Skip to content
TheoSec

//Compliance

The test, and the evidence.

Financial services is one of the few sectors where somebody else decides how often you get tested. Most of that obligation is annual, recurring, and does not care which firm holds which badge — it cares that the work was competent, independent and documented.

01What we satisfy

Three obligations.

For each one: what the rule actually says, what we deliver against it, and where the boundary of what we can sign sits.

DORA — Articles 24 & 25

EU financial entities, excluding microenterprises

The requirement

A documented testing programme covering every ICT system supporting a critical or important function, exercised at least once a year — vulnerability assessment, network security review, source code analysis and scenario-based testing among them.

What we deliver

We run the annual programme and produce the evidence: scope rationale, methodology, findings, remediation tracking and retest.

This is the Article 24/25 testing programme. The separate Article 26/27 threat-led testing regime requires an accredited provider, which we are not — if you are in scope for TLPT we will tell you so and point you at a firm that is.

PCI-DSS 11.4

Anyone storing, processing or transmitting card data

The requirement

Internal and external penetration testing at least every twelve months and after any significant change, following a documented methodology, with segmentation testing where segmentation is claimed.

What we deliver

The test itself, the documented methodology your QSA will ask to see, segmentation validation, and free retest of every finding.

We perform the penetration testing under 11.4. We are not a QSA and not an Approved Scanning Vendor — the RoC assessment and ASV scanning both require certification we do not hold.

SOC 2 & ISO 27001

Fintechs selling to enterprise or entering procurement

The requirement

Neither standard names a testing provider, but both auditors expect evidence of regular independent technical testing and of findings being tracked to closure.

What we deliver

A report written to be handed straight to an auditor, plus the remediation evidence that usually holds the certificate up.

02The boundary

What we cannot sign.

Said plainly and up front, because finding out at procurement stage wastes everyone's quarter.

DORA threat-led testing (Art. 26/27)
The TLPT regime requires testers certified by an accreditation body, five prior TLPT references and specific indemnity cover. We hold none of those. If your regulator has named you for TLPT, you need an accredited firm — and we will say so on the first call.
TIBER-EU and CBEST
Both are accredited-provider frameworks. Same answer: not us. Both also sit on top of ordinary security work that does need doing, and that part we can help with.
QSA assessment and ASV scanning
The PCI Report on Compliance requires a Qualified Security Assessor, and quarterly external scans require an Approved Scanning Vendor. We are neither. We perform the 11.4 penetration testing that sits alongside them.
Certification of any kind
We do not issue certificates, attestations or letters of compliance. We produce technical evidence that your assessor, auditor or regulator uses to reach their own conclusion.

Being small is why this list exists.A firm carrying every accreditation charges for carrying every accreditation, whether your obligation needs it or not. Most fintechs are not in TLPT scope and never will be — for them the badge is somebody else's overhead.

03Worth knowing

Everyone, every year. Not a handful, every three.

Threat-led testing gets the attention because it is dramatic and expensive, and it applies to the institutions a regulator specifically names. Article 25 testing applies to almost every financial entity in the EU that is not a microenterprise, covers every system supporting a critical function, and comes round every single year.

That is the obligation most firms are actually carrying, and it is the one we are built to serve.

Next step

Bring us the requirement, we'll tell you honestly.

Send the clause, the auditor's question, or the security questionnaire that is holding up a deal. If we are the wrong answer we will say so, and usually point you somewhere better.

daniel@theosec.com · +27 63 484 1051