How to answer
Do you perform annual penetration testing by an independent third party?
This is the question FillTrust most often grades as inferred rather than confirmed, because policies state a cadence and cadences are not evidence that a test happened.
Yes. An independent third-party penetration test is performed annually against our production environment. The most recent test was completed in [month, year]; a summary letter is available under NDA.
Square brackets are yours to fill in. FillTrust grades an answer like this implied, not stated when your documents support it.
- Answered from
- The pen test report, or the engagement letter. Your vulnerability management policy states the cadence but not that a test happened.
- Evidence to attach
- Usually a summary or attestation letter rather than the full report, which contains findings you should not circulate.
- Where it is asked
- CAIQ v4.0 · TVM-06SIG LiteISO 27001 Annex A · A.8.8
This question is worth studying because of how it goes wrong rather than whether teams do the testing.
Most security policies contain a sentence like "an annual penetration test is performed against production systems." A drafting tool reading your documents finds that sentence and can honestly report that your documentation supports an annual test. What the sentence does not establish is that a test actually happened, who performed it, or when, and those are the three things the reviewer is asking about. That is exactly the difference between an answer confirmed by your documents and one merely implied by them, which is why FillTrust usually grades this one implied, not stated and puts it in front of a person.
The distinction that matters most is independent third party. Continuous vulnerability scanning, dependency alerts and a cloud security posture tool are all good and none of them is a penetration test. Neither is a test performed by your own engineers, however competent. If what you have is scanning, the honest answer names it as scanning and says whether a third-party test is scheduled. A reviewer can accept that and note it as a risk; they cannot accept discovering it later.
The second is recency. "Annual" implies a date. If the last test was twenty months ago, the answer is that testing is performed annually and the most recent test was [month, year], with the next scheduled for [month]. Volunteering the gap is far better than having it found.
On evidence: send the attestation or summary letter, not the report. The full report is an enumerated list of your weaknesses with reproduction steps. Most reviewers expect the summary and ask for the report only under NDA, and offering it that way in the answer is itself a signal that you have done this before.
How this one goes wrong
Specific to this question, not general advice.
- Counting automated scanning as a penetration test. A scanner is not an independent third party and a reviewer who asks for the report will discover this.
- Answering yes on the strength of a test done at a previous funding round. "Annual" has a date attached.
- Attaching the full report. It is a list of your weaknesses; send the attestation letter and offer the report under NDA.