Skip to main content
New InterSec is now ISO/IEC 42001 certified for AI management systems Read the announcement
Compliance Penetration Testing · Audit-Ready Evidence

Compliance-Driven Penetration Testing

The penetration test your framework requires, scoped to the standard and documented as evidence your assessor will accept. We test with your framework in mind from day one, so the findings map to the control evidence your auditor expects.

A scanner tells you a port is open. It cannot tell you whether that finding satisfies PCI Requirement 11.4, or how to document it so a C3PAO or SOC 2 auditor will accept it. That is what our testers do.

Why InterSec

Federal & regulated pedigreeU.S. Courts, DIB, and public-sector work delivered
Evidence auditors acceptFindings mapped to the control, evidence attached
Certified offensive testersOSCP · CEH · CREST · GPEN
Scoped to your frameworkCMMC, FedRAMP, PCI, SOC 2, HIPAA, ISO 27001
Evidence for
CMMC / NIST 800-171 PCI DSS FedRAMP SOC 2 HIPAA ISO 27001
Framework requirements

Does your compliance framework require a penetration test?

Some frameworks name penetration testing as a hard requirement. Others require an outcome, like a risk assessment or ongoing monitoring, and a penetration test is one of the strongest ways to prove you have delivered it. Which camp your framework sits in tells you what you actually have to buy, and how often.

FrameworkPen test required?Typical frequencyWhat the rule actually says
PCI DSS Yes, explicitly At least every 12 months + after significant change Requirement 11.4 mandates internal (11.4.2) and external (11.4.3) penetration testing; service providers also validate segmentation every 6 months
FedRAMP (Moderate / High) Yes, explicitly Annual assessment + continuous monitoring Control CA-8, performed by a FedRAMP-recognized 3PAO
CMMC Level 2 / NIST SP 800-171 Not as a named control Periodic, set by your assessment cycle Requires periodic vulnerability scanning (3.11.2) and control-effectiveness assessment (3.12.1); a pentest is one method to evidence both
SOC 2 Not required by name Risk-based; commonly annual in practice Trust Services Criteria list pentesting as one example of the monitoring under CC4.1
HIPAA Not required Risk-based, tied to your risk cycle The Security Rule requires a risk analysis and periodic evaluation; a pentest is a recognized method
ISO/IEC 27001:2022 Not explicitly required Risk-based; commonly annual in practice Annex A.8.8 and A.8.29 require the outcome; ISO 27002 recommends pentesting as one route

Two of these six name a penetration test outright. The other four require an outcome a good penetration test proves, on a cadence driven by risk rather than a fixed calendar. In every case the test is worth running; the difference is whether you are meeting a mandate or building evidence, and that changes how we scope and write it up.

Frameworks change over time, and how each applies depends on your contracts and environment. Use this page to get oriented, then confirm the specifics with your compliance or legal team before you scope an engagement.

Framework by framework

Penetration testing for each framework

The same testing supports every framework. What changes is the scope, the documentation, and the evidence each assessor expects.

CMMC

CMMC & NIST 800-171

Home turf. CMMC Level 2 is measured against NIST SP 800-171, which calls for periodic vulnerability scanning (3.11.2) and a control-effectiveness assessment (3.12.1) rather than a named pentest. We run the testing that produces that evidence and prepare you for your C3PAO, and our federal record includes red team and penetration testing for the Administrative Office of the U.S. Courts. It pairs with our CMMC compliance checklist.

FedRAMP

FedRAMP

For Moderate and High cloud systems, control CA-8 requires penetration testing at least annually, performed by a FedRAMP-recognized 3PAO and following published attack-vector guidance. We scope to the FedRAMP model from the outset, so the report maps to your System Security Plan and supports your authorization package instead of creating a second round of work.

SOC 2

SOC 2

SOC 2 does not mandate a pentest. The Trust Services Criteria list it as one example of the monitoring under CC4.1, so the cadence is risk-based rather than fixed. Most organizations run one anyway, because auditors expect the evidence and it clears security questionnaires fast. Weighing a scan against a full test? Our vulnerability assessment services page explains where each one fits.

