main logo icon

Published on

October 1, 2026

|

29 min read

Best Penetration Testing Companies for ISO 27001 (2026): Ranked for Annex A Evidence and Certification Audits

Ranked guide to the best penetration testing companies for ISO 27001 in 2026, scored on Annex A evidence, retests and independence from your certification body under ISO/IEC 17021-1 and 27006-1, verified 1 and 2 October 2026.

Arafat Afzalzada

Arafat Afzalzada

Founder

Web App SecurityNetwork Security

Summarize with AI

ChatGPTPerplexityGeminiGrokClaude

TL;DR

ISO/IEC 27001:2022 names no penetration test in any clause or control title, but a test is the strongest evidence most organizations have for Annex A controls 8.8 Management of technical vulnerabilities and 8.29 Security testing in development and acceptance, with 5.35, 5.36 and 8.34 close behind. Since 31 October 2025 every accredited certificate has had to cite the 2022 edition, because IAF MD 26 required all ISO/IEC 27001:2013 certifications to expire or be withdrawn at the end of the transition period. The rule buyers miss is impartiality. ISO/IEC 17021-1 bars a certification body from management system consultancy, treats internal audits for its own certified clients as a significant threat to impartiality, and ISO/IEC 27006-1 says the body "shall not provide internal information security reviews" of an ISMS it certifies. ANAB listed 50 certification bodies accredited for ISO/IEC 27001 on 1 October 2026, and at least 11 of them sell penetration testing under the same brand or inside the same group. Buy the test from a firm with no tie to the body that certifies you. The best penetration testing companies for ISO 27001 in 2026 are Stingrai, Praetorian, Raxis, Synack, Cobalt, CBIZ Pivot Point Security, BreachLock, Astra Security, A-LIGN and Prescient Security. CBIZ Pivot Point Security, A-LIGN and Prescient Security sit in a company or group that also certifies ISMSs, so use them only when a different body certifies you. Every vendor entry links to a page on the vendor's own site, an accreditation directory, the CREST Marketplace or a public review profile, read on 1 and 2 October 2026.

Since 31 October 2025, every accredited ISO 27001 certificate has had to cite the 2022 edition. The International Accreditation Forum's transition document, IAF MD 26:2023, set that date: "All certifications based on ISO/IEC 27001:2013 shall expire or be withdrawn at the end of the transition period." On 1 October 2026 the ANSI National Accreditation Board's certification body directory listed 50 certification bodies accredited for ISO/IEC 27001, and in Canada the Standards Council of Canada describes itself as "the only internationally recognized accreditation body in Canada offering Information Security Management Systems accreditation." At least 11 of those 50 ANAB-accredited bodies sell penetration testing under the same brand or inside the same group, which is why this ranking scores independence alongside evidence quality.

Where Stingrai fits: Stingrai is a CREST-accredited penetration testing service provider at firm level, founded in Toronto in 2021 with a London office, and its business is offensive security alone. Each human-led engagement is run by two named penetration testers from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP. For an ISMS owner that means a scope built from the Statement of Applicability, findings posted to the PTaaS portal as each one is confirmed, retesting included until findings are resolved, and an attestation letter confirming scope, methodology and retest results with every human-led and hybrid engagement. It runs as a one-time annual engagement timed to your certification or surveillance audit, or as a continuous program. Published pricing is US$3,000 for an Autonomous Pentest and US$6,800 for a Hybrid Pentest, each covering one web application and its APIs (pricing); network, cloud, Active Directory and multi-entity ISMS scopes are quoted.

Quick answer: who are the best penetration testing companies for ISO 27001 in 2026?

The best penetration testing companies for ISO 27001 in 2026 are Stingrai, Praetorian, Raxis, Synack, Cobalt, CBIZ Pivot Point Security, BreachLock, Astra Security, A-LIGN and Prescient Security. Stingrai ranks first for named, certified penetration testers from a CREST-accredited firm whose only business is offensive security, with retesting included and an attestation letter with human-led and hybrid engagements, on one-time or continuous terms. Praetorian, Raxis and Synack follow for the most detailed ISO 27001 testing guidance, a dedicated ISO 27001 testing service with an Annex A mapped report, and ISO 27001 guidance mapped to 8.8, 8.29 and Clause 9. CBIZ Pivot Point Security, A-LIGN and Prescient Security each sit in a company or group that also certifies ISMSs, so they are strongest when a different body certifies you.

This guide ranks providers. For what the standard itself requires, clause by clause, read the companion ISO 27001 penetration testing requirements guide.

What ISO 27001 actually asks of a penetration test

ISO/IEC 27001:2022 does not name penetration testing in any clause title, and none of the 93 control titles in its Annex A reference set contains the word. ISO's free preview on the Online Browsing Platform shows the clause and control titles and the informative front matter, but not the requirement or control text. That text sits behind the paywall, so the control descriptions in this guide are paraphrases, and the titles are quoted exactly as ISO publishes them in the ISO/IEC 27002:2022 contents.

What matters for vendor selection is what each control asks the vendor's deliverable to prove.

Annex A control (title as published)

What the vendor's deliverable has to show

8.8 Management of technical vulnerabilities

Findings with severity, owner, discovery date and closure date, plus a dated retest showing the fix held

8.29 Security testing in development and acceptance

A test tied to a named release or system before or at acceptance, with the acceptance criteria it was judged against

5.35 Independent review of information security

The name of the independent firm, the testers' names and qualifications, and the dates, in the engagement letter or report

5.36 Compliance with policies, rules and standards for information security

Test records that match the cadence your own testing policy states

8.34 Protection of information systems during audit testing

Rules of engagement for testing live systems, agreed with the system owner before testing starts

A vendor that cannot produce all five artifacts is selling a report, not evidence. The pentest evidence guide compares the same artifacts across ISO 27001, SOC 2, PCI DSS and CMMC.

