Processors and Sub-Processors: Pen Test Reports in the DPbD Evidence Pack Clients Expect

Processors and Sub-Processors: Pen Test Reports in the DPbD Evidence Pack Clients Expect

By EJN Labs · 14 Aug 2026 · 8 min read

DPbD security assurance is the evidence a processor or sub-processor supplies to show it builds data protection into its systems, as UK GDPR Article 25 and ICO guidance require. A recent penetration test report is the strongest single item in that evidence pack. Typical UK testing for a SaaS processor runs 3 to 5 days, around £3,300 to £7,000, from a CREST-accredited firm.

Why DPbD security assurance now decides processor deals

DPbD security assurance decides deals because controllers carry a legal duty under UK GDPR to use only processors that provide sufficient guarantees of appropriate technical and organisational measures. Before a contract is signed, and at every renewal, someone on the client side asks for proof your platform is secure.

If you sell software or services that touch personal data, your clients are those controllers, and DPbD security assurance is the name for the proof they request: evidence that your platform was designed and operated securely.

The same pressure cascades down the chain. If you are a sub-processor, your direct customer is itself a processor answering to its controllers, so the evidence demand is passed on to you, usually word for word. A vendor that can hand over a coherent pack with an independent penetration test report at its centre closes security review in days. A vendor that cannot gets stuck in questionnaire loops or loses the deal.

The regulatory driver: what the ICO actually requires

Data Protection by Design and by Default is a mandatory principle of UK GDPR, set out in Article 25 and explained in ICO guidance. Controllers must build data protection into processing from the design stage onward and be able to demonstrate it. Processors are pulled in through Article 28: controllers may only appoint processors that provide sufficient guarantees, and processor contracts must require appropriate security measures.

Here is the honest part. Neither Article 25 nor the ICO’s DPbD guidance names penetration testing as a mandatory control. The requirement is risk-based: measures must be appropriate to the nature, scope, context and purposes of the processing and the risks to individuals. What ICO guidance points to is evidence that security was considered by design and verified in practice, and it encourages regular testing of systems to assess effectiveness. So a pen test report is not a box the law forces you to tick; it is the independent demonstration that the measures you claim on paper hold up against a real attacker.

What belongs in a processor’s DPbD evidence pack

Based on the security reviews our SaaS and MSP clients face, a pack that clears scrutiny quickly contains six things:

  • A current penetration test report or an executive summary plus attestation letter, dated within the last 12 months, with remediation status for every finding
  • A retest confirmation or remediation statement showing high and critical issues were fixed and verified
  • Your Article 28-ready security measures annex, describing encryption, access control, logging and backup arrangements
  • Certifications where you hold them, such as Cyber Essentials Plus or ISO 27001
  • Your sub-processor register and the assurance you collect from each one, so clients can see the chain does not break below you
  • A short secure development summary: how changes are reviewed, how vulnerabilities are triaged, and your patching timescales

Vendors commonly hold four of the six already. The pen test report is the item most often missing, out of date, or scoped so narrowly that the client rejects it. If you are preparing a first engagement, our penetration testing checklist covers what to have ready before testing starts.

What controllers expect the test itself to cover

A report only satisfies a security review if its scope matches the service the client is buying. For a typical SaaS processor that means four surfaces:

  • The web application, including authentication, session handling, tenant isolation and privilege boundaries between customer accounts
  • The APIs behind it, tested with an API penetration test that checks authorisation object by object, not just endpoint by endpoint
  • The cloud environment, covered by a cloud penetration test of IAM roles, storage permissions, network segmentation and secrets handling
  • The external perimeter, so exposed services, admin panels and forgotten subdomains are enumerated and assessed

Tenant isolation deserves special mention. When we scope a multi-tenant SaaS platform, we provision at least two test tenants and attempt to cross the boundary between them, because that is the failure mode a controller fears most: their data reachable from someone else’s account. A report that never mentions cross-tenant testing will draw follow-up questions.

How an engagement runs for a processor

Engagements follow the same arc as any well-run test, starting with scoping: mapping the personal data flows through your service, agreeing which applications, APIs and cloud accounts are in scope, and confirming the test accounts and a safe testing window.

