ISO 27001 Penetration Testing

ISO 27001 Penetration Testing

CREST-accredited penetration testing that gives your ISO 27001 auditor the evidence they expect for Annex A. You get a fixed price, a named UK-based tester, and a report mapped to the controls in your Statement of Applicability. Free retests are included.

  • Unlimited retesting
  • Unlimited pre-retesting
  • No hidden fees
Accredited & recognised
Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified Crown Commercial Service supplier UK Cyber Security Council member
A.8.8
The Annex A control for management of technical vulnerabilities
A.8.29
The Annex A control for security testing in development and acceptance
2022
The ISO/IEC 27001 revision in force, with 93 Annex A controls
3 years
The certification cycle: annual surveillance audits, then recertification
Named client references

When the deadline cannot move, these named UK teams chose EJN Labs and got the result on the timeline they needed

Real EJN Labs clients, named with their permission. They chose us for accreditations they can verify and a CREST team that replies fast, not a sales pipeline.

SquareOne
I would highly recommend EJN Labs to any organisation seeking reliable, detailed, and well-managed penetration testing services, particularly for government or enterprise-level projects.
Imran SaghirProject Lead, SquareOne
Cellori
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
Dan WilcocksonCo-Founder, Cellori
  • CREST approval, publicly verifiable
  • IASME Cyber Essentials body
  • Active testing within 24 hours
  • 100% UK-based testers

Further references, including under NDA, are available on your scoping call.

WHY IT MATTERS
2

the Annex A controls a single penetration test gives your auditor evidence for: A.8.8, managing technical vulnerabilities, and A.8.29, security testing in development and acceptance.

ISO 27001 never says penetration test. Your auditor still expects one

ISO/IEC 27001:2022 never uses the words penetration test, and no clause orders you to run one. A vendor who says ISO 27001 does not require a pen test is technically correct. What the standard does demand is that you identify technical vulnerabilities, act on them, and demonstrate your controls are effective. For the full breakdown, read our guide on penetration testing for ISO 27001.

The useful answer is that a penetration test is the evidence certification auditors recognise most readily. A.8.8 expects you to obtain information about technical vulnerabilities, evaluate your exposure and take action. A.8.29 expects security testing to be defined and performed through the development life cycle. A structured test from an independent tester is the clearest way to produce evidence against both.

We scope every engagement against your Statement of Applicability and time it to your audit calendar, so the deliverable is current evidence your auditor can rely on. Findings are mapped to Annex A control numbers, remediation is practical, and the retest your auditor expects to see evidenced under A.8.8 is included. We also hold ISO 27001 ourselves, so we understand the audit from your side of the table.

ISO 27001 ANNEX A

What an ISO 27001 Penetration Test Covers

ISO 27001 is about evidence, not a fixed checklist. Here is how a penetration test produces evidence against the Annex A controls your certification auditor examines.

A.8.8

Technical vulnerability management

independent identification of exploitable vulnerabilities and their real-world impact, plus retest evidence that fixes worked.

A.8.29

Security testing

structured manual security testing of applications and infrastructure in development and acceptance, as A.8.29 expects.

API

APIs

the interfaces your systems expose and consume.

CLOUD

Cloud environment

the AWS, Azure or GCP configuration inside your ISMS boundary.

APP

Applications

the web applications in your ISMS scope, tested for business-logic and access-control flaws.

NET

Infrastructure

external and internal network, hosts and services in scope.

CHG

Significant-change testing

auditors expect a fresh test after a material change to the applications, infrastructure or cloud in scope.

METHODOLOGY

How an ISO 27001 Engagement Runs

From mapping the systems in your ISMS scope to an audit-ready report and the retest that confirms your fixes, here is how the engagement runs.

01

Scope

We map the systems in your ISMS scope, agree the controls to evidence (A.8.8, A.8.29 and related), and fix the price and timeline.

02

Test

Applications, APIs, cloud and infrastructure, with findings shared live to your portal.

03

Report

An audit-ready report with an executive summary, technical detail, and each finding tied to the Annex A control it evidences, timed to your audit calendar.

04

Retest

We verify your remediation and issue a retest confirmation letter for your auditor.

CREDENTIALS

Verified Accreditations Auditors Accept

Every credential below is independently verifiable. UK procurement teams, FCA supervisors, ISO 27001 / SOC 2 auditors, and cyber insurance underwriters all recognise these standards.

GET YOUR QUOTE

Get your fixed-price quote in 24 hours from a CREST-certified consultant, with no sales pipeline to chase

A fixed-price quote back in one working day, from a CREST-certified consultant. No sales pipeline, no chasing.

