The penetration test
your auditor asks for
Every framework on this page requires independent security testing, and every auditor has an opinion about what makes that testing count. We deliver the report built to their standard: scoped to the boundary, severity rated, remediated, retested to closure and signed.
0
Frameworks covered
0%
Findings retested on request
0h
Critical finding escalation
What XHack delivers
Independent penetration testing scoped to the framework
Findings rated with CVSS v4.0 and mapped to the controls
Remediation support, then an independent retest to closure
A signed attestation letter your auditor files as evidence
What we do not do
Issue certificates, attestation opinions or regulatory approvals
Run your compliance programme, policies or risk assessments
Replace your CPA firm, certification body, QSA or regulator
Claim to make you compliant on the strength of one test
Staying independent of the people who certify you is precisely what makes our evidence worth something to them.
Frameworks
Find the clause you are being asked about
Each framework has its own page covering the exact requirement that drives the testing, what your auditor checks, what we test and what lands in the report.
What makes a report count
Auditors reject penetration tests for predictable reasons
The framework changes. The reasons a report gets pushed back do not. Every engagement we run is built to clear all six of these before it reaches your auditor.
Independent
Performed by a third party with no involvement in building or running the systems tested. Self-assessment does not count for any of these frameworks.
Scoped to the boundary
The test covers what the auditor thinks it covers: the system description, the CDE, the ISMS boundary or the authorization boundary.
Timed correctly
Testing dates inside the review period, and early enough that findings can be closed before it ends.
Manually validated
Every finding proven through safe exploitation. Raw scanner output gets challenged, and rightly so.
Retested to closure
The single thing most reports get wrong. Findings must be fixed and independently verified, not just listed.
Signed and attested
A letter of attestation from the testing firm, stating scope, dates, independence and the retest result.
How an engagement runs
Four steps, whichever framework you name
The clause changes. The work does not. The third step is the one most reports skip, and the one auditors care about most.
Step 1
Scope
We read your system description, CDE definition or ISMS boundary and scope the test to match it exactly, under signed rules of engagement.
Step 2
Test
Grey-box testing to PTES, OWASP WSTG and NIST SP 800-115. Every finding manually validated, anything critical escalated the day we find it.
Step 3
Remediate and retest
Your engineers fix, we re-run the original proof of concept and mark each finding resolved only when it genuinely is.
Step 4
Attest
A report mapped to the framework controls, with a signed attestation letter your auditor files as evidence.
One engagement, several audits
The testing is shared, the mapping is not
Chasing three certifications does not mean three penetration tests. The underlying work is largely the same. What differs is scope, cadence and which controls each finding maps to, and that part is just careful reporting.
| Framework | Clause that drives testing | Named outright | Cadence |
|---|---|---|---|
| SOC 2 | CC4.1 and CC7.1 | Expected | At least annually |
| PCI DSS | Requirement 11.4 | Explicit | At least every 12 months and after significant change. Segmentation every 12 months |
| ISO 27001 | A.8.8, A.8.29 and clause 9.1 | Expected | At least annually |
| GDPR | Article 32(1)(d) | Explicit | Regularly |
| HIPAA | §164.308(a)(8) and §164.308(a)(1)(ii)(A) | Expected | Periodically |
| ISO 42001 | Annex A verification and validation, with AI impact assessment | Expected | Before release and at least annually |
| AI Maturity Assessment | No external mandate | Expected | Every 6 to 12 months |
| TX-RAMP | NIST SP 800-53 CA-8 and RA-5 | Explicit | At least annually |
| NBFC / SECP | SECP cybersecurity advisories and digital lending circulars | Explicit | At least annually |
Pursuing more than one? Say so at scoping. We widen the scope once, test once, and produce mapping for each framework you name. It is materially cheaper than running the same test three times, and your evidence stays consistent across every audit.
Questions
Compliance testing, answered
No, and any firm that says otherwise is overselling. Compliance is a programme you run: policies, risk assessments, controls, training and governance. What we provide is the independent security testing evidence that every one of these frameworks requires, in the form the auditor accepts. That is one specific, critical piece of the picture, and it is the piece most teams cannot produce internally.
Someone independent of us, always. SOC 2 opinions come from licensed CPA firms. ISO certificates come from accredited certification bodies. PCI attestations come from QSAs. TX-RAMP certification comes from Texas DIR. Regulatory approvals come from the regulator. Our independence from those parties is exactly what makes our testing evidence credible to them.
Usually, yes. The underlying testing is much the same. What changes is scope, cadence and how findings are mapped. We scope one engagement against every framework you need and map the findings to each, so a single report and retest cycle serves multiple audits instead of repeating the work.
We change it. Different auditors want different scope statements, attestation wording, mapping tables or evidence formats. Tell us who is assessing you and we match their requirements, and we answer their follow-up questions during fieldwork directly.
Typically two to four weeks of testing depending on scope, then remediation at your pace, then a retest. The attestation letter follows the retest. The most common scheduling mistake is testing too late in the review period to leave room for closing findings.
You hear about it that day, not in the report six weeks later. Critical findings are escalated to your named contact within 24 hours under the rules of engagement, so you can start fixing immediately.
Tell us who is auditing you
Thirty minutes is enough to work out which clause you are being held to, what the scope should be, and when to test so findings can close before your review period ends.