iso27001pentest.com

ISO/IEC 27001 · testing and audit evidence

Scope a test

About iso27001pentest.com

Updated

iso27001pentest.com covers one narrow question and its consequences: what security testing ISO/IEC 27001 actually calls for, and what an accredited auditor will accept as evidence. Readers making certification decisions need to know where guidance comes from, so the provenance is set out here.

Publisher

The site is published by SEQ SIA (reg. No. 40203410806), Lastādijas iela 12 k-3, Riga, LV-1050, Latvia, trading as OffSeq, a provider of penetration testing and security assurance services. Contact: support@offseq.com.

OffSeq is not an accredited certification body. It does not issue ISO/IEC 27001 certificates and is not affiliated with ISO, the IEC, the International Accreditation Forum, ENISA or any national accreditation body. Nothing here is an official interpretation of any standard.

Authorship

SEQ SIA (OffSeq) is responsible for publishing, maintaining and updating this site. Articles use team attribution. Every guide lists its sources so a reader can check the basis for the guidance rather than take it on trust.

How the guidance is sourced

  • Regulatory statements cite the instrument itself. Commission Implementing Regulation (EU) 2024/2690 and Directive (EU) 2022/2555 are quoted from the EUR-Lex text.
  • Certification-process facts, including the three-year cycle and the surveillance and recertification audit-time proportions, are cited to the published IAF mandatory documents.
  • ISO/IEC 27001:2022 clause and Annex A control references are used as identifiers, corroborated where possible against the ENISA technical implementation guidance mapping table. The normative text of the ISO standards is copyright and is not reproduced here. iso.org blocks automated retrieval, so no ISO page is cited as a fetched source, and no sentence on this site is presented as a quotation from a standard.
  • Procurement figures come from the TED search API, with the query terms and the date the counts were taken printed alongside them.
  • Where a widely repeated number is unreliable, we say so. The ISO Survey 2024 certificate figures are printed with the note that the survey changed its collection method that year, because the year-on-year jump is largely a measurement change.
  • The “Updated” date only moves when the text changes. An automated content-hash ledger reverts unearned bumps.

What this site refuses to say

The single most common error in this subject area is asserting that ISO/IEC 27001 mandates penetration testing. It does not, and several pages currently ranking for the term say otherwise. This site will not repeat that claim to make a sale, and it names the controls where a penetration test is the wrong instrument as explicitly as the ones where it is the right one.

Commercial interest

We sell the testing and readiness work this site describes. That is a direct interest in you concluding that you need it, and it should colour how you read every recommendation here.

  • Links to OffSeq are our own service links, not a market comparison. We do not rank or score competing providers or certification bodies.
  • No vendor, tool, platform or certification body pays for a mention. There is no advertising and no affiliate revenue.
  • Where a control does not need a test, we say so, including when that means a smaller engagement or none at all.

Not advice

This site is not legal advice and is not a substitute for your own risk assessment, your Statement of Applicability, or engagement with your certification body. Whether a control applies to you, and what evidence satisfies it, is a decision for your organization and your auditor.

Corrections

Send corrections to support@offseq.com. Substantive changes are made and re-dated in the open. If we have a clause reference wrong, we would rather hear it than keep it.