Security testing
Vendor-neutral guides for founders, CTOs, and auditors — when a pen test is required, how it differs from scanning, SAST/DAST/SCA, cadence, cost, reports, retests, and framework expectations. Not legal advice. Does not replace an independent pen test.
Do I need a penetration test?
Decision guide: when a contract, framework, or regulation requires a penetration test versus optional maturity. PCI DSS 11.4, SOC 2, ISO 27001. Not legal advice.
What is the difference between a penetration test and a vulnerability scan?
Penetration test versus vulnerability scan: automated breadth versus manual exploitation, PCI DSS 11.3 vs 11.4, and why one does not substitute. Not legal advice.
What is the difference between SAST, DAST, and SCA?
SAST, DAST, and SCA compared: what each tests, when in the SDLC, strengths and limits, and how they layer. OWASP, NIST SSDF. Not legal advice.
How often should you do a penetration test?
Penetration-testing cadence: annual baselines, significant-change triggers, PCI DSS 11.4, SOC 2 and ISO 27001 expectations. Not a universal law. Not legal advice.
What does a penetration test cost?
Penetration-test cost drivers: scope, methodology, application vs network vs cloud, retest, seniority. Indicative market observation, not a price list. Not legal advice.
How do you choose a penetration testing company?
Defensible criteria for choosing a penetration-testing company: accreditation, methodology, scoping, retest, reporting. Not a ranking. Not legal advice.
What should a penetration test report include?
Anatomy of a credible penetration-test report: scope, methodology, risk-rated findings, evidence, remediation, retest. Red flags in a weak report. Not legal advice.
What is a penetration test retest?
What a pen-test retest verifies, when it is required, retest versus a full re-engagement, and remediation-window expectations. PCI DSS 11.4. Not legal advice.
What evidence should be kept after a penetration test?
Pen-test evidence inventory: report, authorization, remediation, retest, retention periods, and secure handling of sensitive findings. Not legal advice.
Does SOC 2 require a penetration test?
SOC 2 has no explicit annual pen-test mandate. How testing supports TSC CC4.1, CC7.1, and CC7.2, and what auditors commonly expect. Not legal advice.
Does ISO 27001 require a penetration test?
ISO/IEC 27001:2022 names technical vulnerability management and security testing (A.8.8, A.8.29, A.8.25), not “pen test” verbatim. Annex A mapping. Not legal advice.
What is continuous security testing?
Continuous security testing versus point-in-time pen tests: CI SAST/DAST/SCA, scanning, PTaaS. Complements, does not replace, scoped manual tests. Not legal advice.
How does ShipReady Metrics track security testing evidence?
How ShipReady Metrics organizes pen-test reports, scans, SAST/DAST, remediation, and retests as reviewable evidence. Does not replace an independent pen test.