Overview
US engagements are run from our Sheridan, Wyoming office for SaaS platforms pursuing SOC 2, healthcare technology companies with HIPAA obligations, payment and fintech platforms under PCI DSS, and financial services firms with sector-specific testing mandates.
The deciding factor is usually timing rather than scope. Testing before a SOC 2 observation window opens means findings are closed inside the period; testing after it opens means they sit in the auditor’s sample as open items.
What drives testing here
Local drivers
- SOC 2
- Auditors request testing evidence under CC4.1 and CC7.1, and enterprise buyers ask whether it exists.
- PCI DSS
- Requirement 11.4 mandates annual internal, external and segmentation testing.
- HIPAA
- The Security Rule requires risk analysis and periodic technical evaluation for ePHI systems.
- Sector rules
- NYDFS Part 500 requires annual penetration testing for covered entities; the FTC Safeguards Rule imposes comparable expectations on non-bank financial institutions.
How engagements are delivered
Delivered from our Sheridan, Wyoming office on US business hours, with Karachi extending cover into the evening. Contracting and invoicing in USD.
Delivery model
- US office
- 80 N. Gould St, Sheridan, WY 82801
- Hours
- Mountain Time, with Karachi extending cover into the US evening
- Scheduling
- Readouts scheduled to Eastern, Central or Pacific hours
- Frameworks
- SOC 2, PCI DSS, HIPAA, NYDFS Part 500, FTC Safeguards
- Invoicing
- USD
Most requested here
Web application penetration testing
Authenticated, multi-role testing of your web application: the logic, the roles and the state transitions a scanner cannot reach.
Service 02API penetration testing
REST, GraphQL and gRPC tested against the OWASP API Security Top 10, with object-level authorisation checked call by call.
Service 04Cloud penetration testing
AWS, Azure and GCP tested for the paths that get used: identity escalation, exposed storage and metadata reachable from your own application.
Questions
When should we test relative to our SOC 2 audit?
Before the observation window opens for a Type II. Findings are then remediated and re-verified inside the period, so the auditor sees a closed loop rather than open items in the sample.
Does NYDFS Part 500 require annual penetration testing?
Yes, for covered entities, annual penetration testing plus regular vulnerability assessment, with the results reported to the governing body. Reports are structured for that reporting line.
Can you work with our US auditor directly?
Yes. An auditor-facing summary is produced as standard and direct clarification calls with your assessor are included at no extra cost, scheduled on US hours from our Wyoming office rather than asked to fit someone else’s timezone.
How much does a penetration test cost in the US?
Cost follows scope rather than a US rate card. Delivery from our Sheridan, Wyoming office means North American hours without North American consultancy pricing. A fixed quote follows a short scoping call.
Which is the best penetration testing company in the US?
No single name is an honest answer in a market this size. Ask who performs your test and what they personally hold, whether the firm holds ISO 27001 itself, whether retesting is included, and whether you can review a redacted report before signing.
How often should we test for SOC 2?
Annually, timed before your observation window opens so findings are remediated and re-verified inside the period rather than sitting open in the auditor's sample. For a Type II, timing matters more than anything else about the engagement.
Do you test for HIPAA covered entities and business associates?
Yes. The Security Rule is deliberately technology-neutral: it tells you to evaluate, not how. Testing is how the evaluation standard is satisfied with evidence, and the report is written so it can be filed against the relevant safeguards.
Can you meet US data residency requirements?
Handling and residency terms are agreed before testing starts, and our Wyoming office exists partly for this. Testing prefers seeded accounts and synthetic records, and the report states what was handled and where.