Cyber Defence
Cyber Security

VAPT for ISO 27001: How Penetration Testing Supports Certification (2026)

VAPT for ISO 27001 gives auditors the technical evidence that your controls work. Learn how penetration testing maps to Annex A (A.8.8 technical vulnerability management) and supports, but does not replace, certification.

VAPT for ISO 27001: How Penetration Testing Supports Certification (2026)
Amit Kumar
Amit KumarEthical Hacker & Founder
9 min read

Short answer: VAPT for ISO 27001 means running vulnerability assessment and penetration testing to gather technical evidence that your security controls actually work. VAPT is not the ISO 27001 audit itself, but it directly supports Annex A controls and gives auditors proof of technical vulnerability management.

If you are pursuing ISO/IEC 27001 certification, you have probably been told you need "penetration testing" somewhere in the process. That advice is partly right and partly oversimplified. This guide explains exactly how VAPT (Vulnerability Assessment and Penetration Testing) maps to ISO 27001, which Annex A controls it supports, what evidence an auditor expects, and where VAPT stops and the formal certification audit begins.

What ISO 27001 actually requires

ISO/IEC 27001 is the international standard for an Information Security Management System (ISMS). It is a management-system standard, which means the certificate is awarded for how you govern information security, not for a single technical test. Certification is granted by an accredited certification body after a two-stage audit (Stage 1 documentation review, Stage 2 implementation review), followed by annual surveillance audits.

Crucially, the standard does not contain a line that says "you must run a penetration test." Instead, it requires you to identify risks, select and implement appropriate controls (drawn from Annex A of ISO/IEC 27001:2022), and continually verify that those controls are effective. VAPT is one of the most credible ways to verify that a whole cluster of technical controls is genuinely working, which is why almost every serious ISMS implementation includes it.

How VAPT maps to Annex A controls

The 2022 revision of ISO 27001 reorganised Annex A into 93 controls across four themes. Several of these controls are difficult to evidence without a technical test. VAPT provides that evidence.

Annex A control (2022)What it asks forHow VAPT supports it
A.8.8 Management of technical vulnerabilitiesInformation about technical vulnerabilities must be obtained and exposure evaluatedVAPT identifies, ranks and validates real vulnerabilities across systems
A.8.9 Configuration managementSecure configuration of hardware, software and networksTesting surfaces misconfigurations, weak defaults and hardening gaps
A.8.25 Secure development life cycleSecurity built into developmentApplication and API pentests validate secure coding outcomes
A.8.28 Secure codingSecure coding principles appliedManual testing reveals injection, auth and logic flaws
A.5.7 Threat intelligence / A.8.16 MonitoringAwareness and detection of threatsPentest activity tests whether monitoring and alerting fire

Note that A.8.8 replaces what many practitioners still call by its old 2013 reference, A.12.6.1 "technical vulnerability management." If your consultant or an older template refers to A.12.6, they mean the same theme now covered by A.8.8 in the 2022 version. Either way, this is the control most directly satisfied by a documented VAPT programme.

Why "map" matters to auditors

An auditor is not just looking for a PDF that says "penetration test." They want to see that testing is part of a repeatable process: risk identified, control selected, test performed, findings tracked, remediation verified. A one-off scan disconnected from your risk treatment plan carries far less weight than a VAPT that clearly closes the loop on documented risks.

What evidence auditors expect from VAPT

When we deliver VAPT for clients preparing for ISO 27001, we structure the report so it doubles as audit evidence. A useful evidence package includes:

  • Defined scope tied to your ISMS boundary (which applications, IPs, cloud accounts and APIs were in scope, and why).
  • Methodology reference such as OWASP Testing Guide, OWASP ASVS, PTES or NIST SP 800-115, so the test is repeatable and defensible.
  • Findings with severity ratings (typically CVSS-based) plus clear business impact.
  • Remediation guidance and target timelines aligned to your risk acceptance criteria.
  • Retest evidence confirming high and critical issues were actually fixed, not just logged.
  • Dates and frequency showing testing recurs (commonly annually and after major change).

That last point matters. ISO 27001 emphasises continual improvement, so a single test two years ago is weak evidence. Auditors like to see a schedule: test, remediate, retest, and repeat after significant change.

Where VAPT stops and the ISO audit begins

This is the honest part that many vendors gloss over. A VAPT is not an ISO 27001 audit, and passing a pentest does not certify you. VAPT verifies technical controls. ISO 27001 certification also requires you to demonstrate leadership commitment, documented policies, risk assessment methodology, a Statement of Applicability, internal audits, management reviews, competence and awareness, and more, none of which a penetration test evaluates.

Think of it this way: the certification body audits your management system; VAPT gives you and that auditor confidence that specific technical controls inside the system are effective. You need both. A common, sensible sequence is: build the ISMS, run VAPT to validate technical controls and fix findings, then invite the certification body for Stage 1 and Stage 2 audits.

How often should you test for ISO 27001?