PCI

PCI DSS

The clearest case of the six. Requirement 11.4 explicitly requires internal and external testing at least every 12 months and after any significant change, on a documented methodology such as NIST SP 800-115. We scope to your cardholder data environment, test the segmentation PCI cares about, and document the result so your QSA can use it directly.

HIPAA

HIPAA & ISO 27001

Neither names penetration testing, but both require the security outcome it demonstrates, on a cadence set by risk rather than a fixed calendar. HIPAA's Security Rule calls for a risk analysis and periodic evaluation; ISO 27001 Annex A.8.8 and A.8.29 call for vulnerability management and security testing. We scope to the risk you need to evidence and write the report to slot into your risk analysis or ISMS.

How we deliver

What makes a compliance pentest different

The testing follows recognized methodologies (NIST SP 800-115, the OWASP guides, PTES, with attacker behavior mapped to MITRE ATT&CK). Our penetration testing services page covers the full engagement; what sets a compliance pentest apart is everything wrapped around it.

Scoped to the framework, not just the network

We agree up front on what your assessor needs to see, so the test boundary matches your compliance scope. A PCI test centers on the cardholder data environment; a CMMC test focuses on the systems that handle controlled unclassified information.

A report built for your auditor

Executives get the business-risk summary, engineers get the reproduction steps and the fix, and your assessor gets each finding mapped to the control it satisfies, with evidence attached.

Retesting after you remediate

A finding is not closed until we have verified the fix held. That verification is often the artifact an auditor most wants to see, because it proves the loop actually closed.

Independent by design

InterSec sells services, not software, so there is no product to steer you toward. For frameworks that require an independent tester, that independence is part of what makes the evidence count.

Federal proof. InterSec ran red team and penetration testing in a federal judicial environment, keeping 22 interconnected systems continuously authorized.

Read the U.S. Courts case study
Frequently asked

Compliance penetration testing questions, answered

Does SOC 2 require a penetration test?

No. The SOC 2 Trust Services Criteria do not require a penetration test. They list it as one example of the ongoing monitoring under criterion CC4.1. Most service organizations run one anyway, because auditors expect that evidence and customers ask for it.

Does CMMC require a penetration test?

Not as a named control. CMMC Level 2 is assessed against NIST SP 800-171 Revision 2, which requires periodic vulnerability scanning and a periodic assessment of control effectiveness, not a penetration test specifically. A pentest is one of the strongest ways to produce that evidence before your C3PAO assessment.

Does HIPAA require a penetration test?

No. The HIPAA Security Rule requires a risk analysis and a periodic evaluation of your safeguards. It does not mandate penetration testing, though a pentest is a recognized way to find the technical risks your risk analysis needs to address.

How often do compliance frameworks require penetration testing?

For the frameworks that require it, the cadence is generally at least once a year and again after any significant change to your systems. PCI DSS and FedRAMP both work on an annual cycle. Frameworks that do not require a test outright are usually satisfied by that same annual rhythm.

Can one penetration test cover more than one framework?

Often, yes, if we scope it that way from the start. The underlying testing overlaps heavily across frameworks. The difference is in the documentation and the scope boundaries, so we plan a multi-framework engagement to produce the evidence each assessor needs from a single body of work.

Who is allowed to perform a compliance penetration test?

It depends on the framework. FedRAMP requires a recognized 3PAO. PCI DSS requires an organizationally independent tester. Others simply expect a qualified, independent professional. Because InterSec sells services rather than software, our testers meet the independence bar these frameworks care about.

Does InterSec issue our compliance certification or CMMC result?

No, and no legitimate partner can promise that. For CMMC Level 2, only an authorized C3PAO accredited through The Cyber AB issues the result, and the government issues Level 3. InterSec prepares you for the assessment and produces the evidence, so you walk in ready.

Talk to a compliance pentest specialist

Tell us which framework you answer to and where you are in the process. We will map the testing and the evidence to what your assessor expects, and show you exactly what you will receive before any testing begins.

Booked through Microsoft Bookings · NDA on request · Zero obligation
  • Testing scoped to your framework's boundaries
  • Findings mapped to each control, with evidence attached
  • Executive and technical reporting, plus a live debrief
  • Retesting to confirm your fixes held