Blog · C.18 · Interactive Tool

Penetration testing requirements by framework — the 2026 finder

Select your compliance framework and see exactly what it requires of a penetration test: how often, what scope, whether it is mandatory, and the precise control reference. Covers the GCC regulators and the major international standards.

CBBSAMANCA ECCPCI DSSSOC 2HIPAAISO 27001
Requirements Finder: CBB Twice-Yearly · SAMA Annual + FEER 3-Yr · ECC Periodic · CSCC 6-Month · PCI Annual + On Change · FedRAMP Annual Requirements Finder: CBB Twice-Yearly · SAMA Annual + FEER 3-Yr · ECC Periodic · CSCC 6-Month · PCI Annual + On Change · FedRAMP Annual
// How to use this

Click a framework below to see its penetration testing requirement — frequency, scope, mandatory status and the exact control reference — drawn from the source regulation or standard. Use the master comparison table further down to plan a single test that satisfies several frameworks at once. Every requirement links to a deeper guide where we have one.

// 01 Penetration testing requirements: the master comparison

The full picture at a glance. "Mandatory" means the framework requires penetration testing directly; "Expected" means it is the standard audit evidence without a hard mandate; "Proposed" means a rule change would introduce it.

FrameworkRegionFrequencyStatusReference
CBB RulebookBahrainTwice a year (Jun & Dec)MandatoryOM-5.5 / GR-12.2
SAMA CSFSaudi ArabiaAnnual (+ FEER red team every 3 yrs)Mandatory3.2.4 / FEER
NCA ECCSaudi ArabiaPeriodically (no fixed interval)MandatoryControl 2-11
NCA CSCC (critical systems)Saudi ArabiaEvery 6 monthsMandatoryControl 2-10
PCI DSS v4.0GlobalAnnual + after significant changeMandatoryReq 11.4
FedRAMPUSA (federal)Annual (3PAO)MandatoryRev 5
DORAEU (financial)TLPT every 3 yearsMandatoryArticle 26
SOC 2GlobalTypically annualExpectedTSC (CC4.1)
ISO/IEC 27001GlobalPeriodic (risk-based)ExpectedAnnex A 8.8
HIPAAUSA (health)Annual (if 2024 rule finalised)ProposedSecurity Rule / 800-66

// 02 Can one test satisfy several frameworks?

Frequently, yes — and this is where the finder earns its keep. Penetration testing requirements overlap heavily: they mostly ask for the same thing (competent, independent testing of your real attack surface) expressed in different control language. The efficient strategy is to scope one engagement against the union of the frameworks you are subject to, then have the report map each finding to each framework's reference.

The clearest example is a GCC bank subject to both SAMA and NCA ECC: a single annual test of customer and internet-facing services satisfies SAMA control 3.2.4 and ECC control 2-11 at once. A payment institution can align a CBB test with PCI DSS Requirement 11.4. And a SaaS company pursuing SOC 2 and ISO 27001 can cover both with one well-scoped application and infrastructure test. The two things that make this work are honest scope (covering every asset the strictest framework names) and a report structured for multiple readers.

// 03 Frequently asked questions

How often is penetration testing required by each framework?

CBB: twice a year. SAMA: annual, plus red teaming every three years under FEER. PCI DSS: annual plus after significant change. NCA ECC: periodically; its critical-systems set (CSCC) requires every six months. FedRAMP: annual. SOC 2, ISO 27001 and HIPAA do not fix a mandatory interval but expect periodic testing.

Which frameworks legally mandate penetration testing?

CBB, SAMA, PCI DSS, FedRAMP, NCA ECC and DORA mandate it. SOC 2 and ISO 27001 treat it as expected evidence; HIPAA does not currently mandate it, though a 2024 proposed rule would.

Does one test satisfy multiple frameworks?

Often, if scoped deliberately and the report maps findings to each framework's control reference. GCC banks routinely cover SAMA and NCA ECC with one engagement.

What is the strictest frequency requirement?

CBB (twice a year) and the Saudi CSCC for critical systems (every six months). PCI's "after significant change" trigger can also force more frequent testing.

// 04 Sources

This finder summarises requirements for planning purposes. Frameworks are amended over time and applicability depends on your specific situation — confirm the current control text and scope with the source regulation, or ask us to scope it for you.

AH

Ankur H.

Security & Compliance Specialist, CyberFortify

Maps technical findings to the frameworks auditors and regulators assess — CBB, SAMA, NCA ECC, PCI DSS, SOC 2 and ISO 27001 — so one engagement can satisfy several obligations at once.

Not sure which rules apply to you?

Tell us your sector and region and we'll map your exact penetration testing obligations — then scope a single engagement that satisfies every framework you answer to.

Map my requirements → Compliance consulting →