Compliance & reporting

Penetration testing that satisfies your framework

Most of our clients are being assessed against one or more compliance frameworks. Our engagements are designed to produce the exact evidence those assessments require — a credible test, severity-rated findings, and a remediation retest that closes the item.

SOC 2 (Type I & II)

The requirement

Auditors expect periodic penetration testing as part of your security-monitoring controls.

How an OnSecOps engagement satisfies it

We provide the report and the remediation-retest evidence your auditor files against the Trust Services Criteria — for both Type I and Type II examinations.

HIPAA Security Rule

The requirement

The Security Rule requires periodic evaluation of the safeguards protecting ePHI (§164.308(a)(8)).

How an OnSecOps engagement satisfies it

We test the technical safeguards across your application and infrastructure and document the results as evidence for the evaluation requirement.

ISO 27001

The requirement

Annex A requires technical vulnerability management (A.12.6 in 2013 / A.8.8 in the 2022 revision).

How an OnSecOps engagement satisfies it

Independent penetration-testing evidence demonstrates that technical vulnerabilities are identified and managed — a control your certification body looks for.

PCI-DSS

The requirement

Requirement 11.4 mandates penetration testing of in-scope cardholder-data environments.

How an OnSecOps engagement satisfies it

We scope and test the in-scope environment and deliver the report and retest that satisfy the 11.4 testing requirement.

GDPR

The requirement

Article 32 requires a process for regularly testing the effectiveness of technical measures.

How an OnSecOps engagement satisfies it

A recurring penetration test demonstrates you test the effectiveness of your security of processing — exactly what Article 32(1)(d) calls for.

A note on accuracy. OnSecOps is not a certification body. We support these frameworks and provide the evidence auditors and reviewers ask for — the independent test, the report, the control mapping, and the retest. The certification or attestation itself is issued by your auditor.

Turn your next pen-test into audit evidence.

Book a 30-minute call and we'll map the right engagement to the framework you're being assessed against.

Book a Discovery Call