Skip to content
Compliance reporting

One test. The report in whichever framework is asking.

An assessment is only as useful as the evidence it produces. Vexil generates the same engagement as a technical report, an executive summary, or mapped to the requirement areas of the framework you are being assessed against.

Reporting

One engagement. Six deliverables.

The board wants a page. Your engineers want the request that proves it. Your auditor wants it in their framework. Generate each from the same test, in Word, PDF or Excel.

All severities including informational

Comprehensive

For Your engineering team

Every finding at every severity, with full technical detail, evidence and remediation guidance.

Medium and above

Executive summary

For Leadership and the board

Risk posture and the findings that matter at that altitude, with informational and low-severity observations excluded.

Low and above, with control mapping

PCI DSS v4.0

For Your QSA

Findings mapped to PCI DSS requirement areas, with the software weakness classes the standard enumerates at 6.2.4.

Low and above, with control mapping

SOC 2

For Your auditor

Findings mapped to the Trust Services Criteria, for the security evidence an examination asks for.

Low and above, with control mapping

ISO/IEC 27001:2022

For Your certification body

Findings mapped to Annex A control areas, supporting the technical testing evidence the standard expects.

Low and above, with control mapping

HIPAA Security Rule

For Your compliance officer

Findings mapped to the Security Rule safeguards, for the evaluation requirement under §164.308.

What a penetration test is, and is not. A penetration test is evidence that may support an assessment. It is not a certification or an attestation, and no report produced here claims to be one. Your assessor decides what satisfies the standard.

Control mapping

What the mapping does, and where it stops

A compliance section is only worth including if it can be relied on. Four rules make this one safe to hand to an assessor.

Every requirement area is listed

Including the ones with no findings against them. An area that is simply absent from a report reads as one that was assessed and passed, which is a claim this test cannot make.

Nothing is silently dropped

A finding the mapping cannot place is listed under an unmapped heading. A compliance report that quietly omits findings is indistinguishable from one where none were found.

Mapping is to requirement areas, not sub-requirements

The mapping is deliberately coarse - weakness class to requirement area. PCI is the tightest, because the standard itself enumerates the software weakness classes at 6.2.4. Your assessor makes the final determination.

The caveat ships in the document

Every framework report carries the statement that a penetration test is supporting evidence rather than a certification. It is in the file your auditor opens, not only on this page.

In every framework report: A penetration test is evidence that may support an assessment. It is not a certification or an attestation, and no report produced here claims to be one. Your assessor decides what satisfies the standard.

Formats

Three files, one engagement

Generated on demand, scoped to a whole project or a single application, over every finding or a selection you choose.

  • Word (.docx)

    The primary deliverable. Cover page, methodology, statistics, per-finding detail with evidence, and the compliance annex. Upload your own template and every Word report adopts it.

  • PDF

    The same document as a fixed-layout file, for distribution to people who should not be editing it.

  • Excel (.xlsx)

    Cover sheet, scope and dashboard, the full findings table and a risk rating sheet - plus a control mapping sheet on framework profiles. For teams that track remediation in a spreadsheet.

Compliance FAQ

Compliance questions, answered directly

Including the ones where the honest answer is “it depends on your assessor”.

Does a SOC 2 audit require a penetration test?

The Trust Services Criteria do not name penetration testing as a line item, but auditors routinely accept it as evidence for the criteria covering vulnerability identification and risk assessment, and many ask for it directly. A report mapped to the criteria makes that evidence straightforward to submit rather than something your team has to translate.

Does PCI DSS require a penetration test?

Yes. PCI DSS v4.0 requires external and internal penetration testing at least annually and after significant changes, under requirement 11.4. The standard also enumerates the software weakness classes that must be covered at 6.2.4, which is why the PCI profile maps findings against those areas specifically.

Does ISO 27001 require penetration testing?

ISO/IEC 27001:2022 does not mandate it by name, but Annex A includes controls on technical vulnerability management and secure development that penetration testing is the usual evidence for. The ISO profile groups findings under the relevant Annex A control areas so the link is explicit for your certification body.

Is this a certification?

No. A penetration test is evidence that may support an assessment. It is not a certification or an attestation, and no report produced here claims to be one. Your assessor decides what satisfies the standard. That statement appears inside every framework report as well as on this page.

Can we use our own report template?

Yes, for the Word deliverable. Upload a Word template and every Word report generated for your organisation adopts it, including the compliance mapping section - which is often what a firm reselling the assessment to its own customers needs. The PDF and the spreadsheet are generated from the same engagement but keep the house layout, so if your branding has to appear on all three, ask us on the call rather than assuming it.

What if a finding does not map to any control?

It is listed under an unmapped heading rather than dropped. Silently omitting a finding because the mapping could not place it is the one failure mode in a compliance report that could actually do harm, so the report shows it instead.

Tell us which framework you are being assessed against.

On the scoping call we will tell you what a penetration test can and cannot evidence for that standard, and give you a fixed price for the work that does.