For processors, additions that matter for evidence are built in from the start: we record which controller-facing claims the test is meant to evidence, so the report answers the questions your clients will actually ask.

Second, testing and reporting. UK-based testers work through the agreed scope, keeping any live personal data exposure to the minimum needed to prove a finding. The report grades findings by risk, explains business impact in plain language, and gives specific remediation steps. Because it will circulate outside your business, we also provide an executive summary suitable for sharing with clients without disclosing exploit detail. After you remediate, a retest confirms fixes and produces the closure statement reviewers want, with high and critical verification treated as a priority, typically within 14 days of your fix.

What it costs and how scope drives the price

Penetration testing in the UK is priced by effort. Day rates at accredited firms typically run £1,100 to £1,400, and scope determines how many days the work needs. Typical processor and sub-processor ranges:

Engagement scopeTypical effortTypical cost
Single web app plus external perimeter3 to 5 days£3,300 to £7,000
Web app, APIs and cloud configuration review5 to 8 days£5,500 to £11,200
Multi-tenant platform, several APIs, full cloud estate8 to 12 days£8,800 to £16,800

The main cost drivers are the number of applications and APIs, the size of the cloud estate, whether authenticated multi-tenant testing is required, and whether a retest is included. These are typical UK ranges rather than a quotation; an exact price follows a short scoping call. For a fuller breakdown see our guide to penetration testing costs in the UK, and when comparing suppliers our notes on choosing the best UK penetration testing provider cover the accreditation questions to ask.

How EJN Labs approaches DPbD evidence for processors

EJN Labs is a UK firm delivering CREST-accredited penetration testing, and we hold Cyber Essentials Plus, ISO 27001 and ISO 9001 ourselves, so we sit on both sides of the assurance exchange: we produce evidence for clients and we answer security reviews as a supplier. We scope against your data flows and your clients’ questionnaires, not a generic template. We test with UK-based testers under UK contracts, which matters to controllers assessing transfer risk. And we structure reporting for onward sharing, with a client-safe executive summary and a remediation tracker, so one engagement feeds every security review you face for the next year.

Frequently Asked Questions

Does UK GDPR require processors to have a penetration test?

No, not explicitly. UK GDPR Article 25 makes data protection by design and by default mandatory, and Article 32 requires security appropriate to risk, but neither names penetration testing. Controllers ask for one anyway because an independent test is, in our experience, the evidence they most often accept.

ICO guidance encourages regular testing of the effectiveness of your measures, and an independent pen test is how processors commonly evidence it.

What should a sub-processor include in a DPbD evidence pack?

Six items: a current penetration test report or attestation with remediation status, a retest or closure statement, your security measures annex, certifications such as Cyber Essentials Plus or ISO 27001, your sub-processor register with the assurance you collect from each, and a short secure development summary.

Together these show data protection was designed in and independently verified.

How much does DPbD security assurance testing cost in the UK?

Around £3,300 to £7,000 for a single web application with its external perimeter over 3 to 5 days, at UK day rates of £1,100 to £1,400. Adding APIs and a cloud configuration review takes 5 to 8 days, £5,500 to £11,200, and large multi-tenant estates run 8 to 12 days, £8,800 to £16,800.

Those are typical UK day rates at accredited firms. Exact pricing follows scoping.

How old can a pen test report be before clients reject it?

Twelve months is the practical limit: most controller security reviews expect a report dated within the last 12 months, and many contracts now write annual testing into the processing agreement. A report also ages faster than its date suggests if the platform has changed significantly.

Material releases, new APIs or a cloud migration are all sensible triggers for retesting before the anniversary.

Should we share the full penetration test report with clients?

Usually not: the full report contains exploit detail that should stay inside your business. Share the executive summary and an attestation letter confirming scope, methodology, dates and remediation status, and offer the remediation tracker for open items. Most reviewers accept this arrangement.

A well-structured summary from a CREST-accredited firm answers reviewers’ questions without creating new exposure.

Build the evidence pack your clients expect

If controller security reviews are slowing your deals, one properly scoped engagement produces the report, summary and retest evidence that answers them for the year. Get a CREST penetration testing quote from our UK-based testers and we will return a fixed scope and price.

Leave a Reply

Your email address will not be published. Required fields are marked *