Social Engineering Testing Guide
Social engineering pentesting — phishing, vishing, pretexting, and physical testing explained, plus compliance requirements and scoping.
2026-09-01
Technical controls alone cannot protect your organization. Human factors remain the leading cause of security breaches. Social engineering testing measures how your people respond to manipulation attempts — and it is increasingly required by compliance frameworks.
Types of social engineering testing
| Type | Description | Typical methodology |
|---|---|---|
| Phishing simulation | Emails designed to trick recipients into clicking or sharing credentials | Custom email templates, landing pages, tracking |
| Vishing (voice) | Phone calls impersonating IT support, vendors, or executives | Pre-written scripts, caller ID spoofing |
| Smishing (SMS) | Text messages with malicious links or requests | SMS gateways, shortened URLs |
| Pretexting | Creating a fabricated scenario to extract information | In-person or remote research |
| Physical testing | Attempting to gain physical access to facilities | Tailgating, badge cloning, door checks |
What social engineering testing measures
A well-designed social engineering test evaluates:
- Awareness. Do employees recognize and report suspicious requests?
- Policies. Are reporting procedures followed?
- Technology. Do email filters, MFA, and physical security controls catch attempts?
- Recovery. How quickly does the security team respond to reported incidents?
Compliance requirements
| Framework | Social engineering requirement |
|---|---|
| PCI DSS v4.0 | Requirement 11.4 — includes social engineering controls testing |
| SOC 2 | Expected as part of security awareness testing |
| NIST 800-171 | Implied by personnel security and awareness training controls |
| ISO 27001 | Annex A.7.2 — security awareness, education, and training |
Testing considerations
- Get buy-in from leadership. Social engineering tests can create friction if employees feel tricked. Communicate the educational purpose clearly.
- Set boundaries. Define what is off-limits — do not target specific individuals, do not cause panic, and have a clear stop condition.
- Measure and improve. Track click rates, report rates, and time-to-report across tests to measure improvement.
Add social engineering to your testing program
Affordable Pentesting can integrate social engineering testing with your technical pentest program. Contact us to discuss your assessment needs or start with a technical pentest today.
Related reading: Manual vs AI Penetration Testing