  • CREST and IASME accredited. Testing your auditors and clients already recognise.
  • Fast-track testing within 24 hours where required. Free retest of every fix included.
  • Live findings via your client portal, not a four-week PDF.
  • Fixed, scope-based price from £1,200 for a small penetration test scope, agreed up front. Certifications such as Cyber Essentials are priced separately. Most engagements run £3,000 to £8,000. No day-rate surprises.
What clients say
There wasn’t another company we could find that could deliver what we needed in the timeframe we needed. The client loved it, and we got instant ROI from the engagement.
CelloriDan WilcocksonCo-Founder, Cellori

Under NDA Further named references available on a scoping call.

What happens next
Nazia Khaleeq, Chief Revenue Officer Nazia KhaleeqChief Revenue Officer
  1. Nazia replies the same working dayYou will receive a fixed quote prepared by a CREST-certified consultant.
  2. You approve the scopeEngagement date is set, usually within 24 hours.
  3. Live findings land in your client portalTesting is live with free retests for every fix.
Accredited & recognised
CREST member Cyber Essentials certified Cyber Essentials Plus certified IASME certifying body ISO 27001 certified ISO 9001 certified UK Cyber Security Council Crown Commercial Service supplier

Get your fixed-price quote in 24 hours

24h reply CREST tester Free retests

or book a 20-min scoping call first

We reply within one working day. Your data stays with us. No newsletter signup.

COMPLIANCE READY

Reports Mapped to Every Framework

Findings are explicitly tagged to the relevant control reference. Your audit team submits the report directly without translation work.

PCI DSS v4.0 Requirement 11.4

if you handle card data, the same test evidences Requirement 11.4.

ISO 27001 A.8.8 and A.8.29

the Annex A controls this test evidences directly, with A.8.9, A.8.25 and A.5.36 supported.

SOC 2 CC7.1 and CC4.1

the same evidence supports the Trust Services Criteria your SOC 2 auditor examines.

UK GDPR Article 32

Regular testing of the effectiveness of your security measures.

Cyber Essentials Plus

a separate UK Government-backed certification we also deliver, not a substitute for ISO 27001.

NIST SP 800-115

The technical testing methodology behind the engagement.

PRICING

Transparent ISO 27001 Pen Test Pricing

Priced on scope, at a fair-market day rate of £1,100 to £1,400. No hidden fees, no surprise extras.

✦ ALWAYS · ON EVERY TIER · NO EXCEPTIONS ✦
Free retests, no time limit
Free rescheduling
No cancellation fees
24-hour scope to active testing
Live findings to client portal
Executive + technical report
60-min walkthrough call
Retest confirmation letter
SMALL
From £3,000
2 to 3 day engagement

A single application or a focused ISMS scope.

Get a fixed quote
ENTERPRISE
From £15,000
10+ day engagement

A large estate or multi-entity ISMS.

Get a fixed quote

See how pricing is calculated

WHY EJN LABS

What You Get From an ISO 27001 Pen Test

Six concrete differentiators competitors don’t all match.

Fixed price in 24h

Send your ISO 27001 scope and we return a fixed price and timeline within one working day.

Named CREST-accredited UK tester

Every engagement is run by a named, CREST-accredited, UK-based tester.

Evidence your auditor accepts

Auditor-ready evidence, mapped finding by finding to the Annex A controls your auditor examines.

Live findings to your portal

Findings land in your portal as we test, so remediation can start straight away.

Free retests

We retest your fixes to confirm they held, at no extra charge.

Retest confirmation letter

A retest confirmation letter on completion, for your auditor and your records.

FAQ

Frequently Asked

How long does an ISO 27001 penetration test take?

Typically 2 to 8 days, depending on the systems in your ISMS scope. We confirm the timeline with your fixed quote.

Do I get a named tester?

Yes. A named, CREST-accredited, UK-based consultant runs your test.

Can one test cover both ISO 27001 and SOC 2?

Where the scopes overlap, yes. The same engagement produces evidence for Annex A controls and for SOC 2 criteria CC7.1 and CC4.1, mapped in one report.

When should we test relative to our audit?

Before your Stage 2 or next surveillance audit, and again after any significant change to the systems in scope, so the evidence is current when the auditor asks.

Is a vulnerability scan enough?

A scan carries less weight than a structured test with manual validation; certification auditors weigh the quality of the evidence.

Will the report help our auditor?

It is structured as audit evidence: findings mapped to Annex A control numbers, risk-rated, with a remediation trail and retest. It reads directly against your Statement of Applicability.

What happens if you find vulnerabilities?

We triage by exploitability, give practical remediation, and a retest to confirm the fixes is included.

How much does an ISO 27001 penetration test cost?

Priced on scope at a fair-market day rate of £1,100 to £1,400. Request a fixed quote in 24 hours.

EXPLORE EVERY SERVICE

20+ CREST-accredited testing services in one place

Web, mobile, API, cloud, AI, infrastructure, red team. Pick the test that fits your environment.

Penetration testing services
READY TO START

Get your ISO 27001 pen test scoped in 24 hours

Send us your ISO 27001 scope and audit date and we will return a fixed price, a timeline, and the name of the CREST-accredited tester who will run it.