The certification body impartiality problem

Most buyers never ask who else the testing firm works for. Under the standards that govern certification bodies, it is the first question.

What ISO/IEC 17021-1 says

ISO/IEC 17021-1:2015 is the requirements standard every accredited management system certification body works to, and it is the edition shown on ISO's Online Browsing Platform on 1 October 2026. Its free preview includes the definitions, which the International Accreditation Service also reproduces in its Section 3 summary. A certification audit is an "audit carried out by an auditing organization independent of the client and the parties that rely on certification." Impartiality is the "presence of objectivity." Management system consultancy is "participation in establishing, implementing or maintaining a management system," and one of the standard's two examples reads: "Giving specific advice, instructions or solutions towards the development and implementation of a management system."

The impartiality clauses themselves are not in the preview, so this guide relies on accreditation bodies that quote or summarize them:

  • Clause 5.2.5, quoted by European Accreditation: "The certification body and any part of the same legal entity and any entity under the organizational control of the certification body … shall not offer or provide management system consultancy."

  • Clause 5.2.6, as summarized by the International Accreditation Service: internal audits by the certification body for its certified clients are "a significant threat to impartiality," and the recognized mitigation is that the body "shall not certify a management system on which it provided internal audits for a minimum of two years following the completion of the internal audits."

  • Clause 5.2.7, quoted by European Accreditation: "Where a client has received management systems consultancy from a body that has a relationship with a certification body, this is a significant threat to impartiality," with the same two-year recognized mitigation. A national accreditation body argued in that FAQ that the word "recognized" leaves room for other mitigations, and European Accreditation's answer accepts the two-year rule or a similar mitigation.

  • Clause 4.2, in the International Accreditation Service summary, lists self-review among the threats to impartiality.

What ISO/IEC 27006-1 adds for information security

ISO/IEC 27006-1:2024 sets the extra rules for bodies that certify information security management systems, and its preview confirms it replaced ISO/IEC 27006:2015 and was aligned with ISO/IEC 27001:2022. European Accreditation quotes its clause 5.2.2: "The certification body shall not provide internal information security reviews of the client’s ISMS subject to certification. Furthermore, the certification body shall be independent from the body or bodies (including any individuals) which provide the internal ISMS audit." European Accreditation's answer to that FAQ adds that, unlike ISO/IEC 17021-1, ISO/IEC 27006-1 allows no two-year mitigation when an auditor also provides a client's internal ISMS audit.

None of the quoted text mentions penetration testing. Whether a particular test counts as consultancy, an internal information security review or neither is a judgement each certification body makes under its own impartiality process, and the accreditation body assesses that process. A buyer does not need to win that argument. The clean answer is to buy the test from a firm with no relationship to the body that certifies you, so that the evidence for 5.35, 8.8 and 8.29 is never reviewed by the people who produced it.

Certification bodies that also sell penetration tests

We pulled every body listed as accredited for ISO/IEC 27001 in the ANAB directory on 1 October 2026 and checked the websites of the brands most likely to test. At least 11 of the 50 sell penetration testing under the same brand or inside the same group, and the true number may be higher.

Eleven ANAB-accredited ISO 27001 certification bodies whose brand or group also sells penetration testing

Brand

Certification entity in the ANAB directory

Penetration testing offered by

A-LIGN

A-LIGN Compliance and Security, Inc.

A-LIGN (testing page)

Schellman

Schellman Compliance, LLC

Schellman Compliance, LLC, the entity CREST lists for penetration testing (testing page)

Coalfire

Coalfire Certification, Inc., the certification arm of Coalfire Systems, Inc.

Coalfire (assessment services)

BARR

BARR Certifications LLC

BARR Advisory (testing page)

CBIZ

CBIZ Security & Compliance, LLC

CBIZ Pivot Point Security and CBIZ cybersecurity (testing page)

ControlCase

ControlCase Assessments LLC

ControlCase (testing page)

Baker Tilly

Baker Tilly Certifications LLC

Baker Tilly (testing page)

Sensiba

Sensiba LLP

Sensiba LLP (testing page)

Securisea

Securisea CB, LLC, a wholly owned subsidiary

Securisea (home page)

360 Advanced

360 Advanced Compass Rose

360 Advanced (services)

BSI

BSI Assurance UK Limited

BSI (cybersecurity services)

Outside the ANAB list, risk3sixty ISO Certifications, LLC says it is accredited by the International Accreditation Service for ISO/IEC 27001:2022 while risk3sixty sells penetration testing and ISO 27001 advisory, Prescient Security says it "operates as an independent and impartial Certification Body" and also sells testing, and Thoropass says Thoropass Certification LLC "provides independent ISO 27001 certification audits" alongside its CREST-accredited testing.

Some firms fence the two roles explicitly. PwC Canada, which lists the Standards Council of Canada as its accreditation body for ISO/IEC 27001, offers ISMS internal audit and design services on its ISO/IEC 27001 page under a heading that reads "for non-PwC certified clients." That is the shape of answer to look for from any firm that does both.

ANAB, the Standards Council of Canada and how to check a certificate

A certificate is only as good as the accreditation behind it, and both accreditation bodies that matter to North American buyers publish what they check.

