COMPLIANCE

ISO 27001

ISO/IEC 27001 is the international standard for information security management systems. Annex A defines controls that organisations implement and assess, several of which require evidence of technical security testing. This page explains where testing fits in ISO 27001 and what auditors expect.

THE CERTIFICATION PROCESS

How does ISO 27001 certification work in practice?

ISO/IEC 27001 certification is awarded by an accredited certification body, not by a consultancy or the owner of the standard. The process has two stages. Stage 1 is a documentation review: the auditor examines the ISMS scope, risk assessment, Statement of Applicability, and policies to confirm the management system is suitably designed. Stage 2 is an operating-effectiveness audit: the auditor tests that the controls are actually implemented and operating as described, through interviews, evidence sampling, and observation. Certification is valid for three years, with annual surveillance audits confirming the ISMS continues to operate effectively, and a recertification audit at the end of the cycle.

What changed in ISO 27001:2022?

The 2022 revision restructured Annex A around 93 controls grouped under four themes — organisational, people, physical, and technological — replacing the 2013 version's 114 controls. It added controls for threat intelligence, cloud services, data masking, and secure development, and consolidated others. Organisations certified to the 2013 version were required to transition to the 2022 revision; any new certification or surveillance audit is now conducted against the 2022 Annex A.

How a readiness assessment works

A readiness engagement begins with a gap analysis against the Annex A controls in your ISMS scope, followed by risk assessment and risk treatment planning, control implementation guidance, and an internal audit that mirrors the certification body's approach. The output is a prioritised remediation roadmap and an evidence set aligned to your Statement of Applicability, so that Stage 1 and Stage 2 audits find the management system operating as described and the controls evidenced.

WHAT ISO 27001 REQUIRES

What does ISO 27001 require of our organisation?

ISO/IEC 27001 is the international standard for information security management systems (ISMS). It requires an organisation to define the scope of its ISMS, conduct a risk assessment, select and implement controls to treat those risks, and operate a management system that keeps the controls effective over time. Annex A defines 93 controls grouped under four themes; organisations document their applicability and justification in a Statement of Applicability.

Certification is awarded by an accredited certification body after a Stage 1 (documentation) and Stage 2 (operating effectiveness) audit, with annual surveillance audits thereafter. The standard does not mandate specific tools or frequencies; the ISMS risk assessment defines a risk-based approach to vulnerability management and testing within the risk treatment plan.

Which Annex A controls need testing evidence?

A.8.8 (technical vulnerability management) and A.8.29 (security testing in development and acceptance) are the clearest. A.8.27 (secure system architecture and engineering) and A.5.36 (compliance with policies and standards) may also reference testing depending on your scope and risk assessment.

How often should we test for ISO 27001?

ISO 27001 does not prescribe frequency. The ISMS risk assessment should define a risk-based testing cadence. Annual testing is common for in-scope systems, but higher-risk or rapidly changing systems may warrant more frequent testing aligned to the release cycle.

HOW TESTING MAPS TO ISO 27001

How does penetration testing map to ISO 27001 Annex A?

Penetration testing does not by itself achieve ISO 27001 certification. It provides evidence that specific Annex A controls are operating, particularly A.8.8 and A.8.29. Certification depends on the entire ISMS operating effectively, including risk assessment, management commitment, internal audit, and continual improvement.

Does penetration testing guarantee ISO 27001 certification?

No. Testing supports certification by evidencing specific controls, but certification depends on the full management system operating effectively. The certification decision is the accredited certification body's, made after Stage 1 and Stage 2 audits.

Should testing happen before the Stage 2 audit?

Yes. Testing should be completed with enough time to remediate findings before the Stage 2 audit, so auditors see verified controls. Surveillance audits also expect recent testing evidence within their observation window.

Which VariHunt services support which controls?

  • Web Application Penetration Testing supports A.8.8 and A.8.29 for web-facing applications.
  • Mobile Application Penetration Testing supports the same controls for mobile applications.
  • API Security Testing covers API surfaces under A.8.8 and A.8.27.
  • ISO 27001 Implementation & Audit Support delivers the gap analysis, risk treatment plan, and internal audit.
  • IT Security & Audit Services provides the broader posture assessment mapped to Annex A.

