[ ISO 27001 penetration testing ]
Pentest evidence for ISO 27001.On every release.
AI agents that find vulnerabilities in your web apps, APIs, and infrastructure. Continuously, so A.8.8 is a running process at every surveillance audit, not a report from last year.
See first findings in 24 hours
Built by the team that secured:
Built by the team that secured:
[ what ISO 27001 asks ]
What the controls ask,and what a run gives you.
ISO 27001:2022 does not mandate a penetration test either. These are the controls where certification auditors expect to see one.
4 covered by every run · 2 shared with your assessor
A.8.8 · Technical vulnerabilities
Information about vulnerabilities obtained, exposure evaluated, measures taken (A.12.6.1 in the 2013 edition). Continuous testing with each finding tracked from open to verified fix, in a report per run.
covered by every run
Evidence to keep: report per release, remediation log
A.8.29 · Testing in development
Security testing defined and carried out in development and acceptance (A.14.2.8 and A.14.2.9 in 2013). Every pull request reviewed and every release tested as it ships.
covered by every run
Evidence to keep: PR reviews, release reports
A.5.35 and A.5.36 · Independent review
Independent review of information security and compliance with policies. Autonomous agents outside the team, proving each finding with a working exploit.
covered by every run
Evidence to keep: the report, plus who ran it
Clause 6.1.2 and the SoA · Scope and risk
Testing scope has to match the ISMS scope in the Statement of Applicability, and findings have to reach the risk register. The two gaps auditors cite most. You set the scope; the findings arrive tagged by asset.
shared with your assessor
Evidence to keep: scope statement, risk register entries
Clauses 9.1 and 10.1 · Improvement
Monitoring, measurement, and continual improvement of the ISMS, shown at every surveillance audit. Dated reports across releases, with remediation time visible as a trend.
covered by every run
Evidence to keep: run history, time to fix
The certificate
Whether the ISMS conforms is the certification body's decision, and it covers far more than testing. Parameter supplies the evidence for the technical controls above.
shared with your assessor
Evidence to keep: none; this is the auditor's
[ how it works ]
Connect
A repository, a URL with test accounts, or a read-only cloud role. Testing starts within hours. No scoping call, no engagement to book.
Test every release
Agents test the running app, the code behind it, the cloud it runs on, and the packages it depends on, as different users, every time you ship. Every finding is exploited before it is reported.
Hand over the run
Each run produces a report with scope, method, findings, proof, and remediation status. Re-tests happen on fix, so the evidence is never older than the last release.
[ definition ]
Does ISO 27001 require a penetration test?
Not in so many words. ISO 27001:2022 requires managed technical vulnerabilities (A.8.8), security testing in development and acceptance (A.8.29), and independent review (A.5.35). Certification bodies expect a penetration test as the evidence for those controls, and they expect it to be current at each surveillance audit. Parameter's agents test every release and produce a report from each run, so the evidence is never older than your last deployment.
[ FAQ ]
Frequently asked questionsabout ISO 27001 penetration testing
[ explore ]
Keep reading.The platform, and other frameworks.
AI penetration testing
How the agents work, what they cover, reports, and pricing.
Read more
SOC 2 penetration testing
What a SOC 2 auditor expects from penetration testing, clause by clause, and how a run on every release supplies it.
Read more
PCI pentest
What PCI DSS v4.0 Requirement 11.4 asks, what a QSA wants, and where continuous testing fits alongside the annual test.
Read more
FedRAMP penetration testing
What FedRAMP requires of penetration testing, the 3PAO's role, and how continuous testing supports continuous monitoring.
Read more
Not sure which fits?
Tell us what you are shipping and we will scope the test in minutes.
Book a call
Start testing today.
A URL and credentials is all it takes.
First findings land within 24 hours.
