ANAB in the United States. ANAB's ISO/IEC 27001 accreditation page lists the documents it assesses certification bodies against, including ISO/IEC 27006, IAF MD 26:2023 and IAF MD 29:2024. ANAB told its accredited bodies that they had to use ISO/IEC 27006-1:2024 "for all clients no later than 31 March 2026" (ANAB, September 2024), so audits by ANAB-accredited bodies after that date run under the newer rules, including its informative Annex E, "Guidance for review of implemented ISO/IEC 27001:2022, Annex A controls."

The Standards Council of Canada. SCC's information security program is "based on ISO/IEC 27006 and ISO/IEC 27006-1," and SCC adds: "As a pre-requisite, certification bodies must also be accredited to ISO/IEC 17021-1." SCC is a signatory to the International Accreditation Forum's Multilateral Recognition Arrangement for this program, so "certification to ISO/IEC 27001 by SCC-accredited certification bodies is widely accepted internationally" (SCC).

How to check. IAF CertSearch describes itself in one line: "The official global database for accredited certificates." Three checks are worth making:

  1. Confirm your certification body is accredited for ISO/IEC 27001 by ANAB, SCC or another IAF signatory, and that your certificate cites ISO/IEC 27001:2022.

  2. If a testing vendor claims its own ISO 27001 certificate, look it up the same way.

  3. Search the accreditation directories for the vendor's brand. If its group appears there, put the first question in the buyer checklist below to it before you sign.

What certification auditors look for in penetration test evidence

Auditors read evidence, not intentions. When certificates moved to the 2022 edition, IAF MD 26 told certification bodies that transition audits "shall not only rely on the document review, especially for reviewing the technological information security controls." A penetration test is one of the few documents that shows a technological control working rather than describing it.

The evidence bundle an auditor can sample:

  • Scope traced to the ISMS. The test scope should name the systems inside your ISMS scope and the Statement of Applicability rows it evidences. A test of the wrong systems is a test of nothing the auditor is assessing.

  • Dates inside the certification year. A report dated before your last audit is last year's evidence.

  • Method, independence and named testers. These support 5.35 and let the auditor judge competence without a second interview.

  • A findings register and a retest. These are the 8.8 artifacts: severity, owner, due date, closure date and a dated retest.

  • Rules of engagement. The 8.34 artifact for any testing against live systems.

  • The management review record. The minute where results reached top management closes the loop.

The requirements guide gives sample Statement of Applicability wording and a full evidence bundle. When you shortlist vendors, ask each one for a redacted report and check it carries every item above without your team writing cover notes.

How the test fits Clause 9 (performance evaluation)

Clause 9 is where a penetration test stops being a technical document and becomes ISMS evidence. The clause titles on ISO's preview are 9.1 "Monitoring, measurement, analysis and evaluation," 9.2 "Internal audit" and 9.3 "Management review," followed in Clause 10 by 10.2 "Nonconformity and corrective action." IAF MD 26 notes that the 2022 edition uses the same wording, "Documented information shall be available as evidence," in clauses 9.1, 9.2.2, 9.3.3 and 10.2. The full clause text is not in the free preview, so the walk-through below is built on those titles and that summary.

How a penetration test feeds ISO 27001 clause 9.1, 9.2, 9.3 and 10.2, and what the certification body samples
  1. 9.1, monitoring and measurement. Name penetration testing as a monitoring method and say when it happens, for example once per certification year and on defined change triggers. Once written, the cadence is auditable against you.

  2. The test and the retest. The vendor's report, findings register and retest become the documented information 9.1 asks for.

  3. 9.2, internal audit. Your internal auditor samples the test record. Under ISO/IEC 27006-1 clause 5.2.2 the certification body must be independent from whoever provides that internal ISMS audit, so if one firm runs both your testing and your internal audit, keep both away from your certifier.

  4. 9.3, management review. Results and open risks reach top management, and the minute records the decisions.

  5. 10.2, corrective action. Findings missed by their due date become nonconformities with corrective actions, and the retest is the evidence they were fixed.

What an ISO 27001 test scope should cover

Start from clause 4.3, "Determining the scope of the information security management system," and the Statement of Applicability, not from last year's scope. The areas below are where testing produces evidence for the listed controls; the control titles are quoted from ISO/IEC 27002:2022.

  • External perimeter and remote access. Internet-facing hosts, VPN and remote desktop gateways, and exposed management interfaces, relevant to 8.20 "Networks security" and 8.21 "Security of network services."

  • Internal network and Active Directory. Lateral movement, privilege escalation and segmentation between zones, relevant to 8.2 "Privileged access rights," 8.5 "Secure authentication" and 8.22 "Segregation of networks."

  • Cloud accounts. Identity and access management, cross-account trust and storage policies, relevant to 5.23 "Information security for use of cloud services" and 8.9 "Configuration management."

  • Customer-facing applications and APIs. Authenticated testing across every role for broken authorization and business logic flaws, relevant to 8.29, 8.26 "Application security requirements" and 8.3 "Information access restriction."

  • Environment separation. Whether a foothold in development or test reaches production, relevant to 8.31 "Separation of development, test and production environments."

  • Third-party connections. Integrations and accounts that suppliers use to reach in-scope systems, relevant to 5.21 "Managing information security in the ICT supply chain."

  • People. Phishing and help desk vishing, relevant to 6.3 "Information security awareness, education and training."

For a multi-entity ISMS, record the entity and product against each row so a group-level Statement of Applicability is backed by per-entity evidence, as the requirements guide explains.

How we ranked them

Ten vendors were scored against nine criteria. Every vendor fact links to a page on the vendor's own site, an accreditation directory, the CREST Marketplace or a public review profile, read on 1 and 2 October 2026.

