Compliance pentest
Pentest scoping by framework and industry
Practical guides for CISOs scoping penetration testing under DORA, NIS2, ISO 27001, SOC 2 and PCI DSS. Each guide focuses on a single regulator citation and a single industry, with concrete examples and an honest fit assessment.
ISO 27001
ISO/IEC 27001:2022 Information Security Management
- ISO 27001 pentest for banking: what auditors expect from credit institutions in 2026ISO 27001:2022 does not mandate penetration testing, but certification auditors expect it, and DORA governs the ICT resilience banks still hold ISO 27001 to reassure counterparties. How credit institutions scope pentest for Annex A.8.8, A.8.29, and the supplier controls.
- ISO 27001 pentest for ecommerce: what auditors expect in 2026ISO 27001:2022 does not name penetration testing, but auditors expect it. How ecommerce merchants scope pentest for Annex A.8.8, A.8.29, and PII protection across checkout, cart, and payment integrations.
- ISO 27001 pentest for payments: what auditors expect from PIs, EMIs, and PSPsISO 27001:2022 does not mandate penetration testing, but payment-sector auditors expect it. How payment institutions, e-money issuers, and PSPs scope pentest for Annex A.8.8 and A.8.29 alongside PCI DSS and DORA.
- ISO 27001 pentest for fintech: dual-certification path with DORAFintechs pursuing ISO 27001:2022 in parallel with DORA Article 24 face overlapping testing obligations. How to scope one pentest programme that satisfies both auditors and saves the test-fatigue burn.
- ISO 27001 pentest for healthcare: scoping for health-SaaS and EHR vendors selling to EU hospitalsHealth-SaaS and EHR vendors pursuing ISO 27001:2022 face hospital procurement gating on the cert. How to scope pentest with ISO 27799 health-overlay + MDR-adjacent boundaries in mind.
- ISO 27001 pentest for SaaS: what auditors expect in 2026ISO 27001:2022 does not mandate penetration testing, but auditors expect it. How SaaS companies scope pentest for Annex A.8.8, A.8.29, and the technical-vulnerability controls.
NIS2
Network and Information Security Directive 2
- NIS2 pentest for ecommerce: scoping Article 21 testing for online marketplaces and suppliersNIS2 catches ecommerce mainly through online marketplaces and via supply-chain obligations under Article 21.2(d). How ecommerce CISOs scope pentest as evidence for Article 21 risk-management measures.
- NIS2 pentest for SaaS: when B2B software falls in scope and what Article 21 requiresNIS2 (Directive (EU) 2022/2555) pulls many B2B SaaS into scope as important or essential entities. How SaaS CISOs decide scope and evidence pentest against Article 21(2)(e) and 21(2)(f).
- NIS2 pentest for healthcare: scoping resilience testing where IT meets patient safetyNIS2 classifies healthcare providers as essential entities under Annex I sector 5. How hospital and medical-device CISOs scope pentest where IT systems overlap with patient safety and MDR/IVDR jurisdiction.
- NIS2 pentest for telecom: scoping resilience testing for digital infrastructureNIS2 classifies fixed and mobile network operators as essential entities under Annex I sector 8. How telecom CISOs scope pentest across the IT, OSS/BSS, and signalling boundaries.
- NIS2 pentest for transport: scoping resilience testing for rail, aviation, and road operatorsNIS2 classifies transport operators as essential entities under Annex I sector 2. How transport CISOs scope pentest across the IT and OT-signalling boundary in rail, aviation, and road networks.
- NIS2 pentest for water: scoping resilience testing for drinking and waste-water operatorsNIS2 classifies drinking-water and waste-water operators as essential entities under Annex I sector 1. How water-utility CISOs scope pentest at the IT, OT, and SCADA boundary.
- NIS2 pentest for energy: scoping resilience testing for an essential entityNIS2 Article 21 requires risk-based security testing for energy operators classified as essential entities. How energy CISOs map testing to OT, IT, and ICS boundaries.
PCI DSS
Payment Card Industry Data Security Standard 4.0
- PCI DSS pentest for fintech: scope reduction and the Requirement 11.4 tests that remainFintechs that touch card data (card issuing, wallets, BaaS, embedded finance) minimize PCI scope with tokenization, but PCI DSS 4.0 Requirement 11.4 pentest obligations rarely disappear. How to scope them.
- PCI DSS pentest for payments: scoping Requirement 11.4 for payment institutions, PSPs, and acquirers-issuersPCI DSS 4.0 names penetration testing as a literal control. For payment institutions, PSPs, gateways, and acquirers-issuers, the question is not whether to test but how to scope the CDE, set cadence, and validate segmentation under Requirement 11.4.
- PCI DSS pentest for ecommerce: scoping testing for Level 1 to Level 4 merchantsPCI DSS 4.0 Requirement 11.4 mandates annual external pentesting and after every significant change. How ecommerce merchants scope it based on transaction volume tier.
SOC 2
AICPA SOC 2 Trust Services Criteria
- SOC 2 pentest for ecommerce: what commerce-platform SaaS needs for Type IISOC 2 Type II auditors expect penetration testing as evidence for CC4.1, CC7.1, CC7.2, and CC8.1. How commerce-platform SaaS, subscription billing, and marketplace backends scope testing across the observation period.
- SOC 2 pentest for healthcare: how health-tech SaaS turns testing into Type II evidenceSOC 2 Type II auditors accept penetration testing as primary evidence for CC7.1 and CC4.1. How EHR vendors, telehealth platforms, and digital-health SaaS scope testing when PHI raises the bar.
- SOC 2 pentest for fintech: dual-track testing for EU fintech selling to US enterpriseEU fintechs selling into US enterprise customers face SOC 2 Type II as a procurement gate. How to scope pentest that satisfies SOC 2 CC4.1-CC8.1 while reusing DORA Article 24 evidence.
- SOC 2 pentest for SaaS: a practical 2026 guide for fast-shipping teamsSOC 2 Type II auditors expect penetration testing as evidence for CC4.1, CC7.1, and CC7.2. How fast-shipping SaaS teams scope testing without slowing releases.
DORA
Digital Operational Resilience Act
- DORA pentest for banking: a practical 2026 guide for credit-institution CISOsDORA Article 24-27 plus the SSM/EBA supervisory expectations make pentest scoping in banking different from fintech. How credit institutions scope baseline testing, TLPT designation likelihood, and ICT third-party participation.
- DORA pentest for insurance: scoping resilience testing for undertakings and IORPsDORA applies to insurance undertakings, reinsurance undertakings, and IORPs above the size thresholds. How insurance-sector CISOs scope pentest where Solvency II ORSA + DORA Article 24 stack.
- DORA pentest for payments: scoping resilience testing for PIs, EMIs, and acquirersDORA plus PSD2 plus PCI DSS layer cybersecurity requirements on payment institutions and e-money issuers. How payment-sector CISOs scope pentest where TLPT designation hits hardest.
- DORA pentest for fintech: a practical 2026 guide for CISOsDORA Article 24-27 demands resilience testing and threat-led pentests. How fintech CISOs scope it, who must do TLPT, and how continuous AI pentesting fits the regulation.
Need pentest scoping for a framework or industry not listed?Book a demo