FCA SYSC Evidence: The Pen Test Reports Outsourced Providers Should Keep Ready

FCA SYSC Evidence: The Pen Test Reports Outsourced Providers Should Keep Ready

By EJN Labs · 28 Jul 2026 · 8 min read

FCA SYSC does not name penetration testing, but regulated firms must evidence adequate systems and controls over their outsourced providers, so they ask suppliers for recent penetration test reports during due diligence and annual reviews. A supplier-ready evidence pack normally rests on an annual CREST penetration test of the customer-facing service, typically 4 to 6 days at £1,200 to £1,400 per day, or £4,800 to £8,400.

Why FCA SYSC security assurance lands on your desk as a supplier

FCA SYSC security assurance lands on suppliers because regulated firms cannot outsource their responsibility for supplier risk. The SYSC sourcebook makes FCA-regulated firms responsible for the risks their suppliers introduce, so they push the evidence burden down the supply chain to you.

If you sell software, cloud hosting, payment processing or any critical outsourced service to an FCA-regulated firm, expect requests sooner or later, usually attached to a due diligence questionnaire with a two-week deadline. The Financial Conduct Authority’s sourcebook is mandatory for regulated firms in scope.

In practice a compliance director, CISO or operational resilience lead at your client will ask for proof that your service has been independently security tested, and the suppliers who close deals fastest have that proof ready before the question arrives.

What SYSC actually requires, and what it does not

SYSC requires regulated firms to maintain effective systems and controls proportionate to their risks, and its outsourcing provisions require due skill, care and diligence when relying on third parties for critical or important functions. It contains no line saying a supplier must commission a penetration test.

SYSC is a principles-based sourcebook issued by the Financial Conduct Authority. The firm must supervise the outsourced function, manage its risks, and be able to demonstrate that to the regulator.

Penetration testing enters the picture on a risk basis. Independent technical testing is one of the strongest ways a firm can show its controls over an outsourced service actually work rather than merely exist on paper, so regulated clients almost always treat a pen test as expected evidence: it is the cheapest credible way to discharge their own SYSC obligations for the part of their estate you run. A supplier who cannot produce it forces the client to commission testing themselves, accept a documented risk, or find another supplier.

The reports FCA-regulated clients ask outsourced providers to keep ready

Across the due diligence packs we see from banks, payment firms, insurers and investment managers, the requests converge on a consistent set of documents:

  • A penetration test report for the customer-facing application and its APIs, dated within the last 12 months, from an independent CREST-accredited firm. Where the service is API-first, clients increasingly ask for dedicated API penetration testing rather than a generic web scan.
  • An external infrastructure test covering the internet-facing perimeter of the environment that hosts the regulated client’s data.
  • A cloud configuration review where the service runs on AWS, Azure or GCP, because misconfiguration, not exotic exploitation, is the dominant failure mode in shared-responsibility hosting.
  • A remediation summary or retest letter showing that high and critical findings were fixed and verified, not just recorded.
  • An executive summary or attestation letter suitable for sharing, so the full technical report never leaves your controlled environment.

Two attributes matter as much as the documents themselves: independence, because an internal scan run by your own engineers rarely convinces a regulated firm’s due diligence team, and recency, because a report older than 12 months or predating a major release will stall the procurement. The wider expectations financial services buyers bring to security are covered in our guide to cyber security for financial services.

How an evidence-pack engagement runs

An engagement built to produce SYSC-ready evidence follows the same discipline as any professional penetration test, with extra care over the outputs, because the report is the product your clients will actually read.

  1. Scoping. We map the boundary of the service your regulated clients consume: the application, its APIs, the hosting environment, and any admin planes that could expose client data. Scoping is free and takes one short call plus a questionnaire.
  2. Testing. UK-based testers work the agreed scope against recognised methodologies, combining automated coverage with manual attack paths such as authentication bypass, authorisation flaws between client tenants, and injection into back-end services.
  3. Reporting. You receive a full technical report plus a client-shareable executive summary, with findings rated by real-world impact on the regulated data you process.
  4. Remediation and retest. After fixes, we verify closure and issue a retest letter, the single document that shortens due diligence most because it shows the loop was closed.

Before test day, our penetration testing checklist walks through the access, credentials and approvals to line up so no testing days are lost.

