At the moment, we have two separate projects. One is to address application testing under 6.6, for which we are in discussions with a 3rd party and the second is for annual penetration testing for 11.3. For both we are relying on an experienced 3rd party to deliver, but don't the controls mean the same?