Penetration testing for ISO 27001, SOC 2 and NIS2
An auditor-ready report, delivered in 10 working days.
Manual testing, not scanner output. 18 years in offensive security, published CVEs, CRTO certified.
Certification requires a penetration test. An automated scan does not pass it. The auditor wants evidence, not a Nessus PDF.
Three things, every engagement
Executive and technical report
One page for the auditor and management, the technical detail for your engineers. Business risk, reproduction and the actual fix, not a link to OWASP.
Walkthrough with your team
A session where I walk your developers through every finding and its fix. No report thrown over the wall.
Free retest included
After you fix, I retest within 3 working days and issue a verification appendix, at no extra cost. You reach the audit with the findings closed.
Fixed scope, fixed price
| Service | Price | Turnaround |
|---|---|---|
| Web application pentest (single app) | from €4,500 | 10 working days |
| External infrastructure pentest | from €3,500 | 7 working days |
| Verification retest | Included | 3 days |
Next availability: September.
A fixed quote after a 30-minute scoping call. Remote, worldwide. A periodic re-assessment of the same system, 6 to 12 months later, is 40% of the original.
See the deliverable before you buy
A full anonymised sample report: executive summary, findings mapped to ISO 27001 and SOC 2 controls, proof-of-concept and concrete remediation. No email required.
"We were preparing for our ISO 27001 certification and needed a proper pentest. Martín found issues that our previous vendor and automated scans had completely missed. Clear report, zero fluff, and he took the time to walk our devs through every fix."
Fintech client, ISO 27001 certification
Not a shell consultancy
Public, checkable proof of the work. Published CVEs with my name on them, open-source tooling, a real professional history.
Selling certifications and need the technical piece handled?
I work as a technical partner. You keep the client relationship. I execute, and can deliver under your brand (white label) if you prefer.
Talk to me →The questions auditors and buyers ask
Will the auditor accept the report?
Yes. The report maps each finding to the relevant ISO 27001 Annex A controls (and SOC 2 criteria), documents scope and methodology, and includes the retest evidence auditors ask for. It is written to be attached to your certification evidence.
What if you don't find anything?
A report that documents the tested scope and the controls verified is exactly the evidence the auditor needs. A pentest with no critical findings is not a failed test, it is a closed file: you are paying for the assurance and the evidence, not for a list of problems.
Do you sign an NDA?
Always, before any scoping call that touches sensitive information. I have a standard mutual NDA I can send, or I sign yours.
Do you test in production?
By default, no. Testing runs against a staging environment with demo or synthetic data, which is safer and gives the same coverage. If production testing is genuinely required, it is done only under a specific, detailed contract that defines the window, safeguards, data involved and responsibilities.
What do you need from us to start?
The scope (which app or systems), access to the staging environment, and a couple of test accounts. We agree the rules of engagement in writing before anything begins.
Ready to scope it?
Book a 30-minute call. We define the scope and I send a fixed quote.
Book the scoping call →