The AEOS (Authorized Economic Operator for Security) authorization certifies a company’s reliability within the international supply chain. The Customs Agency requires rigorous cybersecurity standards, verified through the Self-Assessment Questionnaire (SAQ) and on-site audits.
SAQ Requirement 3.7.1.b: Mandatory anti-intrusion tests
Section 3.7.1.b of the SAQ poses a direct question: has the operator conducted anti-intrusion tests? The response must include:
- Description of the tests performed
- Results obtained and vulnerabilities detected
- Corrective actions implemented
This requirement stems from Article 25, paragraph 1, letter j) of Implementing Regulation (EU) 2015/2447, which mandates the protection of the IT system from unauthorized access and manipulation. Firewalls and antivirus software are not enough: active verification that simulates the behavior of a real attacker is required.
How Network Penetration Testing meets AEOS requirements
The Network Penetration Testing verifies infrastructure resilience through attack simulations covering:
- External perimeter: identification of vulnerabilities in services exposed to the Internet
- Internal network: assessment of segmentation and access controls
- Mobile devices: security of laptops, smartphones, and remote staff connections
- Critical systems: protection of servers managing sensitive customs and corporate data
The tests follow recognized methodologies (OSSTMM, OWASP) and produce detailed documentation of the detected vulnerabilities, classified by severity and operational impact.
Documentation required for the customs audit
During the inspection visit, customs officials verify the correspondence between what is declared in the SAQ and actual conditions. The operator must present:
- Technical reports: complete documentation of the tests performed, with details of the vulnerabilities and methodologies used
- Remediation plan: evidence of the corrective actions implemented for each critical issue detected
- Continuous management process: demonstration of the ability to identify and resolve vulnerabilities over time
The documentation must be kept and updated. A structured approach to cybersecurity, supported by periodic Risk Assessments and compliance with standards such as ISO/IEC 27001, strengthens the operator’s position during the audit. To understand how to structure a security governance system compliant with AEOS requirements, it is essential to integrate penetration tests into a broader risk management framework.
Integration with other security controls
Network Penetration Testing is not an isolated activity. To maintain AEOS authorization over time, the operator must demonstrate an integrated approach that includes:
- Continuous Vulnerability Assessment: periodic scans to identify new vulnerabilities (Vulnerability Assessment)
- Patch management: a documented process for updating critical systems
- Access monitoring: logs and controls on access to sensitive customs data
- Staff training: awareness of cyber risks and security procedures
A structured vulnerability management process allows for keeping the critical issues that emerged during tests under control and demonstrating a proactive approach to cybersecurity to auditors.
FAQ – Network Penetration Test for AEOS
- Does the SAQ explicitly require anti-intrusion tests?
- Yes. Question 3.7.1.b asks if anti-intrusion tests have been performed and requires a description of the results. Failure to perform these tests represents a deficiency in the security standards required for AEOS authorization.
- How often should the tests be performed?
- The regulation does not establish a fixed interval, but the SAQ requires indicating the periodicity. Best practices suggest annual tests or whenever significant changes are made to the infrastructure. The frequency should be proportional to the level of risk and the complexity of the corporate network.
- What happens if critical vulnerabilities emerge?
- The identification of vulnerabilities does not preclude authorization, provided that the operator demonstrates that they have implemented documented corrective actions. It is essential to show a structured process for vulnerability management and continuous improvement.
- Should tests only cover the internal network?
- No. Security measures must protect the entire IT system: external perimeter, servers with corporate and customs data, mobile devices, and any point of access to the network. The audit verifies the end-to-end protection of the infrastructure.
- Are the results verified during the audit?
- Yes. During the inspection visit, customs officials physically verify the documentation related to penetration tests, detected vulnerabilities, and corrective actions. All procedures declared in the SAQ must be demonstrable with documentary evidence.
- Do I need an external provider or can I perform the tests internally?
- The regulation does not mandate the use of external providers, but the independence and competence of the testing team are elements that are positively evaluated. A specialized provider guarantees recognized methodologies, professional tools, and documentation compliant with the standards required by the customs audit.
Companies intending to obtain or maintain AEOS authorization must document all Network Penetration Testing activities in detail, providing evidence of the results and corrective actions, and demonstrating continuous management of technical vulnerabilities.
Related insights
- AEO certification and cybersecurity: requirements and the acquisition process
- Vulnerability management for AEOS operators
- Cybersecurity governance for AEOS
- AEO audit and vulnerability tests: what customs officials verify
- SOC monitoring and incident response for AEO operators
- Cybersecurity training for AEO personnel
Want to give your company the highest level of cyber security? ISGroup SRL is here to help with cyber security solutions tailored to your business.
Would you like us to take care of everything for you? Our Virtual CISO and vulnerability management services are a perfect fit for your organization.
Already know what you need? Explore our services:
- Vulnerability Assessment
- Network Penetration Testing
- Web Application Penetration Testing
- Mobile Application Security Testing
- Ethical Hacking
- Training
And much more. Protect your company with the best cybersecurity experts!