EVIDENCE

What evidence do certification auditors expect?

Certification auditors expect evidence aligned to your Statement of Applicability: test reports covering in-scope systems, a vulnerability management process with remediation tracking, and internal audit records. Reports should reference the relevant Annex A controls, include severity and remediation status, and show retest or verification of remediated findings.

What should the test report include for ISO 27001?

The report should define scope, rate findings by CVSS severity, map each finding to the relevant Annex A control, and include remediation status with retest evidence. Reports should be timed so results are current at Stage 2 and during surveillance audits, since evidence older than the audit window may need refreshing.

Is a retest included?

Yes. After remediation, a retest verifies that each fix resolves the original finding without introducing new weaknesses. Verified fixes are documented and an attestation letter is issued. The retest is included in the engagement price.

ENGAGEMENT STRUCTURE

How does VariHunt structure an ISO 27001 engagement?

An ISO 27001 engagement typically begins with a gap analysis against the Annex A controls in your scope, followed by risk assessment and risk treatment planning, control implementation guidance, and internal audit. The output is a prioritised remediation roadmap and evidence aligned to your Statement of Applicability.

What does the advisory deliverable contain?

The deliverable includes the gap analysis mapped to Annex A, the risk assessment and risk treatment plan, Statement of Applicability preparation, and internal audit results. Where testing is included, findings are mapped to the relevant controls with remediation status.

Do you work with our existing ISMS?

Yes. Where an ISMS exists, we align the engagement to it so testing and gaps map to your current controls and risk treatment. Where one does not exist, the advisory can include establishing the ISMS as part of the programme.

GETTING STARTED

What do we need to provide before an ISO 27001-aligned engagement?

Before starting, we need the ISMS scope, the in-scope systems and environments, and the certification stage and timeline. The Statement of Applicability and risk assessment, if available, help us align testing to your controls. Rules of engagement and points of contact are agreed during scoping.

Do you issue the ISO 27001 certificate?

No. Certification is issued by an accredited certification body after Stage 1 and Stage 2 audits. VariHunt provides implementation support and internal audit; the certification decision is the certification body's.

Can you help with the Statement of Applicability?

Yes. The ISO 27001 Implementation & Audit Support service includes risk assessment, risk treatment planning, and Statement of Applicability preparation aligned to the Annex A controls you determine applicable.

FAQ

Frequently asked questions

How long does ISO 27001 testing take?

Duration depends on the number of in-scope systems, the scope of the ISMS, and whether testing supports Stage 2 or a surveillance audit. A precise timeline is agreed during scoping and timed so results are current at the certification audit and within the surveillance observation window.

What methodology do you follow?

Testing follows OWASP WSTG for web and OWASP MASVS for mobile, with PTES informing scoping and reporting and CVSS v3.1 for severity. Findings are mapped to the relevant Annex A controls so auditors can trace evidence to the Statement of Applicability and the risk treatment plan.

Is a retest included?

Yes. After remediation, a retest verifies that each fix resolves the original finding without introducing new weaknesses. Verified fixes are documented and an attestation letter is issued. The retest is included in the engagement price and the engagement is not closed until complete.

What does the report contain?

The report includes an executive summary and a technical section. Each finding has its CVSS severity, proof of concept, root cause, and remediation guidance. Findings are mapped to the relevant Annex A controls, such as A.8.8 and A.8.29, with remediation status and retest evidence.

How does this map to ISO 27001?

Findings map to Annex A controls A.8.8 (technical vulnerability management) and A.8.29 (security testing in development), and where relevant A.8.27 and A.5.36. This lets certification auditors trace testing evidence to the controls in your Statement of Applicability and risk treatment plan.

What do you need from us before starting?

We need the ISMS scope, the in-scope systems and environments, the Statement of Applicability if available, and the certification stage and timeline. Rules of engagement and points of contact are agreed during scoping. Test accounts and written authorisation are confirmed before testing starts.

Discuss your compliance timeline

Book a scoping call to align testing with your audit or regulatory deadlines.