PXL Security LTD, Sofia, Bulgaria Offensive security since 2014[email protected]

Compliance-Driven Pen Testing

The penetration test your audit requires.

Many frameworks mandate regular, independent penetration testing. We deliver that test — scoped to the control, documented for the auditor, and retested — so you arrive at the audit with evidence, not a gap.

Testing, mapped to your controls

We're a testing firm, not an auditor — and that's the point. We perform the independent penetration test the framework requires, then map each finding to the relevant control so your assessor can sign it off with confidence.

Reports are structured for ISO 27001, SOC 2, PCI DSS, DORA and NIS2 evidence, and the retest letter documents closure.

Frameworks we support

  • ISO 27001 testing requirements
  • SOC 2 penetration-testing evidence
  • PCI DSS Requirement 11 testing
  • DORA threat-led and standard testing
  • NIS2 risk-management measures
  • Customer security questionnaires

How it works

  1. Map the requirement

    We align scope to what your framework actually mandates.

  2. Test

    Manual testing to the standard, with evidence.

  3. Document for audit

    Findings mapped to controls, in audit-ready form.

  4. Retest and attest

    We verify fixes and issue a closure letter.

What you receive

Clear deliverables, agreed in the proposal, with no surprises at the end of the engagement.

  • Audit-ready reportStructured for your framework's evidence requirements.
  • Control mappingEach finding tied to the relevant control.
  • Prioritised fixesDeveloper-ready remediation, ranked by risk.
  • Retest letterWritten confirmation of closure for your assessor.

Let's scope your compliance-driven pen testing.

Send a short description of your environment and goals. A senior tester, not a salesperson, will reply with questions, a proposed approach and a quote.

Prefer email? Write to [email protected]. We reply within one business day.