Whatever review you have to pass,
walk in with the evidence
Pick your framework, vendor program, or questionnaire. Each guide shows what the reviewer asks for — and how Pentest Today generates it in hours.
Compliance frameworks
9Pass your SOC 2 audit
SOC 2 is an AICPA report on how your controls meet the Trust Services Criteria — security, availability, processing integrity, confidentiality, and privacy.
Pass your SOC 2 Type II audit
A SOC 2 Type II report tests whether your controls operated effectively across an observation window, not just on paper.
Pass your ISO 27001 certification
ISO/IEC 27001 certifies that you run an Information Security Management System (ISMS) with the Annex A controls in place.
Pass your HIPAA security assessment
The HIPAA Security Rule requires administrative, physical, and technical safeguards for electronic protected health information (ePHI).
Pass your GDPR security review
GDPR Article 32 requires appropriate technical and organizational measures to secure personal data, including regular testing of their effectiveness.
Pass your PCI DSS assessment
PCI DSS protects cardholder data and explicitly requires both internal and external penetration testing at least annually.
Pass your NIST CSF assessment
The NIST Cybersecurity Framework organizes security around Identify, Protect, Detect, Respond, and Recover.
Pass your FedRAMP readiness review
FedRAMP authorizes cloud services for U.S. federal use, built on NIST 800-53 controls and requiring penetration testing.
Pass your CMMC assessment
CMMC verifies that defense contractors protect Controlled Unclassified Information (CUI) per NIST 800-171.
Vendor security reviews
4Pass your Meta Third-Party Assessment (TPA)
Meta requires apps and vendors that access Platform Data to complete an annual Third-Party Assessment (formerly the Data Protection Assessment) with an approved assessor.
Pass your Google Vendor Security Assessment
Google's Vendor Security Assessment reviews how suppliers protect Google and user data before and during an engagement.
Pass your Microsoft SSPA review
Microsoft's Supplier Security and Privacy Assurance (SSPA) program requires suppliers handling Microsoft personal data to attest to the Data Protection Requirements (DPR).
Pass your Salesforce Security Review
AppExchange partners must pass Salesforce's Security Review, which includes scanning and penetration testing of the offering before listing.
Vendor risk platforms
3Pass your Lema AI security review
Lema is an AI-powered third-party risk platform buyers use to assess a vendor's security posture from uploaded evidence and questionnaire answers.
Pass your Whistic security review
Whistic lets vendors publish a Security Profile and respond to customer assessments from a single shared source of evidence.
Pass your Vanta vendor security review
Vanta automates compliance and vendor risk; buyers using Vanta will request evidence of your security controls and tests.
Security questionnaires
3Pass your CAIQ security questionnaire
The Cloud Security Alliance's Consensus Assessments Initiative Questionnaire (CAIQ) is a standardized set of yes/no security questions mapped to the Cloud Controls Matrix.
Pass your SIG security questionnaire
The Shared Assessments Standardized Information Gathering (SIG) questionnaire is a comprehensive third-party risk questionnaire used across industries.
Pass your vendor security questionnaire
Enterprise buyers send a security questionnaire before they'll sign — asking how you test, protect, and monitor their data.