  1. ISO 27001-specific testing evidence on the vendor's own site: a dedicated page, guide or case study, current to the 2022 Annex A.

  2. Independence from certification: whether the vendor, or a company in its group, runs an ISO/IEC 27001 certification body, checked against the ANAB directory and the vendor's own site.

  3. Firm-level accreditation on the CREST Marketplace, and the company certifications listed there.

  4. Named testers, or a stated way of evidencing tester competence for 5.35.

  5. Retest terms stated in writing.

  6. Delivery: one-time and continuous options, and a portal that exports findings.

  7. Evidence artifacts: a report mapped to Annex A and an attestation letter.

  8. North American delivery in the United States, Canada or both.

  9. Pricing transparency.

The 10 companies at a glance

#

Company

HQ

CREST (firm level)

ISO 27001 evidence on its own site

Certification body ties

Retest

One-time or continuous

Best for

1

Stingrai

Toronto, ON (London, UK office)

Penetration Testing

ISO 27001 testing guide; service pages map tests to ISO 27001

Offensive security only

Included

Both

Named testers and audit-ready evidence

2

Praetorian

Austin, TX

Penetration Testing

ISO 27001 testing guide covering 8.8, 8.34 and SoA scoping

None found

Not stated

Both

Continuous evidence between audits

3

Raxis

Atlanta, GA

Not listed

Dedicated ISO 27001 testing service page

None found

Yes; unlimited on Raxis Attack

Both

An Annex A mapped report with an attestation letter

4

Synack

Redwood City, CA

Penetration Testing

Combined SOC 2, PCI DSS and ISO 27001 testing guide covering 8.8, 8.29 and Clause 9

None found

Patch verification

Both

Continuous testing across a large estate

5

Cobalt

Boston, MA

Penetration Testing (Cobalt Labs entity, listed in Germany)

Compliance testing page with an ISO 27001 section; ISO 27001 maintenance article

None found

Free for 6 or 12 months

Both

PTaaS with letters of attestation

6

CBIZ Pivot Point Security

Hamilton, NJ

Penetration Testing

ISO 27001 case study that included network and application tests

Group: CBIZ Security & Compliance, LLC (ANAB)

Not stated

Consultant-led projects

ISO 27001 depth when another body certifies you

7

BreachLock

New York, NY

Penetration Testing (BreachLock Ltd, listed in the UK)

ISO 27001 testing page, written to 2013 control numbers

None found

Free manual retest plus automated retests

Both

Platform testing with unlimited automated retests

8

Astra Security

Claymont, DE (office in Chandigarh, India)

Penetration Testing

ISO 27001 testing guide with an Astra service section; plan listed for ISO 27001

None found

2 human re-scans on Pentest Expert

Annual plans; continuous on Enterprise

A priced test of one target with manual testing

9

A-LIGN

Tampa, FL

Not listed

ISO 27001 and testing article; certification client case study

Same brand: ANAB-accredited certification body

Not stated

Annual tests plus RADAR monitoring

Testing when another body certifies you

10

Prescient Security

Nashville, TN

Penetration Testing

Compliance pentest package aligned to SOC 2 and ISO 27001

Same brand: self-described certification body

Complimentary re-tests; on Cait, 2 within 30 days, then US$250 each

Both

Testing when another body certifies you

"Not stated" means the vendor's own site does not say. "None found" means the vendor's brand did not appear in the ANAB directory and its site did not describe a certification body. Ask for both in writing.


1. Stingrai

Stingrai is a global CREST-accredited penetration testing services company founded in Toronto, Canada in 2021, trusted by companies from startups to enterprises to meet audit requirements for SOC 2, ISO 27001, CMMC, PCI DSS and HIPAA. OSCE³, OSWE, OSEP, CREST CRT certified pentesters, who are also world-class security researchers and bug bounty hunters. Choose from fully human-led or hybrid (AI agents plus human penetration testers) engagements across web, API, mobile, AI and LLM, cloud, network, Active Directory and social engineering penetration tests and red team engagements.

What an ISMS owner can verify. The firm-level accreditation is on the CREST Marketplace supplier page for Stingrai Inc, separate from the CREST CRT certifications individual team members hold. Clutch shows 5.0 from 20 reviews. Two named penetration testers from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP run each human-led engagement, reviewed by the team lead and an engagement partner, and the about page lists team members' published CVEs and bug bounty Hall of Fame listings at Apple, Google and the US Department of Defense. Stingrai's business is offensive security alone: penetration testing, red teaming, adversary simulation, purple teaming and social engineering. For an ISMS owner, that settles the impartiality question in the first scoping call.

How an ISO 27001 scope is tested. The scope is built from your ISMS scope and Statement of Applicability. Network testing covers the external perimeter, lateral movement and segmentation for 8.20 and 8.22. The Active Directory assessment follows ACL abuse and Kerberos and delegation paths to domain admin. Cloud testing covers AWS, Azure and Entra ID, and Google Cloud from the control plane to the workload, for 5.23 and 8.9. Web application and API testing runs black, grey or white box and authenticated across every role, for broken authorization, IDOR and business logic, evidence toward 8.29 for a customer-facing product. Phishing and vishing campaigns cover 6.3.

Evidence and delivery. Each verified finding posts to the PTaaS portal with severity, reproduction steps and remediation guidance as soon as a tester confirms it, and pushes to Jira or GitHub for tracking to closure, which gives you the record for your 8.8 register. Retesting is included at no additional cost, and on human-led engagements the tester who found an issue verifies the fix. Human-led and hybrid engagements include an attestation letter confirming scope, methodology and retest results, and reports are redactable for customers and auditors. Stingrai runs both one-time annual engagements timed to a certification or surveillance audit and continuous programs that test every release.

