How Often Do You Need to Pentest for ISO 27001 Compliance?

Organisations pursuing or maintaining ISO 27001 certification are often surprised to learn that the standard sets no fixed penetration testing schedule. In fact, there is no clause stating whether ISO 27001 security testing must occur monthly, quarterly, or annually.

Instead, ISO 27001 pen testing requirements are woven into a small number of Annex A controls that demand ongoing vulnerability management, leaving the exact cadence for organisations to determine and justify themselves.

This article sets out what the standard actually requires, what auditors expect in practice, and how security leaders can effectively build a testing schedule that ensures compliance without complication.

Does ISO 27001 Require Penetration Testing?

You may be wondering if ISO 27001 even requires penetration testing to begin with. While it’s not explicitly stated in the compliance framework that regular penetration testing is a necessary component to attain the certification, pen testing has become the most accepted and auditor-expected method of demonstrating robust security measures.

Why is that? ISO 27001 requires that organisations “identify, assess, and manage technical vulnerabilities on an ongoing basis” through Annex A controls A.8.8 (management of technical vulnerabilities), A.8.29 (security testing in development and acceptance), and A.8.20 (network security). Keeping this in mind, it’s clear to see why the vast majority of organisations turn to pen testing as a method of proving compliance.

Why Vulnerability Scanning Alone is Insufficient

Since vulnerability scanning alone identifies known issues without validating how they might actually be exploited, security leaders must look for an auditing method more thorough than this. Automated tools are notorious for presenting similar problems, providing a vague overview of your current security environment rather than the necessary, in-depth investigation required for ISO 27001.

Pen testing, therefore, arises as the most sensible solution: it goes beyond flagging known weaknesses and instead demonstrates through genuine attempted exploitation whether security weaknesses can actually be used against your organisation.

In practice, most certification bodies now expect to see at least one penetration test per year as supporting evidence, even though no clause makes this mandatory in name.

How Often Should You Test?

The question of how often your organisation should be conducting pen testing is subjective, but there are a few objective pointers to help you establish a good cadence.

At a very minimum, annual testing has become the industry baseline to achieve ISO 27001.

This is because an annual pen test satisfies the minimum expectation of most certification auditors and provides evidence when a risk assessment is questioned.

For organisations with stable infrastructure, limited change, and a risk profile that isn’t overly complicated, an annual penetration test aligned with the certification audit cycle is usually enough to provide auditors with a fair insight into your security posture.

But the bare minimum is not always the optimal cycle frequency. ISO 27001’s emphasis on continual improvement, expressed through its Plan-Do-Check-Act cycle, positions vulnerability management as an ongoing process rather than a check-box, annual exercise.

A single annual test cannot foresee vulnerabilities in any deployments, infrastructure changes, or patched and unpatched systems that succeed it, leaving you with significant exposure.

That’s why choosing the bare minimum path may still not be enough to fairly account for the changes your organisation will make throughout the rest of the year, and the cadence of your testing schedule should be chosen carefully.

When Is Annual Not Enough?

For organisations operating in higher-risk categories, annual testing alone is unlikely to satisfy either genuine security needs or your auditors. SaaS platforms, fintech businesses, and healthcare providers handling sensitive data typically warrant a more frequent cadence, with biannual or quarterly testing recommended for these sectors.

Supplementing this with regular vulnerability scanning between penetration tests helps maintain visibility during the gaps.

The right frequency ultimately depends on your organisation’s own risk assessment, which ISO 27001 already requires you to maintain. How often your business’s infrastructure changes, the sensitivity of the data you hold, and the criticality of the systems being tested should all inform how often you go beyond the annual minimum to protect your systems.

When to Test Beyond Your Testing Calendar

Setting up a testing calendar that complements the needs of your business is a crucial step in ensuring your security measures are proactive, not just responsive. By figuring out a cadence that works well for your cybersecurity requirements- for example, quarterly- you successfully demonstrate to auditors your clear investment in protecting sensitive assets.

But, unfortunately, even the most well-organised calendar-based testing schedule can leave gaps. Significant infrastructure changes, access control changes, or a large intake of new hires can all introduce new risk to your networks.

That’s why, alongside your scheduled cadence, it is worth building trigger-based testing into your programme so that specific events prompt an out-of-cycle assessment regardless of when the last test took place. Common triggers include:

  • A major infrastructure or application change
  • A new cloud migration or deployment
  • Significant changes to authentication or access control
  • Disclosure of a critical vulnerability affecting your technology stack
  • Post-incident, to confirm that remediation has genuinely closed the attack path

Embedding these triggers into your ISMS ensures that real changes in your risk profile are identified and addressed as they occur, rather than waiting for a date on the calendar to arrive.

Timing Your Test Around the Audit Cycle

Scheduling also matters. Completing your penetration test six to eight weeks before your certification or surveillance audit gives you a realistic window to remediate findings and demonstrate follow-through, rather than presenting an auditor with a list of open vulnerabilities discovered days before assessment.

Retesting to confirm that identified issues have been resolved is increasingly considered good practice, and some organisations build this directly into their testing workflow as a standard step rather than an afterthought.

FAQs: ISO 27001 Penetration Testing Requirements

Is performing penetration testing required for ISO 27001? Not by name, but it is the accepted method of satisfying Annex A controls covering technical vulnerability management and security testing, and most certification auditors expect to see it as supporting evidence.

How often should penetration testing be done for ISO 27001? At least once a year as a baseline, with more frequent testing, such as biannual or quarterly, recommended for organisations with higher risk profiles or rapidly changing infrastructure.

What happens if I only test once a year? Annual testing typically satisfies the minimum auditor expectation, but it leaves long gaps in which new vulnerabilities, changes, and threats go unassessed. Organisations relying solely on annual testing should ensure their risk assessment genuinely supports that decision.

Can vulnerability scanning replace penetration testing for an ISO 27001 audit? No. Vulnerability scanning identifies known issues but does not validate real-world exploitability. Penetration testing complements scanning by simulating how an attacker might actually chain and exploit weaknesses, simply identifying the security vulnerabilities instead of demonstrating how much damage an attacker could do with the right access.

How OnSecurity Can Support Businesses in Achieving ISO 27001 compliance

Tackling ISO 27001 doesn’t have to feel overwhelming. At OnSecurity, our platform-led pentesting makes scheduling effortless, so your testing cadence stays on track without the admin headache. Ready to build a testing schedule that satisfies your risk assessment and keeps you audit-ready? Get a quote from OnSecurity today.

Related Articles