Your Platform Is Your Regulator: The Penetration Testing Requirements Hidden in Developer Policies

Your Platform Is Your Regulator: The Penetration Testing Requirements Hidden in Developer Policies

By EJN Labs · 4 Sep 2026 · 7 min read

Some platform developer policies contain genuine penetration testing requirements, not government regulation but private contract. Amazon’s Selling Partner API Data Protection Policy calls for annual penetration testing, using an industry-recognised methodology, from any application that accesses seller PII. Enforcement is losing API access, not a fine. UK suppliers typically pay £4,400 to £9,800 for the scoped test that satisfies it.

Why do platform developer policies function like regulation?

Platform developer policies function like regulation because losing API access can end a business overnight, the same practical effect as a regulator’s enforcement action, and the review process that decides it sits entirely inside the platform, with no independent appeal and no published tribunal.

For UK software suppliers, this sits alongside the third-party assurance requirements a client’s own procurement team might separately raise, and it points to a wider shift: assurance is moving from paperwork you fill in to technical evidence a platform tests for itself. ISO 27001 does not name penetration testing as a control anywhere in its mandatory clauses, yet a growing list of marketplace and app-platform agreements now do exactly that, in language closer to a technical standard than a legal contract.

Does the Amazon Selling Partner API Data Protection Policy require a penetration test?

Yes, when the application accesses seller PII. Amazon’s Selling Partner API Data Protection Policy calls for penetration testing every 365 days, using an industry-recognised methodology, alongside vulnerability scanning at least every 30 days, and solution providers typically fall within that scope.

That clause sits inside a wider data-protection framework covering encryption, credential handling and access reviews as well as testing, and Amazon is not the only marketplace writing this into its terms. Google’s App Defense Alliance runs a Cloud Application Security Assessment for applications with potential access to sensitive user data, built on the OWASP Application Security Verification Standard, with the level of scrutiny scaling to the app’s assessed risk tier. Neither platform describes itself as a regulator. Both write the obligation into the agreement a developer signs to keep an integration live, and both enforce it the same way, by suspending API credentials rather than issuing a compliance notice.

What should a penetration test cover to satisfy a platform’s security review?

A platform-satisfying test covers the components that touch platform data: the API integration itself, the web application or admin console behind it, authentication and OAuth token handling, and tenant isolation if the product serves more than one customer from shared infrastructure.

Amazon’s own guidance names network infrastructure, cloud environments and application-layer assets, including web applications, APIs and databases, as all requiring coverage. That maps onto familiar scope categories: an API penetration test against every SP-API endpoint the integration calls, a web application penetration test of any dashboard sellers or staff log into, and, where the product is multi-tenant, tenant-isolation testing to confirm one customer’s data cannot leak into another’s session. In our experience, a coverage and limitations statement, setting out exactly what was and was not tested, is worth agreeing before the test starts, since a platform reviewer typically reads it as closely as the findings themselves.

How is platform-mandated testing scoped and evidenced?

Scoping starts from the platform’s own control list, not a generic pentest brief: pull the specific clauses (Amazon’s key security control guidance, a marketplace’s app review checklist) and map each testable control onto a scope line, so the report answers the platform’s questions in its own terms.

We ask for the same three things regardless of which platform is asking: the specific policy clause or checklist item you have been sent, the components that touch its data, and the report format it expects to receive. Amazon’s solution-provider guidance sets remediation deadlines alongside the testing requirement, seven days for critical findings and thirty for high, so we build a retest slot into the schedule from the outset rather than treating it as an afterthought once the report lands. Evidence goes back to the platform as a dated report plus a short summary letter confirming scope, methodology and the standard applied, in a format a reviewer who has never spoken to a tester can still act on.

What does a penetration test for a platform security review cost in the UK?

A day of CREST-accredited testing typically costs £1,100 to £1,400 in the UK market. A platform-scoped test covering an API integration and its supporting web interface usually takes 4 to 7 days, so typically £4,400 to £9,800 in total, with the exact figure set by how many endpoints and tenants are in scope.

That band assumes a single API and one supporting application; testing multiple regional deployments, additional apps, or a broader cloud configuration review adds days on top. Retesting once remediation work is complete is usually quoted separately, at a day or two. For how the wider market prices testing by scope and complexity, our guide to UK penetration testing costs sets out the ranges in more detail, and the fastest way to a figure specific to your integration is a scoped quote rather than a published table.

How EJN Labs approaches platform-driven penetration testing

EJN Labs is a UK-based, CREST-accredited penetration testing firm, certified to ISO 27001 and ISO 9001, with all testing carried out by UK-based testers. When a platform’s developer policy is the driver, we start scoping by reading the actual clause with you.

That might be Amazon’s annual testing requirement for solution providers or an app-marketplace review checklist, so the engagement is built to answer exactly what the platform asks rather than a generic template. We have found the same pattern across marketplace, cloud console and enterprise app-store engagements: the reviewer on the other end is usually a security team reading a report against a checklist, not a person weighing context, so precision in how findings are written up matters as much as finding them. Our report includes a methodology section, a coverage and limitations statement, and CVSS-scored findings, in a structure a platform’s own review team can process without a follow-up call. Where you also face separate procurement-side third-party assurance requirements, one well-scoped engagement usually answers both.

Frequently Asked Questions

What are ‘third-party assurance requirements’ on a supplier questionnaire?

Third-party assurance requirements are the evidence a buyer’s procurement or security team asks a supplier to provide, separate from anything a platform enforces. Typical examples are a CREST-accredited penetration test report or a signed attestation letter confirming independent testing took place.

How often do platforms expect penetration testing evidence?

Annually is the recurring figure across the marketplace policies that name a frequency. Amazon’s guidance for solution providers sets annual penetration testing alongside vulnerability scanning every 30 days, and app-review programmes that name a cadence commonly ask for a report no older than twelve months.

What happens if a platform’s security review finds a problem?

Remediation deadlines apply, then a retest. Amazon’s guidance for solution providers sets seven days to fix critical-risk findings and thirty for high-risk ones, and a platform review typically expects a short retest or written confirmation before access is confirmed as compliant again.

Can a single penetration test satisfy more than one platform’s policy?

Often, yes, if the scope is built wide enough. A test covering the API surface, the web application and tenant isolation will usually satisfy Amazon’s requirement, a Google CASA assessment, and a procurement questionnaire at the same time, provided the report format matches what each one asks for.

What does a platform-mandated penetration test cost in the UK?

A day of CREST-accredited testing typically costs £1,100 to £1,400 in the UK market. A platform-scoped test covering an API integration and its supporting web application usually takes 4 to 7 days, so typically £4,400 to £9,800 in total, with retesting after remediation quoted separately.

Get a test scoped to your platform’s checklist

If a marketplace, cloud console or enterprise app-store review is the reason you need a penetration test, we can scope the work around the specific clause or checklist item you have been sent. Get a CREST pentesting quote and we will map the scope and confirm a price built around what your platform is actually asking for.

For a closer look at specific platform policies, see our deep dive on whether Amazon SP-API requires a penetration test, our comparison of marketplace security reviews against genuine penetration testing, and our guide to proving tenant isolation for multi-tenant SaaS platforms.

Leave a Reply

Your email address will not be published. Required fields are marked *