By requirement
The test your framework actually asks for.
Regulations and standards describe testing in very different terms. For each one, here is what it really expects from security testing, how often, and the evidence your auditor or assessor will want to see.
DORA & threat-led penetration testing
What DORA's resilience-testing chapter asks of financial entities, from yearly testing of critical systems to threat-led penetration testing every three years.
What it asks of testingNIS2 cybersecurity risk-management and security testing
What NIS2 Article 21 means for security testing: showing that your cybersecurity risk-management measures work, including across your supply chain.
What it asks of testingPCI DSS penetration testing
Penetration testing scoped to PCI DSS v4.0.1 Requirement 11.4: internal, external, segmentation and retesting, with evidence your assessor can follow.
What it asks of testingISO/IEC 27001 penetration testing
Security testing that gives ISO/IEC 27001:2022 controls such as 8.8, 8.29 and 5.35 real evidence, without pretending the standard mandates a pentest.
What it asks of testingSOC 2 (AICPA Trust Services Criteria)
Penetration testing scoped to your SOC 2 system description and audit period, with criteria mapping and a retest letter your auditor can review.
What it asks of testingMulti-framework penetration testing: one test, many audits
One annual penetration test, scoped and reported so a single evidence pack supports ISO 27001, SOC 2, PCI DSS, DORA, NIS2 and customer questionnaires.
What it asks of testingWho decides what counts
PXL Security is an independent offensive-security firm, not an auditor, assessor, certification body or regulator. We deliver the testing and the evidence; your auditor, assessor or competent authority decides what they accept. This page is general guidance, not legal advice.
Tell us which requirement you're testing for.
Send a short description of your environment and goals. A senior tester, not a salesperson, will reply with questions, a proposed approach and a quote.