Where Snipe fits. Snipe, Stingrai's autonomous AI penetration testing agent, covers web applications and their APIs only. It hunts broken authorization, IDOR and business logic flaws, reviews code and opens AutoFix pull requests. The Autonomous Pentest is Snipe alone, with no penetration testers; in a Hybrid Pentest, Snipe and the penetration testers test together throughout, with the testers directing its focus. Network, Active Directory, cloud and social engineering scopes are tested by penetration testers.

Pricing: US$3,000 for an Autonomous Pentest and US$6,800 for a Hybrid Pentest per assessment of one web application and its APIs, or US$650 and US$1,275 per month on 12-month continuous plans (pricing). The "No High or Critical Finding = Don't Pay" guarantee applies to the Autonomous Pentest only. Every other scope is quoted through get a quote.

Strength: every claim an auditor or customer might test has a public source, from the CREST listing to the review profile, and offensive security is the firm's only line of business. Limitation: a small team, so multi-entity programs need scheduling lead time, and the fixed-price packages cover one web application and its APIs only. Best for: mid-market and enterprise ISMS owners in the US and Canada who want named, certified penetration testers, an attestation letter and a retest record, one-time or continuous.

2. Praetorian

Praetorian Security, Inc. lists its address in Austin, Texas in its privacy policy. Its ISO 27001 testing guide is the most detailed vendor guidance in this ranking: it maps testing to 8.8, 8.34, 8.25 and 8.9, tells buyers their "penetration testing scope should align with the SoA," and lists what auditors expect, including remediation timelines, assigned owners "and retest results confirming that fixes are effective." Its Guard platform cycles penetration testing, purple teaming and red teaming through the year. CREST lists Praetorian Security, Inc. for Penetration Testing with two years of membership. Retest terms, named testers and pricing are not stated.

Strength: guidance written for the ISMS owner, from Statement of Applicability scoping to surveillance-year evidence. Limitation: the guide leans toward the continuous platform, so confirm that a one-time annual engagement delivers the same Annex A mapped report. Best for: ISMS owners who want continuous testing evidence between surveillance audits.

3. Raxis

Raxis lists 2870 Peachtree Road in Atlanta, Georgia on its contact page, describing "manual penetration testing by senior U.S. engineers since 2011." Its dedicated ISO 27001 penetration testing page is the closest match to what an ISMS owner asks for: "We scope every engagement to your Statement of Applicability and risk assessment," every finding is "tied to the controls your auditor evaluates, including A 8.8 for technical vulnerability management and A 8.29 for security testing," and the deliverable includes "an executive summary, detailed findings mapped to Annex A, methodology, remediation guidance, and an attestation letter." Raxis says it retests after remediation "to confirm the fixes hold," and its Raxis Attack service adds continuous testing with unlimited retesting through the Raxis One portal. Raxis does not appear on the CREST Marketplace; its page cites OSCP-certified engineers. Raxis Attack starts at US$25,000 for one year, depending on scope, on its PTaaS page; one-time test pricing is not published.

Strength: the most ISO-specific deliverable on offer, from SoA scoping to an Annex A mapped report. Limitation: no firm-level CREST accreditation, so evidence tester competence for 5.35 with named testers and their certifications. Best for: ISMS owners who want a report the certification body can read without translation.

4. Synack

Synack lists its global headquarters in Redwood City, California on its contact page. Its combined SOC 2, PCI DSS and ISO 27001 testing guide says testing "provides independent, technical verification that Annex A controls (8.8 and 8.29) function as intended," ties ISO 27001 testing to Clause 9 performance evaluation, and tells buyers that mapping findings to "an ISO 27001 Annex A control" is "what turns a technical report into audit-ready evidence." Its penetration testing page offers everything "from a 14-day test to a continuous pentest with full 365-day coverage," delivered by the Synack Red Team, "a community of 1,500 skilled and vetted" researchers, with triage and patch verification. CREST lists Synack, Inc for Penetration Testing with ISO27001 and UK Cyber Essentials company certifications. Its pricing page lists starting prices of US$4,181 for one AI-led Sara Pentest, US$10,283 for one Standard Pentest and US$27,120 for one Synack14 Pentest, with the Synack Platform billed as a separate line item. On 2 September 2026 Synack and NetSPI announced a definitive agreement to merge, with closing expected in October 2026.

Strength: continuous coverage from a large vetted researcher community, with ISO 27001 guidance written to the 2022 controls. Limitation: testing comes from a vetted researcher community, so ask how individual researcher qualifications are evidenced if your 5.35 justification names a qualified tester. Best for: large estates that want continuous testing and patch verification across many assets.

5. Cobalt

Cobalt Labs Inc. lists its US headquarters at One Boston Place in Boston on its contact page. Its compliance testing page has a dedicated ISO 27001 section, "Proving the security of your information systems is essential to ISO 27001 certification," backed by an ISO 27001 overview in its learning center and an ISO 27001 maintenance article with a section on using Cobalt's pentesting to maintain ISO 27001 compliance. Its penetration testing page states: "Every pentest includes free retesting of individual findings for either a 6 or 12-month period." The same page offers "audit-quality letters of attestation." Testers come from its vetted freelance community. CREST lists the Cobalt Labs entity in Germany for Penetration Testing, with an ISO27001 company certification and eight years of membership. Its pricing page sells the Standard, Premium and Enterprise tiers by quote and lists a limited-time price of US$3,500 per test for its Autonomous Pentest, for tests started and completed before 31 December 2026.

