Using a Penetration Test as ISO/IEC 27001 Audit Evidence
Annex A 8.8 and 8.29 are where a test report becomes audit evidence — provided the scope, timing and independence line up.
Accredited in the United States, Canada and South Korea. Management system certification, GRC compliance, and manual penetration testing for 4,000+ organizations across 20+ countries.
Certification proves your controls are designed well. Penetration testing proves they hold. We do both, and we keep them independent of each other.
Accredited certification across QMS, EMS, ISMS, OHSMS, FSMS and more, delivered through our network of accredited CABs.
ExploreSOC, PCI DSS, GDPR and HIPAA frameworks to align strategy, risk and regulatory obligations.
ExploreExemplar Global-approved lead auditor training and personnel certification programs.
ExploreIndustry skill and discipline certifications accredited from Exemplar Global, United States.
ExploreCertification proves your controls are designed well. Penetration testing proves they hold when somebody attacks them. Our offensive security team tests web applications, APIs, iOS and Android builds by hand — and reports findings in the form your SOC 2, PCI DSS, HIPAA and ISO 27001 auditors ask for.

Cetonix has been certifying management systems since 2008, accredited in the United States (UAF), Canada (SCC) and South Korea (KAB). Auditors on our panel have logged more than 15,000 audit days across 4,000+ engagements we have coordinated in 20+ countries. In 2024 we added an offensive security practice.
Accredited certification across the full spectrum of international management system standards, arranged through CABs accredited for each scope.
Quality Management System
Environmental Management
Occupational Health & Safety
Information Security
Food Safety Management
Medical Devices QMS
Energy Management
Anti-Bribery Management
IT Service Management
Four stages, with fixed scope and a named lead at each one.
We understand your needs and expectations, gather initial information and agree the proposal and excellence roadmap.
We assess the maturity of your management system, deliver auditor and personnel training, and help close gaps before the CAB’s audit.
The appointed accredited CAB audits the implemented system and makes the certification decision. We manage non-conformity closure with you and see the certificate through to issue.
The CAB conducts surveillance and re-assessment audits on its cycle. We coordinate scheduling and keep the programme on track.
Begin an accredited certification or find the right register to verify an existing certificate.
Enroll in Exemplar Global auditor training or verify a training certificate.
Technical writing on penetration testing, compliance and certification.
Annex A 8.8 and 8.29 are where a test report becomes audit evidence — provided the scope, timing and independence line up.
The report is the deliverable. Judge a testing firm by one before you hire them, and know what you are looking at.
Offline functionality means a decision is made somewhere you do not control. Everything interesting follows from that.
Tell us the standard, the framework or the application. We come back with scope, timeline and a fixed quote.