Click a framework below to see its penetration testing requirement — frequency, scope, mandatory status and the exact control reference — drawn from the source regulation or standard. Use the master comparison table further down to plan a single test that satisfies several frameworks at once. Every requirement links to a deeper guide where we have one.
// 01 Penetration testing requirements: the master comparison
The full picture at a glance. "Mandatory" means the framework requires penetration testing directly; "Expected" means it is the standard audit evidence without a hard mandate; "Proposed" means a rule change would introduce it.
| Framework | Region | Frequency | Status | Reference |
|---|---|---|---|---|
| CBB Rulebook | Bahrain | Twice a year (Jun & Dec) | Mandatory | OM-5.5 / GR-12.2 |
| SAMA CSF | Saudi Arabia | Annual (+ FEER red team every 3 yrs) | Mandatory | 3.2.4 / FEER |
| NCA ECC | Saudi Arabia | Periodically (no fixed interval) | Mandatory | Control 2-11 |
| NCA CSCC (critical systems) | Saudi Arabia | Every 6 months | Mandatory | Control 2-10 |
| PCI DSS v4.0 | Global | Annual + after significant change | Mandatory | Req 11.4 |
| FedRAMP | USA (federal) | Annual (3PAO) | Mandatory | Rev 5 |
| DORA | EU (financial) | TLPT every 3 years | Mandatory | Article 26 |
| SOC 2 | Global | Typically annual | Expected | TSC (CC4.1) |
| ISO/IEC 27001 | Global | Periodic (risk-based) | Expected | Annex A 8.8 |
| HIPAA | USA (health) | Annual (if 2024 rule finalised) | Proposed | Security Rule / 800-66 |
// 02 Can one test satisfy several frameworks?
Frequently, yes — and this is where the finder earns its keep. Penetration testing requirements overlap heavily: they mostly ask for the same thing (competent, independent testing of your real attack surface) expressed in different control language. The efficient strategy is to scope one engagement against the union of the frameworks you are subject to, then have the report map each finding to each framework's reference.
The clearest example is a GCC bank subject to both SAMA and NCA ECC: a single annual test of customer and internet-facing services satisfies SAMA control 3.2.4 and ECC control 2-11 at once. A payment institution can align a CBB test with PCI DSS Requirement 11.4. And a SaaS company pursuing SOC 2 and ISO 27001 can cover both with one well-scoped application and infrastructure test. The two things that make this work are honest scope (covering every asset the strictest framework names) and a report structured for multiple readers.
// 03 Frequently asked questions
How often is penetration testing required by each framework?
CBB: twice a year. SAMA: annual, plus red teaming every three years under FEER. PCI DSS: annual plus after significant change. NCA ECC: periodically; its critical-systems set (CSCC) requires every six months. FedRAMP: annual. SOC 2, ISO 27001 and HIPAA do not fix a mandatory interval but expect periodic testing.
Which frameworks legally mandate penetration testing?
CBB, SAMA, PCI DSS, FedRAMP, NCA ECC and DORA mandate it. SOC 2 and ISO 27001 treat it as expected evidence; HIPAA does not currently mandate it, though a 2024 proposed rule would.
Does one test satisfy multiple frameworks?
Often, if scoped deliberately and the report maps findings to each framework's control reference. GCC banks routinely cover SAMA and NCA ECC with one engagement.
What is the strictest frequency requirement?
CBB (twice a year) and the Saudi CSCC for critical systems (every six months). PCI's "after significant change" trigger can also force more frequent testing.
// 04 Sources
- CBB Rulebook OM-5.5 / GR-12.2; SAMA Cyber Security Framework 3.2.4 and the FEER Framework; NCA ECC control 2-11 and CSCC control 2-10 — see our detailed CBB, SAMA and NCA ECC guides for verbatim control text and citations.
- PCI DSS v4.0 Requirement 11.4 (PCI SSC); FedRAMP Rev 5 (fedramp.gov); DORA Article 26 (EU 2022/2554).
- AICPA Trust Services Criteria (SOC 2); ISO/IEC 27001:2022 Annex A 8.8; HHS HIPAA Security Rule and the December 2024 NPRM; NIST SP 800-66.
This finder summarises requirements for planning purposes. Frameworks are amended over time and applicability depends on your specific situation — confirm the current control text and scope with the source regulation, or ask us to scope it for you.