Dunicot A cybersecurity consultancy and advisory firm.

Framework · ISO 27001 & ISMS

ISO 27001 penetration testing and ISMS support

ISO/IEC 27001 does not contain the words “penetration test”. It requires that technical vulnerabilities be identified and managed, that controls be verified as effective, and that the whole thing be evidenced. Testing is how organisations satisfy all three.

Overview

Testing delivered by a consultancy that runs a certified ISMS of its own, with findings written against the Annex A controls your auditor will ask about.

Framework reference

Standard
ISO/IEC 27001:2022, Information security management systems
Our own status
Dunicot Private Limited operates a certified ISO/IEC 27001 ISMS
Evidence
Certificate and scope statement provided on request under NDA
Relevant controls
A.8.8 technical vulnerability management, A.8.29 security testing in development and acceptance, A.5.36 conformance review
Clause link
Clause 9.1 monitoring and evaluation; Clause 8.1 operational planning and control
Cadence
Annually at minimum, plus after significant change, which is what most certification bodies expect

What the framework requires

Annex A.8.8 requires that information about technical vulnerabilities be obtained, exposure evaluated, and appropriate measures taken. An annual independent test, tracked to closure, is the cleanest evidence an auditor can be handed.

Annex A.8.29 requires security testing during development and acceptance. Pre-release testing of significant changes satisfies it, and the retest record shows the process operates rather than existing on paper.

Clause 9.1 asks how you evaluate control effectiveness. A report that shows which controls held under attack, not just which were documented, answers that question directly.

What the engagement delivers

01

Annex A control mapping

Every finding tagged with the Annex A controls it affects, so remediation slots straight into your risk treatment plan.

02

Risk-register-ready output

Findings expressed with likelihood, impact and treatment options in the shape your ISMS risk register already uses.

03

Retest attestation

A signed attestation showing findings raised, remediated and verified, which is the evidence artefact for the audit file.

04

Statement of applicability support

Where a control is marked applicable, the test evidences whether it is operating. Where excluded, the report shows what that exclusion leaves exposed.

05

Surveillance audit continuity

Testing scheduled against your certification cycle so evidence is current at each surveillance audit rather than a year stale.

06

Auditor-facing summary

A standalone document for the certification body containing scope, method, dates and outcomes with no exploitation detail.

Questions

Is Dunicot itself ISO 27001 certified?

Yes. Dunicot Private Limited operates a certified ISO/IEC 27001 information security management system. The certificate and its scope statement are provided to clients and prospects on request under NDA, along with the current statement of applicability. Handling your findings data under a certified ISMS is a material difference when that data is a list of live vulnerabilities in your platform.

Does ISO 27001 actually require a penetration test?

Not by name. It requires technical vulnerability management (A.8.8), security testing in development and acceptance (A.8.29) and evaluation of control effectiveness (Clause 9.1). Certification bodies consistently accept independent penetration testing as evidence for all three, and increasingly expect it for any organisation with a significant internet-facing estate.

How often do we need to test?

Annually as a baseline, plus after significant change to systems in scope. Organisations with continuous deployment commonly run one full annual engagement and shorter delta tests after major releases, which keeps evidence current across the three-year certification cycle.

Can you test before our first certification audit?

Yes, and earlier is better. Testing before the Stage 2 audit means findings are already remediated and evidenced when the auditor arrives, rather than becoming a nonconformity you are fixing under a deadline.

Do you help with the ISMS itself?

The focus is technical testing rather than ISMS consultancy. Reports are structured to drop into an existing ISMS: mapped to Annex A, sized for the risk register, and accompanied by the evidence artefacts auditors ask for.

How much does ISO 27001 penetration testing cost?

Cost follows scope rather than the certification. Annex A control mapping is included in the report rather than charged as an extra, and a fixed quote follows a short scoping call.

What evidence does an auditor actually want?

A dated, repeatable test with defined scope, documented methodology, evidence per finding, tracked remediation and verification that the remediation worked. The last part is what most reports lack, which is why retest and a signed attestation are included rather than optional.

Does testing need to cover everything in our ISMS scope?

Not necessarily, but the gap must be stated. Risk-based scoping is acceptable to certification bodies where the rationale is documented. What is not acceptable is a report that implies full coverage of a scope it never touched, so coverage is recorded per host.

Testing for your ISO 27001 & ISMS deadline

Tell us the audit date and the scope. Engagements are scheduled backwards from your deadline so remediation and retest both land inside it.