ISO 27001 pentest

Independent technical validation for your ISMS and external audit

Get an ISO 27001 pentest

Working toward first-time ISO 27001 certification? Preparing for a recertification audit or transition audit to ISO 27001:2022? Does your ISMS lead auditor require independent technical validation? For all these situations a pentest provides concrete evidence that your security measures actually work.

DongIT delivers ISO 27001 pentests specifically aligned with the Annex A controls from ISO 27001:2022. Findings are mapped to the relevant controls (A.8.8, A.8.20, A.8.29, A.5.35 and more) so you receive a report directly usable for your internal ISMS and external audit.

Our pentests are performed by OSCP-certified ethical hackers under our four-eyes principle. Reporting via our self-developed Security Reporter platform. CCV Keurmerk-accredited. Data stays in Europe. DongIT is itself ISO 27001:2022-certified since 2015.

What we test in an ISO 27001 pentest

An ISO 27001 pentest assesses your applications, infrastructure and networks against the technical Annex A controls of ISO 27001:2022. We explicitly map every finding to the relevant control, so your auditor has standardized evidence directly available.

  • A.8.8 Management of technical vulnerabilities. Active identification and testing of known vulnerabilities in software, systems and configurations.
  • A.8.20 through A.8.22 Network security. Network security, security of network services and segmentation between network segments.
  • A.8.25 Secure development life cycle. Assessment of whether secure development practices are visible in the delivered applications.
  • A.8.26 Application security requirements. Concrete validation of functional and non-functional security requirements in your applications.
  • A.8.28 Secure coding. Testing for common coding errors such as injection, XSS, IDOR and authorization bypasses.
  • A.8.29 Security testing in development and acceptance. Demonstrable implementation of security testing as part of your development and acceptance processes.
  • A.5.35 Independent review of information security. Independent technical review of security measures by an external party.

For organizations that need to cover both ISO 27001 and other frameworks (NIS2, DigiD, DORA) we can double-map findings to multiple frameworks in a single report.

Our approach: from pentest to audit evidence

We follow a structured approach aligned with how ISO 27001 audits work. Every step delivers evidence you can use for your internal ISMS and external auditor.

  1. Scope alignment with your ISMS

    We align the pentest scope with your ISMS scope, Statement of Applicability (SoA) and risk analysis. This ensures the pentest covers the right components for your audit.

  2. Technical pentest

    Manual testing by OSCP-certified ethical hackers under our four-eyes principle, supplemented with automated tooling. Testing per NIST, OWASP and NCSC guidelines.

  3. Reporting with Annex A mapping

    Delivery via Security Reporter. Every finding mapped to the relevant ISO 27001:2022 Annex A control, with CVSS scoring and remediation guidance. Auditor-ready.

  4. Remediation support

    We optionally support your team with interpreting findings and prioritizing remediation within your ISMS Plan-Do-Check-Act cycle.

  5. Retest and audit support

    Formal retest of resolved vulnerabilities. During external audits we can be present to answer technical questions from your auditor directly.

Pentest as part of your PDCA cycle

ISO 27001 is based on the Plan-Do-Check-Act cycle. A pentest provides concrete input to multiple phases of your ISMS:

  • Plan (risk analysis). Pentest findings expose technical vulnerabilities that theoretical risk analysis often leaves invisible.
  • Do (implementation). Our recommendations support concrete implementation of technical security measures.
  • Check (evaluation). A pentest demonstrates whether implemented measures actually work against realistic attack scenarios.
  • Act (adjustment). Findings feed continuous improvement of your ISMS with concrete corrective actions.

For organizations with a mature ISMS we recommend at least annual pentesting, with additional tests after significant changes to architecture or scope.

Combining with other compliance engagements

For many organizations, ISO 27001 overlaps with other compliance frameworks. We can structure your pentest engagement more efficiently by covering multiple frameworks in parallel:

ISO 27001 and NIS2

For essential and important entities that need both ISO 27001 certification and NIS2 reporting. Findings double-mapped to Annex A and article 21 Dutch Cybersecurity Act.

