Australian companies chasing ISO 27001, or already certified and heading into surveillance, keep being told they need a penetration test. Sometimes that comes from the auditor. Sometimes it comes from Annex A control language around technical vulnerability management and independent review. Sometimes it comes from a customer who has mixed ISO up with SOC 2.
Buy the test as evidence, not as a talisman. The certificate on the wall is not ours. The quality of the evidence is.
What auditors actually look for
A named tester or practice, a defined scope that matches the ISMS, a date, a methodology, findings with severity, and evidence that you treated the findings (retest, risk acceptance, ticket). A 90-page Nessus PDF with no owner and no retest is a finding against you, not evidence for you.
Scope to the ISMS, not to the internet
If the ISMS covers the product and the cloud account it runs in, the test should cover the product and the cloud account. Testing the marketing WordPress and calling it the ISO pentest is how you fail the next surveillance audit with a straight face.
Cadence
Annually is the default we see on Statements of Applicability. After material change is the one teams skip. A new tenant-isolation model, a new IdP, a lift into a second cloud: those are test triggers. Put them in the SoA so you are not negotiating with an auditor in the corridor.
We map reports so they can be dropped into an ISO evidence pack. We do not claim VAPT.COM.AU is ISO 27001 certified. If you need that distinction in writing, it is already on this page.