Affordable Pentesting Logo
Social Engineering Testing Guide

Social Engineering Testing Guide

Social engineering pentesting — phishing, vishing, pretexting, and physical testing explained, plus compliance requirements and scoping.

2026-09-01

Technical controls alone cannot protect your organization. Human factors remain the leading cause of security breaches. Social engineering testing measures how your people respond to manipulation attempts — and it is increasingly required by compliance frameworks.

Types of social engineering testing

TypeDescriptionTypical methodology
Phishing simulationEmails designed to trick recipients into clicking or sharing credentialsCustom email templates, landing pages, tracking
Vishing (voice)Phone calls impersonating IT support, vendors, or executivesPre-written scripts, caller ID spoofing
Smishing (SMS)Text messages with malicious links or requestsSMS gateways, shortened URLs
PretextingCreating a fabricated scenario to extract informationIn-person or remote research
Physical testingAttempting to gain physical access to facilitiesTailgating, badge cloning, door checks

What social engineering testing measures

A well-designed social engineering test evaluates:

  • Awareness. Do employees recognize and report suspicious requests?
  • Policies. Are reporting procedures followed?
  • Technology. Do email filters, MFA, and physical security controls catch attempts?
  • Recovery. How quickly does the security team respond to reported incidents?

Compliance requirements

FrameworkSocial engineering requirement
PCI DSS v4.0Requirement 11.4 — includes social engineering controls testing
SOC 2Expected as part of security awareness testing
NIST 800-171Implied by personnel security and awareness training controls
ISO 27001Annex A.7.2 — security awareness, education, and training

Testing considerations

  • Get buy-in from leadership. Social engineering tests can create friction if employees feel tricked. Communicate the educational purpose clearly.
  • Set boundaries. Define what is off-limits — do not target specific individuals, do not cause panic, and have a clear stop condition.
  • Measure and improve. Track click rates, report rates, and time-to-report across tests to measure improvement.

Add social engineering to your testing program

Affordable Pentesting can integrate social engineering testing with your technical pentest program. Contact us to discuss your assessment needs or start with a technical pentest today.

Related reading: Manual vs AI Penetration Testing