Strength: a long retest window and letters of attestation built into the platform. Limitation: the ISO 27001 material is general rather than mapped to Annex A, and the CREST-listed entity is European, so confirm which entity contracts with you. Best for: product teams that want platform-based testing with attestation letters for each release cycle.

6. CBIZ Pivot Point Security

CBIZ Pivot Point Security has its headquarters in Hamilton, New Jersey according to its locations page, and runs a dedicated ISO 27001 consulting practice alongside its testing. An information security case study describes a client that received external and internal credentialed network penetration tests and an application assessment, then "a successful ISO 27001 certification in a nine-month timeframe," followed by ongoing ISO 27001 internal audit services. CREST lists CBIZ Pivot Point Security for Penetration Testing with an ISO27001 company certification and nine years of membership.

The certification body tie. The ANAB directory lists CBIZ Security & Compliance, LLC as accredited for ISO/IEC 27001, with the note that "On April 3 2026, Marcum RAS, LLC completed a name change to CBIZ Security and Compliance, LLC." That puts an accredited ISMS certification body under the same CBIZ brand as a firm that builds ISMSs, runs internal audits and tests them. If Pivot Point consults on or internally audits your ISMS, choose a certification body outside CBIZ, and raise the question with both before you sign.

Strength: ISO 27001 implementation, internal audit and testing experience in one team. Limitation: the group tie above, and retest terms and pricing are not stated. Best for: organizations certified by a body outside CBIZ that want testers who know the standard well.

7. BreachLock

BreachLock Inc. lists its address at 1350 Avenue of the Americas in New York on its contact page. It publishes a dedicated ISO 27001 penetration testing page, and its penetration testing service page says every engagement includes "one free comprehensive manual re-test," with unlimited automated retesting through its platform and results "delivered by a 100% in-house certified pentesting team." CREST lists BreachLock Ltd in the United Kingdom for Penetration Testing, with ISO27001, UK Cyber Essentials and SOC 2 Type 2 company certifications. Its pricing page prices its Standard, Extended and Extensive penetration testing packages by quote, with one, two and a custom number of free manual retests respectively.

Strength: a free manual retest plus unlimited automated retests on every engagement. Limitation: its ISO 27001 page still maps testing to A.12.6.1 and A.12.6.2 from the 2013 edition, which no accredited certificate has cited since 31 October 2025, so require a report mapped to the 2022 Annex A. Best for: teams that want platform-based testing with unlimited automated retests between manual tests.

8. Astra Security

Astra IT, Inc. describes itself in its privacy policy as a Delaware corporation with an address in Claymont, Delaware, and names Czar Securities Private Limited, with an office in Chandigarh, India, alongside it as "Astra." Its ISO 27001 penetration testing guide maps testing to A.8.8 and A.8.29 and includes a section on how Astra supports an ISO 27001 audit: "Astra Security combines automated scanning with expert-led manual pentesting across your entire attack surface: web applications, APIs, cloud infrastructure, and networks." The guide says Astra's reports include "control mapping, CVSS-scored findings, and remediation guidance," and that Astra "retests at no extra cost and issues a certificate that your auditor can independently verify"; that certificate is Astra's own test certificate, not an ISO 27001 certificate. Its pricing page lists the Pentest Expert plan, which adds a "Manual pentest by certified experts" and "2 human re-scans," at US$5,999 a year for one target, with "Pentest for SOC2, ISO 27001, HIPAA etc." listed under the plan; the US$2,999 Pentest Auto plan is an autonomous pentest. CREST lists Astra IT Inc in the United States for Penetration Testing, with an ISO27001 company certification and two years of membership.

Strength: published prices and an ISO 27001 guide written to the 2022 controls, from a CREST-accredited firm. Limitation: the guide still refers once to the 2013 edition's 14 domains, the entry plan's pentest is autonomous, and part of the company sits in India, so ask where your testers are based if data residency matters. Best for: SaaS teams that want a priced test of one target with manual testing and re-scans included.

9. A-LIGN

A-LIGN lists its headquarters at 400 N Ashley Drive in Tampa, Florida on its contact page, and the ANAB directory lists A-LIGN Compliance and Security, Inc. as accredited for ISO/IEC 27001. Its penetration testing page cites "OSCP/OSCE/OSEE-certified testers" and "4,600+ completed engagements," says testing "satisfies your compliance needs for SOC 2 and ISO 27001," and describes the arrangement directly: testing "is backed by the same firm already running your compliance program, handled by two separate, independent teams." It publishes an article on combining penetration testing with an ISO 27001 audit and a case study of a client that earned ISO 27001 certification with A-LIGN and continued with regular penetration testing. Its impartiality page says its review process "ensures that we do not perform audit services for clients where non-audit services have been performed."

Strength: a stated 4,600+ completed testing engagements and a RADAR platform for monitoring between annual tests. Limitation: A-LIGN is itself an ANAB-accredited ISO 27001 certification body, and A-LIGN does not appear on the CREST Marketplace. If A-LIGN certifies you, ask it in writing how that impartiality policy applies to a test before you buy one. Best for: organizations certified by a different body that already use A-LIGN for SOC 2 or other audits.

