ask for it anyway. These articles cover where testing supports ISO 27001, PCI DSS, SOC 2 and UK GDPR, what assessors typically want as evidence, and how to answer supplier assurance questions without handing over exploitable detail.

All articles

12 articles

Compliance & Assurance

Third-Party Security Validation Testing

Independent validation of a supplier's security controls: what it covers, how it differs from an audit, and when it is worth asking for.

Read article
Compliance & Assurance

Cybersecurity Due Diligence in M&A

What technical due diligence covers during an acquisition, how much can realistically be done pre-completion, and what changes deal terms.

Read article
Compliance & Assurance

GDPR Article 32 and Security Testing

Article 32 requires regular testing of security measures without naming a method. How penetration testing can help evidence that obligation.

Read article
Compliance & Assurance

PCI DSS Penetration Testing Requirements

If you’re still treating your annual audit as a checkbox exercise, you’re likely missing the strategic shift toward continuous security validation….

Read article
Compliance & Assurance

Protecting Special Category Data

Where special category data tends to leak — logs, exports, integrations, access control — and what to test when your systems hold it.

Read article
Save time and book a call with us

Enterprise-grade penetration testing, built around your business

CREST-registered testing delivered through a flexible PTaaS model — designed to fit your environment, risk profile and internal teams.