Compliance penetration testing: what SOC 2, PCI DSS, HIPAA, ISO 27001 and DORA each require, and why continuous testing beats an annual certificate.