Which frameworks actually require
a penetration test?
One of these four names penetration testing outright. The other three are more often misquoted than read. This is the clause-level answer for each, what an assessor accepts as evidence, and where organisations most commonly lose the point.
Select at least one framework above and the combined obligation appears here.
The short answer for each.
| Framework | Is testing required? | Cadence | Set by |
|---|---|---|---|
| PCI DSS v4.0 | Explicitly required by name | At least every 12 months and after every significant change. Segmentation controls every 12 months, or every 6 months if you are a service provider. | PCI Security Standards Council |
| SOC 2 | Not named in the criteria, expected in practice | Determined by your own stated control, not by the standard. Most organisations commit to annual testing; if your control description says quarterly, the auditor will test you against quarterly. | AICPA Trust Services Criteria |
| HIPAA Security Rule | Not required today; explicitly proposed | Today: "periodic", defined by your own risk analysis, with annual being the common interpretation. Under the proposal: at least every 12 months, with scanning every 6 months. | HHS Office for Civil Rights |
| Cyber insurance | No standard — the underwriter decides | Whatever you stated on the application. Annual is the most common answer given, and therefore the most common commitment made. | Individual carriers and their application forms |
Verdicts reflect the text of each framework as at August 2026. Compliance requirements change; confirm against the current published standard before relying on any summary, including this one.
One page per framework.
PCI DSS v4.0
Yes. PCI DSS is the one framework on this page that names penetration testing outright and tells you how often to do it. Requirement 11.4 mandates internal and external penetration testing a…
SOC 2
No — and this surprises people. The Trust Services Criteria never use the words "penetration test". SOC 2 is not a checklist of controls; it is an audit of whether the controls you claim are…
HIPAA Security Rule
Not explicitly, as the rule stands. The HIPAA Security Rule requires a periodic technical and non-technical evaluation, and penetration testing is a recognised way to perform it — but the wo…
Cyber insurance
There is no standard to comply with, which makes this the most misunderstood item on the list. Whether a penetration test is required depends entirely on the carrier, the limit you are askin…
Four mistakes that span every framework.
Testing on a calendar, not on change
Almost every framework has a second trigger alongside the annual one: material change to the environment. An estate tested in January and rebuilt in March has an annual test and no current evidence. The change trigger is where most gaps actually open.
Findings without retest
PCI DSS 11.4.4 requires it explicitly; every other assessor asks for it in practice. A finding is closed when the exploit no longer reproduces, not when a ticket is marked done. Remediation without retest evidence is the most common reason a control fails on review.
Scope narrower than the assessment
The test covers the application; the audit covers the system. Whenever the scope of the test is smaller than the scope of the framework, the difference is the part nobody has evidence for — and it is usually the infrastructure and identity layer around the application.
Promising more than you deliver
SOC 2 system descriptions and cyber insurance applications are both representations. Writing “quarterly penetration testing” and performing one test a year does not create a gap in your security; it creates a documented exception, which is worse.
What buyers and auditors ask.
Which compliance frameworks actually require penetration testing?
How often does a penetration test need to be done for compliance?
Does a vulnerability scan count as a penetration test?
Do we need a third-party penetration test, or can we test ourselves?
What evidence do auditors accept from an automated penetration testing platform?
Deadlines across the year are collected in the compliance pentesting calendar, and the difference between satisfying a control and actually being secure is covered in compliance checkbox versus real testing.
See what an assessor would see first.
The free exposure check covers the externally visible hygiene that shows up in every framework — certificates, headers, email authentication — in about ten seconds, with no account.
