Pentest Today.
audit & vendor review playbooks

Whatever review you have to pass, walk in with the evidence

Pick your framework, vendor program, or questionnaire. Each guide shows what the reviewer asks for — and how Pentest Today generates it in hours.

Compliance frameworks

9
compliance framework→

Pass your SOC 2 audit

SOC 2 is an AICPA report on how your controls meet the Trust Services Criteria — security, availability, processing integrity, confidentiality, and privacy.

compliance framework→

Pass your SOC 2 Type II audit

A SOC 2 Type II report tests whether your controls operated effectively across an observation window, not just on paper.

compliance framework→

Pass your ISO 27001 certification

ISO/IEC 27001 certifies that you run an Information Security Management System (ISMS) with the Annex A controls in place.

compliance framework→

Pass your HIPAA security assessment

The HIPAA Security Rule requires administrative, physical, and technical safeguards for electronic protected health information (ePHI).

compliance framework→

Pass your GDPR security review

GDPR Article 32 requires appropriate technical and organizational measures to secure personal data, including regular testing of their effectiveness.

compliance framework→

Pass your PCI DSS assessment

PCI DSS protects cardholder data and explicitly requires both internal and external penetration testing at least annually.

compliance framework→

Pass your NIST CSF assessment

The NIST Cybersecurity Framework organizes security around Identify, Protect, Detect, Respond, and Recover.

compliance framework→

Pass your FedRAMP readiness review

FedRAMP authorizes cloud services for U.S. federal use, built on NIST 800-53 controls and requiring penetration testing.

compliance framework→

Pass your CMMC assessment

CMMC verifies that defense contractors protect Controlled Unclassified Information (CUI) per NIST 800-171.

Vendor security reviews

4

Vendor risk platforms

3

Security questionnaires

3