ISO 27001:2022 VAPT Evidence: What Auditors Actually Check
June 25, 2026
The ISO 27001:2022 revision consolidated Annex A from 114 controls organised in 14 domains to 93 controls organised in 4 themes. The transition deadline for existing certifications was October 31, 2025, and 2026 is the first full assessment cycle where every certified organisation is being surveilled against the 2022 revision. Certification body auditors have refined their expectations for VAPT evidence during this period, and organisations preparing for 2026 surveillance audits benefit from understanding what has become standard audit practice.
The Structural Impact of the 2022 Revision
The reorganisation of Annex A affected VAPT evidence organisation more than it affected VAPT content. Controls that were previously grouped under Communications Security (former A.13) or Operations Security (former A.12) are now distributed across the 4 themes — Organisational (A.5), People (A.6), Physical (A.7), and Technological (A.8). VAPT evidence packages that were organised around the 2013 domain structure require restructuring to align with the 2022 theme structure or explicit cross-reference mapping between the two structures.
Eleven new controls were added in 2022, several of which have direct VAPT relevance. A.5.7 (Threat intelligence), A.5.23 (Information security for use of cloud services), A.5.30 (ICT readiness for business continuity), A.7.4 (Physical security monitoring), A.8.9 (Configuration management), A.8.10 (Information deletion), A.8.11 (Data masking), A.8.12 (Data leakage prevention), A.8.16 (Monitoring activities), A.8.23 (Web filtering), and A.8.28 (Secure coding) all introduce or expand assessment expectations that touch VAPT.
A.5.23 (cloud services security) has become one of the more scrutinised new controls because most certified organisations now use significant cloud services. Auditors expect evidence that cloud services in use have been assessed against organisational security requirements — VAPT of cloud environments, review of cloud provider security documentation, and assessment of cloud-specific configuration against benchmarks like CIS AWS Foundations or CIS Azure Foundations. Organisations that added cloud services after certification without updating the risk assessment or VAPT programme scope frequently receive findings under A.5.23.
Methodology Documentation Auditors Expect
A.5.35 (Independent review of information security) requires periodic independent reviews of the information security programme. VAPT is the most common evidence organisations offer for this control, and auditors have developed clear expectations for how the independence and methodology should be documented. The methodology document should specify the standards followed (NIST SP 800-115, OWASP Testing Guide, OSSTMM, PTES), the scope of testing, the qualifications required of testers, and the review process for findings.
The independence of the reviewer is a growing area of audit scrutiny. VAPT conducted by the internal team responsible for the systems being tested does not satisfy the independence requirement. VAPT conducted by a separate internal team with organisational independence, or by external testers, does satisfy the requirement provided the independence is documented. AI-powered VAPT platforms operated by a separate function from the systems team, with documented separation of responsibilities, are increasingly recognised as satisfying independence in the same way as external consultants.
Methodology documentation that is generic — copied from a standard reference without organisation-specific adaptation — receives less audit weight than methodology tailored to the organisation's specific environment and risk profile. Auditors have become adept at identifying boilerplate methodology documents. A methodology that describes what tools are used, what scope is covered, what specific business logic considerations apply to the organisation's applications, and what remediation triage process is applied is substantially more credible than a generic reference.
Evidence of Coverage Against Annex A Controls
A.8.29 (Security testing in development and acceptance) requires that security testing be defined and executed as part of development and acceptance processes. VAPT evidence must demonstrate not just that testing occurred but that testing coverage aligns with what the development lifecycle actually produces. Organisations that ship features weekly should have VAPT evidence corresponding to those releases; a single annual VAPT report is insufficient evidence of security testing being part of the development lifecycle.
Coverage evidence should demonstrate what was tested, not just findings from the testing. Auditors have increasingly asked for scope documentation showing which applications, endpoints, and features were included in each VAPT cycle. A report that lists findings without documenting what was in scope creates ambiguity about whether the tested surface is representative of the certified scope or a subset. Continuous VAPT platforms that log every assessment automatically produce this coverage evidence as a byproduct of operation.
A.8.8 (Technical vulnerability management) requires processes to obtain vulnerability information, evaluate exposure, and take appropriate measures. VAPT provides the exposure evaluation input to this process. Evidence should demonstrate the chain from vulnerability identification through triage to remediation, with timestamps and responsibility assignments at each step. This evidence chain is what distinguishes vulnerability management from vulnerability reporting; auditors distinguish between the two.
Remediation Tracking and Verification
Every finding identified in VAPT should have a documented remediation status. Findings that have been remediated should have verification evidence — a subsequent test confirming the remediation is effective. Findings that have been accepted as residual risk should have documented risk acceptance signed at an appropriate authority level. Findings that are pending remediation should have a target date and responsible owner. Findings without any of these statuses represent open audit issues.
The verification evidence for remediated findings is where organisations frequently fall short. It is common to remediate a finding and update its status to "closed" without documenting that verification testing was performed. Auditors will ask for the verification evidence, and finding it produced during the audit rather than at remediation time undermines confidence in the remediation process. AI-powered VAPT platforms with automatic re-testing generate the verification evidence as a natural output of the remediation workflow.
Risk acceptance documentation for findings that will not be remediated should include the risk owner's signature, the rationale for accepting the risk, any compensating controls, and the review date for reconsidering the acceptance. Blanket "accepted risk" entries without specific justification are treated by auditors as evidence of poor risk management rather than evidence of informed risk acceptance. The specific rationale and review commitment demonstrate that the risk is being managed rather than ignored.
Common Findings in 2022-Revision Audits
Insufficient cloud services scope is the most commonly reported new audit finding under the 2022 revision. Organisations with cloud service consumption that expanded after certification frequently have not updated their VAPT scope to include the new services, producing findings under A.5.23. The remediation is straightforward — update scope, perform VAPT, document evidence — but the finding is preventable with scope reviews aligned to actual service consumption.
Configuration management evidence (A.8.9) has been a source of findings for organisations that did not previously produce systematic configuration documentation. VAPT reports that identify configuration issues are useful input to configuration management but do not constitute configuration management themselves. A defensive VAPT programme feeds findings into the configuration management process rather than treating VAPT reports as the configuration management artifact.
Threat intelligence integration (A.5.7) is a new control where audit expectations are still developing. Auditors are looking for evidence that threat intelligence informs security controls — VAPT scope prioritisation, detection rule development, and vulnerability triage. Organisations that subscribe to threat intelligence services without demonstrating how the intelligence changes their security programme decisions may satisfy A.5.7 formally but should expect audit questions about the intelligence programme's effectiveness.