10. Prescient Security

Prescient Security lists its address at 1900 Church Street in Nashville, Tennessee on its contact page. Its pricing page sells a Compliance Penetration Testing package, starting at US$3,000, for audit evidence aligned to SOC 2, ISO 27001 or customer due diligence questionnaires, alongside Traditional Penetration Testing starting at US$6,000. Its penetration testing page offers "complimentary re-tests" and "letters of attestation," while the pricing page's Cait AI penetration tester subscription includes up to two retests within 30 days of each scan, with extra retests at US$250 each. CREST lists Prescient Security LLC for Penetration Testing with ISO27001, ISO42001 and SOC 2 Type 2 company certifications and nine years of membership. Its ISO certification page says Prescient Security "operates as an independent and impartial Certification Body," and its impartiality page says "We do not offer management system consultancy or any other form of consultancy to companies or individuals, for any ISO standards."

Strength: a published compliance testing package with re-tests and attestation letters, from a CREST-accredited firm. Limitation: the same brand certifies ISMSs, so ask how its impartiality review treats a test of a system it certifies, or buy the test only if another body certifies you. Best for: organizations certified elsewhere that want a fast compliance test with attestation letters.


Firms considered and not ranked

Several familiar firms were left out because we found no current ISO 27001-specific testing page or case study on their own sites in searches on 1 and 2 October 2026.

NCC Group holds the widest CREST accreditation set we checked, and its penetration testing page lists ISO 27001 among the regulations testing helps meet, but its ISO 27001 offer is implementation and certification support and its ISO 27001 certification guide does not cover testing, so we found no ISO 27001-specific testing page or case study.

Schellman, Coalfire and BARR each run an ANAB-accredited ISO 27001 certification body and sell testing, as the table above shows, and none publishes an ISO 27001-specific testing page we could find. Schellman and Coalfire appear in the SOC 2 ranking and the PCI DSS ranking. risk3sixty pairs ISO 27001 advisory, a sister certification body accredited by the International Accreditation Service and CREST-accredited testing. Thoropass pairs a certification entity with CREST-accredited testing; the only ISO 27001 testing material we found on its site is a 2023 multi-framework help article that cites the 2013 control A.12.6.1.

GuidePoint Security, Optiv and Tevora are CREST-accredited testers whose sites offer ISO 27001 assessment or consulting, without a testing page or case study written for ISO 27001. Kroll and NetSPI, also CREST-accredited, had no ISO 27001-specific testing page we could find. In Canada, OKIOK of Laval, Quebec holds ISO 27001 certification itself and builds ISO 27001 programs alongside testing, and the Canada ranking covers the national market.

How much does ISO 27001 penetration testing cost in 2026?

There is no ISO price, only scope. Stingrai publishes its package prices: US$3,000 for an Autonomous Pentest, which is Snipe alone with no penetration testers, and US$6,800 for a Hybrid Pentest, where penetration testers and Snipe test together, each per assessment of one web application and its APIs. The same tiers run at US$650 and US$1,275 per month on 12-month continuous plans. Every other scope, including network, Active Directory, cloud and multi-entity ISMS programs, is quoted through get a quote, with current figures on the pricing page.

The bands below are indicative, taken from our penetration testing cost guide for US dollars and the Canadian cost guide for standard Canadian scopes.

ISMS scope

Indicative US band

Indicative Canadian band (standard scope)

Test scoped to an ISO 27001 ISMS boundary

US$5,000 to US$50,000

Quoted per scope

Customer-facing web application

US$5,000 to US$30,000

C$12,000 to C$25,000

External network

US$5,000 to US$40,000 (network)

C$15,000 to C$35,000

Internal network and Active Directory

US$5,000 to US$40,000 (network)

C$20,000 to C$35,000 internal; C$25,000 to C$35,000 Active Directory

Cloud accounts

US$10,000 to US$50,000

C$25,000 to C$40,000

Organization-wide testing, mid-market (150 to 500 employees)

US$20,000 to US$50,000

Quoted per scope

Annual enterprise program

US$50,000 to US$150,000 or more

C$60,000 to C$90,000 (continuous program)

Three things move an ISO 27001 quote: how many entities and products sit inside the ISMS scope, whether internal network and Active Directory testing is included, and how many applications need authenticated testing across roles. The cost calculator gives a starting figure.

Buyer checklist: questions to put to every vendor

The RFP template and statement of work template turn these into procurement language.

  1. Does your firm, or any company in your group, operate an ISO/IEC 27001 certification body? If yes, which one, and is it ours?

  2. Have you, or any company in your group, provided ISMS consultancy or internal ISMS audits to us? If yes, tell our certification body before it audits the evidence.

  3. Who exactly will test, and can we see their names and certifications before we sign?

  4. Where is your firm-level accreditation listed, and which legal entity signs our statement of work?

  5. Will the report map each finding to a 2022 Annex A control and state scope, dates, method and tester independence?

  6. Is retesting included, within what window, and does it produce its own dated record?

  7. Will you sign rules of engagement covering windows, safety constraints and escalation for live systems?

  8. Can findings be exported into our risk register with severity, owner and dates?

  9. Can you run per-entity scopes and reports for a multi-entity ISMS under one agreement?

  10. Do you offer both one-time annual tests and continuous testing, so our policy cadence matches what we buy?

Frequently Asked Questions

Who are the best penetration testing companies for ISO 27001 in 2026?

The best penetration testing companies for ISO 27001 in 2026 are Stingrai, Praetorian, Raxis, Synack, Cobalt, CBIZ Pivot Point Security, BreachLock, Astra Security, A-LIGN and Prescient Security. Stingrai ranks first: a CREST-accredited penetration testing service provider at firm level whose business is offensive security alone, with two named penetration testers from a team holding OSCE³, OSWE, OSEP, CREST CRT and CISSP on each human-led engagement, retesting included and an attestation letter with human-led and hybrid engagements, one-time or continuous. CBIZ Pivot Point Security, A-LIGN and Prescient Security sit in a company or group that also certifies ISMSs, so use them only when a different body certifies you.

