What Heads of Compliance Ask SaaS Vendors About ISO 29147 Disclosure

What Heads of Compliance Ask SaaS Vendors About ISO 29147 Disclosure

By EJN Labs · 17 Aug 2026 · 8 min read

Heads of Compliance ask SaaS vendors for ISO 29147 security assurance in three forms: a published vulnerability disclosure policy, proof that reported vulnerabilities are triaged and fixed, and independent penetration testing that validates the process works. ISO 29147 does not mandate a pen test, but buyers routinely expect one. Typical UK testing behind this evidence costs £4,400 to £12,600 depending on scope.

Why ISO 29147 security assurance questions are landing in your inbox

Security questionnaires from manufacturing, OT and IoT-heavy buyers now routinely ask SaaS vendors for ISO 29147 security assurance, which is why the requests are landing in your inbox. ISO/IEC 29147 is the international standard for vulnerability disclosure, published by ISO.

The standard describes how an organisation should receive vulnerability reports from outside researchers and how it should disclose fixes to those who depend on its products.

Heads of Compliance ask about it because their own regulators and customers increasingly ask about supply-chain evidence. A compliance lead at a manufacturer cannot inspect your codebase, so they probe whether you have a working route for security researchers to tell you about flaws, whether you act on those reports, and whether an independent firm has tested your platform recently. Your answers decide whether procurement moves forward or stalls.

What ISO 29147 actually is, and what it is not

ISO 29147 is a voluntary process standard for vulnerability disclosure, not a certifiable or regulated one. It sets out how to publish a disclosure policy, provide a contact channel for researchers, acknowledge and track reports, and communicate advisories when a fix ships. No UK regulator fines you for lacking it.

There is no certification scheme in the way there is for ISO 27001. Its companion standard, ISO/IEC 30111, covers the internal side: how you triage, remediate and verify the vulnerabilities once they arrive.

Critically, ISO 29147 does not clearly mandate penetration testing. Nothing in the standard says “commission an annual pen test”. What it does is create an evidence expectation. A disclosure process only proves useful if vulnerabilities are actually found, handled and closed, and independent testing is the most direct way to demonstrate that the pipeline works end to end. That is why compliance teams pair the two questions: “show us your disclosure policy” and “show us your latest penetration test report”.

The five questions Heads of Compliance actually ask

Across supplier due diligence, the same questions recur. Crisp answers, with evidence attached, shorten security review from months to weeks.

  1. Do you have a published vulnerability disclosure policy, and where can we read it? They want a public page with a security contact, safe-harbour language for researchers, and expected response times.
  2. How do you triage and remediate reported vulnerabilities? This is the ISO 30111 side: severity ratings and remediation timescales by severity.
  3. When were you last penetration tested, by whom, and what was in scope? A test from a CREST-accredited firm within the last twelve months, covering the platform the buyer will actually use, is the expected answer.
  4. Were the findings fixed, and can you prove it? A retest confirmation or a summary letter carries more weight than a raw report of open issues.
  5. How do you notify customers when a vulnerability affects them? Buyers in OT and manufacturing environments have change-control windows; they need advisories early enough to plan patching.

What evidence to prepare before the questionnaire arrives

Prepare four items: a disclosure policy page aligned to ISO 29147, an internal handling procedure aligned to ISO 30111, an executive summary of your most recent penetration test, and a remediation statement showing critical and high findings closed. In our experience the pack needs exactly these four.

The strongest position is a small, consistent evidence pack you can send within a day of being asked.

The testing element should mirror how customers consume your service. For most SaaS platforms that means the web application and its APIs, the cloud environment underneath, and the external perimeter. Our API penetration testing and cloud penetration testing services map directly onto the components compliance teams ask about. If you are unsure what a defensible scope looks like, our penetration testing checklist walks through the decisions step by step.

How an ISO 29147 aligned testing engagement runs

Engagements run in four stages, starting with scoping: a short call that maps your platform, identifies the components your customers touch, and agrees what a compliance reviewer will expect to see covered. For SaaS estates, scoping begins at the tenant boundary.

The tenant boundary matters because it is the question every multi-tenant buyer silently asks: can another customer reach my data? Cross-tenant authorisation checks, API object-level access controls and cloud IAM boundaries usually anchor the test plan.

