Compliance frameworks we test against
Most US organizations commission testing because an auditor, an enterprise customer or an insurer asked. We scope so one engagement produces evidence for every framework you answer to.
SOC 2
Independent testing evidence for the Common Criteria and the vendor questionnaires that gate enterprise deals.
PCI DSS 4.0
Requirement 11.4 internal and external testing, plus segmentation validation where you rely on it.
HIPAA
The technical half of a Security Rule risk analysis for providers, payers and digital health.
CMMC 2.0
NIST SP 800-171 and DFARS evidence for defense contractors handling controlled unclassified information.
FedRAMP
Penetration testing to the PMO attack vectors for cloud services pursuing federal authorization.
NIST CSF
Something measured rather than asserted to report under the Identify and Protect functions.
ISO 27001
Annex A 8.29 verification evidence for organizations certifying to the 2022 revision.
GDPR
Article 32 regular testing of technical measures, for US firms handling EU personal data.
PTES
The Penetration Testing Execution Standard — the methodology our engagements are built on.
Testing for a specific audit?
Tell us the framework and the deadline. We will scope the engagement to the evidence your assessor needs.