Parameter

[ ISO 27001 penetration testing ]

Pentest evidence for ISO 27001.On every release.

AI agents that find vulnerabilities in your web apps, APIs, and infrastructure. Continuously, so A.8.8 is a running process at every surveillance audit, not a report from last year.

See first findings in 24 hours

Built by the team that secured:

Apple
Google
Microsoft
U.S. Department of Defense
T-Mobile
Henkel
Epic Games
AT&T
Yahoo

[ what ISO 27001 asks ]

What the controls ask,and what a run gives you.

ISO 27001:2022 does not mandate a penetration test either. These are the controls where certification auditors expect to see one.

4 covered by every run · 2 shared with your assessor

A.8.8 · Technical vulnerabilities

Information about vulnerabilities obtained, exposure evaluated, measures taken (A.12.6.1 in the 2013 edition). Continuous testing with each finding tracked from open to verified fix, in a report per run.

covered by every run

Evidence to keep: report per release, remediation log

A.8.29 · Testing in development

Security testing defined and carried out in development and acceptance (A.14.2.8 and A.14.2.9 in 2013). Every pull request reviewed and every release tested as it ships.

covered by every run

Evidence to keep: PR reviews, release reports

A.5.35 and A.5.36 · Independent review

Independent review of information security and compliance with policies. Autonomous agents outside the team, proving each finding with a working exploit.

covered by every run

Evidence to keep: the report, plus who ran it

Clause 6.1.2 and the SoA · Scope and risk

Testing scope has to match the ISMS scope in the Statement of Applicability, and findings have to reach the risk register. The two gaps auditors cite most. You set the scope; the findings arrive tagged by asset.

shared with your assessor

Evidence to keep: scope statement, risk register entries

Clauses 9.1 and 10.1 · Improvement

Monitoring, measurement, and continual improvement of the ISMS, shown at every surveillance audit. Dated reports across releases, with remediation time visible as a trend.

covered by every run

Evidence to keep: run history, time to fix

The certificate

Whether the ISMS conforms is the certification body's decision, and it covers far more than testing. Parameter supplies the evidence for the technical controls above.

shared with your assessor

Evidence to keep: none; this is the auditor's

[ how it works ]

Connect

A repository, a URL with test accounts, or a read-only cloud role. Testing starts within hours. No scoping call, no engagement to book.

Test every release

Agents test the running app, the code behind it, the cloud it runs on, and the packages it depends on, as different users, every time you ship. Every finding is exploited before it is reported.

Hand over the run

Each run produces a report with scope, method, findings, proof, and remediation status. Re-tests happen on fix, so the evidence is never older than the last release.

[ definition ]

Does ISO 27001 require a penetration test?

Not in so many words. ISO 27001:2022 requires managed technical vulnerabilities (A.8.8), security testing in development and acceptance (A.8.29), and independent review (A.5.35). Certification bodies expect a penetration test as the evidence for those controls, and they expect it to be current at each surveillance audit. Parameter's agents test every release and produce a report from each run, so the evidence is never older than your last deployment.

[ FAQ ]

Frequently asked questionsabout ISO 27001 penetration testing

Start testing today.

A URL and credentials is all it takes.

First findings land within 24 hours.