Does ISO 27001 require a penetration test?

No. ISO/IEC 27001:2022 does not name penetration testing in any clause title, and none of the 93 Annex A control titles contains the word. A test is the strongest evidence most organizations have that controls such as 8.8 Management of technical vulnerabilities and 8.29 Security testing in development and acceptance are working, and any testing cadence you are held to is the one you wrote into your own policy, risk treatment plan or customer contracts.

Which ISO 27001 Annex A controls does a penetration test give evidence for?

The strongest mappings are 8.8 Management of technical vulnerabilities and 8.29 Security testing in development and acceptance. A third-party test also supports 5.35 Independent review of information security, testing at the cadence your policy states supports 5.36 Compliance with policies, rules and standards for information security, and agreed rules of engagement support 8.34 Protection of information systems during audit testing.

Can my ISO 27001 certification body also do my penetration test?

It is best avoided. ISO/IEC 17021-1 bars a certification body from management system consultancy and treats internal audits for its own certified clients as a significant threat to impartiality, and ISO/IEC 27006-1 clause 5.2.2, as quoted by European Accreditation, says the body shall not provide internal information security reviews of the ISMS it certifies. None of this text names penetration testing, so the certification body judges each case under its own impartiality process. Buying the test from a firm with no tie to your certifier avoids the question entirely.

Which ISO 27001 certification bodies also sell penetration testing?

On 1 October 2026 the ANAB directory listed 50 certification bodies accredited for ISO/IEC 27001, and at least 11 sell penetration testing under the same brand or inside the same group: A-LIGN, Schellman, Coalfire, BARR, CBIZ, ControlCase, Baker Tilly, Sensiba, Securisea, 360 Advanced and BSI. Outside ANAB, risk3sixty, Prescient Security and Thoropass also pair a certification entity with testing.

How do I check that an ISO 27001 certification body is accredited in the US or Canada?

In the United States, search the ANAB certification body directory for ISO/IEC 27001. In Canada, search the Standards Council of Canada's directory of accredited organizations; SCC describes itself as the only internationally recognized accreditation body in Canada offering information security management systems accreditation, and its program requires certification bodies to be accredited to ISO/IEC 17021-1. A certificate from a body accredited by ANAB or another IAF Multilateral Recognition Arrangement signatory can also be recognized in Canada. IAF CertSearch, the official global database for accredited certificates, can confirm whether a certificate in its database is valid and was issued by an accredited body.

Are ISO/IEC 27001:2013 certificates still valid?

No. IAF MD 26:2023 required all certifications based on ISO/IEC 27001:2013 to expire or be withdrawn at the end of the transition period on 31 October 2025, so every accredited certificate now cites ISO/IEC 27001:2022. A vendor whose testing material still maps to 2013 control numbers such as A.12.6.1 should give you a report mapped to the 2022 Annex A.

How does a penetration test fit ISO 27001 Clause 9?

Under 9.1 Monitoring, measurement, analysis and evaluation you name penetration testing as a method and decide when it runs. The report, findings register and retest become the documented information that clause asks for, your internal auditor samples them under 9.2, the results reach top management under 9.3, and findings missed by their due date become corrective actions under 10.2.

How much does an ISO 27001 penetration test cost in 2026?

Stingrai publishes US$3,000 for an Autonomous Pentest (Snipe alone, no penetration testers) and US$6,800 for a Hybrid Pentest per assessment of one web application and its APIs, or US$650 and US$1,275 per month on 12-month continuous plans; every other scope is quoted. Indicative bands from our cost guides put a test scoped to an ISO 27001 ISMS at US$5,000 to US$50,000 and a standard Canadian internal network test at C$20,000 to C$35,000.


Ready to scope an ISO 27001 penetration test?

A penetration test fails as ISO 27001 evidence in three predictable ways: it misses the ISMS scope, its findings register is never closed, or it comes from a firm tied to the body that reviews it. Stingrai's penetration testing supports your ISO 27001 program with evidence built for the Statement of Applicability: named, certified penetration testers from a CREST-accredited firm, findings and retests tracked in one portal, and an attestation letter with human-led and hybrid engagements, delivered as a one-time annual engagement or as continuous coverage. Book a free scoping call, get a quote for a multi-entity ISMS scope, or see the published package prices on the pricing page.

0 views

0

X

Related reading

Best Penetration Testing Companies for Construction and Engineering Firms (2026)
Network SecuritySocial Engineering

Best Penetration Testing Companies for Construction and Engineering Firms (2026)

The best penetration testing companies for construction and engineering firms in 2026, ranked, with what CMMC, CPCSC, owners and insurers actually require.

30 min read

Best Enterprise Penetration Testing Companies (2026): Ranked for Global Programs, Procurement and Continuous Coverage
Network SecurityWeb App Security

Best Enterprise Penetration Testing Companies (2026): Ranked for Global Programs, Procurement and Continuous Coverage

The best enterprise penetration testing companies in 2026, ranked on capacity, CREST and threat-led schemes, vendor security, MSA terms and board reporting.

31 min read

Best Penetration Testing Companies for Hotels and Hospitality (2026): Ranked for PCI DSS, Guest Data and Franchise Networks
Network SecurityWeb App Security

Best Penetration Testing Companies for Hotels and Hospitality (2026): Ranked for PCI DSS, Guest Data and Franchise Networks

The best penetration testing companies for hotels and hospitality groups in 2026, ranked, with what PCI DSS 11.4, the FTC Marriott order and PIPEDA require.

31 min read

Contents

X