The standard does not fix a frequency, but good practice, and most auditor expectations, land on:

  • At least annually for internet-facing and business-critical systems.
  • After any major change, such as a new application release, cloud migration or network redesign.
  • Regular vulnerability scanning (monthly or quarterly) between full penetration tests to catch drift.

How Cyber Defence supports ISO 27001-aligned VAPT

Cyber Defence is an ISO-certified, GeM-registered VAPT provider based in Hisar, Haryana, founded by Amit Kumar (CEH, CRTA). We deliver manual VAPT across web applications, mobile apps, APIs, networks and cloud, with reports structured to serve as third-party evidence for ISO 27001, DPDP and similar reviews. Every engagement includes a free retest of remediated findings and a completion certificate that your auditor can accept as independent verification.

To be clear and honest about our positioning: we provide independent technical testing that supports your certification. We are not a certification body and do not issue ISO 27001 certificates, and we make no claim of CERT-In empanelment. Our role is to give you defensible technical evidence and a fixed, verified security posture before your auditor arrives.

If you want to build the underlying skills in-house, our VAPT training covers the same methodologies we use on live engagements. You can also review our regional service pages for VAPT services in Haryana and VAPT services in Delhi, or read our guides on VAPT cost in India and what goes into a VAPT report to plan your engagement.

Common mistakes that weaken your audit evidence

Over many ISO 27001 engagements we see the same avoidable errors undermine otherwise good preparation. Watch for these:

  • Scoping the test smaller than the ISMS. If your Statement of Applicability claims coverage of systems that were never tested, an auditor will notice the gap. Your VAPT scope should visibly correspond to your declared ISMS boundary.
  • Treating the report as the finish line. A findings report with no remediation log and no retest tells the auditor you found problems but cannot prove you fixed them. Closure evidence is what turns a test into a control.
  • Testing once and forgetting. Continual improvement is a core ISO 27001 principle. A single historical test with no schedule for the next one signals a project, not a process.
  • Ignoring internal and cloud attack surface. External web-app testing alone rarely reflects your full ISMS. Internal network segments, identity systems and cloud configurations often hold the highest-impact risks.
  • No link to risk treatment. Findings that are not fed back into your risk register and treatment plan look disconnected from the management system the certificate is really about.

Integrating VAPT into the ISMS lifecycle

The most audit-ready organisations treat VAPT as a recurring input to the Plan-Do-Check-Act cycle that underpins ISO 27001. In the Plan phase, risk assessment identifies which assets need testing. In the Do phase, controls are implemented. In the Check phase, VAPT independently verifies those controls and feeds results into internal audit and management review. In the Act phase, remediation and process improvements close the loop, and the next test confirms progress. When your testing is described this way in your documentation, an auditor sees a mature, self-correcting system rather than a compliance box being ticked once a year.

Practical checklist before your ISO 27001 audit

  • Define your ISMS scope, then scope VAPT to match it.
  • Map each test to specific Annex A controls (especially A.8.8, A.8.9, A.8.25, A.8.28).
  • Fix critical and high findings, then obtain retest confirmation.
  • Keep the report, remediation log and retest evidence together for the auditor.
  • Feed findings back into your risk register and treatment plan.
  • Schedule the next test so you can show continual verification.

FAQ

Is penetration testing mandatory for ISO 27001?

Not explicitly. ISO 27001 does not name penetration testing as a required activity, but it requires you to verify that technical controls are effective. VAPT is the most widely accepted way to do that, so in practice almost all certified organisations perform it.

Does passing a VAPT mean I am ISO 27001 certified?

No. VAPT validates technical controls only. Certification also requires documented policies, risk assessment, a Statement of Applicability, internal audits and management review, all assessed by an accredited certification body, not by a pentest.

Which Annex A control does VAPT satisfy?

Primarily A.8.8 (management of technical vulnerabilities) in the 2022 version, which older documents call A.12.6.1. It also supports A.8.9, A.8.25 and A.8.28 relating to secure configuration and secure development.

How often should we run VAPT for ISO 27001?

At least annually for critical and internet-facing systems, and again after any major change. Many organisations add quarterly vulnerability scanning between full penetration tests to catch new issues early.

Will a VAPT report be accepted by our ISO auditor?

A well-structured report with defined scope, recognised methodology, severity-rated findings, remediation guidance and retest evidence is normally accepted as evidence of technical vulnerability management. Cyber Defence formats reports specifically for this purpose.

Can Cyber Defence certify us for ISO 27001?

No, and any VAPT vendor claiming to is misleading you. Certification comes from an accredited certification body. We provide the independent technical testing and evidence that supports certification, plus a completion certificate accepted as third-party proof.

Ready to prepare your technical controls for ISO 27001? Talk to Cyber Defence for an ISO-aligned VAPT with free retest and an auditor-ready report. Call +91-75175-72000 to scope your engagement.

Talk to a Cyber Defence Expert

Get a free consultation on cybersecurity, training and certifications. Our team responds within 10 minutes during business hours.