NOTE—02

PCI DSS, ISO 27001, and SOC 2 do not ask the same thing.

The honest first question is not which badge to put on a proposal. It is which requirement actually applies, which control outcome the buyer must evidence, and which testing method can support it.

01

PCI DSS v4.0.1: an explicit scoped requirement

Where PCI DSS applies, Requirement 11.4 defines penetration-testing methodology, scope, independence, recurrence, significant-change testing, correction, and repeat testing. The engagement must still confirm the cardholder-data environment and the exact applicable elements; a tester does not certify PCI compliance merely by delivering a test.

02

ISO/IEC 27001: risk-treatment evidence

ISO/IEC 27001 is an outcome- and risk-based management-system standard. An independent test can support vulnerability-management and security-testing controls selected in the Statement of Applicability, but the standard does not impose a universal annual penetration test on every certified organization.

03

SOC 2: persuasive control evidence

SOC 2 is an attestation examination, not a certification and not a blanket pentest mandate. Testing becomes specifically relevant through the entity's commitments and control description, the auditor's judgment, a customer contract, or another adopted requirement.

04

Write the claim at the right level

Use ‘designed to address applicable requirements’ only after applicability is confirmed; ‘supports readiness or control evidence’ for outcome frameworks; and ‘mapped to’ for voluntary methods and taxonomies. Never imply endorsement, certification, or guaranteed compliance.

05

Primary sources and review record

Reviewed 15 August 2026. Version basis: PCI DSS v4.0.1; ISO/IEC 27001:2022; and the AICPA Trust Services Criteria, using the 2017 criteria with points of focus revised in 2022. Applicability owner: the client's authorized compliance owner confirms which requirements and controls apply. Redline maps agreed testing evidence to that scope; it does not certify or guarantee compliance.

PCI—LIB

PCI DSS v4.0.1 document library

The PCI Security Standards Council's official library for the standard and supporting material.

Open the PCI SSC document library
AICPA—TSC

AICPA Trust Services Criteria

AICPA's official criteria document, including the points of focus revised in 2022.

Open the AICPA criteria

NEXT DECISION

Turn the principle into a working scope.

The scoping interview creates a structured draft for human review. It does not send messages or proposals automatically.

Scope an engagement