What it costs and how scope drives the price

UK penetration testing is priced on effort, at day rates of £1,200 to £1,400, with the number of days driven by what you expose to regulated clients: how many applications and APIs, how many user roles and tenants, and how large the external and cloud footprint is.

Typical UK ranges for supplier evidence-pack work:

ScopeTypical effortTypical UK cost
External infrastructure test of the hosting perimeter2 to 4 days£2,400 to £5,600
Web application and API test of the customer-facing service4 to 6 days£4,800 to £8,400
Cloud configuration review (AWS, Azure or GCP)3 to 5 days£3,600 to £7,000
Combined annual evidence pack with retest letter6 to 10 days£7,200 to £14,000

The application and API test, at £4,800 to £8,400 for a typical platform, is the document most due diligence teams ask for first. Combining workstreams into one annual engagement is usually cheaper than commissioning them separately because scoping, access and reporting are shared. For what moves the numbers, see our guide to penetration testing cost in the UK; for an exact price against your own estate, use the quote form.

How EJN Labs approaches FCA SYSC evidence packs

Testing built for the reader, not just the finding

EJN Labs is a UK firm delivering CREST-accredited penetration testing, and we hold Cyber Essentials Plus and ISO 27001 ourselves, so we sit both sides of the assurance table and know what a compliance reviewer needs to see. When we scope a supplier estate we start from the question your client’s due diligence team will ask: which systems touch regulated data, and where could one client’s data reach another’s. Tenant isolation, API authorisation and cloud identity boundaries therefore get manual attention on every engagement rather than being left to scanners, because cross-tenant exposure is the finding an FCA-regulated client fears most.

All testing is carried out by UK-based testers, reports include a shareable executive summary as standard, and retest verification is built in rather than sold as an extra. The outcome is a pack you can hand to any FCA-regulated client and expect zero follow-up questions.

Frequently Asked Questions

Does FCA SYSC require suppliers to have a penetration test?

No, SYSC contains no explicit penetration testing mandate for suppliers. It requires FCA-regulated firms to maintain effective systems and controls and to manage the risks of outsourced functions, and testing becomes commercially necessary because those clients demand proof that supplier controls work.

Independent testing is the strongest practical evidence available, so regulated clients routinely require recent penetration test reports through contracts and due diligence, even though testing is never legally named in the sourcebook.

What penetration test reports should an outsourced provider keep ready?

Keep four documents current: an application and API penetration test of the customer-facing service, an external infrastructure test of the hosting perimeter, a cloud configuration review if you run on AWS, Azure or GCP, and a retest letter confirming high and critical findings were fixed.

Add a shareable executive summary to the pack, so the full technical report never has to leave your control.

How much does an FCA SYSC evidence-pack penetration test cost?

Expect £2,400 to £14,000 depending on scope, at UK day rates of £1,200 to £1,400. A web application and API test of the customer-facing service usually takes 4 to 6 days, £4,800 to £8,400, and a combined annual pack runs 6 to 10 days, £7,200 to £14,000.

An external infrastructure test runs 2 to 4 days (£2,400 to £5,600) and a cloud configuration review 3 to 5 days (£3,600 to £7,000). Exact pricing depends on scope, so request a quote.

How recent does a penetration test report need to be for FCA-regulated clients?

Within the last 12 months is the expectation of most due diligence teams, and many contracts specify annual testing. A report also loses credibility if your platform has had a major release since it was issued, so freshness is judged against your platform as well as the calendar.

Retesting after significant architectural change is sensible even inside the annual window, and aligning your test date with your busiest renewal season keeps the evidence fresh when it matters.

Should we share the full penetration test report with regulated clients?

Usually not. Share an executive summary or attestation letter describing scope, methodology, tester accreditation and the remediation status of findings, because the full report contains detailed technical findings that could aid an attacker if it leaks through a client’s own systems.

If a client’s security team insists on deeper review, offer a walkthrough of the full report under NDA.

Get your evidence pack ready before the next due diligence request

Every week without current test evidence is a week a due diligence questionnaire can stall a deal. Tell us what your regulated clients consume and we will scope a CREST evidence pack with a fixed price. Request a penetration testing quote and we will come back with days, cost and the earliest start date.

Leave a Reply

Your email address will not be published. Required fields are marked *