Comprehensive
For Your engineering team
Every finding at every severity, with full technical detail, evidence and remediation guidance.
Reporting
The board wants a page. Your engineers want the request that proves it. Your auditor wants it in their framework. Generate each from the same test, in Word, PDF or Excel.
For Your engineering team
Every finding at every severity, with full technical detail, evidence and remediation guidance.
For Leadership and the board
Risk posture and the findings that matter at that altitude, with informational and low-severity observations excluded.
For Your QSA
Findings mapped to PCI DSS requirement areas, with the software weakness classes the standard enumerates at 6.2.4.
For Your auditor
Findings mapped to the Trust Services Criteria, for the security evidence an examination asks for.
For Your certification body
Findings mapped to Annex A control areas, supporting the technical testing evidence the standard expects.
For Your compliance officer
Findings mapped to the Security Rule safeguards, for the evaluation requirement under §164.308.
What a penetration test is, and is not. A penetration test is evidence that may support an assessment. It is not a certification or an attestation, and no report produced here claims to be one. Your assessor decides what satisfies the standard.
Control mapping
A compliance section is only worth including if it can be relied on. Four rules make this one safe to hand to an assessor.
Including the ones with no findings against them. An area that is simply absent from a report reads as one that was assessed and passed, which is a claim this test cannot make.
A finding the mapping cannot place is listed under an unmapped heading. A compliance report that quietly omits findings is indistinguishable from one where none were found.
The mapping is deliberately coarse - weakness class to requirement area. PCI is the tightest, because the standard itself enumerates the software weakness classes at 6.2.4. Your assessor makes the final determination.
Every framework report carries the statement that a penetration test is supporting evidence rather than a certification. It is in the file your auditor opens, not only on this page.
In every framework report: A penetration test is evidence that may support an assessment. It is not a certification or an attestation, and no report produced here claims to be one. Your assessor decides what satisfies the standard.
Formats
Generated on demand, scoped to a whole project or a single application, over every finding or a selection you choose.
The primary deliverable. Cover page, methodology, statistics, per-finding detail with evidence, and the compliance annex. Upload your own template and every Word report adopts it.
The same document as a fixed-layout file, for distribution to people who should not be editing it.
Cover sheet, scope and dashboard, the full findings table and a risk rating sheet - plus a control mapping sheet on framework profiles. For teams that track remediation in a spreadsheet.
Compliance FAQ
Including the ones where the honest answer is “it depends on your assessor”.
The Trust Services Criteria do not name penetration testing as a line item, but auditors routinely accept it as evidence for the criteria covering vulnerability identification and risk assessment, and many ask for it directly. A report mapped to the criteria makes that evidence straightforward to submit rather than something your team has to translate.
Yes. PCI DSS v4.0 requires external and internal penetration testing at least annually and after significant changes, under requirement 11.4. The standard also enumerates the software weakness classes that must be covered at 6.2.4, which is why the PCI profile maps findings against those areas specifically.
ISO/IEC 27001:2022 does not mandate it by name, but Annex A includes controls on technical vulnerability management and secure development that penetration testing is the usual evidence for. The ISO profile groups findings under the relevant Annex A control areas so the link is explicit for your certification body.
No. A penetration test is evidence that may support an assessment. It is not a certification or an attestation, and no report produced here claims to be one. Your assessor decides what satisfies the standard. That statement appears inside every framework report as well as on this page.
Yes, for the Word deliverable. Upload a Word template and every Word report generated for your organisation adopts it, including the compliance mapping section - which is often what a firm reselling the assessment to its own customers needs. The PDF and the spreadsheet are generated from the same engagement but keep the house layout, so if your branding has to appear on all three, ask us on the call rather than assuming it.
It is listed under an unmapped heading rather than dropped. Silently omitting a finding because the mapping could not place it is the one failure mode in a compliance report that could actually do harm, so the report shows it instead.
On the scoping call we will tell you what a penetration test can and cannot evidence for that standard, and give you a fixed price for the work that does.