Skip to content
Compliance evidence

Security testing you can use as evidence.

Independent penetration testing can form part of an organization's security testing and evidence program.

Frameworks and requirements

Where independent testing fits — and where it stops.

SOC 2

SOC 2

Independent web, API and infrastructure testing designed to support SOC 2 evidence collection for security-related criteria.

CyberZ does not perform SOC 2 examinations or issue SOC 2 reports. Your auditor decides how evidence is used.

Details
PCI DSS

PCI DSS

External, internal, web application and segmentation penetration testing scoped to the applicable PCI DSS requirements and your environment.

Completing a test does not by itself establish PCI DSS compliance; your QSA or self-assessment process determines that.

Details
NIST

NIST guidance

Testing that can be mapped to NIST guidance on security assessment and vulnerability management where relevant to your program.

CyberZ does not certify alignment with any NIST framework or publication.

CIS

CIS Controls

Penetration testing and remediation verification that organizations reference under CIS Controls safeguards for penetration testing.

Mapping to specific safeguards is informational and depends on your implementation.

CUST

Customer security requirements

Reports, executive summaries and attestation letters for enterprise procurement, vendor risk reviews and security questionnaires.

Each customer decides what evidence satisfies their requirements.

ENT

Enterprise security assessments

Independent validation that a prospect's or partner's security team can review alongside your own controls documentation.

A point-in-time assessment of a defined scope, not a guarantee of security.

Plain language

What CyberZ is, and is not.

Precision here protects you as much as us. Auditors and enterprise buyers read these documents carefully.

CyberZ is

  • An independent penetration testing and security assessment provider.
  • A source of technical evidence: reports, findings, retest results and a certificate that states what was tested and when.
  • A partner that scopes testing around the controls and systems your program actually covers.

CyberZ is not

  • A SOC 2 auditor or a certification authority for any framework. CyberZ does not perform SOC 2 examinations or issue SOC 2 reports.
  • A government-approved certification body.
  • An organization that can certify a company as secure or guarantee security for any period of time. Security assessments represent a point-in-time evaluation and do not constitute a guarantee that the assessed systems remain secure or free from vulnerabilities after the assessment.
Evidence you receive

Built to be handed over.

Executive summary, technical report, findings with severity and CVSS, evidence, remediation guidance, retest results and — on request — the CyberZ Penetration Testing Certificate with a public verification page.

Next step

Request a security assessment.

Tell us what you need tested, when, and which evidence you need at the end. We reply with scoping questions, not a sales deck.