Penetration testing that satisfies your framework
Most of our clients are being assessed against one or more compliance frameworks. Our engagements are designed to produce the exact evidence those assessments require — a credible test, severity-rated findings, and a remediation retest that closes the item.
SOC 2 (Type I & II)
The requirement
Auditors expect periodic penetration testing as part of your security-monitoring controls.
How an OnSecOps engagement satisfies it
We provide the report and the remediation-retest evidence your auditor files against the Trust Services Criteria — for both Type I and Type II examinations.
HIPAA Security Rule
The requirement
The Security Rule requires periodic evaluation of the safeguards protecting ePHI (§164.308(a)(8)).
How an OnSecOps engagement satisfies it
We test the technical safeguards across your application and infrastructure and document the results as evidence for the evaluation requirement.
ISO 27001
The requirement
Annex A requires technical vulnerability management (A.12.6 in 2013 / A.8.8 in the 2022 revision).
How an OnSecOps engagement satisfies it
Independent penetration-testing evidence demonstrates that technical vulnerabilities are identified and managed — a control your certification body looks for.
PCI-DSS
The requirement
Requirement 11.4 mandates penetration testing of in-scope cardholder-data environments.
How an OnSecOps engagement satisfies it
We scope and test the in-scope environment and deliver the report and retest that satisfy the 11.4 testing requirement.
GDPR
The requirement
Article 32 requires a process for regularly testing the effectiveness of technical measures.
How an OnSecOps engagement satisfies it
A recurring penetration test demonstrates you test the effectiveness of your security of processing — exactly what Article 32(1)(d) calls for.
A note on accuracy. OnSecOps is not a certification body. We support these frameworks and provide the evidence auditors and reviewers ask for — the independent test, the report, the control mapping, and the retest. The certification or attestation itself is issued by your auditor.
Turn your next pen-test into audit evidence.
Book a 30-minute call and we'll map the right engagement to the framework you're being assessed against.
Book a Discovery Call