More about NIS2 pentest

ISO 27001 and DigiD

For government organizations with both ISO 27001 certification and a DigiD connection. One coordinated engagement covering both assessment requirements.

More about DigiD pentest

ISO 27001 and DORA

For financial entities with both ISO 27001 and DORA obligations. Pentest findings mapped to both frameworks, including preparation for TIBER-NL.

Request DORA pentest

ISO 27001 and NEN 7510

For healthcare organizations and healthcare IT vendors. Combination of ISO 27001 technical assessment with NEN 7510-specific healthcare controls.

Request NEN 7510 pentest

ISO 27001 and BIO2

For Dutch government organizations combining ISO 27001 with BIO2. Directly usable for ENSIA reporting.

Request BIO2 pentest

ISO 27001 and customer requirements

Enterprise clients increasingly require both ISO 27001 certification and concrete pentest reporting as a condition. We deliver reporting you can share directly.

Request a quotation

What does an ISO 27001 pentest cost?

The price depends on the size of your ISMS scope, the number of systems and applications and any combined scopes with other compliance frameworks. For clearly defined engagements we offer standard packages. For more complex engagements with multiple systems or combined compliance scopes we work with a scoping conversation and a tailored quotation.

  • Quick Pentest, €2,960 excl. VAT
  • Expert Pentest, from €5,040 excl. VAT (most chosen)
  • Extensive Pentest, from €7,200 excl. VAT
  • Enterprise and multi-scope engagements, tailored quotation

ISMS scope as starting point

For every ISO 27001 engagement we start with a scoping conversation covering your ISMS boundaries, Statement of Applicability and risk analysis. This ensures full coverage.

Frequently asked questions about ISO 27001 pentesting

Below are the most frequently asked questions about the ISO 27001 pentest. For a complete overview please visit our FAQ page.

Do you work with ISO 27001:2013 or ISO 27001:2022?

We work per ISO 27001:2022. The transition period from 2013 to 2022 expired on 31 October 2025, so all active certifications must now be on the 2022 version. Findings are mapped to the new Annex A structure (93 controls in 4 categories).

Is DongIT itself ISO 27001-certified?

Yes. DongIT has been ISO 27001:2022-certified since 2015 and maintains continuous certification through annual audits. We know first-hand how an audit works from the inside and which evidence your auditor values.

Which Annex A controls do you cover in a pentest?

The technical Annex A controls from ISO 27001:2022, including A.5.35 (independent review), A.8.8 (technical vulnerabilities), A.8.20 through A.8.22 (network security), A.8.25 through A.8.29 (secure development and testing). Which controls are specifically relevant depends on your scope and SoA.

How often should I have a pentest performed for ISO 27001?

ISO 27001 does not prescribe a specific frequency, but the standard does require "demonstrable technical validation" of security measures. Market standard is annually, with additional tests after significant changes to architecture, scope or threat landscape. Your certification body often provides clarity on expectations in practice.

Can a pentest help with my first certification audit?

Yes. For first-time certification we recommend a pentest in the early phase of certification preparation, so you have time to resolve findings before the audit. We can align reporting with what certification bodies (KPMG, DNV, LRQA and others) typically expect.

What if there are critical findings during audit preparation?

For critical findings you receive an interim report with remediation prioritization. Our specialists can support with interpretation and resolution. Formal retest confirms that fixes actually work, so you can approach your audit with confidence.

Do you work together with certification bodies?

We are independent and not affiliated with a specific certification body. Our reports meet the standards used by all major certification bodies. We are however familiar with the specific focus areas of various bodies and can account for them.

How long does an ISO 27001 pentest take?

Active testing time ranges from 32 hours for a compact ISMS scope to 120 hours or more for extensive multi-scope engagements. Total duration from scoping conversation to final report is typically 4 to 8 weeks, longer for larger engagements.

Ready for your ISO 27001 audit?

Working toward first-time certification, recertification or transition audit to 2022? We start with a complimentary scoping conversation covering your ISMS boundaries and audit planning. Response within one business day. Quotation within three business days.