Second, testing: UK-based testers work through the agreed scope, typically over one to two weeks, with critical findings escalated to you immediately rather than at report time. Third, reporting: you receive a full technical report plus an executive summary written for exactly the audience asking these questions, a Head of Compliance who needs assurance, not exploit detail. Fourth, retest: once fixes land, we verify them and issue a confirmation you can attach to any questionnaire. EJN Labs is CREST accredited and certified to ISO 27001 and ISO 9001, so the assurance you pass on is itself independently audited.

What it costs and how scope drives the price

Scope drives the price: UK penetration testing is priced by effort, and day rates at a CREST-accredited firm typically run £1,100 to £1,400. The shape of the engagement you commission, and therefore the number of days it takes, is what moves the total.

The table below shows typical ranges for the engagement shapes SaaS vendors commission when preparing ISO 29147 security assurance evidence. Full pricing context is in our guide to penetration testing cost in the UK.

Engagement scopeTypical effortTypical UK cost
Cloud configuration review2 to 4 days£2,200 to £5,600
API penetration test3 to 5 days£3,300 to £7,000
External infrastructure and web application4 to 6 days£4,400 to £8,400
Combined web, API and cloud assessment6 to 9 days£6,600 to £12,600

These are typical ranges, not quotes. A single-product platform with one API sits at the lower end; a multi-tenant platform with several integrations and a complex cloud estate sits higher. The fastest route to a firm figure is our quote form.

How EJN Labs approaches ISO 29147 assurance for SaaS vendors

We treat supplier due diligence as the real deliverable, not just the test. That changes how we work. Scope is written so it answers the buyer’s questionnaire line by line: the components named in the scope match the components the compliance team asked about. Findings are severity-rated in language that maps cleanly onto disclosure timelines, so the same data feeds your ISO 30111 handling records. And the executive summary is written to be forwarded, because that is what happens to it.

All testing is delivered by UK-based testers under our CREST penetration testing methodology, with ISO 27001 and ISO 9001 certified processes behind the engagement. If you are comparing suppliers before you commit, our guide to choosing the best UK penetration testing provider sets out the accreditation and reporting questions worth asking.

Frequently Asked Questions

Does ISO 29147 require a penetration test?

No. ISO/IEC 29147 is a voluntary standard describing how to receive and disclose vulnerabilities, and it does not mandate penetration testing. In practice, the compliance teams who ask about ISO 29147 almost always request a recent independent test in the same questionnaire, so plan for both together.

Testing gets requested alongside because it is the clearest evidence that your disclosure and remediation process works end to end.

What is the difference between ISO 29147 and ISO 30111?

ISO 29147 covers the external interface, how researchers report vulnerabilities to you and how you publish advisories to customers. ISO 30111 covers the internal process, how you triage, remediate and verify those vulnerabilities once received. Reviewers usually expect to see both working together.

In evidence terms that means a public disclosure policy backed by a documented internal handling procedure with severity-based timescales.

What evidence do Heads of Compliance usually accept?

Four items cover most questionnaires: a published vulnerability disclosure policy, an internal vulnerability handling procedure, an executive summary of a penetration test by a CREST-accredited firm within the last twelve months, and a retest or remediation statement showing critical and high findings closed.

A summary letter is usually preferred over a full technical report.

How much does ISO 29147 aligned penetration testing cost?

Typically £4,400 to £8,400 for an external infrastructure and web application test over 4 to 6 days, rising to £6,600 to £12,600 for a combined web, API and cloud assessment over 6 to 9 days, at day rates of £1,100 to £1,400.

Exact pricing depends on your platform’s size and complexity, so request a scoped quote.

Can a SaaS vendor get certified against ISO 29147?

No. No formal certification scheme exists for ISO 29147 in the way it does for ISO 27001, so a SaaS vendor aligns with the standard rather than certifying against it. That is why evidence matters more than badges when a compliance reviewer raises the question.

A public disclosure policy, documented handling processes and independent penetration testing collectively demonstrate alignment in a way a reviewer can verify quickly.

Turn the ISO 29147 question into a closed deal

Every security questionnaire your prospects send is a chance to be the vendor with the fastest, cleanest answers. A scoped penetration test from a CREST-accredited firm, with a forwardable summary and a retest confirmation, does most of that work for you. Tell us about your platform through our CREST pentesting quote form and we will come back with a defined scope and a fixed price, usually within one working day.

Leave a Reply

Your email address will not be published. Required fields are marked *