By EJN Labs · 10 Sep 2026 · 7 min read
Cloud suppliers increasingly need two things in one evidence pack: a vulnerability disclosure process aligned with ISO 29147 and an independent penetration test report. ISO 29147 does not require penetration testing, but buyers commonly treat a recent test as proof that a disclosure programme actually works. Pairing both typically costs £4,400 to £12,600 in the UK market, depending on scope.
Why do cloud buyers now ask for ISO 29147 evidence alongside a pen test report?
Cloud buyers ask for both because a disclosure policy alone proves nothing without evidence someone actually looked for something to disclose. Procurement teams now treat ISO 29147 alignment as one checkbox and a penetration test as proof that checkbox is real.
This is a shift from a few years ago, when a questionnaire asked for one or the other. Now the two questions often sit in the same row of a spreadsheet, and buyers have learned that a policy with no history of inbound reports, and no test behind it, is effectively unfalsifiable.
How does ISO 29147 evidence fit into a cloud buyer’s third-party assurance requirements?
ISO 29147 evidence fits in as one line among many: it confirms you have a defined channel for vulnerability reports, while a separate penetration test confirms that channel has something to report on. Neither alone satisfies a full set of third-party assurance requirements.
ISO/IEC 29147 is the international standard covering how an organisation receives and coordinates vulnerability reports from outside researchers. It sets out a process, not a testing methodology, and does not require a penetration test. Buyers often go further, close to verbatim, asking whether testing follows an OWASP and NCSC aligned methodology, meaning work benchmarked against the OWASP Web Security Testing Guide and NCSC guidance on penetration testing, not an unstructured scan. That question sits alongside the ISO 29147 question, not inside it.
What should a cloud supplier’s evidence pack actually contain?
A complete evidence pack has three parts: a published disclosure policy naming a contact route and response timescale, a penetration test report covering the service the buyer actually uses, and a short attestation letter tying the two together for the reviewer.
Each element does a different job. The policy shows you have a process. The report shows it has been exercised against your real attack surface, not a checklist. The attestation letter, close to what buyers call VAPT packaging with a CREST-aligned attestation letter, is a one-page summary a reviewer can file directly.
- Disclosure policy. A published route for outside researchers to report a vulnerability, a response timescale, and confirmation that good-faith reports will not lead to legal action.
- Penetration test report. Independent testing of the service the buyer will actually use, dated within the last twelve months, with the methodology stated on the first page.
- Attestation letter. A short summary document, separate from the full findings, that a compliance reviewer can file directly.
- Remediation evidence. Confirmation, or a retest report, that findings above an agreed severity were closed before the pack went out.
How do you sequence a penetration test around a live disclosure programme?
Sequence the test to run once your disclosure channel has been live a few weeks, so inbound reports are triaged first and do not collide with planned findings. We ask for your current policy and any open reports before scoping starts.
Suppliers who already have a mature disclosure channel usually skip straight to scoping. Suppliers building the policy from scratch tend to run the two workstreams in parallel, since publishing the policy takes a lawyer or a policy template far less time than a proper test takes to run.
- Policy review. We read your current disclosure policy and any open reports before scoping, so testing does not duplicate something already found.
- Scoping call. We confirm which cloud services, APIs and accounts sit in scope, along with the methodology reference your buyer has asked for.
- Testing window. The technical work itself, run against a live or a mirrored environment depending on your risk appetite and change windows.
- Reporting and attestation. A findings report plus the short attestation letter, timed to land before your questionnaire deadline rather than after it.
What does this evidence pack typically cost in the UK market?
Expect UK day rates of £1,100 to £1,400 for CREST-accredited testing. Pairing a cloud service test with a disclosure programme review typically takes 4 to 9 days depending on scope, so £4,400 to £12,600 in total, with the exact figure set by scoping rather than a rate card.
What moves a supplier between the rows below is mostly the number of services in scope and whether cloud configuration review sits alongside application and API testing. Our guide to penetration testing costs in the UK covers the wider pricing picture across engagement types.
| Scope | Typical effort | Typical UK cost |
|---|---|---|
| Single cloud service or API, paired with a disclosure programme review | 4 to 6 days | £4,400 to £8,400 |
| Full SaaS platform: web, API and cloud configuration, plus attestation letter | 7 to 9 days | £7,700 to £12,600 |
| Multi-service cloud platform with staged disclosure review across products | 10 to 14 days | £11,000 to £19,600 |
| Retest after remediation | 1 to 2 days | £1,100 to £2,800 |
These are typical UK ranges, not a quote. Scope, not seniority or margin, is what moves the price, and the only way to get an exact figure for your platform is to scope it through the quote form.
How EJN Labs approaches penetration testing for cloud suppliers building this evidence pack
EJN Labs is a CREST-accredited penetration testing firm, certified to ISO 27001 and ISO 9001, with UK-based testers throughout. For cloud and SaaS suppliers building this evidence pack, we read your disclosure policy and any inbound reports before scoping, so testing targets what a buyer’s security team will query.
Our cloud penetration testing service covers the infrastructure and configuration layer, paired with API penetration testing where a platform’s attack surface runs through its integrations rather than a browser. Every report states its methodology on the opening page, and we produce a short attestation letter alongside the full findings. If you are comparing providers, our guide to choosing a UK penetration testing provider covers the questions worth putting to any firm, including us.
Frequently Asked Questions
Does having a vulnerability disclosure policy replace the need for a penetration test?
No, a disclosure policy and a penetration test answer different questions. The policy shows you can receive and triage a report; the test shows what a tester actually found. Buyers commonly ask for both because an untested policy has never faced a real attacker’s perspective.
What goes into a cloud supplier’s paired evidence pack?
A paired evidence pack contains a published disclosure policy with a named contact route, a recent penetration test report scoped to the service the buyer actually uses, and a short attestation letter summarising both, plus remediation evidence for high findings.
Do buyers really ask us to confirm OWASP and NCSC aligned methodology?
Yes, this is one of the more specific questions cloud buyers ask, often phrased close to that wording. It means confirming your test is benchmarked against the OWASP Web Security Testing Guide and NCSC guidance on penetration testing, not an unstructured scan.
What does this evidence pack typically cost in the UK market?
Typical UK day rates for CREST-accredited testing run £1,100 to £1,400. A single cloud service paired with a disclosure review typically takes 4 to 6 days, so £4,400 to £8,400. A fuller SaaS platform typically takes 7 to 9 days, so £7,700 to £12,600.
How long does it take to put a paired evidence pack together?
Building both pieces together typically takes three to five weeks from a standing start: one to two weeks to draft a disclosure policy, then a testing window of one to two weeks, plus report and attestation letter turnaround. Suppliers with a channel already live need only the testing stage.
Get the pen test that backs up your ISO 29147 disclosure evidence
If a questionnaire is asking for ISO 29147 disclosure evidence and a penetration test in the same breath, we can scope both around your platform and your deadline. Get a CREST pentesting quote and we will confirm days and price for the scope.
Related research
For the buyer’s side of this question, see what heads of compliance ask SaaS vendors about ISO 29147 disclosure. For the underlying mandate question, see ISO 29147 without a bug bounty. For the wider service this evidence usually draws on, see SaaS penetration testing.




Leave a Reply