← Glossary·Security

Penetration Test (Pen Test)

SOC 2ISO 27001PCI DSSHIPAA

Authorised offensive simulation of an attacker to identify exploitable vulnerabilities.

A penetration test is an authorised, scope-bound offensive engagement simulating a realistic attacker to identify exploitable vulnerabilities. Common variants: external network, internal network, web/application, cloud, API, social engineering, and red team.

Why it matters
Annual pen tests by a qualified third party are explicit in PCI DSS 11.4 and effectively required by SOC 2 and ISO 27001 to evidence ‘independent assessment of controls’.

Related terms

Vulnerability Management
Continuous discover-prioritise-remediate cycle for software vulnerabilities (CVEs) and misconfigurations.

Does your program actually cover Penetration Test (Pen Test)?

Run a free ComplianceIQ audit against SOC 2 and we'll surface every gap on this — and the other controls auditors flag — with the exact clause references to fix.

Free SOC 2 auditBack to glossary