Pentest Today.
audit & vendor review playbooks

Whatever review you have to pass, walk in with the evidence

Pick your framework, vendor program, or questionnaire. Each guide shows what the reviewer asks for — and how Pentest Today generates it in hours.

Compliance frameworks

9
compliance framework

Pass your SOC 2 audit

SOC 2 is an AICPA report on how your controls meet the Trust Services Criteria — security, availability, processing integrity, confidentiality, and privacy.

compliance framework

Pass your SOC 2 Type II audit

A SOC 2 Type II report tests whether your controls operated effectively across an observation window, not just on paper.

compliance framework

Pass your ISO 27001 certification

ISO/IEC 27001 certifies that you run an Information Security Management System (ISMS) with the Annex A controls in place.

compliance framework

Pass your HIPAA security assessment

The HIPAA Security Rule requires administrative, physical, and technical safeguards for electronic protected health information (ePHI).

compliance framework

Pass your GDPR security review

GDPR Article 32 requires appropriate technical and organizational measures to secure personal data, including regular testing of their effectiveness.

compliance framework

Pass your PCI DSS assessment

PCI DSS protects cardholder data and explicitly requires both internal and external penetration testing at least annually.

compliance framework

Pass your NIST CSF assessment

The NIST Cybersecurity Framework organizes security around Identify, Protect, Detect, Respond, and Recover.

compliance framework

Pass your FedRAMP readiness review

FedRAMP authorizes cloud services for U.S. federal use, built on NIST 800-53 controls and requiring penetration testing.

compliance framework

Pass your CMMC assessment

CMMC verifies that defense contractors protect Controlled Unclassified Information (CUI) per NIST 800-171.

Vendor security reviews

4

Vendor risk platforms

3

Security questionnaires

3